Polymarket Users Lose $3.1M PUSD in Front-End Malicious Script Attack; Funds Bridged to Ethereum
Blockchain intelligence firm AMLBot reported that Polymarket users on Polygon were compromised via a front-end malicious script injection, resulting in the theft of approximately $3.1 million in PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing authorization transactions, draining wallets of all PUSD. The stolen funds were converted to USDC.e via Relayer, bridged to Ethereum, swapped for ETH, and distributed across three new wallets holding roughly 1,891.9 ETH. The attack mirrors the 2024 1inch incident where the Lottie Player library was compromised, highlighting the growing threat of third-party script attacks on DeFi frontends.


