Attack Overview: $3.1M Lost in Phishing Incident
Polymarket, a leading decentralized prediction market platform, suffered a phishing attack that drained approximately $3.1 million worth of PUSD from 11 user wallets. Blockchain intelligence firm AMLBot detected that the stolen funds were immediately bridged from the Polygon chain to Ethereum mainnet, complicating recovery efforts. Polymarket has committed to fully reimbursing all affected users and is cooperating with investigators to trace the stolen assets.
Attack Details: Wallet Compromise, Not Protocol Bug
The incident did not exploit any vulnerability in Polymarket's smart contracts. Instead, attackers used phishing techniques to trick users into signing malicious transactions or revealing private keys, enabling direct theft of PUSD stablecoins. PUSD is Polymarket's native stablecoin used for oracle reports and settlement. The cross-chain transfer to Ethereum suggests the hacker plans to swap PUSD for ETH or other major assets via decentralized exchanges.
Response and Security Recommendations
Polymarket has vowed to fully refund all 11 victims, and is working with security firms and on-chain analytics teams to track and potentially recover the funds. The team advises all users to: revoke any suspicious contract approvals, use hardware wallets or isolated addresses for large holdings, and beware of unofficial links and fake domains. This incident highlights that users of DeFi platforms must remain vigilant against social engineering attacks, even when the underlying protocols are secure.
Market Impact and Broader Implications
The market reaction has been relatively muted, with Polymarket's PVOL token showing no significant price volatility, reflecting confidence in the platform's ability to cover losses. However, phishing attacks remain a persistent threat in the DeFi space, with multiple incidents in 2025 causing cumulative losses exceeding tens of millions of dollars. Users should regularly use tools like revoke.cash to audit and remove unnecessary token approvals and enable multifactor authentication where possible.

