Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Hackers Stole $3 Million from Polymarket Users via Compromised Third-Party Vendor

What Happened
Polymarket confirmed on Thursday, June 25, 2026, that a third-party vendor it relied on was compromised, allowing attackers to inject malicious code directly into the platform's website frontend. Users who interacted with the affected interface had their funds drained without any exploit of Polymarket's core smart contracts.
Blockchain monitoring firm PeckShield reported on X that the attack looked like a phishing campaign targeting Polymarket users, with losses estimated at roughly $3 million in cryptocurrency. Blockchain analyst Specter reviewed on-chain data and found the stolen assets originated as PUSD, Polymarket's own U.S. dollar-pegged stablecoin. The attacker converted the PUSD to approximately 1,893 ETH and bridged it from Polygon to Ethereum, a standard laundering technique used to obscure the trail, according to The Next Web.
Victim counts vary slightly across sources. PeckShield cited more than 11 victims. KuCoin and PANews, both citing Decrypt, put the number at around 15 accounts.
Supply Chain Attack, Not a Direct Hack
Polymarket's own infrastructure was NOT breached at the smart contract level. A vendor that Polymarket depended on was tampered with, and the malicious script rode in through that dependency. Polymarket said it has removed the affected dependency and "contained" the incident, according to its post on X.
Polymarket spokesperson Connor Brandi confirmed to TechCrunch that the breach led to funds being stolen. Brandi declined to name the compromised vendor or answer specific questions about the scope of the attack. The company has not publicly identified how many users were affected.
Second Incident in Two Months
This is NOT Polymarket's first security failure of 2026. In May, blockchain investigator ZachXBT flagged a separate incident in which roughly $520,000 to $700,000 was drained from Polymarket smart contracts on the Polygon network, according to The Next Web and PANews. That breach stemmed from a compromised six-year-old private key tied to an internal employee wallet used for top-ups and paying user rewards, not a platform-wide exploit.
Two distinct security failures within roughly two months at the same platform raises a legitimate question about how thorough Polymarket's vendor vetting and internal key management are.
A Brutal Week for Polymarket
The hack arrived at the worst possible time. On Sunday, the Wall Street Journal published an investigation finding that Polymarket had paid online creators to post deceptive videos showing fabricated bets and fake winnings. The Journal reviewed more than 1,100 videos and found that none of the wagers, which displayed nearly $2 million in supposed value, were placed on the live platform. Polymarket responded by saying it would audit its promotional content.
Beyond the fraud allegations: a Google engineer was charged last month with insider trading after reportedly using internal Google search data to profit more than $1 million on Polymarket predictions. And Spain blocked the platform in May over missing gambling licenses, according to The Next Web.
The Fairest Defense Available
Polymarket's defenders point out that supply chain attacks are among the hardest threats to defend against in software security. When a trusted third-party vendor is compromised, the victim platform has limited visibility into the breach until it manifests. Companies like SolarWinds and Okta have faced similar vectors, and the blame fell primarily on the attackers, not the platforms. Polymarket's decision to refund affected users in full, if it follows through, is also the right response. None of this is unique to crypto.
That said, the argument weakens given the May private key breach. A pattern of two incidents in rapid succession suggests systemic security gaps, not just bad luck.
What Comes Next
Polymarket has committed to full refunds for affected users, but as of June 25, 2026, no timeline for those refunds has been publicly stated and the company has not disclosed the identity of the compromised vendor. That vendor identification matters: other platforms that use the same dependency could be at risk right now and may not know it.
The stolen ETH has been consolidated into a single wallet address, according to PANews. Whether law enforcement has been engaged, and whether any blockchain forensics firms are actively tracing the funds, has not been confirmed by any source reviewed here.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.