TLDR Polymarket confirms a security breach linked to a third-party authentication provider. Users who signed up via Magic Labs reported drained accounts after suspiciousTLDR Polymarket confirms a security breach linked to a third-party authentication provider. Users who signed up via Magic Labs reported drained accounts after suspicious

Polymarket Addresses Third-Party Provider Flaw After User Account Breach

2025/12/24 16:55
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

TLDR

  • Polymarket confirms a security breach linked to a third-party authentication provider.
  • Users who signed up via Magic Labs reported drained accounts after suspicious logins.
  • The issue affected a small group of users, with Polymarket resolving the breach.
  • Polymarket vows to contact impacted users following the third-party vulnerability.

Polymarket, a decentralized prediction market platform, confirmed a security breach affecting several users. The breach was linked to a vulnerability in a third-party authentication provider, particularly impacting users who had signed up through Magic Labs. Users affected by the breach reported that their balances were drained after experiencing suspicious login attempts.

Reports Surface of Drained Accounts

The breach was first reported by users on social media platforms like Reddit and X, with individuals detailing how their accounts had been compromised. One user shared their experience on Reddit, stating, “Today I woke up and see 3 attempts to login to Polymarket — My device isn’t compromised, Google found nothing suspicious, all other services are fine.” The user later discovered that all their deals were closed, and their balance was reduced to just $0.01.

Other users reported similar incidents, where their Polymarket accounts were drained despite having two-factor authentication enabled on their email. The issue appears to have primarily affected users who signed up through Magic Labs, which facilitates non-custodial Ethereum wallets using email sign-ins. Magic Labs is known to attract first-time crypto users who don’t already have digital wallets.

Acknowledgment and Resolution from Polymarket

On December 23, Polymarket acknowledged the breach on its official Discord channel. The platform confirmed that it had identified and resolved the issue, assuring users that no ongoing risks remained. In their statement, Polymarket explained that the vulnerability stemmed from a third-party authentication provider and promised to contact the users impacted by the breach.

“We recently identified and resolved a security issue affecting a small number of users,” Polymarket noted. “The issue was caused by a vulnerability introduced by a third-party authentication provider. We will be in contact with impacted users,” the platform further clarified.

However, Polymarket did not provide specific details regarding the number of affected users or the total financial losses from the breach. Additionally, the identity of the third-party provider has not been disclosed.

Previous Security Issues and Ongoing Concerns

This latest incident is not the first time Polymarket has faced security concerns related to third-party services. In September 2024, a similar breach occurred involving Google logins. Users reported that attackers exploited a vulnerability in a third-party authentication system, draining USDC funds from their wallets. Polymarket had attributed the breach to targeted exploits related to the third-party service used for Google logins.

In November 2024, a separate phishing campaign exploited Polymarket’s comment sections, resulting in over $500,000 in user losses. Fraudulent links were shared in the comment sections, prompting users to log in through email, which led to stolen funds.

Ongoing Security Measures and User Safety

Polymarket emphasized that it has resolved the current security issue and assured users that there are no lingering risks. The platform has stated its commitment to reaching out to affected users to assist them further.

Despite these measures, the repeated nature of such security issues raises questions about the long-term security of platforms that rely on third-party authentication providers. With crypto-related hacks and scams on the rise, users are urged to remain vigilant and follow best practices for securing their accounts.

The post Polymarket Addresses Third-Party Provider Flaw After User Account Breach appeared first on CoinCentral.

시장 기회
매직 로고
매직 가격(MAGIC)
$0.06573
$0.06573$0.06573
+2.51%
USD
매직 (MAGIC) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.