← Radar

Incident case file

Sign in to watch

Polymarket — Frontend Supply-Chain Phishing Drain

Incident date June 25, 2026

2 views

ContainedPolygon → EthereumFrontend supply-chain attack (third-party vendor compromise)Cluster: POLY-FE-2026-06

Estimated loss

$2.9M

Victims identified

11
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: Consolidation address (confirmed via Etherscan + analyst Specter): 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD (holds ~1,892.92 ETH, ≈$2.92M). Staging wallets: 0xC771A30a7c1aCA828eeEF7B822ac864a64cBaAe2; 0xC44F2Ca6B30A54d17a62ceF8FAdaF2e8C8632eC4; 0x10366AdBB5C4101A65C840Da6639546179C5A107; 0x7BCECe0d8fd92ECCf39Bc35242c6D9aAc0aA75A6.

Funds moved to: Stolen PUSD (Polymarket's stablecoin) bridged from Polygon to Ethereum and swapped into ETH, consolidated at 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD. Incoming transfer batches into the consolidation address: 138.7 / 832.8 / 114 / 210 / 272 / 325.4 ETH. Funds remained in the attacker wallet as of report date (no further movement confirmed). Polymarket publicly committed to fully refund all affected users from company treasury, independent of fund recovery.
A third-party vendor providing a frontend dependency was compromised, allowing injection of a malicious script into Polymarket's frontend for a subset of users. The script targeted holders of PUSD specifically. Polymarket's core smart contracts were not affected — this is a supply-chain / frontend compromise, not a contract exploit. Official statement (@PolymarketTrade, June 25, 2026): 'This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our fr

Timeline: T-X (undisclosed): Third-party frontend vendor used by Polymarket is compromised; ingress method not publicly disclosed. T0 (morning of June 25, 2026, exact time undisclosed): Malicious JavaScript is served to a subset of Polymarket users via the compromised dependency, draining PUSD from connected wallets (11+ victims, fewer than 15 per Bubblemaps). T+hours: Analyst Specter is first to flag suspicious fund movement on X (June 25, 2026). T+same day: Polymarket confirms the breach via its official X account (@PolymarketTrade), states the affected dependency has been removed and the incident contained, and commits to full reimbursement of affected users. PeckShieldAlert corroborates the PUSD outflow and the ~$2.94M figure the same day. T+1 day (June 26, 2026): Continued media coverage and consolidation of the technical picture; this is the last documented activity for the incident as of report compilation. Stolen funds remain in 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD; no further movement or recovery confirmed.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)