Polymarket Confirms Supply Chain Attack, $3 Million Stolen
Polymarket, a cryptocurrency-based prediction market, confirmed a supply chain attack.
Key points
- Polymarket suffered a supply chain attack.
- Malicious JavaScript injected via a third-party frontend vendor.
- Approximately $3 million stolen from user accounts.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Jun 29, 2026
- Updated
- Jun 30, 2026
- Confidence
- Medium
- Evidence
- 4 sources
Structured assessment
Signal analysis
It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch exposure paths that could affect data, operations or third-party trust.
- Source type: supplier or third-party involvement
Business impact
- Impact area
- Unknown
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
Polymarket, a cryptocurrency-based prediction market, confirmed a supply chain attack. A breach of a third-party frontend vendor led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent transactions, resulting in approximately $3 million being stolen from fewer than 15 accounts. The backend systems remained unaffected.
When was this signal reported?
Shadow Tier lists Jun 29, 2026 as the signal date.
Which organization is connected to this signal?
Polymarket is the organization connected to this public signal.
Explore Polymarket