Polymarket disclosed on X that attackers compromised a third-party vendor and injected malicious code into the platform's frontend, triggering a phishing attack that drained approximately $2.94 million from at least 11 user wallets. The platform said it has removed the affected dependency, contained the incident, and will fully reimburse all affected users.
Vendor compromise triggered front-end phishing
Blockchain analyst Specter identified the attack as a phishing campaign rather than a protocol exploit. The injected script allowed attackers to drain funds from connected wallets after users interacted with the compromised interface. Polymarket confirmed that the malicious dependency was removed and the incident is contained. Josh Stevens, the company's vice president of engineering, had previously stated that user funds and smart contracts remained secure after a separate private key incident.
Attack details and user refunds
Specter estimated that at least 11 wallets were drained. Polymarket pledged full refunds but did not disclose whether any funds were recovered. DefiLlama recorded the incident as the 89th reported crypto security breach of Q2 2025, making it the highest quarterly total by incident count on the platform's records.
On-chain security incidents hit quarterly record
DefiLlama also reported $74.9 million in losses across 29 crypto exploits in June, up from May's $60.5 million but far below April's $644 million. The largest June attack was the $36 million Humanity Protocol exploit. Other major incidents included a $4.7 million Secret Network bridge exploit, two separate $2.1 million Aztec exploits, and a $1.7 million Taiko bridge exploit. DefiLlama noted that private key compromises accounted for 43% of exploit losses over the past 30 days, fake proof exploits 10%, and reverse MEV honeypots 8%.
Previous private key exploit
About a month earlier, Polymarket suffered a separate incident where attackers exploited a six-year-old private key used for internal top-up operations, stealing roughly $600,000. Security researchers including ZachXBT, PeckShield, and Bubblemaps flagged suspicious activity involving Polymarket's UMA CTF Adapter contract on Polygon. Bubblemaps reported attackers withdrew 5,000 POL every 30 seconds, totaling about $600,000. Polymarket protocol contributor Shantikiran Chanal attributed the incident to a compromised wallet used for internal operations, not a contract or core infrastructure vulnerability. Stevens stated at the time that all permissions linked to the compromised key had been revoked.

