Incident case file
Sign in to watchPolymarket — Frontend Supply-Chain Phishing Drain
3 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatT-X (undisclosed): Third-party frontend vendor used by Polymarket is compromised; ingress method not publicly disclosed. T0 (morning of June 25, 2026, exact time undisclosed): Malicious JavaScript is served to a subset of Polymarket users via the compromised dependency, draining PUSD from connected wallets (11+ victims, fewer than 15 per Bubblemaps). T+hours: Analyst Specter is first to flag suspicious fund movement on X (June 25, 2026). T+same day: Polymarket confirms the breach via its official X account (@PolymarketTrade), states the affected dependency has been removed and the incident contained, and commits to full reimbursement of affected users. PeckShieldAlert corroborates the PUSD outflow and the ~$2.94M figure the same day. T+1 day (June 26, 2026): Continued media coverage and consolidation of the technical picture; this is the last documented activity for the incident as of report compilation. Stolen funds remain in 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD; no further movement or recovery confirmed.
Sources and coverage
- Articlecryip.cohttps://cryip.co/polymarket-frontend-hack-third-party-vendor-3-million-june-2026/
- Articlebitcoinfoundation.orghttps://bitcoinfoundation.org/news/prediction-markets/polymarket-hack/
- Articlethenextweb.comhttps://thenextweb.com/news/polymarket-hack-3-million-stolen-third-party-breach
- Articlecryptometer.iohttps://www.cryptometer.io/news/polymarket-frontend-hack-leads-to-3-million-in-user-losses/
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlex.comhttps://x.com/PolymarketTrade
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)