Polymarket Says Users Will Be Refunded After $2.9M Frontend Theft

Polymarket said a vendor compromise allowed attackers to inject a malicious script into its frontend, leading to a $2.9 million theft. The company said it contained the incident, removed the affected dependency and will refund users.

Polymarket Says Users Will Be Refunded After $2.9M Frontend Theft

What happened?

Polymarket said a vendor compromise allowed attackers to inject a malicious script into its frontend, leading to a $2.9 million theft. The company said it contained the incident, removed the affected dependency and will refund users.

Why it matters

Polymarket said it was hit by a compromise that led to $2.9 million being stolen from users after attackers injected a malicious script into the platform’s frontend. The prediction market platform said the issue was contained and that users affected by the theft will be refunded.

Polymarket said it was hit by a compromise that led to $2.9 million being stolen from users after attackers injected a malicious script into the platform’s frontend. The prediction market platform said the issue was contained and that users affected by the theft will be refunded.

The incident matters because it points to a recurring risk for crypto platforms: even when core systems are not described as breached, compromised third-party dependencies can create a path to user losses through the interface people rely on to interact with a service. For users, the episode is a reminder that frontend and vendor security can be as important as smart contract or wallet security.

According to the supplied report, Polymarket removed the affected dependency after identifying the compromise. The company also said it had contained the malicious activity, limiting the immediate impact of the attack.

The theft adds to broader concerns around supply-chain security in crypto, where injected scripts or compromised vendors can expose users during routine platform interactions. In this case, Polymarket’s stated response centers on containment, dependency removal and reimbursement for affected users.

No additional details were provided in the supplied material about the attackers, the exact number of affected users or the timing of the refunds. Polymarket’s commitment to reimburse users is the central user-facing outcome disclosed in the source.

Source: Cointelegraph

Keep exploring

Related stories

Bitget to Leave Japan and Close Remaining Positions by Year-End

Bitget to Leave Japan and Close Remaining Positions by Year-End

Bitget plans to exit the Japanese market and close all remaining positions by the end of the year. The move adds to ongoing shifts among crypto companies navigating Japan’s regulatory environment.

Read
State of Crypto countdown highlights key industry developments

State of Crypto countdown highlights key industry developments

CoinDesk’s State of Crypto coverage counts down recent developments shaping the crypto policy and market landscape. The report frames these changes as important for how companies and participants navigate the sector.

Read
Strategy Keeps STRC Dividend at 12%

Strategy Keeps STRC Dividend at 12%

Strategy said it is holding the dividend on its STRC preferred stock at 12%. The decision keeps the payout unchanged for investors in the company’s yield-focused security.

Read