Polymarket customers lose $3 million in supply-chain attack
Polymarket, a prediction market platform, will reimburse roughly $3 million to customers after attackers compromised a third-party vendor and injected malicious code into the platform's frontend, draining user funds. The company says it will cover all losses from the incident.
Why this matters: The attack did not come through Polymarket's own code. It came through a vendor they trusted. That is the supply-chain problem in plain terms: you can do everything right on your end and still get hit through someone else's door. Users had no way to see the risk. The script looked like part of the site because, technically, it was. Reimbursement is good. But the real issue is that platforms need to own the security of everything their users encounter, including the third-party code running quietly in the background.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.