Skip to main content
Back to overview
Medium

Polymarket Confirms Supply Chain Attack, $3 Million Stolen

Polymarket, a cryptocurrency-based prediction market, confirmed a supply chain attack.

Key points

  • Polymarket suffered a supply chain attack.
  • Malicious JavaScript injected via a third-party frontend vendor.
  • Approximately $3 million stolen from user accounts.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Partner actor

Possible third-party involvement

03

Potential impact

Potential business exposure

Impact remains under assessment

Published
Jun 29, 2026
Updated
Jun 30, 2026
Confidence
Medium
Evidence
4 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible third-party involvement

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: supplier or third-party involvement

Business impact

Potential business exposure
Impact area
Unknown

Mentioned entities

PolymarketPolymarket Confirms Supply Chain AttackMillion Stolen PolymarketJavaScriptAttackersPolymarketMalicious JavaScriptApproximately

Quick context

Questions about this signal

What happened in this signal?

Polymarket, a cryptocurrency-based prediction market, confirmed a supply chain attack. A breach of a third-party frontend vendor led to malicious JavaScript being injected into its website. Attackers tricked users into approving fraudulent transactions, resulting in approximately $3 million being stolen from fewer than 15 accounts. The backend systems remained unaffected.

When was this signal reported?

Shadow Tier lists Jun 29, 2026 as the signal date.

Which organization is connected to this signal?

Polymarket is the organization connected to this public signal.

Explore Polymarket