🧔♂️ A friendly human may check it before it goes live. More news here
Polymarket front-end hack drains $3.1m from 11 wallets
Blockchain intelligence firm AMLBot said on June 27 that hackers stole about US$3.1 million in PUSD from 11 user wallets on Polymarket, after malicious code from a compromised third-party vendor reached some users through its front end.
PUSD is Polymarket’s native collateral and settlement token for trading on the platform.
AMLBot said the assets were stolen on Polygon and immediately bridged to Ethereum.
Polymarket said on June 25 that it removed the affected dependency and would fully refund impacted users.
Security researchers described the breach as a front end supply chain attack rather than a smart contract or back end exploit, and Polymarket has not publicly identified the vendor.
The attack reportedly used hidden wallet approval prompts to route funds to attacker-controlled wallets, echoing a 2023 dependency compromise that affected more than 100 decentralized finance front ends.
It follows a March incident in which investigators said more than US$520,000 was drained from two Polygon smart contracts, though Polymarket said the funds were safe, and a December security incident tied to an unidentified third-party login provider.
🔗 Source: CoinDesk
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




