Prediction market platform Polymarket is facing increased pressure after losses from its recent security breach climbed to an estimated $3.1 million.
Updated figures released by blockchain security firm AMLBot show that the phishing attack affected at least 11 user wallets, exceeding earlier estimates and raising fresh questions about third-party security risks and the platform’s commitment to fully reimburse victims.
The incident comes at a time when Polymarket is already facing growing regulatory scrutiny over its business practices, adding further challenges for one of the crypto industry’s largest prediction market platforms.
Losses Increase to $3.1 Million
Blockchain intelligence firm AMLBot reported that attackers stole approximately $3.1 million worth of PUSD from 11 wallets connected to Polymarket users.
According to the investigation, the stolen assets were initially drained on the Polygon network before being bridged to Ethereum, where the attackers converted the funds into approximately 1,893 ETH.
The latest estimate is higher than the earlier reported loss of roughly $2.94 million, indicating that investigators continue uncovering additional stolen funds.
Security researcher Specter Analyst was among the first to identify the incident, describing it as a coordinated phishing campaign targeting Polymarket users.
Third-Party Vendor Compromise
Polymarket stated that the attack was not caused by a vulnerability in its core protocol.
Instead, the company said a compromised third-party vendor allowed malicious code to be injected into portions of the platform’s frontend.
According to Polymarket, the attackers used the compromised dependency to display fraudulent wallet approval requests to certain users.
The company said it has since:
- Contained the incident
- Removed the affected dependency
- Contacted impacted users
- Committed to fully reimbursing victims
In a statement posted on June 25, Polymarket said:
“We’ve contained it and removed the affected dependency.”
The platform also pledged to refund all affected users in full.
How the Attack Worked
Unlike attacks targeting smart contracts, this incident focused on the website interface itself.
Frontend attacks manipulate the code users interact with inside their web browsers.
Although the website may appear completely legitimate, hidden malicious scripts can generate deceptive wallet approval requests.
If users unknowingly approve those requests, attackers can gain permission to transfer digital assets directly from connected wallets.
Because the blockchain itself remains secure, these attacks are often difficult to detect until after funds have already been stolen.
Security Researchers Trace the Funds
Blockchain security firms quickly tracked the stolen assets after the attack.
According to PeckShield, the attacker transferred the stolen PUSD from Polygon to Ethereum before swapping the assets into approximately 1,893 ETH.
Specter Analyst also reported that the stolen cryptocurrency was consolidated into a single Ethereum address following the phishing campaign.
Blockchain transparency allows investigators to monitor fund movements, although recovering stolen assets remains significantly more difficult.
Third-Party Dependencies Create Hidden Risks
The incident has once again highlighted the growing cybersecurity risks associated with third-party software dependencies.
Modern cryptocurrency platforms often rely on external services for functions such as:
- Website analytics
- User interface components
- Payment integrations
- Security tools
- Infrastructure libraries
Even when a platform’s smart contracts remain fully secure, vulnerabilities introduced through third-party code can expose users to phishing attacks.
As decentralized applications continue becoming more sophisticated, supply chain security is becoming an increasingly important area of focus.
Previous Security Incidents Add Pressure
The latest breach is not the first security issue involving Polymarket.
Earlier this year, blockchain investigator ZachXBT reported a suspected exploit involving more than $520,000 allegedly drained from two Polygon smart contracts.
Polymarket later stated that customer funds remained safe in that incident.
The platform also experienced security concerns in December, when users reported suspicious login attempts and missing funds linked to its Discord community.
While the circumstances differed from the latest phishing attack, the repeated incidents have increased attention on the platform’s overall security practices.
Crypto Hacks Continue Rising in 2026
According to DefiLlama, the Polymarket attack represents the 89th reported cryptocurrency security breach during the second quarter of 2026.
That makes the current quarter one of the busiest periods on record for reported crypto-related exploits.
Recent attacks have targeted various parts of the digital asset ecosystem, including:
- Smart contracts
- Frontend websites
- Wallet integrations
- Authentication systems
- Third-party software providers
The growing number of incidents has prompted many companies to increase investment in cybersecurity and supply chain protection.
Regulatory Attention Is Also Increasing
The security breach comes as Polymarket faces growing political and regulatory scrutiny in the United States.
Recently, U.S. Senators Adam Schiff and John Curtis urged the Commodity Futures Trading Commission (CFTC) to investigate allegations involving the platform’s advertising practices.
Among the concerns raised were claims that prediction markets may have been promoted using:
- Simulated trading websites
- Staged transactions
- Undisclosed influencer campaigns
The senators also questioned whether current regulatory oversight provides sufficient consumer protection for prediction market platforms.
Legal Battle Over Prediction Markets Continues
Polymarket is also involved in broader legal debates surrounding sports prediction contracts.
Several U.S. states, including Kentucky, argue that certain event-based prediction markets resemble unlicensed sports betting.
Meanwhile, the CFTC maintains that federally regulated prediction contracts should fall under derivatives law rather than state gambling regulations.
The outcome of these legal disputes could significantly influence how prediction market platforms operate across the United States in the future.
The Bottom Line
Polymarket’s latest phishing incident has grown into a $3.1 million security breach, underscoring the increasing risks posed by compromised third-party software rather than vulnerabilities in blockchain protocols themselves.
While the company has pledged to fully reimburse affected users and has already removed the malicious code, the attack highlights how frontend compromises can bypass even secure smart contracts by targeting users directly.
Combined with rising regulatory scrutiny and ongoing legal challenges surrounding prediction markets, the incident adds another difficult chapter for Polymarket as it works to rebuild user confidence.
As cryptocurrency platforms continue expanding, strengthening third-party security and protecting users from sophisticated phishing attacks will remain just as important as securing blockchain infrastructure itself.
Disclaimer: This article is for informational purposes only and should not be considered financial or investment advice. Users should always verify wallet requests carefully before approving blockchain transactions and follow recommended security practices when interacting with decentralized applications.


































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































