📍Polymarket confirms a security incident – some accounts have been drained of funds
Polymarket confirms a security incident that caused some user accounts to have their entire balances drained. The project emphasizes that it is not a smart contract error or an on-chain protocol issue, but rather stems from a third-party login/authentication service.
📌 The vulnerability has been patched, and the incident is no longer occurring. Polymarket has not disclosed the number of affected accounts or damages, stating that they are directly contacting the relevant users.
📌 Many reports indicate that users did not click phishing links, did not expose their emails, but still had their accounts accessed and funds withdrawn → the weakness lies in the Web2 layer (login/OTP).
🔍 The protocol was not hacked, but users still lost money. This is a familiar paradox: Web3 is decentralized on the blockchain, yet risks are concentrated in Web2 onboarding. When control of the login is in the hands of a third party, the gateway to assets becomes a system vulnerability.
Polymarket confirms a security incident that caused some user accounts to have their entire balances drained. The project emphasizes that it is not a smart contract error or an on-chain protocol issue, but rather stems from a third-party login/authentication service.
📌 The vulnerability has been patched, and the incident is no longer occurring. Polymarket has not disclosed the number of affected accounts or damages, stating that they are directly contacting the relevant users.
📌 Many reports indicate that users did not click phishing links, did not expose their emails, but still had their accounts accessed and funds withdrawn → the weakness lies in the Web2 layer (login/OTP).
🔍 The protocol was not hacked, but users still lost money. This is a familiar paradox: Web3 is decentralized on the blockchain, yet risks are concentrated in Web2 onboarding. When control of the login is in the hands of a third party, the gateway to assets becomes a system vulnerability.

