시가 총액
24시간 볼륨
16099
암호화폐
58.01%
Bitcoin 공유

Polymarket users lose nearly $3 million in suspected phishing attack

Polymarket users lose nearly $3 million in suspected phishing attack


Cryptopolitan
2026-06-25 21:21:53

Popular on-chain analyst Specter just reported a major Polymarket breach today that stole up to $2.94 million from about 11 accounts combined. According to Specter , the stolen funds were originally held as PUSD (Polymarket’s USD-pegged collateral token), swapped into ETH and sent to a final address. While 11 victims have been identified so far, the final count may still increase as investigators continue to trace more transactions. Why always Polymarket? Polymarket has faced phishing and social engineering attacks since last year. Each one exploited different entry points but followed the same playbook: tricking users into handing over credentials, then clearing their wallets before they notice. Earlier this month, Polymarket’s VP of Engineering, Josh Stevens, addressed a case where a user was swindled out of more than $2 million. The victim had entered a one-time password into a fake website that looked exactly like Polymarket, which allowed the attacker to compromise the victim’s Magic Link wallet (an email-based login system), and drain their funds instantly. Stevens stressed that while the impact was massive, the breach took place on a scam site and did not stem from a flaw in Polymarket’s own platform. That attack came after a $520,000 drain from the platform’s UMA CTF Adapter contract on Polygon in May. According to on-chain investigator ZachXBT , the attack was caused by a compromised deployer key. Airdrop speculation may be fueling the threat The phishing risk facing Polymarket users is compounded by growing speculation around a potential POLY token airdrop. On June 25, X user Tiptop noted that Polymarket had quietly updated its FAQ page, removing language that previously stated the platform “does not have a token” and scrubbing references to having no plans for an airdrop or token generation. Polymarket CMO Matthew Modabber confirmed token and airdrop plans in an October 2025 interview, saying the team wanted to create “a token with true utility, longevity, and to be around forever,” as Cryptopolitan reported. That confirmation prompted users to adjust their trading behavior in hopes of qualifying for a future distribution. The hype around potential airdrops makes it easy for scammers to trick people with fake eligibility checkers and claim pages. Another round of airdrop speculation has started spreading on social media, as Web3 profiles have reported that Polymarket recently removed the explicit denial of an airdrop from its FAQ page. Polymarket faces other reputational headaches The risks on the platform have gone beyond phishing. Last December, SlowMist found a Polymarket copy-trading bot on GitHub embedded with malicious code meant to steal and transmit private keys to hackers. Another investigation conducted by StepSecurity in March also uncovered a compromised GitHub organization that was distributing fake trading bots designed to compromise user accounts. The platform also faces reputational headwinds. According to a Wall Street Journal investigation, Polymarket paid influencers around $2,000 to $3,000 per month to post scripted videos showing fake trading profits. Apparently, the influencers were told to hide that they were being paid, and even ordered to redo clips if they weren’t exciting enough. They were also instructed to make the fake winnings appear as if they were real, organic experiences. Combined with the phishing campaigns and malicious bot ecosystem, the pattern now creates doubts about user safety on a platform where prediction market open interest recently hit a record $1.48 billion, according to a16z Crypto data cited by Cryptopolitan . Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free .


면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.