Polymarket confirms user accounts breached via third-party authentication vulnerability

2025-12-24 14:07

Polymarket has recently confirmed that several of its users were affected by a security breach, which it says was due to a vulnerability in a third-party authentication service.

The Polymarket team has officially acknowledged the incident that several users had been reporting over the past week, prompting renewed concerns about account safety.

Polymarket users report suspicious login attempts

Initial reports of suspicious activity began surfacing earlier in the week, where multiple Polymarket users were seen detailing accounts of their losses across platforms like X and Reddit.

According to one user going by the username Sandwich_1337, their account was drained without any major red flags from their end.

“Today I woke up and see 3 attempts to login to polymarket. My device isn’t compromised, google found nothing suspicious, all other services are fine,” the user wrote.

In the comments, another Reddit user reported a similar experience where they received several login attempt notifications, after which their account balance was emptied.

“I am not a crypto bro clicking on airdrop links or connecting my wallet to random sites. I haven’t even logged into Polymarket for two months […] My email security is locked down. I have 2FA on my email account that requires a physical confirmation on my phone to authorize a new login. It is borderline impossible to access my email without my physical device, which was in my pocket all day,” the user wrote.

Meanwhile, some users on social media speculate that the breach may be affecting a subset of users who had signed up for the platform through Magic Labs, a service that allows email-based access and automatically generates non-custodial Ethereum wallets.

While Polymarket acknowledged the issue on its official Discord channel, it said the incident was linked to a “third-party authentication provider.”

However, it did not provide any additional information other than the fact that the incident only affected a “small number of users.”

Further, it did not disclose the extent of the financial damage caused by the incident and noted that the issue had since been resolved, adding that no other risks remain.

“We will be in contact with impacted users,” Polymarket added.

Details regarding the next steps for affected users were not available at the time of writing.

Not the first time

This is not the first time Polymarket users have been targeted in security-related incidents.

Last year, in August, multiple users reported that their USDC balances had been drained shortly after logging in via their Google accounts.

The attackers reportedly exploited a “proxy” function call to siphon funds to a recurring phishing address, targeting those who used the Magic Labs SDK.

Polymarket support confirmed at least five such attacks by late September.

More recently, in November, a major phishing operation unfolded when hackers exploited Polymarket’s comment section to post phishing links that pushed malicious scripts onto user devices once clicked.

Losses, at the time, were estimated to exceed $500,000.

The post Polymarket confirms user accounts breached via third-party authentication vulnerability appeared first on Invezz

origin »

SpherePay (SAY) íà Currencies.ru

$ 0 (+0.00%)
Îáúåì 24H $0
Èçìåíåèÿ 24h: 0.00 %, 7d: 0.00 %
Cåãîäíÿ L: $0 - H: $0
Êàïèòàëèçàöèÿ $0 Rank 99999
Äîñòóïíî / Âñåãî 0 SAY

authentication accounts email having drained despite protections

authentication accounts → Ðåçóëüòàòîâ: 48


Ôîòî:

DeFi-Focused Crypto Wallet Ambire Now Out Of Beta

After undergoing extensive auditing and beta testing with more than 5,000 accounts, the first non-custodial wallet with email authentication, Ambire Wallet has been launched to the public. Ambire wallet is a new-generation non-custodial and open-source smart wallet that offers its users easy access to DeFi enhanced user experience and a focus on security. Ambire is […]

2021-12-17 23:52


Coinbase Promises to Deposit Stolen Funds to At Least 6,000 Hacked Accounts

Cryptocurrency exchange Coinbase, which has about 68 million users globally, disclosed this week that hackers stole from at least 6,000 of its customers. According to a breach notification letter sent by the exchange to affected customers, hackers used a vulnerability to bypass Coinbase’s SMS multi-factor authentication security feature.

2021-10-4 18:08


Twitter Hacker Managed to Scam Only 12 Bitcoin After Duping Major Accounts Using ‘Internal Tools’

A security incident on Twitter duped businesses and people into sending at least $120,000 worth of Bitcoin to an anonymous online wallet, half of which has already been spirited to other accounts. Given that some of the Twitter accounts targeted were using two-factor authentication (2FA) and strong passwords, the hack may be internal to twitter. […]

2020-7-16 15:35


Bithumb releases identity authentication system to comply with global requirements

The cryptocurrency space in South Korea accounts for nearly 20% of the world’s crypto-transactions. However, the country's crypto-industry has consistently been on the defensive against stifling resThe post Bithumb releases identity authentication system to comply with global requirements appeared first on AMBCrypto.

2019-12-4 07:23


Ethereum employment ecosystem Opolis integrates Fortmatic’s web3 ID

Opolis, a project building a next-generation employment ecosystem for the self-sovereign worker, today announced a new partnership with Fortmatic to utilize web3 identity authentication. The partnership will allow Opolis members to easily access their employment accounts with their email or phone number and have their identity authenticated through Fortmatic on the Ethereum blockchain.

2019-11-13 23:33


Ôîòî:

PSA: Your Android phone is now a security key for signing in to Google on iOS

Google has announced that it’s now possible to log into your Google accounts from your iPhones and iPads using your Android phone as a hardware authentication key. The development comes almost more than a month after the internet giant made it easy for Google users to sign in to their accounts on their laptops or PCs using their Android smartphones as hardware security keys.

2019-6-13 09:52


LocalBitcoins Users Scammed of Bitcoin in Phishing Attack, Forum Suspended

Users of the peer-to-peer OTC Bitcoin trading service LocalBitcoins have been targeted by cyber criminals as part of a phishing scam, resulting in the user’s Bitcoin being stolen. Forum users were being redirected to a phishing site, which was prompting the users to input two-factor authentication codes that were used to access user accounts and empty.

2019-1-26 16:37


Ôîòî:

2FA codes are great for security, except when 26M of them are leaked

Just when you thought two-factor authentication was enough to secure your online accounts, a troubling discovery shows how this system can be comprised, thanks to human error. TechCrunch reports that a database of text messages containing more than 26 million 2FA codes, password reset links, and delivery tracking details was left out in the open … This story continues at The Next Web

2018-11-16 13:22