Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ripple IPO and XRP holders: what you would get

    June 28, 2026

    Fears of $27M Venus Protocol hack turn out to be phishing attack on power user

    June 28, 2026

    Ethereum Foundation Board of Directors Update

    June 28, 2026
    Facebook X (Twitter) Instagram
    Cryptify Now
    • Home
    • Features
      • Typography
      • Contact
      • View All On Demos
    • Typography
    • Buy Now
    X (Twitter) Instagram YouTube LinkedIn
    Cryptify Now
    You are at:Home » Polymarket hack losses rise to $3.1M as refund pledge faces scrutiny
    Crypto

    Polymarket hack losses rise to $3.1M as refund pledge faces scrutiny

    James WilsonBy James WilsonJune 28, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Polymarket’s latest security incident has grown larger after blockchain intelligence firm AMLBot updated the estimated losses to about $3.1 million.

    Summary

    • Polymarket’s frontend phishing attack now shows $3.1 million in losses across 11 user wallets.
    • The platform says a compromised third-party vendor injected malicious code into parts of its frontend.
    • The refund pledge comes as lawmakers press regulators over alleged deceptive prediction market advertising practices.

    The prediction market platform had earlier promised to refund affected users after saying a third-party vendor compromise allowed malicious code to reach some users through its frontend.

    Hack losses rise to $3.1M

    AMLBot said hackers stole about $3.1 million in PUSD from 11 user wallets. The firm said the funds were taken from Polygon and quickly bridged to Ethereum.

    Polymarket Under Attack

    Polymarket users were drained of ~$3.1M in PUSD on Polygon via phishing / malicious EIP-7702 delegated execution.

    Funds were converted to USDC.e via Relay, bridged to Ethereum, swapped to ETH, and consolidated at… pic.twitter.com/bG3GYZZ1D9

    — AMLBot (@AMLBotHQ) June 27, 2026

    The update raises the loss figure from earlier estimates near $2.94 million. Specter Analyst had first flagged the attack as a phishing campaign that drained funds from at least 11 wallets holding PUSD.

    Polymarket said in a June 25 post that it found a third-party vendor had been compromised. The company said the vendor issue allowed attackers to inject a malicious script into the platform’s frontend for some users.

    “We’ve contained it & removed the affected dependency.” It also said it was contacting affected users and “refunding them in full,” the platform said.

    Frontend attack targeted user wallets

    The attack appears to have targeted users through the website interface rather than the core protocol. That type of attack can trick users into approving harmful wallet activity while they believe they are using the normal platform.

    PeckShield said the attacker bridged stolen funds from Polygon to Ethereum and swapped them into about 1,893 ETH. Specter also said the funds were consolidated into an Ethereum address after the phishing activity.

    A frontend attack can be difficult for users to detect in real time. The site may look normal, but the code loaded in the browser can create unsafe wallet prompts.

    The incident also puts focus on third-party dependencies. Even if a platform’s smart contracts remain unchanged, outside code used in a website can create risk for users who connect wallets.

    Earlier incidents add pressure

    The latest incident follows other Polymarket security issues. In March, blockchain investigator ZachXBT flagged a suspected breach after more than $520,000 was reportedly drained from two Polygon smart contracts.

    Polymarket later said funds were safe in that case. In December, the platform also confirmed an incident on its Discord channel after users reported missing funds and suspicious login attempts.

    A previous report said the latest attack was recorded by DefiLlama as the 89th crypto security breach of the second quarter. The same report said that count made the quarter the highest on record by number of reported incidents.

    The growing incident count shows why platforms now face closer checks across smart contracts, wallets, login systems, frontend code and outside vendors.

    Regulatory scrutiny widens

    The hack also arrives as Polymarket faces new regulatory attention. A recent report said U.S. Senators Adam Schiff and John Curtis urged the CFTC to review allegations tied to deceptive advertising practices.

    The senators asked whether Polymarket promoted markets through simulated trading websites, staged transactions and undisclosed paid influencer campaigns. They also questioned whether the CFTC has enough tools to oversee prediction markets and protect users.

    Polymarket and Kalshi are also part of a wider legal fight over sports event contracts. Kentucky has accused prediction market firms of offering unlicensed sports betting, while the CFTC has argued that federally regulated event contracts fall under its authority.

    As previously reported, the cases may help decide whether sports-linked prediction markets answer mainly to federal derivatives rules or state gambling laws.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleStarknet stutters, turns off and on again twice in one day
    Next Article Ethereum Foundation Board of Directors Update
    James Wilson

    Related Posts

    Ripple IPO and XRP holders: what you would get

    June 28, 2026

    Tether brings $23B gold push into crypto-backed loans

    June 28, 2026

    XRP holds near $1 as ETF inflows and on-chain activity rise

    June 28, 2026
    Leave A Reply Cancel Reply

    Top Posts

    The Ethereum Launch Process | Ethereum Foundation Blog

    April 29, 2026

    Exclusive: Burwick Law chief reveals vision for New York

    April 29, 2026

    Crypto presale strength, market news, and the best crypto to invest in now 

    April 29, 2026

    Top Crypto Compliance Frameworks Worldwide

    April 29, 2026
    Don't Miss

    Ripple IPO and XRP holders: what you would get

    By James WilsonJune 28, 2026

    Brad Garlinghouse said one word, “maybe,” and the XRP community heard a promise. Asked whether…

    Fears of $27M Venus Protocol hack turn out to be phishing attack on power user

    June 28, 2026

    Ethereum Foundation Board of Directors Update

    June 28, 2026

    Polymarket hack losses rise to $3.1M as refund pledge faces scrutiny

    June 28, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    About Us
    About Us

    CryptifyNow: Your daily source for the latest insights, news, and analysis in the ever-evolving world of cryptocurrency.

    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Ripple IPO and XRP holders: what you would get

    June 28, 2026

    Fears of $27M Venus Protocol hack turn out to be phishing attack on power user

    June 28, 2026

    Ethereum Foundation Board of Directors Update

    June 28, 2026
    Lithosphere News Releases

    Lithosphere Integrates AI Mock Providers for Continuous Integration Workflows

    April 30, 2026

    Lithosphere Deploys Full-Stack Development Environment for AI-Native Applications

    May 1, 2026

    AGII Introduces Scalable AI Execution Layer for Decentralized Systems

    May 1, 2026
    Copyright © 2026

    Type above and press Enter to search. Press Esc to cancel.