Supplier Breach Turns Polymarket Site Into Theft Point
A third-party compromise turned Polymarket’s own website into the attack surface, so users could lose crypto during a normal visit instead of from a backend breach the platform could quietly contain. The break is on the client side. The page itself was altered for some users, and that is where the theft happened.
Polymarket says a vendor compromise let attackers inject malicious code into its site, confirmed that some users had funds stolen, and said it has contained the incident and will refund victims. PeckShield separately reported a phishing campaign against Polymarket users and estimated losses at around $3 million, with a blockchain analyst reporting more than 11 victims.
For operators of payment, wallet, and crypto platforms, the risk persists wherever third-party scripts or vendors can alter what users load in the browser. The trust boundary is the page, not just the server.