Polymarket hack losses rise to $3.1M as refund pledge faces scrutiny

0
0

Polymarket’s recent security breach has become more serious after new estimates showed that losses were higher than first reported.

Blockchain security firm AMLBot now estimates that hackers stole around $3.1 million from users during the attack. Earlier reports had placed the losses closer to $2.94 million.

According to AMLBot, the stolen funds came from 11 user wallets holding PUSD on the Polygon network. The attackers quickly moved the funds to Ethereum, making it more difficult to trace and recover the assets.

Polymarket previously confirmed that the incident was caused by a compromise involving a third-party service provider. The company said attackers were able to inject malicious code into parts of its website, exposing some users to fraudulent wallet prompts.

The platform stated that the problem was quickly identified and contained. The affected software dependency was removed, and Polymarket pledged to fully reimburse all users who lost funds in the attack.

Unlike attacks that target a blockchain protocol directly, this incident appears to have focused on the website interface, also known as the frontend. In these types of attacks, users may see what looks like a normal website while hidden malicious code generates harmful wallet approval requests.

Because the platform itself can appear legitimate, frontend attacks are often difficult for users to detect in real time.

Security researchers reported that the stolen assets were moved from Polygon to Ethereum and later converted into approximately 1,893 ETH. Investigators also found that the funds were consolidated into a single Ethereum wallet after the phishing operation.

The incident has once again highlighted the risks associated with third-party software and services. Even when a platform’s core smart contracts remain secure, vulnerabilities in external tools or website components can still expose users to significant risks.

This is not the first security issue linked to Polymarket. Earlier this year, blockchain investigator ZachXBT reported a suspected breach involving more than $520,000 from Polygon-based smart contracts, although Polymarket later said user funds remained safe in that case.

The company also dealt with security concerns in late 2025 after users reported suspicious activity involving its Discord community and account access attempts.

The latest breach comes during a period of growing concern about security across the crypto industry. According to previous reports, the second quarter of the year recorded one of the highest numbers of crypto-related security incidents on record.

At the same time, Polymarket is facing increased regulatory attention in the United States. Several lawmakers have recently called for closer scrutiny of prediction market platforms and questioned whether current regulations provide enough protection for users.

The company is also involved in broader legal debates surrounding prediction markets and event-based contracts, particularly those linked to sports outcomes. Regulators and state authorities continue to debate whether these products should be treated as financial contracts or as forms of gambling.

As investigations continue, the Polymarket incident serves as another reminder that security risks in the crypto industry extend beyond smart contracts and blockchains. Website infrastructure, third-party vendors, and user-facing applications can be just as important when it comes to protecting customer funds.