Polymarket Users Hit by Phishing Attack: Estimated Loss of $2.94 Million, Multiple Addresses Identified by Specter

Polymarket Users Hit by Phishing Attack: Estimated Loss of $2.94 Million, Multiple Addresses Identified by Specter

N
News Editor
2026-06-25 14:30:43
Blockchain analytics account Specter disclosed a suspected phishing attack on Polymarket, with estimated losses of $2.94 million. The attacker drained funds from over 11 wallets holding PUSD, converted the assets to ETH, and consolidated them into one address. Specter also revealed four additional related theft addresses and urged users to stay vigilant, review wallet permissions, and guard against such security threats.
Polymarketphishingsecurity incidentonchain analysiscryptocurrencyasset securityscamSpecter

Incident Overview

On June 25, 2026, blockchain analytics account Specter took to social media to disclose a suspected phishing attack on the popular prediction market platform Polymarket. Preliminary estimates indicate that funds from at least 11 wallets were compromised, with total losses reaching $2.94 million. The affected wallets held PUSD, the dollar-pegged stablecoin used on Polymarket for settling prediction bets. The attacker gained unauthorized access through phishing techniques, swiftly converted the stolen PUSD into ETH, and consolidated the funds into a single on-chain address in an attempt to obfuscate the flow of assets.

Polymarket is an Ethereum-based prediction market where users wager on outcomes of real-world events using PUSD. Given the high volume of fund flows, such platforms are frequent targets for phishing attacks. Following the incident, Specter promptly issued a warning to help the community identify the threat.

Attack Details and Related Addresses

According to Specter’s analysis, the attacker likely used fake website links or malicious smart contract approval requests to trick users into signing transactions or granting token transfer permissions. Once authorized, the attacker drained all PUSD from the victims’ wallets, converted them to ETH, and transferred the ETH in multiple batches to a single destination address—a tactic designed to evade on-chain tracking.

In addition to the main consolidation address, Specter also disclosed four other addresses suspected of being involved in the theft. These addresses may belong to the same attacker or serve as temporary wallets for intermediate transfers. The community is encouraged to monitor these addresses to track the attacker’s next moves. Specter also urged other Polymarket users to check their wallets for any suspicious approvals and revoke questionable contracts immediately.

Security Reminders and Recommendations

Specter advised all Polymarket users to remain vigilant, immediately review their wallet approval records and recent transaction signatures, and avoid clicking on any suspicious links or signing unknown smart contract calls. He also recommended limiting the allowance granted to each contract to only the minimum required for the current transaction, and regularly revoking authorizations that are no longer needed.

For all cryptocurrency holders, this incident underscores the critical importance of private key management and approval security. Hardware wallets are a reliable option for storing large amounts of assets, and users should develop a habit of periodically auditing their approvals. As of now, Polymarket’s official team has not released a public statement regarding the incident, but users can take the above measures on their own to mitigate the risk of asset loss.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.