QooryBeta
Back to narratives
SecurityActive
Conversation intelligence

Polymarket suffers supply chain attack via compromised third-party JS vendor

Polymarket lost approximately $3.1 million after attackers compromised a third-party JavaScript vendor used by its frontend. Malicious script injected into the site prompted users to approve fraudulent wallet transactions, draining pUSD stablecoins from up to 15 wallets.

Heat
82
Confidence
95%
Evidence
8
Updated

Why It Happened

The attacker exploited a supply chain weakness: the third-party JS vendor's code was not audited for security, allowing the injection of malicious logic that altered user wallet approval requests. Polymarket's smart contracts themselves were not breached.

Outcome So Far

Stolen funds (~$3.1M in pUSD) were swapped to 1,893 ETH, bridged from Polygon to Ethereum mainnet, and then laundered. No additional details on recovery or further actions have been confirmed.

Actors

Timeline order

Post
Parent event 01

X conversation update

1 related posts from @SlowMist_Team

Related posts@SlowMist_Team
@SlowMist_Team
Open on X4.4K views · 6 likes · 0 reposts

Post
Parent event 02

Halborn warns about supply chain attack risks

Halborn Security tweets that smart contract audits do not protect against supply chain attacks, citing the Polymarket incident as a clear example.

Related posts@__Raiders@HalbornSecurity
@__Raiders
Open on X1.0K views · 14 likes · 2 reposts
@HalbornSecurity
Open on X2.2K views · 4 likes · 1 reposts

Post
Parent event 03

X conversation update

3 related posts from @SlowMist_Team, @BullishTimes_, @HalbornSecurity

Related posts@SlowMist_Team@BullishTimes_@HalbornSecurity
@SlowMist_Team
Open on X11.2K views · 58 likes · 5 reposts
@BullishTimes_
Open on X290 views · 13 likes · 5 reposts
@HalbornSecurity
Open on X1.5K views · 2 likes · 4 reposts

Post
Parent event 04

X conversation update

1 related posts from @SlowMist_Team

Related posts@SlowMist_Team
@SlowMist_Team
Open on X12.7K views · 45 likes · 7 reposts

Post
Parent event 05

Polymarket hack disclosed

BullishTimes reports that Polymarket was drained for $3.1M via a compromised third-party JS vendor. The malicious script injected into the frontend caused users to approve unauthorized transfers. Funds were swapped to ETH and bridged to Ethereum mainnet.

Related posts@BullishTimes_
@BullishTimes_
Open on X56 views · 6 likes · 1 reposts