Polymarket2026-06-28 17:31:30Polymarket Users Lose $3.1M in PUSD to Frontend Script Injection Attack – Similar to 2024 1inch ExploitBlockchain intelligence firm AMLBot reports that Polymarket users on Polygon lost approximately $3.1 million in PUSD after a malicious script was injected into the platform's frontend. The attacker leveraged EIP-7702 delegate calls to trick users into signing transactions, then drained their wallets. Stolen funds were swapped via Relay, bridged to Ethereum, and converted into ETH now held across three wallets (totaling ~1,891.9 ETH). The attack mirrors the 2024 1inch Lottie Player incident, highlighting the critical risk of compromised third-party scripts in DeFi frontends.2120
Polymarket2026-06-28 17:01:38Polymarket Users Lose $3.1M in PUSD via Frontend Malicious Script: EIP-7702 Delegate Call Phishing AnalysisBlockchain intelligence firm AMLBot reports that Polymarket users on Polygon were hit by a malicious frontend script, losing approximately $3.1 million worth of PUSD. The attack leveraged EIP-7702 delegate execution to trick users into signing authorization transactions, instantly draining their wallets. Stolen funds were converted to USDC.e via Relay, bridged to Ethereum, swapped to ETH, and spread across three new wallets holding ~1891.9 ETH. The incident mirrors a 2024 attack on 1inch, where the Lottie Player library was compromised to inject wallet-draining scripts, highlighting ongoing risks from third-party script supply chains.1980
Polymarket2026-06-28 15:01:46Polymarket Users Lose $3.1M in Front-End Script Injection Attack Exploiting EIP-7702 DelegationBlockchain intelligence firm AMLBot has detected a front-end script injection attack on Polymarket users on Polygon, resulting in the theft of approximately $3.1 million in PUSD. The attacker injected malicious scripts into the frontend, tricking users into signing EIP-7702 delegate execution authorizations, which allowed the attacker to drain wallets. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum, swapped for ETH, and concentrated into three new wallets holding roughly 1,891.9 ETH. AMLBot draws parallels to the 2024 1inch attack, where the Lottie Player library was compromised, highlighting the persistent risk of third-party script vulnerabilities leading to frontend contamination.2000
Polymarket2026-06-28 14:31:39Polymarket Users Lose $3.1M in PUSD Front-End Script Attack — Method Matches 2024 1inch IncidentBlockchain intelligence firm AMLBot detected a front-end malicious script attack targeting Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million worth of PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing fraudulent authorization transactions, emptying wallets. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum, swapped to ETH, and concentrated into three new wallets holding ~1,891.9 ETH. The attack mirrors the 2024 1inch incident involving a compromised Lottie Player library, highlighting persistent risks from third-party front-end dependencies in DeFi. AMLBot urges platforms to strengthen script auditing and users to verify authorization requests.2030