Attack Overview
On June 27, decentralized prediction market platform Polymarket fell victim to a phishing attack. Hackers drained approximately $3.1 million worth of PUSD (Polymarket's USD-pegged stablecoin) from 11 user wallets. According to blockchain intelligence firm AMLBot, the stolen funds were immediately bridged from Polygon to Ethereum mainnet after the exploit, complicating asset recovery efforts.
Fund Tracking and Impact
AMLBot reported that the attacker moved the pilfered PUSD across chains via a cross-chain bridge, and the flow of funds is still under investigation. The incident directly impacted 11 wallets but did not compromise Polymarket's core smart contracts, indicating the attack focused on duping users into signing malicious transactions or granting unauthorized allowances. The $3.1 million loss is moderate by DeFi phishing standards, but the stablecoin nature of PUSD results in a clear dollar-denominated impact.
Project Response and User Protection
Polymarket quickly responded by pledging full reimbursement to all affected users and collaborating with security teams and law enforcement to trace the funds. This proactive stance helps maintain community trust and prevent liquidity concerns. Users are strongly advised to review wallet approvals (e.g., using Revoke.cash), revoke suspicious contract permissions, and remain vigilant against unknown links or signature prompts.
Security Recommendations
Phishing attacks on DeFi platforms highlight the need for heightened user awareness. Best practices include: ① Avoid clicking unverified links, especially on social media or direct messages; ② Use hardware wallets or cold storage for large balances; ③ Regularly audit and revoke unnecessary token approvals; ④ Employ security tools (e.g., wallet guard extensions) to detect phishing sites. Polymarket will issue further security guidance and user advisories in the coming days.

