Polymarket To Refund Users After Fraudsters Swipe Millions Into Websites



In short

  • Hackers exploited another vendor to steal nearly $3 million from a handful of Polymarket users.
  • Polymarket says the issue has been resolved and affected users will be refunded in full.
  • This marks the second security incident for the platform in two months.

One of Polymarket’s third-party vendors went down on Thursday, the prediction market said, leaving its site vulnerable to a breach that analysts said could have cost millions of dollars in losses to platform users.

Polymarket declined to comment when reached Decryptand he did not publicly say which of his sellers had been deceived. But the attack allowed hackers to inject malicious code into the futures market, the company said. X post.

In the end, the fraudsters stole $3 million from customers.

Developers at Bubblemaps noted that the potential damage from the hack was limited, with less than 15 accounts affected. The blockchain research firm did not immediately respond Decryptrequest for comments.

Polymarket said it is in the process of fully refunding affected customers, and that the front issue has been found and removed.

It is not yet clear what measures the prediction market will take to prevent it from happening in the future, as it depends on some external, third-party businesses that appear to be directly involved in the site’s operations.

The attackers appear to have stolen money from Polymarket customers’ wallets that contained pUSD, Polymarket’s dollar-denominated stablecoin backed by USDCwhich is used to manage all transactions on the platform. He then converted the stolen money into ETH, making it Ethereum bagwhere, as in writing, they remain.

Last month, Polymarket suffered again to hackof a wallet used by company employees to add and pay user fees. The theft cost the company nearly $700,000, and may have been caused by a lack of privacy. It did not appear to affect the company’s infrastructure or pose a significant risk, analysts said at the time.

Both the use case and the current one, however, show the potential for hackers to penetrate large companies at the edge, even with advanced protocols that are secure.

Daily Debrief A letter

Start each day with top stories right here, including originals, podcasts, videos and more.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *