On June 25, 2026, attackers injected malicious JavaScript into Polymarket's frontend through a compromised third-party vendor, draining approximately $3.1 million in pUSD from 11 user wallets. Blockchain intelligence firm AMLBot traced the stolen funds from Polygon to Ethereum, where they were sw...
"There are no user losses." — William LeGate, Growth Lead, Polymarket
On June 25, 2026, attackers injected malicious JavaScript into Polymarket's frontend through a compromised third-party vendor, draining approximately $3.1 million in pUSD from 11 user wallets. Blockchain intelligence firm AMLBot traced the stolen funds from Polygon to Ethereum, where they were swapped into roughly 1,893 ETH and parked across three fresh wallets. The attack lasted a matter of hours before Polymarket contained the breach and removed the affected dependency.
The incident marks the second security breach at Polymarket in 35 days — following a $700,000 internal operations wallet compromise on May 22, 2026, caused by a six-year-old private key that had never been rotated. Neither breach exploited smart contract logic. Both targeted operational infrastructure: vendor code in June, key management in May. The pattern underscores a structural reality across crypto platforms: protocol-layer security has improved; everything around it has not.
Polymarket committed to full refunds for all impacted users. The attack occurred during peak platform activity tied to the 2026 FIFA World Cup, with World Cup winner markets alone generating $3.3 billion in cumulative volume. Monthly unique wallets on the platform had nearly tripled to 840,000 by early 2026. The platform, valued at $8 billion as of April 2026 with $2.3 billion in total funding and a CFTC-regulated U.S. arm, is the largest prediction market globally by volume.
Early on June 25, 2026, a third-party vendor used by Polymarket was compromised. Through that breach, attackers injected malicious JavaScript into the platform's frontend — the user-facing website layer — which was then served to users interacting with the site during a critical window.
The attack did not target Polymarket's smart contracts, backend infrastructure, or on-chain settlement logic. Instead, the malicious script intercepted user interactions at the browser level. When affected users connected their wallets and attempted standard platform operations, the injected code prompted them to sign or approve fraudulent transactions. These approvals granted the attacker access to drain pUSD — Polymarket's USDC-backed trading currency — directly from connected wallets.
According to AMLBot's forensic analysis, the attack leveraged malicious EIP-7702 delegated execution. EIP-7702, introduced as part of Ethereum's Pectra upgrade, allows externally owned accounts (EOAs) to temporarily delegate execution to smart contract code. In legitimate use, this enables account abstraction features such as transaction batching and gasless operations. In this case, the attacker induced victims to sign a single authorization tuple that granted execution control, bypassing the need for individual transaction approvals.
Blockchain analytics firm Bubblemaps confirmed the damage was limited to approximately 15 accounts. Polymarket discovered the compromise, removed the affected dependency, and contained the breach within hours.
AMLBot's on-chain investigation provided the most granular accounting of the attack's financial flow:
0xe65b1C586757c5510B60F998Eebb14C1eF71E1eDThe attacker moved funds rapidly, bridging cross-chain within minutes of the initial drains. The use of Relay for the USDC.e conversion and a Polygon-to-Ethereum bridge suggests a pre-planned extraction route designed to reach Ethereum's deeper liquidity pools and more established mixer/obfuscation infrastructure.
Blockchain security firm PeckShield independently confirmed the loss figure at approximately $3 million. The slight variance between PeckShield's $3 million estimate and AMLBot's $3.1 million figure reflects rounding differences and the timing of on-chain snapshots.
As of June 27, 2026, the stolen ETH remained parked and had not been moved through mixing services, according to CoinDesk reporting.
The June breach was not an isolated event. On May 22, 2026, Polymarket suffered a separate security incident when an attacker exploited a compromised private key to drain approximately $700,000 from an internal operations wallet on the Polygon network.
The attacker withdrew funds in batches of roughly 5,000 POL (Polygon's native token) approximately every 30 seconds, quickly moving assets before the platform could react. Total losses comprised approximately $458,000 in USDC and more than $200,000 in POL from the UMA CTF Adapter contract.
Polymarket developer Josh Stevens confirmed at the time that the incident was "not a contract hack" but rather a compromise of an old private key — reportedly six years old — that had never been rotated to a modern key management system. The private key predated Polymarket's current security infrastructure. Following the incident, Polymarket announced plans to migrate all private keys to a Key Management Service (KMS).
The May incident did not affect user funds. But it exposed a gap in operational security hygiene: a key created in 2020, when Polymarket was a nascent startup, still had signing authority over production infrastructure in 2026, when the platform was processing billions in monthly volume.
The security incidents occurred against the backdrop of Polymarket's rapid growth into one of crypto's most widely used consumer applications:
| Metric | Figure | Source | |---|---|---| | Valuation | $8 billion (April 2026) | Bloomberg | | Total funding raised | $2.3 billion across 7 rounds | Tracxn | | Largest investor | ICE (NYSE parent), $1.6B total stake | PR Newswire | | Monthly unique wallets | 840,000 (February 2026) | TRM Labs | | Global prediction market volume | ~$24 billion/month (April 2026) | Pew Research | | Polymarket + Kalshi market share | 85–90% of global volume | Pew Research | | World Cup winner market volume | $3.3 billion cumulative | KuCoin | | Regulatory status (U.S.) | CFTC Designated Contract Market | CFTC |
The timing of the June attack is notable. The 2026 FIFA World Cup began on June 11, 2026, driving a surge in Polymarket trading activity. World Cup-related markets generated $66 million in 24-hour transaction volume with $352.7 million in liquidity at the time of the attack. A platform handling that volume of real-time user interactions presents a larger attack surface — more connected wallets, more active sessions, more opportunities for malicious script injection to reach users.
Polymarket operates a CFTC-regulated U.S. arm via an Amended Order of Designation issued November 25, 2025. The company is also seeking approval to lift restrictions on its main international platform for U.S. users, which would further expand its user base and regulatory obligations.
The Polymarket attack fits within a broader pattern of supply chain attacks targeting crypto frontends in 2026. Rather than attempting to exploit audited smart contract code — which has become progressively harder — attackers are targeting the softer layers: vendor dependencies, npm packages, frontend code, and developer tooling.
Key incidents in 2026 include:
Axios npm compromise (March 2026): The widely used JavaScript HTTP client, with over 100 million weekly npm downloads, was compromised when an attacker hijacked the lead maintainer's npm account. Two malicious versions deployed a cross-platform remote access trojan. According to Palo Alto Networks' Unit 42, the attack had widespread impact across both crypto and traditional applications.
TrapDoor campaign (May 2026): Socket researchers identified more than 34 malicious packages across npm, PyPI, and Crates.io, specifically targeting crypto, DeFi, and AI developers with credential-harvesting payloads. The campaign spanned three package ecosystems simultaneously.
ethers-jss and coinbase-wallet-utils (May 2026): Two malicious npm packages impersonating legitimate cryptocurrency development utilities were published on May 9, 2026, targeting Web3 developers.
A September 2025 Sygnia report documented that npm supply chain operations can move from package publication to active crypto-draining malware deployment in as little as 16 minutes.
This reflects a structural shift in the crypto threat landscape. As an existing webthreepedia comparative analysis noted, 76% of crypto losses in Q2 2026 stemmed from supply chain and operational failures rather than smart contract exploits. The Polymarket incident is a direct manifestation of this trend applied to a consumer-facing prediction market.
The economic logic is straightforward: auditing and formally verifying on-chain code has become standard practice. But the frontend — the browser-based interface where users sign transactions — relies on a complex web of third-party JavaScript dependencies, CDNs, and vendor integrations that are rarely subjected to equivalent scrutiny. The attack surface has migrated from the protocol layer to the application layer.
