Post
X conversation update
1 related posts from @SlowMist_Team
Polymarket lost approximately $3.1 million after attackers compromised a third-party JavaScript vendor used by its frontend. Malicious script injected into the site prompted users to approve fraudulent wallet transactions, draining pUSD stablecoins from up to 15 wallets.
The attacker exploited a supply chain weakness: the third-party JS vendor's code was not audited for security, allowing the injection of malicious logic that altered user wallet approval requests. Polymarket's smart contracts themselves were not breached.
Stolen funds (~$3.1M in pUSD) were swapped to 1,893 ETH, bridged from Polygon to Ethereum mainnet, and then laundered. No additional details on recovery or further actions have been confirmed.
1 related posts from @SlowMist_Team
Halborn Security tweets that smart contract audits do not protect against supply chain attacks, citing the Polymarket incident as a clear example.
3 related posts from @SlowMist_Team, @BullishTimes_, @HalbornSecurity
1 related posts from @SlowMist_Team
BullishTimes reports that Polymarket was drained for $3.1M via a compromised third-party JS vendor. The malicious script injected into the frontend caused users to approve unauthorized transfers. Funds were swapped to ETH and bridged to Ethereum mainnet.