Attack Details
According to blockchain intelligence firm AMLBot, decentralized prediction market Polymarket was hit by a phishing attack on June 27, 2026. Hackers drained approximately $3.1 million worth of PUSD (Polymarket's native stablecoin) from 11 user wallets. The stolen funds were immediately bridged from the Polygon network to Ethereum, indicating the attackers' sophistication in evading on-chain tracing.
Project Response & Security Recommendations
Polymarket has announced full refunds for all affected users and is cooperating with security teams to track the stolen funds. Importantly, the attack did not exploit any vulnerability in Polymarket's protocol contracts; instead, it relied on phishing social engineering to trick users into signing malicious token approvals. Users are strongly advised to audit their wallet allowances, revoke any suspicious contract approvals using tools like Revoke.cash, and avoid clicking unknown links. This incident underscores the persistent threat of phishing in DeFi, where user-side security remains the weakest link. Even with robust smart contracts, end-user vigilance and proper wallet hygiene are critical to preventing asset loss.

