Low-Cost Order Attack Exploits Polymarket’s Offchain-Onchain Timing Gap, Draining Market-Maker Liquidity
Prediction market Polymarket uses an offchain matching and onchain settlement model that speeds up trading but creates a state-synchronization gap. For less than NT$0.10, attackers could move assets, revoke approvals or cancel orders before settlement, rendering tens of thousands of dollars in market-making liquidity unavailable and leaving market makers with involuntary losses. Research published in June 2026 estimated that the tactics generated at least $1.49 million in profit.
Polymarket completed a core V2 fix on May 4, 2026, rewriting its underlying trading architecture, with the results becoming apparent a week after launch. The rate of anomalous “ghost fills” fell from a peak of 30% to 0.17%. Researchers also tracked 1.95 million failed settlement transactions, about 980,000 of which were attributed to 35 attack variants. The attacks had exposed $1.78 billion in trading volume to risk, with the failure rate reaching 24.3% during peak periods.
All Coverage
2 original reportsThe Backstory
The history behind this eventPolymarket Adopts TWAP After Bitcoin Contract Manipulation
Polymarket’s five-minute Bitcoin up-or-down contracts relied on Chainlink oracle data tied to Binance spot prices to determine payouts. That design left settlement vulnerable to brief, relatively inexpensive price moves at the end of each contract. The episode highlights a broader weakness in ultra-short prediction markets: even when an oracle reports genuine market data, traders may still influence the underlying venue at the precise moment that decides the outcome.
Academic researchers found that more than 800 accounts traded Bitcoin on Binance during the final 10 seconds before Polymarket settlements, influencing oracle prices and generating about $8.2 million in profit. Retail traders absorbed 93% of the resulting losses, according to the study. Polymarket responded by introducing a 30-second time-weighted average price, or TWAP, for settlement and adding liquidity incentives, sharply reducing the scope for last-second price manipulation.
Polymarket Hacked for $2.9 Million, Pledges Full User Reimbursements
Polymarket is a decentralized prediction market where users trade on the outcomes of political, economic and other events using crypto assets. The incident did not involve a breach of its core protocol. Instead, a third-party supply-chain compromise injected a malicious script into its front end, highlighting how website interfaces and external dependencies can remain vulnerable entry points for wallet theft.
Polymarket confirmed on June 25, 2026, that a third-party vendor had been compromised. It said the attack had been blocked and the affected dependency removed, with initial losses estimated at about $2.94 million. On June 27, AMLBot revised the toll to 11 wallets and about $3.1 million in PUSD. The platform pledged to reimburse users in full.
Polymarket Settlement Wallet Exploited for More Than $600,000 in POL
Polymarket is a decentralized prediction market built on Polygon that uses the UMA oracle and CTF Adapter to determine event outcomes and settle contracts. The attack targeted an UMA CTF Adapter wallet used internally by the team to replenish settlement funds. Because the wallet is part of the platform’s operational process, the incident raised concerns about the reliability of its settlement mechanism.
In July 2026, onchain investigator ZachXBT flagged a suspected exploit of the wallet, with the attacker draining 5,000 POL roughly every 30 seconds. Losses were initially estimated at $520,000 before exceeding $600,000. Polymarket said the vulnerability had been contained and that the affected wallet was used only for internal funding. User funds, positions and market settlements were not affected.
Polymarket Denies Breach After Hacker Claims Intrusion, Releases 300,000 Records
Polymarket is a prediction-market platform that provides trading data through blockchain networks and APIs, with much of its user activity accessible through public interfaces. The dispute is not only about whether a breach occurred. It also raises questions about whether the platform can clearly define the boundaries between public data, personal privacy and API security, potentially affecting trust among market participants and regulators.
Hacker xorcat claimed to have breached Polymarket by exploiting an API vulnerability and posted more than 300,000 user records and an exploitation tool on a forum. Polymarket subsequently denied that any data had been leaked, saying the material consisted of publicly accessible on-chain and API information. As of July 19, 2026, a significant discrepancy remained between the two accounts.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →