
The prediction market raised its estimated losses to $3.1 million and said affected users will be fully refunded after malicious code was injected through a third-party frontend dependency.
Polymarket said it contained a supply-chain attack after attackers injected malicious code into its frontend through a compromised third-party vendor or dependency. The prediction market updated the estimated losses to $3.1 million from roughly 15 user accounts and said affected users will be fully refunded. The stolen assets were initially in pUSD, a platform stablecoin, and were later converted into ETH and consolidated in a single wallet. The incident adds to concerns about security risks tied to external software vendors and dependencies, which can expose user funds even when a platform’s core systems are not directly breached, while also risking added regulatory scrutiny and pressure on user trust.