Polymarket customers lose $3 million in supply-chain attack
Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.
- Disclosed
- Last updated
- Blast radius
- Polymarket platform users; estimated $3 million in customer losses
- Ecosystems
- Attack vectors
- Affected entities
- PolymarketFrontend compromised via third-party vendor breach
Polymarket, a prediction market platform, suffered a supply chain attack in which malicious scripts were injected into its frontend. The attack was enabled by a breach at a third-party vendor that Polymarket relied upon, rather than a direct compromise of Polymarket's own systems.\n\nThe attack resulted in approximately $3 million in losses for Polymarket customers. The company responded by committing to fully reimburse all affected users for their losses.\n\nThis incident exemplifies third-party vendor risk in SaaS platforms, where dependencies on external vendors can create attack surface even when the primary service provider's security is sound.
Remediation
- Audit and strengthen third-party vendor security requirements and monitoring
- Implement Content Security Policy (CSP) headers to restrict script injection
- Deploy frontend integrity monitoring to detect unauthorized script injection
- Conduct forensic analysis to identify the compromised vendor and scope of breach
- Review and enhance vendor risk management and supply chain security practices
Sources
- Polymarket customers lose $3 million in supply-chain attack · BleepingComputer
Cite this entry
"Polymarket customers lose $3 million in supply-chain attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 26, 2026; last updated June 29, 2026. https://supplychainattack.org/incident/polymarket-customers-lose-3-million-in-supply-chain-attack-ldljc5
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activehigh
Ernst & Young data breach claimed by ShinyHunters extortion gang
ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.
ShinyhuntersOtherThird-party vendor breach - containedhigh
LastPass confirms data breach in Klue supply chain attack
LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.
OtherThird-party vendor breach - activehigh
Context.ai OAuth Token Compromise
Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.
OtherAccount takeoverThird-party vendor breach - containedcritical
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed to create unauthorized admin accounts on WordPress sites running BdThemes plugins. The attack targeted administrators' browsers to inject malicious configuration.
OtherUpdate-server compromise