Polymarket Confirms User Account Hack Linked to Authentication Vulnerability

Polymarket states that a Magic Labs email login flaw enabled unauthorized access and asset theft, now patched with outreach to affected users underway.

Fact Check
The evidence from the provided sources consistently and strongly supports the statement. Several relevant sources from different crypto news platforms (Coinness, Cryptonomist, Bitget, RootData) all report on a security breach at Polymarket. There is no conflicting information among the relevant sources. Specifically, the two core claims of the statement are well-supported:1. **"Polymarket confirmed a user account hack..."**: One high-authority source explicitly states that Polymarket confirmed the breach and user losses in 'a statement on its official Discord,' pointing to a primary source confirmation from the company itself. This is corroborated by several other news snippets that also report the confirmation.2. **"...due to an authentication vulnerability."**: A high-authority source directly ties the breach to a vulnerability with a 'Third-Party Auth' service. Another source contains a news blurb that uses the exact phrase "third-party authentication vulnerability." This directly supports the stated cause of the hack.The irrelevant sources concerning Texas politics and CISA were correctly disregarded. The high degree of consistency across multiple, independent news outlets makes the reported information highly credible.
Summary

Polymarket has fixed a security issue caused by a vulnerability in Magic Labs, its third-party ID provider. Accounts using Magic Labs email login were accessed without authorization and saw funds stolen despite two-factor authentication. The flaw is now patched, and Polymarket is contacting victims. The company states there is no ongoing risk from the incident.

Terms & Concepts
  • Two-Factor Authentication: A security process requiring two different forms of identification to access an account, typically a password and a verification code.
  • Authentication Vulnerability: A weakness in authentication systems that could allow unauthorized access to user accounts.
  • Prediction Market Platform: An online service where participants trade shares based on outcomes of future events.