Polymarket committed to covering the $3.1 million in user losses out of corporate funds. This decision has several economic implications:
Direct cost: $3.1 million — material but manageable for a platform with $2.3 billion in funding and an $8 billion valuation. The loss represents approximately 0.04% of the platform's valuation.
Reputational cost: More difficult to quantify. The attack occurred during peak World Cup engagement, when Polymarket was onboarding new users at scale. Two breaches in 35 days — regardless of user-fund impact — erode the trust proposition that prediction markets depend on. Users must believe their wallets are safe when connected to the platform.
Insurance gap: Unlike traditional CFTC-regulated exchanges, which participate in clearing and guaranty fund frameworks, prediction markets operating on-chain have limited formal insurance mechanisms. Polymarket's ability to self-fund the $3.1 million refund is a function of its venture capital cushion, not a structural safety net.
Vendor accountability: The identity of the compromised third-party vendor has not been publicly disclosed. The economic relationship between platform operators and their frontend dependency providers remains largely opaque. There is no standardized framework for vendor security auditing or liability allocation in the crypto frontend supply chain.
The breach introduces questions for Polymarket's regulatory standing. As a CFTC Designated Contract Market, Polymarket is subject to the same core requirements as traditional futures exchanges, including self-regulatory obligations related to market supervision and system safeguards.
CFTC Regulation System Safeguards (17 CFR § 38.1051) requires DCMs to maintain a program of risk analysis and oversight with respect to their operations and automated systems. The scope of "automated systems" in the context of blockchain-based platforms — particularly regarding third-party frontend vendors — remains an open question.
The platform's application to extend its main international exchange to U.S. users could face additional scrutiny following two breaches in rapid succession. Regulators typically evaluate operational resilience as part of market access decisions.
More broadly, the incident highlights a gap in crypto regulatory frameworks: most oversight focuses on custody, trading, and settlement. Frontend security — the actual interface through which users authorize transactions — falls into a gray area between cybersecurity regulation and financial market oversight.
$3.1 million was stolen from 11 Polymarket user wallets on June 25, 2026, via a supply chain attack on a third-party frontend vendor. No smart contracts were exploited.
The attack leveraged malicious EIP-7702 delegated execution, allowing the attacker to gain execution control through a single user authorization rather than individual transaction approvals.
This was Polymarket's second breach in 35 days. The May 22 incident — a $700K drain from an internal wallet via a six-year-old private key — exposed legacy key management gaps.
Frontend supply chain attacks represent the dominant attack vector in 2026. The shift from protocol-layer exploits to application-layer compromises reflects improved smart contract security and lagging operational security standards.
Polymarket committed to full user refunds, funded from corporate reserves. The $3.1 million cost represents 0.04% of the platform's $8 billion valuation.
Regulatory exposure is uncertain. As a CFTC Designated Contract Market, Polymarket's system safeguard obligations may extend to frontend vendor management, but the regulatory framework has not been tested on this specific attack vector.
The Polymarket frontend attack is a case study in the migration of crypto risk. The protocol layer — smart contracts, on-chain settlement, validator economics — has benefited from years of auditing, formal verification, and billion-dollar bug bounty programs. The application layer — frontend code, vendor dependencies, key management, developer tooling — has not received equivalent investment.
For a platform processing $24 billion in monthly sector-wide prediction market volume, valued at $8 billion, and regulated by the CFTC, $3.1 million in user losses is financially immaterial. The refund commitment mitigates direct user harm. But the incident surfaces a deeper structural question: as crypto platforms scale to serve millions of users through browser-based interfaces, who is responsible for the security of the JavaScript dependency chain between a user's wallet and the underlying protocol?
The answer, for now, is no one in particular. The compromised vendor remains unnamed. The liability framework is undefined. The regulatory requirements are ambiguous. Two breaches in five weeks at the industry's most prominent prediction market suggest this ambiguity carries real cost.