
Polymarket, a cryptocurrency-based prediction market where users bet real money on the outcomes of world events, suffered a supply-chain attack that cost about 15 customers a combined $3 million. Hackers did not break into Polymarket’s own servers. Instead, they compromised a third-party vendor that supplies code to Polymarket’s website. Once the vendor’s systems were breached, the attackers inserted a hidden JavaScript snippet that appeared on the official Polymarket website. When affected users visited the site, the malicious code silently prompted their crypto wallets to approve transactions to accounts controlled by the attackers. The stolen funds — roughly $3 million in stablecoins — were then swapped for Ethereum and moved out. Polymarket has confirmed it will fully reimburse the affected customers.
This kind of attack is called a supply-chain compromise: the website you visit is legitimate, but malicious code was slipped into it by someone who hacked one of the vendors that supplies software to that site. You can do everything right — visit the official URL, check the padlock icon — and still be affected, because the threat entered through a back door you can’t see.
How to check if you’re affected
Affected products include any browser wallet extension — MetaMask, Coinbase Wallet, Rainbow, or similar — that was connected to polymarket.com during the attack window in late June 2026. To check whether you were impacted:
- Open your wallet’s Transaction History and look for any approvals or transfers you don’t recognise from late June 2026.
- Use a token-approval reviewer such as Revoke.cash to view and revoke any spending approvals that look suspicious.
- If you used Polymarket recently and notice unexpected activity, contact Polymarket support — the company has pledged to make affected users whole.
Going forward, consider keeping only the minimum funds needed in any wallet connected to betting or DeFi sites, with your main holdings in a separate account.
