Major Phishing Attack Drains Nearly $3 Million from Polymarket Users
The cryptocurrency community is on high alert following a significant security breach. Renowned on-chain analyst Specter has raised alarms about an ongoing phishing campaign specifically targeting users of the prediction market platform Polymarket, with substantial financial losses already confirmed.
Analysis of the Attack and Fund Movement
Specter's on-chain monitoring reveals that the attack has compromised at least 11 wallets holding PUSD, the stablecoin utilized on the Polymarket platform. After successfully siphoning funds, the attackers promptly converted the stolen PUSD into Ethereum (ETH) via decentralized exchanges, a common tactic to obfuscate the trail of stolen assets.
Initial estimates put the total loss at approximately $2.94 million, a figure that may increase as the incident unfolds. Specter noted that the attack vector bears the hallmarks of a classic phishing scheme, potentially involving fake official websites, misleading airdrop links, or impersonated customer support direct messages designed to trick users into granting permissions.
Critical Security Recommendations from Experts
In light of the escalating sophistication of on-chain threats, Specter offered crucial security advice for all DeFi and prediction market participants:
- Verify All Links: Avoid clicking on links from unsolicited emails, social media DMs, or Telegram groups, especially those requesting asset-related actions.
- Utilize Hardware Wallets: For significant holdings, consider storing assets in a hardware wallet not connected to your daily browsing environment.
- Beware of Excessive Approvals: Regularly review and revoke unnecessary smart contract allowances using dedicated approval-checking tools.
- Enable Transaction Previews: Scrutinize all transaction details—particularly recipient addresses and amounts—before confirming them in your wallet.
Latest Developments and Broader Implications
Specter confirmed that his team continues to track the attacker's addresses and subsequent fund movements. This incident serves as another stark reminder of the persistent threats within the crypto ecosystem, underscoring the vital importance of user education and awareness of evolving attack methods, particularly in nascent sectors like prediction markets.
Polymarket has not yet released an official detailed statement regarding the attack. The community is urging the project to provide official security guidance promptly and assist affected users in tracing their assets. Further details regarding the attack's mechanics and additional protective measures are expected as the investigation progresses.