Polymarket supply-chain attack steals about $3 million after frontend dependency compromise

Polymarket supply-chain attack steals about $3 million after frontend dependency compromise

The prediction market raised its estimated losses to $3.1 million and said affected users will be fully refunded after malicious code was injected through a third-party frontend dependency.

ETH

Fact Check
The core claim is confirmed by Polymarket's own official statement (a third-party vendor compromise injected malicious JavaScript into the frontend, contained, dependency removed, refunds issued) and corroborated by multiple independent outlets. Cointelegraph and The Next Web report ~$2.94M-$3M stolen, and The Next Web confirms the stolen pUSD was bridged from Polygon to Ethereum and converted to ~1,893 ETH, matching the 'swapped into ETH' element. The main minor discrepancy is the affected-user count: the claim says 'roughly 15 users,' while reports cite 'at least 11' or 'over 11' victims. This is within the variance expected for an evolving incident and does not undermine the substance of the claim.
Summary

Polymarket said it contained a supply-chain attack after attackers injected malicious code into its frontend through a compromised third-party vendor or dependency. The prediction market updated the estimated losses to $3.1 million from roughly 15 user accounts and said affected users will be fully refunded. The stolen assets were initially in pUSD, a platform stablecoin, and were later converted into ETH and consolidated in a single wallet. The incident adds to concerns about security risks tied to external software vendors and dependencies, which can expose user funds even when a platform’s core systems are not directly breached, while also risking added regulatory scrutiny and pressure on user trust.

Terms & Concepts
  • supply-chain attack: A cyberattack carried out through a compromised outside vendor, service, or software dependency.
  • frontend: The user-facing website or application interface through which users interact with a platform.
  • dependency: A third-party software component used by an application that can introduce risk if compromised.