Polymarket Users Lose $3.1M in Front-End Script Attack; Technique Mirrors 2024 1inch Incident
According to AMLBot monitoring, Polymarket users on Polygon network suffered a front-end malicious script intrusion, losing approximately $3.1 million in PUSD. The attack exploited EIP-7702 delegate execution to trick users into signing malicious authorizations. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum mainnet, and swapped to ETH, currently held as 1,891.9 ETH across three new wallets. The method closely resembles the 2024 1inch attack where the Lottie Player library was compromised to inject wallet-draining scripts, highlighting the persistent threat of third-party front-end dependencies in DeFi.

