# Polymarket Pledges Full Reimbursement After $3M Phishing Attack

*Published June 29, 2026*
*Source: [https://www.securityweek.com/3-million-reportedly-stolen-in-polymarket-hack/](https://www.securityweek.com/3-million-reportedly-stolen-in-polymarket-hack/)*

## Executive Summary

Polymarket has promised to refund users after a security breach involving a third-party vendor led to the theft of $3 million in cryptocurrency. The breach involved a phishing attack that compromised the platform's frontend through a malicious script.

## Article

Polymarket, a decentralized cryptocurrency-based prediction market, is taking significant steps to address a recent security breach that resulted in the theft of approximately $3 million. The platform, which allows users to trade predictions on various real-world events, discovered that a third-party vendor had been compromised. This breach led to the injection of a malicious script into Polymarket's frontend, affecting some users.

In response to the incident, Polymarket has committed to fully reimbursing all affected users. However, specific details regarding the number of impacted users and the exact amount of cryptocurrency stolen remain unclear. The company has taken immediate action to contain the breach and has removed the compromised dependency from its systems.

Blockchain security firm PeckShield reported that the attacker executed the theft through a phishing campaign, successfully stealing pUSD, Polymarket's USDC-backed trading currency. The stolen funds were then moved from the Polygon network to Ethereum and converted into approximately 1,893 ETH. At least 11 victims have been identified so far, though the identity of the attacker remains unknown.

Polymarket has not provided any further details beyond their initial statement on social media. Efforts to reach out to the company for more information have not yielded additional comments at this time.
