:

POLYMARKET HIT BY $3M SUPPLY-CHAIN ATTACK

AI DESK1 MIN READ
FRI, JUN 26, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Polymarket customers lost an estimated $3 million after hackers injected malicious code into the platform's frontend through a compromised third-party vendor. The company plans to fully reimburse affected users.

The attack exploited a breach at a third-party vendor integrated with Polymarket's infrastructure, allowing attackers to inject malicious scripts directly into the platform's user interface. Customers unknowingly executed the code while accessing Polymarket, resulting in unauthorized fund transfers. Polymarket disclosed the incident and committed to covering the full $3 million loss for impacted users. The platform has since patched the vulnerability and is conducting a security review of its vendor dependencies. Supply-chain attacks represent a growing threat to crypto platforms and financial services. By targeting trusted third parties rather than companies directly, attackers can bypass security measures and gain access to large user bases. This incident underscores the risks of integrating external code and services without rigorous security vetting.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.

JUST NOWSecurity Desk

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.

2H AGOIndustry Desk

A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.

4H AGOSecurity Desk

The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.