Polymarket to Refund Users After $2.94M Frontend Phishing Attack

Polymarket to Refund Users After $2.94M Frontend Phishing Attack

N
News Editor 01
2026-07-24 10:50:16
Polymarket confirmed a third-party vendor compromise led to malicious code injection into its frontend, draining about $2.94M from at least 11 wallets. The platform removed the dependency, contained the incident, and promised full refunds. The breach is the 89th Q2 crypto security incident, a quarterly record.
Polymarketphishingsecurity breachrefundDeFiLlama

Polymarket disclosed on X that attackers compromised a third-party vendor and injected malicious code into the platform's frontend, triggering a phishing attack that drained approximately $2.94 million from at least 11 user wallets. The platform said it has removed the affected dependency, contained the incident, and will fully reimburse all affected users.

Vendor compromise triggered front-end phishing

Blockchain analyst Specter identified the attack as a phishing campaign rather than a protocol exploit. The injected script allowed attackers to drain funds from connected wallets after users interacted with the compromised interface. Polymarket confirmed that the malicious dependency was removed and the incident is contained. Josh Stevens, the company's vice president of engineering, had previously stated that user funds and smart contracts remained secure after a separate private key incident.

Attack details and user refunds

Specter estimated that at least 11 wallets were drained. Polymarket pledged full refunds but did not disclose whether any funds were recovered. DefiLlama recorded the incident as the 89th reported crypto security breach of Q2 2025, making it the highest quarterly total by incident count on the platform's records.

On-chain security incidents hit quarterly record

DefiLlama also reported $74.9 million in losses across 29 crypto exploits in June, up from May's $60.5 million but far below April's $644 million. The largest June attack was the $36 million Humanity Protocol exploit. Other major incidents included a $4.7 million Secret Network bridge exploit, two separate $2.1 million Aztec exploits, and a $1.7 million Taiko bridge exploit. DefiLlama noted that private key compromises accounted for 43% of exploit losses over the past 30 days, fake proof exploits 10%, and reverse MEV honeypots 8%.

Previous private key exploit

About a month earlier, Polymarket suffered a separate incident where attackers exploited a six-year-old private key used for internal top-up operations, stealing roughly $600,000. Security researchers including ZachXBT, PeckShield, and Bubblemaps flagged suspicious activity involving Polymarket's UMA CTF Adapter contract on Polygon. Bubblemaps reported attackers withdrew 5,000 POL every 30 seconds, totaling about $600,000. Polymarket protocol contributor Shantikiran Chanal attributed the incident to a compromised wallet used for internal operations, not a contract or core infrastructure vulnerability. Stevens stated at the time that all permissions linked to the compromised key had been revoked.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.