
Polymarket experienced a $2.9 million theft due to a third-party vendor compromise. The platform has assured users that they will be fully refunded.
A third-party vendor compromise allowed attackers to inject a malicious script into Polymarket's frontend, resulting in losses estimated at $2.94 million from at least 11 user wallets. The platform confirmed that the compromise has been contained and the affected dependency removed. Users will be fully refunded for their losses.