Hackers Drain Over $600K in Crypto From Polymarket: Details

Polymarket suffered a major security breach after attackers drained up to $660K in POL and USDC, splitting the stolen funds across 15 wallets.
Senior Editor
Crypto hacker sentenced over $250 million crypto heist
Crypto hacker sentenced over $250 million crypto heist

Key Points

Attackers drained between $520K and $660K from a compromised Polymarket operational wallet using repeated 5,000 POL transfers every 30 seconds.
Blockchain investigator ZachXBT first identified the exploit, while reports showed the attacker split funds across roughly 15 wallets and routed some through ChangeNOW.
Polymarket confirmed user funds and market resolution systems remain safe, blaming the incident on a compromised private key rather than a smart contract vulnerability.

Leading prediction market giant Polymarket has suffered a major security breach. Attackers targeted an internal wallet with compromised private keys and reportedly siphoned funds gradually over several hours. The attackers drained roughly $520,000 to $660,000 worth of crypto assets in the exploit.

Blockchain investigator ZachXBT was among the first to identify the exploit. According to on-chain data from PeckShieldAlert, the attacker removed roughly 5,000 POL tokens every 30 seconds before distributing the stolen funds across approximately 15 separate wallets. The breach has quickly gained attention due to Polymarket’s growing influence as one of the largest blockchain-based prediction platforms.

Attackers Slowly Drain Funds From Compromised Wallet

Initial reports suspected the compromised component was tied to Polymarket’s UMA CTF adapter infrastructure on Polygon. However, Polymarket has issued a public response through engineer Shanti Kiran, blaming the exploit on a compromised wallet used for internal operations. The wallet had a 6-year old private key, which the exploiter must have found, enabling them to siphon the assets.

Reports estimate the attacker drained approximately $458,000 in USDC and roughly $199,700 worth of POL tokens. Combined estimates place total losses between $520,000 and $660,000. Meanwhile, at the time of reporting, the drainage activity appeared to have stopped.

The attack also unfolded gradually. On-chain records showed repeated transfers occurring every few seconds or minutes. In many cases, the attacker removed close to 5,000 POL per transaction, every 30 seconds. The repeated small transfers likely helped the attacker avoid immediate detection while steadily draining funds over time.

Polymarket Attacker Siphons $660,000 in POL And USDC
Polymarket Attacker Siphons $660,000 in POL and USDC

Investigators also found that the attacker fragmented the stolen assets across roughly 15 different wallet addresses shortly after the exploit. Portions of the funds moved through swaps and routing services such as ChangeNOW. Attackers often split stolen assets across multiple wallets to complicate blockchain tracing efforts and reduce the risk of asset freezes.

Polymarket Says User Funds Remain Safe

According to Polymarket’s statement, user funds and market resolution systems remain unaffected. Revealing the private key compromise that led to the exploit, the statement attempted to assuage fears about Polymarket’s core smart contracts or prediction market infrastructure. The company also confirmed it is rotating backend keys and investigating whether any additional internal secrets may have been compromised.

The distinction is important because it suggests the breach stemmed from operational security weaknesses instead of a direct smart contract exploit. Many of this year’s crypto attacks have targeted similar infrastructure, as well as backend systems and admin permissions.

Recent industry data from PeckShield showed that crypto bridge exploits alone have already caused more than $328 million in losses this year. Attackers increasingly focus on operational vulnerabilities because major smart contracts now undergo heavier auditing and formal security reviews.

Disclaimer: CoinRemark is an independent digital magazine focused on delivering timely news, analysis, and opinion about the cryptocurrency and blockchain industry. While CoinRemark may collaborate with partners or feature sponsored content, our editorial team maintains full independence in reporting and analysis. Any sponsored articles or press releases will always be clearly labeled as such.

© 2025 CoinRemark. All Rights Reserved. The content provided is for informational purposes only and should not be construed as legal, tax, investment, financial, or professional advice. Readers are encouraged to conduct their own research before making any decisions related to cryptocurrency or digital assets.

Josiah Oluwadare

Josiah Oluwadare is a crypto and emerging tech writer with over eight years of experience. He covers market trends, on-chain developments, and institutional adoption across the digital asset space. With a background in Biomedical Technology, Josiah brings an analytical approach to breaking down complex crypto stories into clear, engaging reports.
See profile

Fear & Greed Index

Extreme Fear Fear Neutral Greed Extreme Greed
28/100
Fear

Loading...

POL
$---.-- --.--%
Market Cap $---.--B
24h Volume $---.--B
Circulating Supply ---.--M
Rank #---
Risk Score ---
7d Change --.--%

Loading cryptocurrency information...

Fear & Greed Index

Extreme Fear Fear Neutral Greed Extreme Greed
28/100
Fear

Loading...

POL
$---.-- --.--%
Market Cap $---.--B
24h Volume $---.--B
Circulating Supply ---.--M
Rank #---
Risk Score ---
7d Change --.--%

Loading cryptocurrency information...