Polymarket confirms hackers stole $3M from users after third-party vendor was compromised
Polymarket confirmed hackers stole approximately $3 million in cryptocurrency from over 11 users after a third-party vendor was compromised, injecting malicious code into the prediction market's frontend. The stolen funds were bridged from Polygon to Ethereum and converted into roughly 1,893 ETH. Polymarket says it has contained the incident and is refunding affected users in full. The attack was a supply chain compromise — no core smart contracts were exploited. The breach is the latest in a string of bad news for Polymarket, which also faced a separate $520K smart contract drain in May, a Wall Street Journal investigation into deceptive promotional videos, a Google engineer insider trading charge, regulatory blocks in multiple countries, and a $345 million governance dispute.