A compromised third-party provider let attackers inject malicious code into Polymarket’s website interface, while the platform said it would reimburse affected users and the breach draws scrutiny from the CFTC.
Hack-related losses tied to Polymarket climbed to roughly $3.1 million after 11 wallets were affected in a phishing attack carried out through malicious code injected into the platform’s website interface. Polymarket said the breach stemmed from a compromised third-party service provider rather than its blockchain or smart contracts, and said it would fully reimburse impacted users. The incident highlights a broader shift in crypto security risks toward frontend infrastructure and software supply-chain attacks, even as the breach adds pressure on the prediction market and draws renewed attention from the CFTC, the U.S. derivatives regulator.