Polymarket, the decentralized prediction market platform, lost between $600,000 and $700,000 in POL tokens on May 22 after an attacker gained access to a private key for a dormant operational wallet. The exploit targeted an internal address used by a backend refiller service, not a smart contract, and user funds remained safe. On-chain investigator ZachXBT flagged the suspicious activity first.
How the exploit unfolded
The compromised wallet was an externally owned account (EOA) — a simple address, not a contract. The private key, roughly six years old, had been sitting dormant before the attacker activated it. Once inside, the thief scripted a steady siphon: roughly 5,000 POL every 30 seconds. The tokens were then routed to exchanges and mixing services, including ChangeNOW, to obscure the trail.
Initial estimates pegged the loss near $520,000, but Polymarket later revised the figure to between $600,000 and $700,000, mostly in POL. The attacker likely gained the key through a leak or compromise of the old wallet's credentials.
What wasn't exploited
Polymarket moved quickly to correct early reports that suggested a smart contract vulnerability. The UMA CTF Adapter, which is audited code, was not exploited. The drained wallet was an internal ops wallet, not part of the platform's core resolution infrastructure. Active markets and core contracts continued to work normally throughout the incident.
The company said user funds were never at risk. The wallet in question was used for operational tasks, not for holding user deposits or settlement balances.
Polymarket's response
After detecting the breach, Polymarket's team rotated the leaked key, revoked all associated permissions, and migrated the affected operations to a key management system (KMS). The company said the move should prevent similar incidents going forward.
ZachXBT, the on-chain sleuth who first spotted the suspicious outflows, provided early analysis that helped the team identify the source quickly. Polymarket has not publicly named the attacker or disclosed whether law enforcement has been contacted.
The investigation is ongoing. Polymarket has not said whether it will pursue legal action or offer a bounty for the return of funds. The platform continues to operate normally, but the incident raises questions about the security of long-dormant keys in crypto operations — especially those tied to backend infrastructure that may not be under constant monitoring.




