Polymarket Refunds Users After June 25 Frontend Hack Drains $3.1 Million From Wallets
Image: TradingView

Polymarket Refunds Users After June 25 Frontend Hack Drains $3.1 Million From Wallets

22 May, 2026.Crypto.15 sources

The story in 15 seconds

  • Polymarket's frontend breach drained about $3.1 million from fewer than 15 wallets.
  • Polymarket will fully refund all affected users.
  • A compromised third-party vendor enabled a malicious frontend script.

The divide · 1 of 3

How the theft mechanism is framed (frontend malicious script vs phishing).

Different labels shift blame between malware and phishing tactics.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
15 sources
Western Alternative
10
Other
3
Western Mainstream
1
Local Western
1

Western Alternative

@coindesk
@coindesk

Polymarket hack updated to $3.1 million days after the platform promised users full refunds

27 June, 2026

Read the original →
Bitget
Bitget

THORChain exploit tied to malicious node and GG20 flaw

22 May, 2026

Read the original →
CoinDesk
CoinDesk

ZachXBT reports a $520,000 exploit on Polymarket on Polygon; the team says the funds are safe.

22 May, 2026

Read the original →
CoinDesk
CoinDesk

Alleged insiders are making more than $1.2 million on Polymarket ahead of the U.S. strike on Iran.

27 June, 2026

Read the original →
Cointelegraph
Cointelegraph

Polymarket team says user funds safe as exploit losses climb above $600K

22 May, 2026

Read the original →
Crypto Briefing
Crypto Briefing

Polymarket updates hack loss to $3.1M, pledges full refunds to affected users

27 June, 2026

Read the original →
CryptoPotato
CryptoPotato

Polymarket to Refund Users After Hackers Steal $3M in Frontend Attack

26 June, 2026

Read the original →
CryptoRank
CryptoRank

$3M Exploit Hits Polymarket: Users to Receive Full Refunds After Third-Party Breach

26 June, 2026

Read the original →
MEXC Exchange
MEXC Exchange

Polymarket Clarifies $660,000 Drain Was Not a Contract Exploit

22 May, 2026

Read the original →
TradingView
TradingView

Polymarket team says user funds safe as exploit losses climb above $600K

22 May, 2026

Read the original →

Other

BanklessTimes
BanklessTimes

Polymarket Suffers $600K Private Key Breach, User Funds Safe

22 May, 2026

Read the original →
SecurityWeek
SecurityWeek

$3 Million Reportedly Stolen in Polymarket Hack

26 June, 2026

Read the original →
The Currency analytics
The Currency analytics

Polymarket Hit by $600K Exploit Tied to Private Key Breach, User Funds Safe

22 May, 2026

Read the original →

Western Mainstream

Benzinga
Benzinga

Polymarket Says 'Contained And Removed' Malicious Bug After Third-Party Vendor Was Hacked; Will Refund Im

26 June, 2026

Read the original →

Local Western

KuCoin
KuCoin

Polymarket LP Incentive Mechanism: Four Key Points and Cost Traps

22 May, 2026

Read the original →

Full story

Frontend vendor breach

Polymarket said a compromised third-party vendor injected a “malicious script” into its frontend for some users, draining about $3.1 million in user funds from up to 15 wallets after a security breach on June 25.

Polymarket hack updated to $3

@coindesk@coindesk

The platform said the attack targeted Polymarket’s frontend through a compromised third-party vendor, and that its core smart contracts were never actually breached.

Image from @coindesk
@coindesk@coindesk

On-chain analysts tracked stolen pUSD as it was swapped for ETH and consolidated into fewer wallets, with PeckShield, SpecterAnalyst, and GoPlus Security cited for tracking activity.

Benzinga reported Polymarket contained the breach after discovering the vendor compromise on Thursday morning and said it was “refunding them in full,” while SecurityWeek said Polymarket promised to fully refund users affected by the attack.

In a separate incident earlier this year, Polymarket said a May 22 breach drained between $520,000 and $700,000 from an internal wallet on the Polygon network, with user funds not affected.

Refund pledge and estimates

Bubblemaps said the attacker drained nearly $3 million from under 15 wallets, and SecurityWeek reported PeckShield estimated roughly $3 million worth of pUSD was stolen via a phishing campaign.

CoinDesk later described the hack as being updated to $3.1 million days after Polymarket promised full refunds, citing AMLBot’s update that the theft was from 11 user wallets and that the assets were stolen from Polygon and bridged to Ethereum.

Image from BanklessTimes
BanklessTimesBanklessTimes

Polymarket Traders, using an official Polymarket Traders badge, told users on X that “We’ve contained it & removed the affected dependency,” and said it was “contacting impacted users & refunding them in full.”

CoinDesk also quoted Polymarket’s post: “We've contained it and removed the affected dependency. We're contacting impacted users and refunding them in full.”

Specter Analyst was also cited by CoinDesk, saying “It appears there may be a phishing attack targeting Polymarket users, with estimated losses of $2.94M so far.”

Broader scrutiny and risks

Beyond the June frontend incident, CoinDesk reported Polymarket is under investigation in connection with false or deceptive marketing practices, following a Wall Street Journal article about deceptive social media promotions.

Polymarket said it successfully contained a security breach after discovering a third-party vendor had been compromised on Thursday morning

BenzingaBenzinga

CoinDesk also tied the hack to broader regulatory scrutiny, noting that the news followed reports that the prediction platform is under federal investigation and that U.S. regulators weigh how to police insider trading on event contracts.

In a separate thread of market conduct, CoinDesk reported that Kalshi suspended and charged two users for insider trading, including a visual-effects designer for Beast Games by MrBeast, and said Kalshi fined him more than $20,000.

The same CoinDesk reporting described how the CFTC issued a notice warning that insider trading on event contracts could violate U.S. law, and quoted Chairman Mike Selig calling exchanges the first line of defense.

Meanwhile, the Crypto Briefing framed the repeated user-fund losses as a regulatory implication, stating that “Repeated security breaches that result in user fund losses tend to attract the kind of regulatory attention that no crypto platform wants.”

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Crypto