TradeRadarNews
crypto

Polymarket Hack Losses Soar to $3.1M Amid Refund Promises

Polymarket's hack losses jump to £3.1 million, days after pledging full refunds. The platform faces a federal probe and ongoing security issues.

TradeRadarNews Australia Editorial
Polymarket Hack Losses Soar to $3.1M Amid Refund Promises
Prediction market giant Polymarket is facing increased scrutiny as the estimated losses from a recent cyberattack have escalated to approximately $3.1 million. This updated figure comes just days after the platform publicly assured users of full refunds for their compromised funds. The incident, where hackers allegedly siphoned PUSD tokens from 11 user wallets on the Polygon network and subsequently transferred them to Ethereum, has been confirmed by blockchain intelligence firm AMLBot. Polymarket attributed the breach to a compromised third-party vendor, stating that a malicious script was injected into its frontend. The company has since rectified the vulnerability, removed the offending dependency, and reiterated its commitment to fully reimburse affected PUSD token holders. This phishing attack marks another blow for Polymarket, following a series of security setbacks and amidst ongoing reports of a federal investigation into the platform’s marketing practices, which are alleged to be false or deceptive. AMLBot, a key blockchain intelligence firm, updated its assessment on Saturday, confirming the theft of roughly $3.1 million in PUSD from 11 user accounts. The firm detailed that the assets were swiftly moved from Polygon and bridged to the Ethereum blockchain, and AMLBot continues to monitor Polymarket's accounts for further activity. Polymarket had not yet responded to requests for comment by Saturday morning US time. Immediately following the public disclosure of the attack, Polymarket swiftly pledged full refunds to all victims holding its native collateral and settlement token, PUSD. This token is integral to all trading activities on the decentralised prediction platform. In an official communication on X (formerly Twitter) on Thursday, Polymarket stated: "This morning we discovered a third-party vendor had been compromised, injecting a malicious script into our frontend for some users. We've contained it and removed the affected dependency. We're contacting impacted users and refunding them in full." Blockchain security firm PeckShield also reported on Thursday via X that a sophisticated phishing campaign had targeted Polymarket users. Initial estimations from PeckShield suggested the attackers had bridged approximately 1,893 ETH in stolen funds. Specter Analyst, another blockchain intelligence platform, corroborated these reports on Thursday, indicating estimated losses of around $2.94 million from what appeared to be a phishing attack targeting Polymarket users. One affected user, identified as Ash, publicly shared their experience on X, detailing that their wallet had been compromised without prior knowledge. Ash also disclosed both their own and the attacker's wallet addresses, providing crucial transparency into the incident. This latest security breach adds to Polymarket's growing list of recent incidents. In March, blockchain investigator ZachXBT brought attention to a suspected security breach where over $520,000 was reportedly drained from two smart contracts on the Polygon blockchain. At that time, Polymarket maintained that the funds were secure. Furthermore, in December, the platform acknowledged a security incident on its Discord channel after numerous users reported missing funds and suspicious activity.