Polymarket Customers Lose $3 Million in Supply-Chain Attack on Prediction Market Platform

Polymarket, the decentralized prediction market platform, announced it will fully reimburse customers after attackers stole an estimated $3 million through a supply-chain attack targeting the platform’s frontend code. The breach originated at a third-party vendor whose systems were compromised, allowing the attackers to inject a malicious script into Polymarket’s website. Users who visited the platform and interacted with it during the window of compromise had funds drained from their accounts without authorization.

The attack is a textbook example of a supply-chain compromise: rather than attacking Polymarket directly, the criminals targeted a weaker link in the software delivery chain. Once malicious code was introduced at the vendor level, it was served to all Polymarket visitors as if it were legitimate site functionality. This approach is increasingly favored by threat actors because it can bypass the security measures of the primary target entirely by exploiting trusted third-party relationships.

Polymarket’s commitment to reimburse affected users limits the financial harm to individual customers, but the incident underscores broader concerns about the security of third-party integrations in cryptocurrency and fintech platforms. The prediction market has not yet publicly identified the compromised vendor or detailed what security changes are being implemented to prevent similar incidents. Security researchers have noted that web3 platforms, which often rely on complex ecosystems of third-party scripts and services, are particularly attractive targets for supply-chain injection attacks due to the direct connection between frontend code and user funds.

Read the original report →