{"id":10230,"date":"2026-06-26T08:27:44","date_gmt":"2026-06-26T08:27:44","guid":{"rendered":"https:\/\/cryptonews.uk.com\/?p=10230"},"modified":"2026-06-26T08:27:44","modified_gmt":"2026-06-26T08:27:44","slug":"polymarket-vendor-breach-opens-door-for-3m-crypto-heist","status":"publish","type":"post","link":"https:\/\/cryptonews.uk.com\/?p=10230","title":{"rendered":"Polymarket Vendor Breach Opens Door for $3M Crypto Heist"},"content":{"rendered":"<p><\/p>\n<div>\n<div id=\"blockquote-block_df213af31b95bb8a2ef1a53ba966be41\" class=\"blockquote-container\" style=\"border-color: #5100fc\">\n<div class=\"blockquote-text\">\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A compromised third-party vendor let attackers inject malicious code into Polymarket\u2019s front-end, draining about US$3 million (AU$4.35 million) in user funds.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">On-chain investigators at Bubblemaps found fewer than 15 accounts were affected, with the attackers converting stolen funds into roughly 1,893 ETH.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Polymarket pledged to refund impacted customers in full and said the front-end issue had been contained, but declined to name the breached vendor.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>Polymarket confirmed Thursday that a hack on one of its third-party vendors allowed attackers to inject malicious code into the prediction market\u2019s front-end, draining roughly US$3 million (AU$4.35 million) in user funds before the company contained the breach.<\/p>\n<p>The attack did not target Polymarket\u2019s smart contracts. Instead, the compromised vendor served a malicious script to some users\u2019 browsers, which accessed their wallets and drained pUSD, the platform\u2019s USDC-backed stablecoin used to settle all trades.\u00a0<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our frontend for some users. We&#8217;ve contained it &amp; removed the affected dependency. We&#8217;re contacting impacted users &amp; refunding them in full.<\/p>\n<p>\u2014 Polymarket Traders (@PolymarketTrade) June 25, 2026<\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The attackers then bridged the stolen funds from Polygon to Ethereum and swapped them into about 1,893 ETH, consolidating the proceeds in a single wallet in a common move to obscure the trail and liquidate quickly.\u00a0<\/p>\n<p>Because the malicious code lived in the website rather than the blockchain, affected users had little way to detect that the interface they trusted had been tampered with.<\/p>\n<p><strong>Related: Senate Democrats Demand Probe Into Trump Family Crypto Venture\u2019s UAE Links<\/strong><\/p>\n<h2 class=\"wp-block-heading\" id=\"h-damage-contained\">Damage Contained<\/h2>\n<p>On-chain investigators at Bubblemaps concluded the damage was largely contained, with fewer than 15 user accounts affected.\u00a0<\/p>\n<p>Polymarket said it would refund impacted customers in full and confirmed the front-end issue had been contained and the affected dependency removed. The limited account count suggests the malicious script reached only a subset of users before the company caught and pulled it.<\/p>\n<p>The company declined to name the compromised vendor or comment further, leaving open questions about how the supply-chain weakness was introduced and whether other platforms relying on the same provider could be exposed.<\/p>\n<p>The breach was Polymarket\u2019s second in two months. In May, a wallet exploit involving compromised employee credentials led to about US$700,000 (AU$1.02 million) in losses, attributed to a private-key compromise rather than a website flaw.<\/p>\n<p>Together, the two episodes point to operational and third-party risk rather than weaknesses in the underlying protocol.\u00a0<\/p>\n<p>Front-end and supply-chain attacks bypass audited smart contracts entirely, striking the website layer and outside dependencies that users rarely scrutinise, a vector that has become an increasingly attractive target as on-chain code itself grows harder to crack.\u00a0<\/p>\n<p><strong>Read more: Australian Crypto Unicorn Immutable Scales Back Game Development in AI Pivot\u00a0\u00a0<\/strong><\/p>\n<\/p><\/div>\n<p>Crypto Heists,Polymarket#Polymarket #Vendor #Breach #Opens #Door #Crypto #Heist1782462463<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A compromised third-party vendor let attackers inject malicious code into Polymarket\u2019s front-end, draining about US$3 million (AU$4.35 million) in user funds. On-chain investigators at Bubblemaps found fewer than 15 accounts were affected, with the attackers converting stolen funds into roughly 1,893 ETH. Polymarket pledged to refund impacted customers in full and said the front-end issue<\/p>\n","protected":false},"author":1,"featured_media":10231,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[423,62,835,3373,815,792,5163],"class_list":["post-10230","post","type-post","status-publish","format-standard","has-post-thumbnail","category-bitcoin","tag-breach","tag-crypto","tag-door","tag-heist","tag-opens","tag-polymarket","tag-vendor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.6 (Yoast SEO v26.6) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Polymarket Vendor Breach Opens Door for $3M Crypto Heist - Crypto News: Latest Cryptocurrency News and Analysis<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.uk.com\/?p=10230\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Polymarket Vendor Breach Opens Door for $3M Crypto Heist\" \/>\n<meta property=\"og:description\" content=\"A compromised third-party vendor let attackers inject malicious code into Polymarket\u2019s front-end, draining about US$3 million (AU$4.35 million) in user funds. On-chain investigators at Bubblemaps found fewer than 15 accounts were affected, with the attackers converting stolen funds into roughly 1,893 