A compromised third-party vendor allowed hackers to inject malicious code into Polymarket's interface, stealing approximately $3 million from more than 11 users. The predictive markets platform brought the incident under control and announced full reimbursement for the victims. In an industry under increasing scrutiny, the breach reignites questions about the security of front-end layers.

In brief
- Hackers stole approximately $3 million from more than 11 Polymarket users through a compromised third-party provider.
- The malicious code targeted the web interface and not the smart contracts, tricking victims into approving fraudulent transactions.
- Polymarket provides full reimbursement to victims and has removed the third-party dependency that caused the breach.
How did the pirates bypass Polymarket's defenses?
Blockchain security firm Peckshield put the damage at $3 million, spread across at least 11 victims. However, Polymarket did not suffer a direct breach. The attackers targeted a third-party provider whose code was distributed via the platform's web interface, injecting a fraudulent script that prompted users to validate false transactions.
This type of attack, known as “supply chain compromise,” is particularly feared in the crypto industry. Rather than attacking the systems of a directly secure platform, hackers go back to its software dependencies.
Visitors who loaded the compromised page were shown legitimate-looking signature requests, which actually gave attackers control of their wallets.
According to Polymarket itself, the platform has removed the affected dependency and is now fully under control of the incident. On-chain markets have never exposed blocked funds ; only users who approved the fraudulent transactions saw their wallets empty.
A sector under regulatory and security pressure
The incident comes as prediction markets go through a period of increased voting. Polymarket and its competitor Kalshi had a record April 2026, and Polymarket claims over 100 million transactions to date. This visibility attracts regulators as much as attackers.
On the regulatory side, the CFTC recently initiated legal action against Kentucky, which is trying to apply its own rules to prediction markets by likening them to sports betting, a battle of jurisdiction between federal authority and local legislators which illustrates the persistent regulatory tensions around platforms like Polymarket and Kalshi.
The platform had also deployed Chainalysis monitoring tools to strengthen the integrity of its markets. This June hack adds operational security to an already loaded list of concerns.
This hack demonstrates a well-known reality of DeFi protocols and exchange platforms: the robustness of smart contracts does not protect against flaws that occur upstream, in the visible layer. Polymarket is managing the crisis with rapid reimbursements, but confidence in the security of web interfaces remains the weak link in the sector.
Maximize your Tremplin.io experience with our 'Read to Earn' program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.
