Polymarket updates hack loss to $3.1M, pledges full refunds to affected users
Polymarket, the decentralized prediction market that became a household name during the 2024 US election cycle, confirmed that a security breach on June 25 drained approximately $3.1 million in user funds. The platform has committed to making every affected user whole through full refunds.
The attack targeted Polymarket’s frontend through a compromised third-party vendor, meaning the platform’s core smart contracts were never actually breached. Between 11 and 15 wallets were impacted, with the stolen funds consisting primarily of pUSD, Polymarket’s USDC-backed stablecoin.
A supply-chain problem, not a protocol problem
Polymarket moved quickly to remove the affected dependency from its system and began contacting impacted users. On-chain analysts from PeckShield, SpecterAnalyst, and GoPlus Security tracked the stolen pUSD as it was swapped for ETH and consolidated into fewer wallets.
The company has emphasized that its underlying protocols remain secure.
Second breach in a month
This isn’t Polymarket’s first security incident this year. On May 22, a separate breach drained between $520,000 and $700,000 from an internal wallet on the Polygon network. That earlier attack was attributed to a suspected private key compromise, and Polymarket said at the time that user funds were not affected.
Two incidents in roughly five weeks paints a pattern that’s hard to ignore. The May breach hit internal funds. The June breach hit user funds. Different attack vectors, different targets, but the same platform finding itself on the wrong end of security failures at an uncomfortable frequency.
What this means for prediction market users and crypto investors
Supply-chain attacks are notoriously difficult to prevent because they exploit trust relationships with external vendors rather than flaws in a platform’s own code. Smart contract audits have become table stakes in the industry, with projects routinely commissioning multiple audit firms before launch. But frontend dependencies often receive far less scrutiny, despite being the layer that users actually interact with.
Regulatory implications also loom. Polymarket has already navigated complex regulatory waters, including a previous settlement with the CFTC. Repeated security breaches that result in user fund losses tend to attract the kind of regulatory attention that no crypto platform wants, particularly when the platform operates in a space that regulators are already watching closely.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
The US dollar weakens for the second consecutive month! Increased US Treasury repo raises policy concerns; Wall Street expects a further decline in September
The US dollar weakened for the second consecutive month in August. The US Treasury's plan to accelerate the repurchase of government bonds has led overseas investors to express new concerns about US policy direction, reviving market speculation that the Trump administration's policies may favor a weaker dollar.

Oxford Economics: Canada’s Economic Output May Drop 0.3% by 2027 as Retaliatory Tariffs Against U.S. Could Backfire
Oxford Economics warns that the new round of retaliatory tariffs against the US, scheduled to be implemented by Canada on September 8, may provide protection for some domestic manufacturers, but overall could cause more industries to face increased cost pressures and drag down Canada’s economic growth.

94% of Argentina peso crypto trading volume now stablecoins: a16z crypto
Strategy opposes MSCI plan to exclude MSTR from index, calls move discriminatory
