Polymarket has been reportedly compromised, with over 300,000 records leaked.

PANews reported on April 29th that, according to a disclosure by Dark Web Informer on the X platform, the decentralized prediction market platform Polymarket has been suspected of being compromised, with over 300,000 records and an exploit kit leaked to a cybercrime forum. The attackers claim the data was obtained through undocumented API endpoints, pagination bypasses, and CORS misconfigurations, with the extraction date being April 27, 2026. The leaked data includes approximately 10,000 user personal identification information entries, 41,000 comments, 485,000 market metadata entries, 250,000 active CLOB markets, and 292 event submitter/resolver addresses. The attackers also provided proof-of-concept code for several vulnerabilities, including CVE-2025-62718 (CVSS 9.9), CORS misconfiguration, and CVE-2024-51479 (CVSS 7.5). The attackers claim that Polymarket does not have a bug bounty program and did not notify the platform beforehand.

Share to:

Author: PA一线

This content is for market information only and is not investment advice.

Follow PANews official accounts, navigate bull and bear markets together
PANews APP
慢雾:检测到一笔利用存在漏洞的EIP-7702账户的恶意交易,损失约54.93枚ETH
PANews Newsflash