{"id":735511,"date":"2026-06-26T00:45:23","date_gmt":"2026-06-25T21:45:23","guid":{"rendered":"https:\/\/buradabiliyorum.com\/en\/polymarket-confirms-hackers-stole-3m-from-users-after-third-party-vendor-was-compromised\/"},"modified":"2026-06-26T00:45:23","modified_gmt":"2026-06-25T21:45:23","slug":"polymarket-confirms-hackers-stole-3m-from-users-after-third-party-vendor-was-compromised","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/polymarket-confirms-hackers-stole-3m-from-users-after-third-party-vendor-was-compromised\/","title":{"rendered":"Polymarket confirms hackers stole $3M from users after third-party vendor was compromised"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6a3dfb7c48d4e\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6a3dfb7c48d4e\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/polymarket-confirms-hackers-stole-3m-from-users-after-third-party-vendor-was-compromised\/#TLDR\" >TL;DR<\/a><\/li><\/ul><\/nav><\/div>\n<div id=\"article-main-content\">\n<div class=\"postContent-tldr\">\n<h4 class=\"postContent-offsetTitle\"><span class=\"ez-toc-section\" id=\"TLDR\"><\/span>TL;DR<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p><em>Hackers drained roughly three million dollars from Polymarket users via a compromised vendor that injected malicious code into its frontend.<\/em><\/p>\n<\/div>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/techcrunch.com\/2026\/06\/25\/polymarket-says-hackers-stole-users-funds\/\" target=\"_blank\" rel=\"nofollow noopener\">Polymarket confirmed on Thursday that hackers stole funds from users after a third-party vendor was compromised,<\/a> allowing malicious code to be injected into the prediction market\u2019s website. Blockchain monitoring firm PeckShield estimated the losses at roughly three million dollars worth of cryptocurrency, drained from more than 11 victims.<\/p>\n<p>The company said in a post on X that it had \u201c<em>contained<\/em>\u201d the incident and removed the affected dependency. Polymarket said it is contacting victims and \u201c<em>refunding them in full,<\/em>\u201d though it did not specify how many users were affected or name the compromised vendor.<\/p>\n<p>Polymarket spokesperson Connor Brandi confirmed to TechCrunch that the breach led to funds being stolen but declined to provide additional details. The company did not respond to specific questions about the incident.<\/p>\n<div class=\"inarticle-wrapper latest channel-cta hs-embed-tnw\">\n<div id=\"hs-embed-tnw\" class=\"channel-cta-wrapper\">\n<div class=\"channel-cta-img\"><img decoding=\"async\" class=\"js-lazy\" src=\"https:\/\/media.thenextweb.com\/hardfork-2018\/uploads\/visuals\/tnw-newsletter.png\"\/><\/div>\n<p><img decoding=\"async\" src=\"https:\/\/media.thenextweb.com\/hardfork-2018\/uploads\/visuals\/tnw-newsletter.png\"\/><\/p>\n<div class=\"channel-cta-input\">\n<p class=\"channel-cta-title\">The \ud83d\udc9c of EU tech<\/p>\n<p class=\"channel-cta-tagline\">The latest rumblings from the EU tech scene, a story from our wise ol&#8217; founder Boris, and some questionable AI art. It&#8217;s free, every week, in your inbox. Sign up now!<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>On-chain data reviewed by blockchain analyst Specter showed funds being drained from victim wallets holding PUSD, Polymarket\u2019s stablecoin. The stolen assets were rapidly bridged from Polygon to Ethereum and converted into roughly 1,893 ETH, a common tactic used by attackers to obscure the trail and liquidate funds quickly.<\/p>\n<p>The attack was a supply chain compromise rather than a direct breach of Polymarket\u2019s own infrastructure. A third-party vendor\u2019s code was tampered with, and the malicious <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">script<\/a> was served to some users through Polymarket\u2019s frontend. Users who interacted with the affected interface had their funds siphoned without the platform\u2019s core smart contracts being exploited.<\/p>\n<p>It is not the first time Polymarket\u2019s security has been tested this year. In May, blockchain investigator ZachXBT flagged a separate incident in which roughly $520,000 was drained from two smart contracts on the Polygon network. Polymarket said at the time that the losses stemmed from a compromised six-year-old private key tied to an internal operations wallet, not from a platform exploit.<\/p>\n<p>The hack caps what has been Polymarket\u2019s worst week. On Sunday, a Wall Street Journal investigation revealed that the company had paid online creators to post deceptive videos showing fabricated bets and fake winnings. The Journal reviewed more than 1,100 videos and found that none of the wagers, representing nearly two million dollars in displayed value, were placed on the live platform, prompting Polymarket to say it would audit its promotional content.<\/p>\n<p>The scandals arrive during a period of intensifying regulatory and legal pressure. A Google engineer was charged last month with insider trading after using internal search data to profit more than one million dollars on Polymarket. Spain blocked the platform in May over missing gambling licences, joining France, Belgium, Poland, Italy, and India in restricting access.<\/p>\n<p>Polymarket has also faced structural questions about its governance. A $345 million dispute over an Iran peace deal contract earlier this month exposed how just nine anonymous cryptocurrency wallets control more than half the voting power used to resolve contested outcomes on the platform.<\/p>\n<p>The company, founded by Shayne Coplan, became the dominant prediction market during the 2024 US presidential election and has continued to grow rapidly. Combined monthly trading volume across Polymarket and rival Kalshi quadrupled from under five billion dollars to 24 billion dollars between September 2025 and April 2026. Whether that growth trajectory survives a convergence of security failures, marketing fraud, and regulatory crackdowns is the question the company now faces.<\/p>\n<\/p><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMN63nwsw68G3Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" target=\"_blank\" >Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/thenextweb.com\/news\/polymarket-hack-3-million-stolen-third-party-breach\" target=\"_blank\" >Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TL;DR Hackers drained roughly three million dollars from Polymarket users via a compromised vendor that injected malicious code into its frontend. Polymarket confirmed on Thursday that hackers stole funds from users after a third-party vendor was compromised, allowing malicious code to be injected into the prediction market\u2019s website. Blockchain monitoring firm PeckShield estimated the losses&#8230;<\/p>\n","protected":false},"author":1,"featured_media":735512,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/media.thenextweb.com\/2026\/06\/polymarket-hack-3-million-stolen-third-party-breach.avif","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-735511","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/735511","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=735511"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/735511\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/735512"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=735511"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=735511"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=735511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}