Polymarket2026-10-06 10:05:11Polymarket Rebuilds Core Contracts With Protocol V2 and Eyes Nov. 2 Cutover for New MarketsPolymarket is replacing the smart contracts that have powered its prediction markets since launch, rolling out a rebuilt system called Protocol V2. Rajath Alex, the company’s head of protocol, said on X that the redesign starts at the position-token layer and restructures how markets, collateral and settlement work across the platform. A limited set of canary markets began trading on V2 in production on Monday and will continue through Oct. 30, while new markets are tentatively scheduled to move to the new system on Nov. 2. The new architecture collapses a multi-layer setup into a single ERC-1155 position contract, one exchange, one router and pUSD as the only collateral asset. It also introduces an OracleAggregator that can connect to UMA, Chainlink and future oracle providers, while laying technical groundwork for bridging positions, collateral and resolutions to other chains when Polymarket expands beyond one network. Alex said the code was audited by Cantina, Certora, Quantstamp, Sigma Prime, Zellic and Pashov Audit Group, with formal verification by Certora. A bug bounty offers up to $5 million for critical issues. For regular app and website users, Polymarket’s migration guide says no technical migration is required apart from approval prompts, though positions held under the old framework will not be converted.20
Polymarket2026-06-28 20:31:31Polymarket Users Lose ~$3.1M PUSD in Front-End Malicious Script Attack on PolygonBlockchain intelligence firm AMLBot has detected a malicious script injection attack targeting Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million in PUSD stablecoins. Attackers embedded malicious code into the platform's front end, tricking users into signing EIP-7702 delegation transactions that emptied their wallets. The stolen funds were converted to USDC.e via Relay, bridged to Ethereum, swapped for ETH, and consolidated into approximately 1,891.9 ETH across three new wallets. AMLBot draws parallels to the 2024 attack on 1inch, where the Lottie Player library was compromised, leading to front-end contamination.2120
Polymarket2026-06-28 18:01:19Polymarket Users Lose $3.1M PUSD in Front-End Malicious Script Attack; Funds Bridged to EthereumBlockchain intelligence firm AMLBot reported that Polymarket users on Polygon were compromised via a front-end malicious script injection, resulting in the theft of approximately $3.1 million in PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing authorization transactions, draining wallets of all PUSD. The stolen funds were converted to USDC.e via Relayer, bridged to Ethereum, swapped for ETH, and distributed across three new wallets holding roughly 1,891.9 ETH. The attack mirrors the 2024 1inch incident where the Lottie Player library was compromised, highlighting the growing threat of third-party script attacks on DeFi frontends.2040
Polymarket2026-06-28 17:31:30Polymarket Users Lose $3.1M in PUSD to Frontend Script Injection Attack – Similar to 2024 1inch ExploitBlockchain intelligence firm AMLBot reports that Polymarket users on Polygon lost approximately $3.1 million in PUSD after a malicious script was injected into the platform's frontend. The attacker leveraged EIP-7702 delegate calls to trick users into signing transactions, then drained their wallets. Stolen funds were swapped via Relay, bridged to Ethereum, and converted into ETH now held across three wallets (totaling ~1,891.9 ETH). The attack mirrors the 2024 1inch Lottie Player incident, highlighting the critical risk of compromised third-party scripts in DeFi frontends.2150
Polymarket2026-06-28 17:01:38Polymarket Users Lose $3.1M in PUSD via Frontend Malicious Script: EIP-7702 Delegate Call Phishing AnalysisBlockchain intelligence firm AMLBot reports that Polymarket users on Polygon were hit by a malicious frontend script, losing approximately $3.1 million worth of PUSD. The attack leveraged EIP-7702 delegate execution to trick users into signing authorization transactions, instantly draining their wallets. Stolen funds were converted to USDC.e via Relay, bridged to Ethereum, swapped to ETH, and spread across three new wallets holding ~1891.9 ETH. The incident mirrors a 2024 attack on 1inch, where the Lottie Player library was compromised to inject wallet-draining scripts, highlighting ongoing risks from third-party script supply chains.2020
Polymarket2026-06-28 15:01:46Polymarket Users Lose $3.1M in Front-End Script Injection Attack Exploiting EIP-7702 DelegationBlockchain intelligence firm AMLBot has detected a front-end script injection attack on Polymarket users on Polygon, resulting in the theft of approximately $3.1 million in PUSD. The attacker injected malicious scripts into the frontend, tricking users into signing EIP-7702 delegate execution authorizations, which allowed the attacker to drain wallets. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum, swapped for ETH, and concentrated into three new wallets holding roughly 1,891.9 ETH. AMLBot draws parallels to the 2024 1inch attack, where the Lottie Player library was compromised, highlighting the persistent risk of third-party script vulnerabilities leading to frontend contamination.2020
Polymarket2026-06-28 14:31:39Polymarket Users Lose $3.1M in PUSD Front-End Script Attack — Method Matches 2024 1inch IncidentBlockchain intelligence firm AMLBot detected a front-end malicious script attack targeting Polymarket users on the Polygon network, resulting in the theft of approximately $3.1 million worth of PUSD. The attacker exploited EIP-7702 delegate execution to trick users into signing fraudulent authorization transactions, emptying wallets. Stolen funds were converted via Relay to USDC.e, bridged to Ethereum, swapped to ETH, and concentrated into three new wallets holding ~1,891.9 ETH. The attack mirrors the 2024 1inch incident involving a compromised Lottie Player library, highlighting persistent risks from third-party front-end dependencies in DeFi. AMLBot urges platforms to strengthen script auditing and users to verify authorization requests.2070
Polymarket2026-06-27 14:40:37Polymarket Phishing Attack: $3.1 Million Stolen from User Wallets, Full Refund PromisedPolymarket 近日遭受钓鱼攻击,黑客从11个用户钱包窃取约310万美元的PUSD代币,资金从Polygon链跨链转移至以太坊。该攻击针对用户钱包而非协议合约,项目方已承诺全额退款,并配合调查。此事件再次警示用户需警惕钓鱼风险,检查钱包授权。2060