HomeCoinsLitecoinPolymarket Third-Party Vendor Compromise Drains $2.9M from Users

Polymarket Third-Party Vendor Compromise Drains $2.9M from Users

A third-party vendor compromise discovered Thursday allowed attackers to inject a malicious script into Polymarket’s frontend, affecting multiple users.

Blockchain analyst Specter said the malicious script appeared to facilitate a phishing attack that drained an estimated $2.94 million from at least 11 Polymarket user wallets.

Polymarket said on X that the compromise has been contained and that the affected dependency has been removed. It added that users would be fully refunded.

Cointelegraph has approached Polymarket for comment but did not receive a response before publication.

The attack was the 89th reported crypto security breach of the second quarter, according to DefiLlama data, extending the most-hacked quarter on record by incident count.

Read More:  What happens when ChatGPT becomes the front door to crypto

Source: Specter

Crypto exploit losses reach $74.9M across 29 June incidents

Crypto exploit losses climbed to $74.9 million across 29 reported incidents in June, surpassing May’s $60.5 million total but remaining far below April’s $644 million, according to DefiLlama data.

Total value hacked by monthly sum, 1-year chart. Source: DefiLlama.

The largest June incidents included the $36 million Humanity Protocol exploit, the $4.7 million Secret Network bridge exploit, two separate Aztec exploits worth $2.1 million each and a $1.7 million bridge exploit on Taiko.

Read More:  Organizations Urge Congress to Ban Sports Betting on Prediction Markets in CLARITY Act

Related: About 60% of World Cup bettors on Polymarket are first-time crypto users

Over the past 30 days, private key compromises accounted for 43% of reported exploit losses, making them the leading attack vector, according to DefiLlama. Fake proof exploits accounted for 10%, followed by reverse MEV honeypots at 8%, which present deceptive trading opportunities to lure and manipulate automated trading bots.

About a month before Polymarket’s latest attack, the prediction market disclosed a separate $600,000 exploit that was traced to a six-year-old private key used for internal top-up operations. Josh Stevens, Polymarket’s vice president of engineering, said the platform’s contracts and user funds remained safe and that all permissions tied to the key had since been revoked.

Read More:  Bitcoin Falls To Key Support As New Headwinds Emerge

Total value hacked by technique over the past 30 days. Source: DefiLlama

Polymarket currently holds over $450 million in total value locked, up 301% from $112 million a year ago, according to DefiLlama.

Magazine: Should users be allowed to bet on war and death in prediction markets?

Facebook Comments Box

LATEST POSTS

Forget ETF flows, Bitcoin’s real threat is a hidden $39,900 liquidation wall

US spot Bitcoin ETFs took in roughly $999 million over seven straight days of inflows from July 14 to July 22, according to data from...

Australia Takes Telegram to Court Over Extremist Content

Telegram, the messaging platform used by more than 1 billion people worldwide, is facing a major legal challenge in Australia over claims that it failed...

Most Popular