← Radar

Incident case file

Sign in to watch

Polymarket — Frontend Supply-Chain Phishing Drain

Incident date 2026-06-24

3 views

ContainedPolygon → EthereumFrontend supply-chain attack (third-party vendor compromise)Cluster: POLY-FE-2026-06

Estimated loss

$2.9M

Victims identified

11
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

Consolidation address (confirmed via Etherscan + analyst Specter): 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD (holds ~1,892.92 ETH, ≈$2.92M). Staging wallets: 0xC771A30a7c1aCA828eeEF7B822ac864a64cBaAe2; 0xC44F2Ca6B30A54d17a62ceF8FAdaF2e8C8632eC4; 0x10366AdBB5C4101A65C840Da6639546179C5A107; 0x7BCECe0d8fd92ECCf39Bc35242c6D9aAc0aA75A6.

Funds moved to

Stolen PUSD (Polymarket's stablecoin) bridged from Polygon to Ethereum and swapped into ETH, consolidated at 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD. Incoming transfer batches into the consolidation address: 138.7 / 832.8 / 114 / 210 / 272 / 325.4 ETH. Funds remained in the attacker wallet as of report date (no further movement confirmed). Polymarket publicly committed to fully refund all affected users from company treasury, independent of fund recovery.

Linked

A third-party vendor providing a frontend dependency was compromised, allowing injection of a malicious script into Polymarket's frontend for a subset of users. The script targeted holders of PUSD specifically. Polymarket's core smart contracts were not affected — this is a supply-chain / frontend compromise, not a contract exploit. Official statement (@PolymarketTrade, June 25, 2026): 'This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our fr

Chronology

1 beat
  1. T-X (undisclosed): Third-party frontend vendor used by Polymarket is compromised; ingress method not publicly disclosed. T0 (morning of June 25, 2026, exact time undisclosed): Malicious JavaScript is served to a subset of Polymarket users via the compromised dependency, draining PUSD from connected wallets (11+ victims, fewer than 15 per Bubblemaps). T+hours: Analyst Specter is first to flag suspicious fund movement on X (June 25, 2026). T+same day: Polymarket confirms the breach via its official X account (@PolymarketTrade), states the affected dependency has been removed and the incident contained, and commits to full reimbursement of affected users. PeckShieldAlert corroborates the PUSD outflow and the ~$2.94M figure the same day. T+1 day (June 26, 2026): Continued media coverage and consolidation of the technical picture; this is the last documented activity for the incident as of report compilation. Stolen funds remain in 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD; no further movement or recovery confirmed.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)