Polymarket Suffers $2.9M Breach After Script Injection, Users Set to Receive Full Refunds

26-Jun-2026 Crypto Economy

TL;DR:

  • Polymarket suffered a $2.94 million theft after a malicious script was injected into its frontend through a third-party provider.
  • At least 11 user wallets were drained in the attack, which stands as incident number 89 of the second quarter of 2026 for the crypto industry.
  • The platform confirmed it contained the issue, removed the affected dependency, and will reimburse all impacted users.

compromised third-party provider was the entry vector that allowed attackers to inject a malicious script into the frontend of Polymarket, the decentralized prediction markets platform. Blockchain analyst Specter identified the attack as a phishing scheme that resulted in the theft of approximately $2.94 million from at least 11 user wallets.

The platform communicated through X that the attack was contained and the affected dependency was removed. It also confirmed that all impacted users will be fully reimbursed.

Polymarket Joins the Long List of Victims

The Polymarket incident was recorded as number 89 of the second quarter of 2026, according to data from DefiLlama, making this period the quarter with the highest number of reported attacks by incident in the entire history of the sector. In June alone, losses from exploits reached $74.9 million across 29 reported incidents, surpassing the $60.5 million of May, though well below the $644 million recorded in April.

Among the most notable cases of the month are the Humanity Protocol exploit for $36 million, the attack on the Secret Network bridge for $4.7 million, two separate exploits on Aztec valued at $2.1 million each, and an attack on the Taiko bridge for $1.7 million. Over the total of the last 30 days, private key leaks accounted for 43% of total losses, consolidating their position as the dominant attack vector.

A History of Vulnerabilities

This is not the first security incident Polymarket has faced. Approximately one month ago, the platform disclosed that it had fallen victim to a $600,000 exploit attributed to a six-year-old private key used in internal operations. Josh Stevens, vice president of engineering at the company, stated at the time that contracts and user funds remained safe and that all permissions associated with that key had been revoked.

polymarket post

Despite the incidents, Polymarket holds more than $450 million in total value locked, representing a growth of 301% compared to the $112 million recorded a year ago, according to DefiLlama.

Also read: DeFi Hacks 2026: Why Auditing The Code No Longer Helps
WHAT'S YOUR OPINION?
Related News