ETH. Polymarket pledged to refund impacted customers in full and said the front-end issue\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.uk.com\/?p=10230\" \/>\n<meta property=\"og:site_name\" content=\"Crypto News: Latest Cryptocurrency News and Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-26T08:27:44+00:00\" \/>\n<meta name=\"author\" content=\"\u884c\u653f\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u884c\u653f\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=10230\",\"url\":\"https:\/\/cryptonews.uk.com\/?p=10230\",\"name\":\"Polymarket Vendor Breach Opens Door for $3M Crypto Heist - Crypto News: Latest Cryptocurrency News and Analysis\",\"isPartOf\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=10230#primaryimage\"},\"image\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=10230#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/06\/polymarket-breach-vendor.jpg\",\"datePublished\":\"2026-06-26T08:27:44+00:00\",\"author\":{\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\"},\"breadcrumb\":{\"@id\":\"https:\/\/cryptonews.uk.com\/?p=10230#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cryptonews.uk.com\/?p=10230\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=10230#primaryimage\",\"url\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/06\/polymarket-breach-vendor.jpg\",\"contentUrl\":\"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/06\/polymarket-breach-vendor.jpg\",\"width\":1920,\"height\":1080},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cryptonews.uk.com\/?p=10230#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cryptonews.uk.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Polymarket Vendor Breach Opens Door for $3M Crypto Heist\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cryptonews.uk.com\/#website\",\"url\":\"https:\/\/cryptonews.uk.com\/\",\"name\":\"Crypto News: Latest Cryptocurrency News and Analysis\",\"description\":\"Latest Crypto &amp; Bitcoin News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/cryptonews.uk.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf\",\"name\":\"\u884c\u653f\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g\",\"caption\":\"\u884c\u653f\"},\"sameAs\":[\"http:\/\/demo3.aiwalls.com\/coinbase\"],\"url\":\"https:\/\/cryptonews.uk.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Polymarket Vendor Breach Opens Door for $3M Crypto Heist - Crypto News: Latest Cryptocurrency News and Analysis","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.uk.com\/?p=10230","og_locale":"en_US","og_type":"article","og_title":"Polymarket Vendor Breach Opens Door for $3M Crypto Heist","og_description":"A compromised third-party vendor let attackers inject malicious code into Polymarket\u2019s front-end, draining about US$3 million (AU$4.35 million) in user funds. On-chain investigators at Bubblemaps found fewer than 15 accounts were affected, with the attackers converting stolen funds into roughly 1,893 ETH. Polymarket pledged to refund impacted customers in full and said the front-end issue","og_url":"https:\/\/cryptonews.uk.com\/?p=10230","og_site_name":"Crypto News: Latest Cryptocurrency News and Analysis","article_published_time":"2026-06-26T08:27:44+00:00","author":"\u884c\u653f","twitter_card":"summary_large_image","twitter_misc":{"Written by":"\u884c\u653f","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/cryptonews.uk.com\/?p=10230","url":"https:\/\/cryptonews.uk.com\/?p=10230","name":"Polymarket Vendor Breach Opens Door for $3M Crypto Heist - Crypto News: Latest Cryptocurrency News and Analysis","isPartOf":{"@id":"https:\/\/cryptonews.uk.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.uk.com\/?p=10230#primaryimage"},"image":{"@id":"https:\/\/cryptonews.uk.com\/?p=10230#primaryimage"},"thumbnailUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/06\/polymarket-breach-vendor.jpg","datePublished":"2026-06-26T08:27:44+00:00","author":{"@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf"},"breadcrumb":{"@id":"https:\/\/cryptonews.uk.com\/?p=10230#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.uk.com\/?p=10230"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/?p=10230#primaryimage","url":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/06\/polymarket-breach-vendor.jpg","contentUrl":"https:\/\/cryptonews.uk.com\/wp-content\/uploads\/2026\/06\/polymarket-breach-vendor.jpg","width":1920,"height":1080},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.uk.com\/?p=10230#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.uk.com\/"},{"@type":"ListItem","position":2,"name":"Polymarket Vendor Breach Opens Door for $3M Crypto Heist"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.uk.com\/#website","url":"https:\/\/cryptonews.uk.com\/","name":"Crypto News: Latest Cryptocurrency News and Analysis","description":"Latest Crypto &amp; Bitcoin News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.uk.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/822778c5844e0d16d43dce6630f4f1bf","name":"\u884c\u653f","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cryptonews.uk.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e4c2d23409b09e004cef3facbe677e95c5401f9e29680f3a311e0130c5748089?s=96&d=mm&r=g","caption":"\u884c\u653f"},"sameAs":["http:\/\/demo3.aiwalls.com\/coinbase"],"url":"https:\/\/cryptonews.uk.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/10230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10230"}],"version-history":[{"count":0,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/posts\/10230\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=\/wp\/v2\/media\/10231"}],"wp:attachment":[{"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10230"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10230"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.uk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}