Polymarket, the world’s largest decentralized prediction market platform. It is facing a suspected smart contract exploit after attackers reportedly drained morePolymarket, the world’s largest decentralized prediction market platform. It is facing a suspected smart contract exploit after attackers reportedly drained more

Polymarket Exploited — Attacker Steals $660K and Counting

2026/05/22 18:10
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Polymarket, the world’s largest decentralized prediction market platform. It is facing a suspected smart contract exploit after attackers reportedly drained more than $660,000 from a Polygon-based adapter contract on May 22, 2026. 

The incident was first flagged by on-chain investigator ZachXBT. He warned that Polymarket’s UMA CTF Adapter contract may have been compromised. According to multiple blockchain trackers, the attacker continuously withdrew small batches of POL and MATIC tokens every few seconds. Through a suspected exploit tied to legacy oracle infrastructure. The ongoing drain has quickly turned into one of the biggest Polymarket News stories of the month.

ZachXBT Flags Suspicious Polymarket Activity

The initial Polymarket ZachXBT alert identified two affected contracts:

  • 0x871D7c0f9E19001fC01E04e6cdFa7fA20f929082
  • 0x91430CaD2d3975766499717fA0D66A78D814E5c5

The suspected attacker wallet was identified as:

  • 0x8F98075db5d6C620e8D420A8c516E2F2059d9B91

Blockchain monitoring data later showed repeated withdrawals of roughly 5,000 MATIC every 20-30 seconds. Some transactions exceeded 9,900 MATIC before funds were routed through additional wallets. Lookonchain later confirmed the exploit had surpassed $660,000 in losses. While warning users to avoid new deposits or trading activity until more information becomes available.

UMA Adapter Contract Appears Targeted

Early reports suggest the exploit involves Polymarket’s UMA CTF Adapter on Polygon. The adapter acts as a bridge between UMA’s oracle infrastructure and Polymarket’s Conditional Tokens Framework. That system helps resolve prediction market outcomes across the platform. Security researchers believe the attacker may have exploited an old private key or legacy permission setup tied to the adapter contract. Rather than breaching Polymarket’s core trading infrastructure directly. The repeated small transfers suggest an automated draining strategy rather than a single large exploit transaction. Community members also warned that funds may already be moving toward laundering routes or intermediary wallets.

Why This Matters for Investors

For users and traders, the exploit raises fresh concerns about smart contract security across decentralized prediction markets. Polymarket processes large betting volumes tied to elections, geopolitics, and financial markets. Therefore, any exploit can damage user confidence quickly. 

Some traders now fear:

  • Temporary liquidity withdrawals
  • Reduced trading activity
  • Increased platform caution
  • Broader trust issues around DeFi prediction markets

If the exploit continues growing, competitors could temporarily benefit as users shift activity elsewhere. The incident also highlights how even mature DeFi platforms remain exposed to infrastructure vulnerabilities.

Developers Face Another Security Wake-Up Call

For developers, the exploit reinforces the importance of key rotation, continuous audits, and strict contract permission management. Legacy adapter contracts and oracle integrations often become overlooked attack surfaces over time. This case may push more DeFi teams toward:

  • Multi-signature controls
  • Formal verification tools
  • Real-time monitoring systems
  • Faster emergency pause mechanisms

The attack could also accelerate discussions around oracle security standards across Polygon and broader DeFi ecosystems.

Polymarket Response and Outlook

At the time of writing, Polymarket had not released a full public technical breakdown of the exploit. However, community alerts continue advising users to remain cautious until contract activity stabilizes. As Polymarket news continues developing. The investigators will likely focus on whether funds can be frozen or partially recovered through coordinated blockchain tracing efforts. For now, the incident serves as another reminder that security remains one of crypto’s biggest long-term challenges. Especially as decentralized finance platforms continue scaling globally.

The post Polymarket Exploited — Attacker Steals $660K and Counting  appeared first on Coinfomania.

시장 기회
Smart Blockchain 로고
Smart Blockchain 가격(SMART)
$0.004956
$0.004956$0.004956
-1.64%
USD
Smart Blockchain (SMART) 실시간 가격 차트

SPACEX(PRE) Launchpad Is Live

SPACEX(PRE) Launchpad Is LiveSPACEX(PRE) Launchpad Is Live

Start with $100 to share 6,000 SPACEX(PRE)

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

No Chart Skills? Still Profit

No Chart Skills? Still ProfitNo Chart Skills? Still Profit

Copy top traders in 3s with auto trading!