Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News

    Polymarket Loses $2.9M to Theft, Plans Full User Refunds

    26 June 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Polymarket Loses $2.9m To Theft, Plans Full User Refunds
    Polymarket Loses $2.9m To Theft, Plans Full User Refunds

    A third-party vendor compromise allowed attackers to inject malicious code into Polymarket’s frontend, leading to a phishing drain from user wallets, according to blockchain analyst Specter. The incident was discovered on Thursday and reportedly targeted at least 11 Polymarket users, with Specter estimating losses of $2.94 million.

    Polymarket said on X that the issue has been contained, the affected dependency removed, and that users will be fully refunded. While Cointelegraph attempted to follow up for additional comment, no response was received before publication.

    Key takeaways

    • Specter attributed the Polymarket incident to malicious script injection following a vendor compromise, with an estimated $2.94 million drained from at least 11 wallets.
    • Polymarket states the compromise has been contained and that the impacted dependency was removed, with full user refunds promised.
    • DefiLlama data shows June exploit losses reached $74.9 million across 29 incidents—more than May’s $60.5 million, but far below April’s $644 million.
    • Across the last 30 days, private key compromises accounted for 43% of reported exploit losses, making it the leading attack vector.
    • DefiLlama’s breakdown points to other recurring methods, including “fake proof” exploits (10%) and reverse MEV honeypots (8%).

    Polymarket: vendor compromise leads to frontend phishing

    Specter said the malicious script appeared to be designed to facilitate phishing, ultimately draining funds from multiple Polymarket wallets. The key operational detail in the account is that the attacker did not need to compromise Polymarket’s core smart contracts directly; instead, the issue originated from a third-party vendor compromise that enabled code injection into the platform’s frontend.

    That distinction matters for users because frontend-based attacks can succeed even when on-chain contracts remain intact. In practice, phishing scripts can trick users into approving malicious actions, entering credentials into spoofed interfaces, or signing transactions that benefit attackers.

    Polymarket’s response emphasized containment and remediation: the platform said the compromise has been stopped, the problematic dependency removed, and affected users will receive full refunds. With those steps, the immediate risk of further wallet draining should decline, though users will still want to monitor their accounts and transaction history for any suspicious approvals.

    Why this sits within a larger pattern of crypto incidents

    The Polymarket event comes amid a sustained run of reported crypto security breaches. DefiLlama data lists the Polymarket incident as the 89th reported crypto security breach of the second quarter. That count extends what DefiLlama categorization describes as the most-hacked quarter on record by incident count.

    Earlier in June, DefiLlama’s monthly totals already reflected elevated activity. June exploit losses climbed to $74.9 million across 29 reported incidents, surpassing May’s $60.5 million. However, April’s $644 million remains the standout outlier for magnitude, underscoring that while breach frequency remains high, individual months can vary dramatically based on whether large incidents occur.

    June’s reported exploit losses: the biggest June incidents

    DefiLlama’s aggregation highlights several of the largest June events. The most prominent was the $36 million Humanity Protocol exploit. Other notable losses included the $4.7 million Secret Network bridge exploit, two Aztec-related exploits worth $2.1 million each, and a $1.7 million bridge exploit tied to Taiko, according to the article’s cited figures and linked coverage.

    Taken together, the list shows that bridge ecosystems and cross-chain integrations continue to attract high-impact attacks. While frontend phishing attacks like Polymarket’s are distinct from bridge exploits, both categories fall under the broader umbrella of “exploit losses”—the measurable outcomes when attackers successfully compromise systems or user interactions.

    Attack vectors over the last month: key compromise still leads

    DefiLlama data summarized in the piece indicates that the primary driver of reported exploit losses over the past 30 days was private key compromise, responsible for 43% of losses. Fake proof exploits accounted for 10%, while reverse MEV honeypots made up 8% of losses, based on DefiLlama’s breakdown.

    The vector mix is useful because it shifts how defensive priorities are framed. Private key compromise suggests either user-side weakness (including wallet security practices) or operational weaknesses involving signing keys—issues that often persist across unrelated protocols. Meanwhile, fake proof and reverse MEV honeypots reflect more sophisticated adversarial tactics at the application and execution layers, targeting how systems validate claims or how trading bots execute orders.

    The article also notes that roughly a month before Polymarket’s latest attack, the prediction market disclosed a separate $600,000 exploit traced to a six-year-old private key used for internal top-up operations. Polymarket leadership said at the time that user funds and contracts were safe and that permissions tied to the key had been revoked, emphasizing that the platform has dealt with operational key risks before.

    Polymarket’s scale and what users should monitor next

    DefiLlama data cited in the article places Polymarket’s total value locked at over $450 million, up 301% from $112 million a year earlier. As platforms grow, they often become more attractive targets—not only for contract-level attacks but also for the broader supply-chain and integration risks that can surface through third-party dependencies.

    Going forward, readers should watch for two signals: confirmation from Polymarket and security analysts that the injected frontend dependency is fully removed and no similar vendor-based pathways remain, and whether wallet-level incidents prompt changes in how users interact with the platform (for example, renewed scrutiny of approvals and transaction prompts). With refunds promised, the immediate impact may be contained, but the recurrence of earlier key-related disclosures underscores that operational security remains a critical focus for both users and the platforms they rely on.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Standard Chartered Says Saylor’s Btc Pivot Needs Clear Investor Messaging

    Standard Chartered Says Saylor’s BTC Pivot Needs Clear Investor Messaging

    3 hours ago
    Saylor’s Btc Pivot Message Needs Clarity, Stanchart Says Investors

    Saylor’s BTC pivot message needs clarity, StanChart says investors

    4 hours ago
    Pakistan Crypto Regulator Calls For Dialogue After Ruling On Crypto Payments

    Pakistan Crypto Regulator Calls for Dialogue After Ruling on Crypto Payments

    9 hours ago
    Pakistan Crypto Regulator Opens Dialogue After Court Ruling On Payments

    Pakistan Crypto Regulator Opens Dialogue After Court Ruling on Payments

    10 hours ago
    Cambridge: Ethereum’s Pos Energy Use Trails Lower-End Estimates

    Cambridge: Ethereum’s PoS energy use trails lower-end estimates

    12 hours ago
    Cambridge Research Finds Ethereum’s Proof-Of-Stake Energy Use At Low End

    Cambridge Research Finds Ethereum’s Proof-of-Stake Energy Use at Low End

    13 hours ago

    Search Crypto News

    Featured Crypto News

    How Ai Is Changing Music: Virtual Artist Lunayah Releases "new Beginning"

    How AI Is Changing Music: Virtual Artist Lunayah Releases “New Beginning”

    1 June 2026

    Latest News

    • Standard Chartered Says Saylor’s BTC Pivot Needs Clear Investor Messaging
    • Saylor’s BTC pivot message needs clarity, StanChart says investors
    • Pakistan Crypto Regulator Calls for Dialogue After Ruling on Crypto Payments
    • Pakistan Crypto Regulator Opens Dialogue After Court Ruling on Payments
    • Cambridge: Ethereum’s PoS energy use trails lower-end estimates
    • Cambridge Research Finds Ethereum’s Proof-of-Stake Energy Use at Low End
    • Saylor and Adam Back Criticize BIP-110 Ordinals Proposal
    • Saylor and Adam Back Criticize BIP-110 Ordinals Proposal
    • Empery Digital Shares Jump After Bitcoin Treasury Sale for AI Datacenter
    • Empery Digital stock jumps after Bitcoin treasury sale funds AI datacenter

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Crypto.com
    AVATRADE

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Crypto.com
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!