Prediction market platform Polymarket has confirmed a frontend supply chain attack that resulted in approximately $3.1 million being stolen from eleven user wallets. The attack, which began around June 25, involved a compromised third-party vendor that injected a malicious script into Polymarket’s website, targeting the platform’s dollar-pegged pUSD token.
The stolen assets were swapped for approximately 1,893 ETH and bridged from the Polygon network to the Ethereum mainnet. Polymarket says it has contained the attack by removing the compromised dependency and fixing the underlying vulnerability. The company has pledged to fully reimburse all affected users.
This marks the second security breach for Polymarket in roughly five weeks, raising questions about the platform’s security posture and vendor management practices as it continues to process significant trading volume in the prediction markets space.
Sources
- BleepingComputer — Polymarket customers lose $3 million in supply chain attack
- Halborn — Explained: The Polymarket Hack (June 2026)
- Crypto.news — Polymarket hack losses rise to $3.1M
Commentary
Frontend supply chain attacks are becoming the go-to playbook for crypto platform compromises, and Polymarket’s second breach in five weeks suggests systemic issues with their dependency management and vendor security review process. When a malicious third-party script can drain user wallets directly, the entire trust model of the frontend is broken.
For the broader DeFi and crypto ecosystem, this is a recurring lesson: your frontend is only as secure as your least-audited dependency. The rapid bridge from Polygon to Ethereum mainnet also demonstrates how quickly stolen funds can be laundered across chains. Polymarket’s commitment to reimburse users is commendable, but the pattern of repeat incidents demands a more fundamental security overhaul.
