Supply chain attacks have displaced smart contract exploits as the primary loss vector in cryptocurrency security. Infrastructure compromises — including vendor breaches, npm package hijacking, and frontend code injection — accounted for $2.2 billion, or 76%, of all hack-related losses in 2025, a...
"The attacker bridged the stolen funds from Polygon to Ethereum and swapped them into approximately 1,893 ETH." — PeckShield, Blockchain Security Firm (June 26, 2026)
Supply chain attacks have displaced smart contract exploits as the primary loss vector in cryptocurrency security. Infrastructure compromises — including vendor breaches, npm package hijacking, and frontend code injection — accounted for $2.2 billion, or 76%, of all hack-related losses in 2025, according to Chainalysis. That trend has accelerated into 2026.
On June 25, 2026, Polymarket became the latest target when attackers compromised a third-party vendor to inject malicious JavaScript into the prediction market's frontend, draining approximately $3 million from fewer than 15 user wallets. It was the platform's second security incident in 35 days. In May, a compromised six-year-old private key drained $520,000 from internal operations wallets. Neither attack exploited Polymarket's smart contracts.
The pattern is not new but is intensifying. The February 2025 Bybit breach — $1.5 billion stolen via a compromised Safe{Wallet} developer workstation — demonstrated that multi-signature security is irrelevant when the signing interface itself is corrupted. The December 2023 Ledger Connect Kit attack poisoned over 100 DeFi frontends through a single npm package. In March 2026, the Axios npm library (100 million weekly downloads) was trojanized to harvest crypto wallets and cloud credentials. The attack surface has shifted from on-chain logic to the JavaScript dependency graph that every Web3 frontend relies on.
On June 25, 2026, Polymarket users began approving transactions they did not initiate. A compromised third-party vendor had allowed attackers to inject malicious JavaScript into the platform's production frontend. The script phished users into granting token approvals for pUSD — Polymarket's USDC-backed stablecoin on Polygon — which the attacker then drained.
According to blockchain analytics firm Bubblemaps, fewer than 15 wallets were affected. PeckShield traced the stolen funds — approximately $2.94 million in pUSD — as they were bridged from Polygon to Ethereum and swapped for approximately 1,893 ETH.
Polymarket's response was swift. The company stated it had "contained and removed the affected dependency" and pledged full reimbursement for all impacted users. The platform's smart contracts and backend infrastructure were never breached.
This was Polymarket's second security incident in five weeks. On May 22, 2026, blockchain investigator ZachXBT flagged $520,000 drained from two Polymarket-linked contracts on Polygon. That breach was traced to a compromised private key from a six-year-old internal operations wallet used for reward payouts. Again, no smart contract was exploited.
The two incidents followed different attack paths — vendor compromise versus leaked private key — but arrived at the same conclusion: Polymarket's on-chain code was not the problem. Its off-chain infrastructure was.
| Date | Target | Vector | Loss | Impact Scope | |------|--------|--------|------|--------------| | Dec 2023 | Ledger Connect Kit | Phished npm developer account | $600K+ | 100+ DeFi frontends | | Feb 2025 | Bybit (via Safe{Wallet}) | Compromised developer workstation | $1.5B | Single exchange cold wallet | | Mar 2026 | Axios npm package | Trojanized npm package | Undisclosed | 100M+ weekly downloads exposed | | Mar 2026 | AppsFlyer Web SDK | CDN-hosted SDK rewrite | Undisclosed | 100K+ applications | | Apr 2026 | Bitwarden CLI | Compromised GitHub Action | Undisclosed | Password manager users | | May 2026 | Polymarket (internal) | Six-year-old private key | $520K | Internal operations wallets | | May 2026 | npm ecosystem (TeamPCP) | 600+ malicious packages | Undisclosed | OpenAI, TanStack, Mistral AI dependencies | | Jun 2026 | Polymarket (frontend) | Third-party vendor JS injection | $3M | <15 user wallets |
The common thread: none of these attacks exploited the target's smart contracts. Every one of them targeted the software supply chain — the libraries, SDKs, build pipelines, and vendor integrations that sit between users and the blockchain.
The crypto industry has spent years and hundreds of millions of dollars on smart contract auditing. Firms like Trail of Bits, OpenZeppelin, and Halborn have made on-chain code materially safer. According to CrowdFund Insider, compromised accounts and infrastructure attacks now account for more than 50% of all DeFi incidents by count — overtaking traditional smart contract exploits for the first time.
Chainalysis data from 2025 confirms the dollar-value picture is even more skewed: infrastructure attacks caused $2.2 billion of the $3.4 billion in total losses. Smart contract bugs — the category that receives the most audit attention — accounted for a diminishing share.
The problem is not that audits are worthless. The problem is that they cover one layer of a multi-layer stack. A typical DeFi frontend depends on:
None of these layers are covered by a smart contract audit. Most are not covered by any audit at all.
