Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Polymarket to refund users after $2.94M frontend phishing attack

    June 26, 2026

    WBTC relaunches on TRON, but abandoned version is bigger

    June 26, 2026

    The Ecosystem Support Program’s Next Chapter

    June 26, 2026
    Facebook X (Twitter) Instagram YouTube
    X (Twitter) Instagram YouTube LinkedIn
    Block Hub News
    • Lithosphere News Releases
    • Altcoins
      • Bitcoin
      • Coinbase
      • Litecoin
    • Crypto
    • Ethereum
    • Blockchain
    Block Hub News
    You are at:Home » Polymarket to refund users after $2.94M frontend phishing attack
    Crypto

    Polymarket to refund users after $2.94M frontend phishing attack

    James WilsonBy James WilsonJune 26, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Polymarket has confirmed that attackers compromised a third party vendor and used the access to inject malicious code into the platform’s frontend, leading to a phishing attack that drained an estimated $2.94 million from users.

    Summary

    • Polymarket said a third party vendor compromise enabled a phishing attack that stole about $2.94 million from at least 11 user wallets.
    • The platform removed the malicious dependency, contained the incident and said all affected users will receive full refunds.
    • DefiLlama recorded the attack as the 89th crypto security breach of the second quarter, the highest quarterly total by incident count on its records.

    Polymarket disclosed on X that it has removed the affected dependency, contained the incident, and will fully reimburse affected users. 

    This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our frontend for some users. We’ve contained it & removed the affected dependency. We’re contacting impacted users & refunding them in full.

    — Polymarket Traders (@PolymarketTrade) June 25, 2026

    Blockchain analyst Specter estimated that the attack drained funds from at least 11 wallets after the malicious script appeared on the platform’s frontend.

    It appears there may be a phishing attack targeting Polymarket users, with estimated losses of $2.94M so far.

    The attacker has drained funds from 11+ victim wallets holding PUSD, swapped the stolen assets for ETH, and consolidated the proceeds into the following address:… pic.twitter.com/6WfS0JhdDG

    — Specter (@SpecterAnalyst) June 25, 2026

    Frontend compromise targets user wallets

    Specter identified the attack as a phishing campaign rather than a protocol exploit. The analyst said the injected script enabled attackers to steal funds from connected wallets after users interacted with the compromised interface.

    DefiLlama recorded the incident as the 89th reported crypto security breach of the second quarter, making it the highest quarterly total by incident count in the platform’s records.

    DefiLlama also reported $74.9 million in losses across 29 crypto exploits during June. That total exceeded May’s $60.5 million but remained well below April’s $644 million.

    The platform listed the $36 million Humanity Protocol exploit as June’s largest attack. Other major incidents included a $4.7 million exploit involving the Secret Network bridge, two separate $2.1 million exploits affecting Aztec, and a $1.7 million bridge exploit on Taiko.

    DefiLlama reported that private key compromises accounted for 43% of exploit losses over the past 30 days. Fake proof exploits represented 10% of losses, while reverse MEV honeypots accounted for 8%.

    Previous exploit traced to compromised private key

    Polymarket disclosed a separate security incident about a month earlier after attackers exploited a six year old private key used for internal top up operations and stole about $600,000.

    Security researchers, including ZachXBT, PeckShield, and Bubblemaps, initially flagged suspicious activity involving Polymarket’s UMA CTF Adapter contract on Polygon. Bubblemaps reported that attackers withdrew 5,000 POL every 30 seconds before estimating total losses at roughly $600,000.

    Polymarket protocol contributor Shantikiran Chanal later attributed that incident to a compromised wallet used for internal operations rather than a vulnerability in the platform’s contracts or core infrastructure. 

    Josh Stevens, the company’s vice president of engineering, stated at the time that user funds and smart contracts remained secure and that all permissions linked to the compromised key had been revoked.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWBTC relaunches on TRON, but abandoned version is bigger
    James Wilson

    Related Posts

    FBI gives OneCoin victims final days to claim recovery funds

    June 26, 2026

    Tom Lee’s BitMine stakes 86% of ETH pile before Russell entry

    June 26, 2026

    BitGo cuts nearly 15% of staff as AI and stablecoins take priority

    June 26, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Polymarket to refund users after $2.94M frontend phishing attack

    June 26, 20260 Views

    WBTC relaunches on TRON, but abandoned version is bigger

    June 26, 20260 Views

    The Ecosystem Support Program’s Next Chapter

    June 26, 20260 Views

    FBI gives OneCoin victims final days to claim recovery funds

    June 26, 20260 Views
    Don't Miss

    Ondo joins DTCC tokenization working group for U.S. markets

    By James WilsonMay 4, 2026

    DTCC has formed a tokenization working group for U.S. markets and tapped Ondo alongside BlackRock,…

    dLocal Launches Stablecoin Payments

    April 27, 2026

    Crypto exchanges too slow to react to RAVE collapse, ZachXBT

    April 27, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    Demo
    X (Twitter) Instagram YouTube LinkedIn
    Our Picks

    Polymarket to refund users after $2.94M frontend phishing attack

    June 26, 2026

    WBTC relaunches on TRON, but abandoned version is bigger

    June 26, 2026

    The Ecosystem Support Program’s Next Chapter

    June 26, 2026
    Most Popular

    Ondo joins DTCC tokenization working group for U.S. markets

    May 4, 20266 Views

    dLocal Launches Stablecoin Payments

    April 27, 20265 Views

    Crypto exchanges too slow to react to RAVE collapse, ZachXBT

    April 27, 20265 Views
    © 2026 - 2026

    Type above and press Enter to search. Press Esc to cancel.