BitcoinPolymarket Suffers $700K Breach After Internal Admin Wallet is...

Polymarket Suffers $700K Breach After Internal Admin Wallet is Compromised

-


Key Takeaways

Polymarket Faces Security Event: No User Funds Affected

Polymarket, one of the largest prediction markets in the world, experienced a security incident that alerted the platform’s community.

On Friday, blockchain intelligence researcher ZachXBT pointed to a possible compromise of the platform’s admin address on Polygon, noting that a significant amount of funds had already been drained.

Polymarket Security Incident

According to Bubblemaps, the attackers had been withdrawing 5,000 POL every 30 seconds, splitting the funds across 16 addresses, including centralized exchanges and other services. At the time of writing, reports indicated that the losses reached $700K.

The platform later acknowledged the security event, with Polymarket’s Shantikiran Chanal stating that they were “aware of the security reports linked to rewards payout,” but claiming that user funds and market resolution functions were safe.

“Findings point to a private key compromise of a wallet used for internal operations, not contracts or core infrastructure,” he specified. Furthermore, he explained that Polymarket was rotating its private keys for backend services and conducting an investigation for any internal secrets that could have been affected in the incident.

In April, Polymarket reached trading volumes of over 9 billion. An exploit in the platform’s contracts, depending on its nature, could put these funds in jeopardy.

Nonetheless, Josh Stevens, VP of Engineering at Polymarket, offered a short post-mortem report, shedding more light on the situation.

“We had a 6-year-old private key that was compromised. This was in the internal top-up config, which is why funds were being sent to it. We have rotated this key, revoked all prod permissions and are moving all PKs to KMS keys from now on,” he declared, coinciding with earlier reports that pointed to a private key being compromised.

“No polymarket or UMA contracts have been exploited. All user funds are safe, and using Polymarket.com is safe, so business as usual,” he concluded.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

Kash Patel’s clothing brand website shut down after reports it was hacked

The merchandise website of FBI director Kash Patel was taken offline on Friday after reports that it had...

Permanent Jobs Fall in UK as Temporary Placements Rise: Report

UK permanent job placements fell in April while temporary hires rose due to economic uncertainty and global conflict,...

Bitcoin Pizza Day 2026: Why This $1Bn Lesson Matters for Every New Investor

On May 22, 2010, a programmer named Laszlo Hanyecz traded 10,000 BTC for two pizzas worth roughly $41....

Advertisement

Bitcoin Loses Key Support Levels, HYPE Sets New ATH, Markets Brace for New Fed Chair: Weekly Recap

Aside from HYPE, the other two big weekly gainers are NEAR and VVV. Perhaps the most anticipated financial...

Must read

You might also likeRELATED
Recommended to you