Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Polymarket customers lose $3M in supply-chain attack

A supply-chain attack on the Polymarket prediction market platform resulted in customers losing approximately $3 million. The attackers compromised a third-party service used by Polymarket to steal funds from users' accounts.

Background

- Polymarket is a popular crypto-based prediction market platform where users bet on the outcomes of real-world events (e.g., elections, sports). It runs on the Polygon blockchain and saw massive growth during the 2024 US election cycle. - A "supply chain attack" means the attackers didn't hack Polymarket directly; instead, they compromised a third-party service or software that Polymarket relied on, injecting malicious code to steal user funds. - $3 million in crypto was stolen from users who had approved certain token contracts — likely via a "wallet drainer" script hidden inside a trusted integration. This type of attack exploits the trust users place in front-end interfaces. - The incident highlights a growing vulnerability in DeFi (decentralized finance): even if a smart contract is secure, the web interface or supporting infrastructure can be compromised, leading to mass theft of approved tokens.