Tools Crypto Exploit Tracker exploit-0026
Exploit record
Polymarket
- Loss
- $3M
- Attack vector
- Supply Chain
- Chain
- Polygon
- Sector
- DeFi
What happened
In late June 2026 Polymarket users lost about $3 million after a compromised third-party vendor was used to inject malicious JavaScript into the prediction market's front end.
The injected script ran silently in users' browsers on the legitimate site and prompted routine-looking wallet signatures that authorised unintended transfers; 11 user wallets were affected. Stolen funds were bridged from Polygon to Ethereum, swapped to roughly 1,893 ETH and consolidated into a single wallet. Polymarket's smart contracts were not exploited, and the company promised full refunds to victims holding its PUSD collateral.
Sources
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
