:

POLYMARKET HIT BY $3M SUPPLY-CHAIN ATTACK

AI DESK1 MIN READ
FRI, JUN 26, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Polymarket customers lost an estimated $3 million after hackers injected malicious code into the platform's frontend through a compromised third-party vendor. The company plans to fully reimburse affected users.

The attack exploited a breach at a third-party vendor integrated with Polymarket's infrastructure, allowing attackers to inject malicious scripts directly into the platform's user interface. Customers unknowingly executed the code while accessing Polymarket, resulting in unauthorized fund transfers. Polymarket disclosed the incident and committed to covering the full $3 million loss for impacted users. The platform has since patched the vulnerability and is conducting a security review of its vendor dependencies. Supply-chain attacks represent a growing threat to crypto platforms and financial services. By targeting trusted third parties rather than companies directly, attackers can bypass security measures and gain access to large user bases. This incident underscores the risks of integrating external code and services without rigorous security vetting.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Researchers have identified 39 distinct methods for compromising passkey authentication, exploiting weaknesses beyond the underlying FIDO2 cryptography.

5H AGOSecurity Desk

A critical remote code execution vulnerability affecting all Chromium versions is currently being exploited in the wild. The flaw bypasses the browser's sandbox protection, allowing attackers to execute arbitrary code with full system access.

9H AGOSecurity Desk

Mullvad is discontinuing its public encrypted DNS servers and redirecting resources to sponsor Quad9, an alternative privacy-focused DNS provider. The move consolidates the privacy DNS landscape.

13H AGOIndustry Desk

Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.

16H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.