NewsJune 20, 2026
Polymarket Pledges Refunds After Frontend Supply-Chain Attack
A compromised third-party frontend dependency reportedly led users to approve malicious transactions; Polymarket said affected users would be refunded.
In June 2026, a compromised third-party dependency injected malicious code into Polymarket’s frontend and prompted some users to approve fraudulent transactions. Reporting placed the loss at approximately $3.1 million in PUSD across a small number of wallets. Polymarket removed the affected dependency and pledged full refunds. The incident did not indicate a compromise of Polymarket’s core smart contracts.\n\nWhy it matters for traders: Interface and wallet-approval security can create losses even when underlying contracts remain intact. Users should verify transaction permissions and revoke suspicious approvals.\n\nSources: Polymarket incident statements and independent blockchain-security reporting, cross-checked on July 20, 2026.
Markets in this story
Automatically matched by topic
Written by hi