Polymarket hack — June 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 25, 2026 |
| Target type | Other |
| Loss | $3,000,000Published estimates range $2,940,000 to $3,000,000Price at time of incident |
| Method | Supply chain or frontend compromiseClient-side supply-chain compromise. A third-party vendor whose script Polymarket already loaded was breached, and malicious JavaScript was injected into the polymarket.com front end. For a subset of visitors the script rendered fraudulent token-approval prompts inside the legitimate interface; users who signed them let the attacker move their pUSD. Polymarket's smart contracts were not compromised, and because the script came from an allowed origin, content security policy did not block it. |
| Chains | Polygon, Ethereum |
| Outcome | Users reimbursed |
What happened
On 25 June 2026 Polymarket said attackers had stolen roughly $3 million of customer funds after malicious code was injected into the prediction market's front end. Polymarket stated on X that a third-party vendor had been hacked and that it would fully reimburse all affected users. The incident became public on 26 June. The platform's smart contracts were not touched. c/side's analysis describes a client-side supply-chain compromise: a compromised third-party vendor injected a wallet-drainer script, and for a subset of visitors it rendered fraudulent ERC-20 approval and signature requests inside the legitimate interface. Users who signed those prompts granted the attacker the ability to move their pUSD, the USDC-backed token Polymarket uses. Content security policy did not stop it because, as c/side puts it, CSP allow-lists script sources rather than script behaviour — the script loaded from an already-permitted origin. The code was injected only for some users, a conditional delivery pattern that helps such attacks evade routine scanning. The losses were concentrated. Blockchain analytics firm Bubblemaps counted fewer than 15 affected accounts; Halborn's write-up cites at least eleven impacted wallets, as does c/side, relaying Specter's on-chain analysis. Stolen pUSD was bridged from Polygon to Ethereum, swapped into roughly 1,893 ETH and consolidated. Figures differ only modestly. Polymarket's own statement and most coverage say about $3 million; the most granular on-chain reconstruction, Specter's as reported by c/side, puts the confirmed total at about $2.94 million drained from at least 11 wallets. No reconciled final number has been published and the compromised vendor has not been named. Polymarket had disclosed a separate incident the previous month in which about $700,000 was taken from an internal reward-distribution wallet, which observers attributed to a private-key compromise.
On-chain references
Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.
Attacker addresses
- 0xe65b1C586757c5510B60F998Eebb14C1eF71E1eD
Sources
- Decrypt (quoting Polymarket's official X statement and Bubblemaps)Secondary · retrieved 2026-08-01
- c/sideSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- UnchainedSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Polymarket hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/polymarkethttps://itokenly.com/hacks/polymarketPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.