The npm registry — home to over 2.5 million JavaScript packages — has become the most consequential attack surface in Web3 security.
In May 2026, a campaign attributed to the group TeamPCP compromised over 600 packages on npm and PyPI, affecting dependencies used by OpenAI, TanStack, and Mistral AI, according to Palo Alto Networks' Unit 42 research. The campaign distributed what researchers called the "Mini Shai-Hulud" worm — malicious code that propagated across package dependency trees.
Separately, nine fake Polymarket packages were published to npm on May 20, 2026, by an account using a Proton Mail address. The packages falsely claimed wallet keys were "encrypted before they leave your machine." In reality, the code exfiltrated private keys to attacker-controlled servers, as documented by SafeDep.
The Axios attack in March 2026 demonstrated the scale risk. With approximately 100 million weekly downloads, a trojanized version of the HTTP client library harvested SSH keys, cloud credentials (AWS, Azure, GCP), Kubernetes tokens, .env files, API keys, and crypto wallet data while providing full remote shell access to affected systems.
These are not exotic, state-sponsored operations requiring nation-state resources. Many exploit the fundamental trust model of open-source package management: developers install packages, packages auto-update, and updated code runs with the same permissions as the application itself.
The Bybit breach of February 21, 2025 — $1.5 billion in 401,000 ETH drained in a single transaction — was the largest theft in cryptocurrency history. The FBI attributed the attack to TraderTraitor, its designation for North Korea's Lazarus Group cluster.
The attack path was a supply chain compromise of Safe{Wallet}, the multi-signature wallet infrastructure used by Bybit to manage its Ethereum cold storage. According to investigations by CrowdStrike and Mandiant, the attackers:
The core lesson: multi-signature wallets provide no additional security when the signing interface is compromised. Every signer saw the same fraudulent data.
CrowdStrike's 2026 Financial Services Threat Landscape Report documented that DPRK-nexus actors drove a 51% year-over-year increase in digital asset theft in 2025, stealing a reported $2.02 billion across the sector. The Lazarus Group has stolen over $6.75 billion in cryptocurrency since 2017, according to the FBI.
CrowdStrike further reported that FAMOUS CHOLLIMA, another North Korean APT cluster, doubled its operations using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks — extending the supply chain attack concept from code to personnel.
Several technical countermeasures exist, though none are comprehensive:
Subresource Integrity (SRI): Adds cryptographic hashes to script tags; the browser refuses to execute code if the hash doesn't match. Effective against CDN tampering, but useless when the compromise originates at the trusted source — as in the AppsFlyer SDK attack of March 2026, where the CDN itself was the attack vector.
Content Security Policy (CSP): Restricts which domains can serve executable code. Reduces attack surface but cannot prevent attacks through whitelisted third-party vendors — exactly the vector used against Polymarket.
npm lockfiles and pinned dependencies: Prevent automatic updates from pulling in compromised versions. Standard practice, but frequently ignored in frontend projects where developers run npm update without reviewing changelogs.
Runtime behavioral monitoring: Flags anomalous script behavior (unexpected network requests, unauthorized DOM manipulation) after execution. Tools like Blockaid detected the Ledger Connect Kit attack within minutes in December 2023. However, adoption remains low across the DeFi ecosystem.
Vendor security audits: The most direct mitigation for the Polymarket-style attack. Assessing third-party vendor security posture before granting code execution rights in production environments. According to the Verizon 2025 Data Breach Investigations Report, third-party involvement in breaches doubled from 15% to 30% in a single year — the largest single-year shift the report has ever recorded.
No single measure addresses the full attack surface. The shift requires defense-in-depth: vendor audits, pinned dependencies, SRI, CSP, runtime monitoring, and human verification of transaction details outside the potentially compromised interface.
The crypto industry has spent a decade hardening its smart contracts. That work has paid off: direct on-chain exploits are declining as a share of total losses. The attack surface has shifted to the software supply chain — the JavaScript dependencies, third-party vendors, build pipelines, and developer workstations that connect users to the blockchain.
This shift is not unique to crypto. The Verizon DBIR's doubling of third-party breach involvement, CrowdStrike's documentation of AI-enabled supply chain infiltration, and the TeamPCP campaign across npm all indicate a systemic trend affecting all software. Crypto is disproportionately targeted because the payoff is immediate: unlike traditional data breaches, stolen cryptocurrency is liquid and largely irreversible.
The economic implication is direct. Every dollar spent on smart contract auditing while ignoring vendor security, dependency management, and frontend integrity is a misallocation. The value distribution framework for Web3 security spending needs to reflect where the losses actually occur — and in 2025 and 2026, they occur overwhelmingly in the supply chain.
The Polymarket incidents — two breaches, two different vectors, neither touching smart contracts — are not anomalies. They are the new baseline.