YFarmX

Tools Crypto Exploit Tracker exploit-0026

Exploit record

Polymarket

Loss
$3M
Attack vector
Supply Chain
Chain
Polygon
Sector
DeFi

What happened

In late June 2026 Polymarket users lost about $3 million after a compromised third-party vendor was used to inject malicious JavaScript into the prediction market's front end.

The injected script ran silently in users' browsers on the legitimate site and prompted routine-looking wallet signatures that authorised unintended transfers; 11 user wallets were affected. Stolen funds were bridged from Polygon to Ethereum, swapped to roughly 1,893 ETH and consolidated into a single wallet. Polymarket's smart contracts were not exploited, and the company promised full refunds to victims holding its PUSD collateral.

Sources

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026