Security3 min read
Polymarket Customers Lose $3 Million in Supply-Chain Attack via Compromised Third-Party Vendor
Tags Infrastructure · Enterprise · Consumer
BleepingComputer·

Polymarket confirmed customers lost approximately $3 million in a supply-chain attack where hackers breached a third-party vendor and injected a malicious script into the prediction market platform's frontend. Polymarket committed to fully reimburse affected customers. CISA highlighted the incident as part of broader warnings about third-party dependency risks in web applications.
Technical significance
Frontend supply-chain attacks remain a critical vulnerability for web applications. This incident reinforces the need for strict Content Security Policy, subresource integrity checks, and third-party script monitoring in production applications.