Polymarket lost $3.1M in a phishing attack. Refunds are coming, but the vendor still hasn't been named.
Eleven user wallets, one supply-chain attack, and Polymarket still won't say which vendor let the attacker in.

CryptoVibe Desk · polymarket · phishing · hack

- →AMLBot reports a phishing attack drained approximately $3.1M in PUSD from 11 Polymarket wallets, with stolen funds bridged to Ethereum and converted to ETH.
- →The attack came through a third-party vendor connected to Polymarket, not the platform directly, leaving the exact entry point unresolved and other exposed apps unnamed.
- →Watch for on-chain refund transactions to the 11 affected wallets, and whether Polymarket publicly names the compromised vendor within two weeks of the June 27 disclosure.
- supply-chain attack → An attack that targets a vendor or service provider used by a company, not the company itself, letting attackers reach many users at once.
- PUSD → Polymarket's dollar-pegged token used to place bets on the platform.
Polymarket users lost an estimated $3.1M yesterday. AMLBot, a blockchain intelligence firm, says the funds were drained from 11 wallets in a supply-chain phishing attack.
The money moved quickly. Attackers bridged the stolen PUSD from Polygon to Ethereum and converted it to ETH, per The Defiant. No destination wallet cluster has been publicly identified.
The attacker got in through a third-party vendor connected to Polymarket, not through the platform directly. That vendor still hasn't been named, and that's the catch. The attack vector remains unresolved.
Polymarket has pledged full refunds to affected users. As of publication, there is no public timeline, no stated mechanism, and no on-chain evidence that money has moved.
If you were one of the 11 wallets, your funds are promised back. But every other app connected to the same unnamed vendor is still exposed.
Polymarket's choice to withhold the vendor name leaves every platform on the same stack exposed. The refund pledge has no on-chain footprint, still.
On-chain refund transactions to the 11 affected wallets, and a public naming of the third-party vendor, within two weeks of the June 27 disclosure.
Primary links and supporting reads used by the desk for this story.
Forward this.











