Decentralized prediction market platform Polymarket has confirmed a security breach affecting a number of its users. The incident, which led to user accounts being drained of funds, has been attributed to a vulnerability in a third-party authentication provider. Reports of the breach began surfacing earlier this week on social media platforms like X and Reddit, with affected users detailing significant financial losses.
Key Takeaways
-
Polymarket experienced a security breach impacting a small number of users.
-
The breach is attributed to a vulnerability in a third-party authentication provider.
-
Affected users reported drained account balances and unauthorized login attempts.
-
The platform states the issue has been resolved with no ongoing risks.
-
Polymarket will contact affected users directly.
User Account Breaches and Fund Drains
Users began reporting suspicious activity on their Polymarket accounts, including multiple unauthorized login attempts, despite their devices and other online services remaining secure. In several instances, users woke up to find their trading positions closed and their account balances depleted, often down to a mere $0.01. Some users noted that they had not clicked on any suspicious links and had two-factor authentication enabled on their email, suggesting a potential bypass at the provider level.
Focus on Third-Party Authentication Provider
Polymarket officially acknowledged the incident on its Discord channel, confirming that a "vulnerability introduced by a third-party authentication provider" was the cause. While the platform did not disclose the specific provider or the total value of assets stolen, it assured users that the issue has been resolved and no further risks remain. The company stated it would be reaching out to all impacted users.
Reports from users suggest that accounts signed up through Magic Labs, a service that facilitates email logins and automatically creates non-custodial Ethereum wallets, were particularly affected. This method is popular among new crypto users who may not have prior experience with digital asset wallets.
Past Security Incidents at Polymarket
This is not the first security challenge Polymarket has faced. In September 2024, users who logged in via Google accounts reported similar wallet drains, where attackers exploited "proxy" function calls to move funds. Polymarket at the time also investigated these incidents as potentially linked to third-party authentication providers. Additionally, a phishing campaign exploiting the platform's comment sections last month resulted in over $500,000 in user losses.
Sources
-
Polymarket cites third-party vulnerability in recent user account hack, The Block.
-
Polymarket says third-party provider caused reported account breaches — TradingView News, TradingView — Track All Markets.
-
Users report Polymarket breach tied to third-party authentication, MEXC.
-
Polymarket Security Breach: How a Third-Party Vulnerability Exposed User Funds, MEXC.
-
Polymarket Confirms User Account Breach, ForkLog.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.