BackAMLBot

AMLBot

Polymarket
2026-06-28 19:31:15

Polymarket Users Lose $3.1M in Front-End Script Attack; Technique Mirrors 2024 1inch Incident

According to AMLBot monitoring, Polymarket users on Polygon network suffered a front-end malicious script intrusion, losing approximately $3.1 million in PUSD. The attack exploited EIP-7702 delegate execution to trick users into signing malicious authorizations. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum mainnet, and swapped to ETH, currently held as 1,891.9 ETH across three new wallets. The method closely resembles the 2024 1inch attack where the Lottie Player library was compromised to inject wallet-draining scripts, highlighting the persistent threat of third-party front-end dependencies in DeFi.

1030
Polymarket Users Lose $3.1M in Front-End Script Attack; Technique Mirrors 2024 1inch Incident
2026-06-28 18:31:27

Polymarket Users Lose $3.1M PUSD in Front-End Script Attack; Funds Traced to Three Wallets

Blockchain intelligence firm AMLBot reported on June 28 that Polymarket users on Polygon network were hit by a malicious front-end script injection, resulting in losses of approximately $3.1 million in PUSD. The attacker exploited the EIP-7702 delegation execution mechanism to trick users into signing authorization transactions, then drained their wallets. The stolen funds were converted to USDC.e via Relay, bridged to Ethereum, and finally swapped to ETH — currently ~1,891.9 ETH spread across three newly created wallets. AMLBot highlighted the similarity to the 2024 1inch front-end attack where the Lottie Player library was compromised. This incident underscores the vulnerability of third-party scripts in DeFi frontends and the need for stricter content security policies.

1070
Polymarket Users Lose $3.1M PUSD in Front-End Script Attack; Funds Traced to Three Wallets
Polymarket
2026-06-28 18:01:19

Polymarket Users Lose $3.1M PUSD in Front-End Malicious Script Attack; Funds Bridged to Ethereum

Blockchain intelligence firm AMLBot reported that Polymarket users on Polygon were compromised via a front-end malicious script injection, resulting in the theft of approximately $3.1 million in PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing authorization transactions, draining wallets of all PUSD. The stolen funds were converted to USDC.e via Relayer, bridged to Ethereum, swapped for ETH, and distributed across three new wallets holding roughly 1,891.9 ETH. The attack mirrors the 2024 1inch incident where the Lottie Player library was compromised, highlighting the growing threat of third-party script attacks on DeFi frontends.

1020
Polymarket Users Lose $3.1M PUSD in Front-End Malicious Script Attack; Funds Bridged to Ethereum
Polymarket
2026-06-28 17:31:30

Polymarket Users Lose $3.1M in PUSD to Frontend Script Injection Attack – Similar to 2024 1inch Exploit

Blockchain intelligence firm AMLBot reports that Polymarket users on Polygon lost approximately $3.1 million in PUSD after a malicious script was injected into the platform's frontend. The attacker leveraged EIP-7702 delegate calls to trick users into signing transactions, then drained their wallets. Stolen funds were swapped via Relay, bridged to Ethereum, and converted into ETH now held across three wallets (totaling ~1,891.9 ETH). The attack mirrors the 2024 1inch Lottie Player incident, highlighting the critical risk of compromised third-party scripts in DeFi frontends.

1070
Polymarket Users Lose $3.1M in PUSD to Frontend Script Injection Attack – Similar to 2024 1inch Exploit
Polymarket
2026-06-28 17:01:38

Polymarket Users Lose $3.1M in PUSD via Frontend Malicious Script: EIP-7702 Delegate Call Phishing Analysis

Blockchain intelligence firm AMLBot reports that Polymarket users on Polygon were hit by a malicious frontend script, losing approximately $3.1 million worth of PUSD. The attack leveraged EIP-7702 delegate execution to trick users into signing authorization transactions, instantly draining their wallets. Stolen funds were converted to USDC.e via Relay, bridged to Ethereum, swapped to ETH, and spread across three new wallets holding ~1891.9 ETH. The incident mirrors a 2024 attack on 1inch, where the Lottie Player library was compromised to inject wallet-draining scripts, highlighting ongoing risks from third-party script supply chains.

1030
Polymarket Users Lose $3.1M in PUSD via Frontend Malicious Script: EIP-7702 Delegate Call Phishing Analysis
Polymarket
2026-06-28 15:01:46

Polymarket Users Lose $3.1M in Front-End Script Injection Attack Exploiting EIP-7702 Delegation

Blockchain intelligence firm AMLBot has detected a front-end script injection attack on Polymarket users on Polygon, resulting in the theft of approximately $3.1 million in PUSD. The attacker injected malicious scripts into the frontend, tricking users into signing EIP-7702 delegate execution authorizations, which allowed the attacker to drain wallets. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum, swapped for ETH, and concentrated into three new wallets holding roughly 1,891.9 ETH. AMLBot draws parallels to the 2024 1inch attack, where the Lottie Player library was compromised, highlighting the persistent risk of third-party script vulnerabilities leading to frontend contamination.

1020
Polymarket Users Lose $3.1M in Front-End Script Injection Attack Exploiting EIP-7702 Delegation
Polymarket
2026-06-28 14:31:39

Polymarket Users Lose $3.1M in PUSD Front-End Script Attack — Method Matches 2024 1inch Incident

Blockchain intelligence firm AMLBot detected a front-end malicious script attack targeting Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million worth of PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing fraudulent authorization transactions, emptying wallets. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum, swapped to ETH, and concentrated into three new wallets holding ~1,891.9 ETH. The attack mirrors the 2024 1inch incident involving a compromised Lottie Player library, highlighting persistent risks from third-party front-end dependencies in DeFi. AMLBot urges platforms to strengthen script auditing and users to verify authorization requests.

1050
Polymarket Users Lose $3.1M in PUSD Front-End Script Attack — Method Matches 2024 1inch Incident
Polymarket
2026-06-27 14:40:37

Polymarket Phishing Attack: $3.1 Million Stolen from User Wallets, Full Refund Promised

Polymarket 近日遭受钓鱼攻击,黑客从11个用户钱包窃取约310万美元的PUSD代币,资金从Polygon链跨链转移至以太坊。该攻击针对用户钱包而非协议合约,项目方已承诺全额退款,并配合调查。此事件再次警示用户需警惕钓鱼风险,检查钱包授权。

1040
Polymarket Phishing Attack: $3.1 Million Stolen from User Wallets, Full Refund Promised