June 29, 2026
Date: June 29, 2026
To investigate this high-profile frontend exploit, the ChainBounty Threat Intelligence team deployed the SentinelTX Blockchain Forensic Intelligence System. Our forensic specialists executed a rigorous, multi-hop trace tracking assets across heterogeneous networks (Polygon to Ethereum Mainnet) to assemble an immutable chain of custody:
On June 25, 2026, Polymarket's web deployment interface was targeted via a third-party vendor supply chain compromise. The adversary successfully injected a malicious JavaScript payload into the platform's frontend, altering contract call triggers to siphon user wallet balances. The total loss from this incident is estimated at approximately USD 2,940,000 in Polymarket USD (PUSD).
On-chain analysis reveals that after siphoning the PUSD on the Polygon network, the attacker rapidly converted the assets into USDC.e and bridged them over to the Ethereum Mainnet. The incoming flows were then consolidated into a single Ethereum master aggregation address: 0xe65b1c586757c5510B60F998Eebb14C1Ef71EleD.
A total of 1,893 ETH was collected at this nexus point and subsequently parsed out into four distinct structural pathways:
Timestamp (UTC) | Event Description | Block Height | Transaction Hash (TX) | Associated Addresses |
|---|---|---|---|---|
2026-06-25 | Malicious JS injection starts via compromised third-party vendor | N/A | N/A | Polymarket Frontend Network |
2026-06-25 21:55:11 | Attacker initiates minor L1 dispersion transfer (Path D) | 25397458 | 0xf2c690d8bf1b7a12b3126cdb0adc2c43c3e82134f38fa1fb52f1345ef7e6e6fc | 0xe65b1c58...1eD -> 0xe3c8c6cfcfb8edfa83b86e5a98e58568f78bd922 |
2026-06-25 22:19:47 | Attacker routes gas capital to structural mixer node (Path C) | 25397581 | 0xc807fc375cadf9c2b8f8c0e4c67795dd42199c094f28914424e55537041be605 | 0xe65b1c58...1eD -> 0x5a6b2f8fab6cf480c93d152ef96d1e0c830fe587 |
2026-06-26 07:08:23 | Master wallet funds secondary storage wallet (Path B) | 25400213 | 0x67fdfea184253b97f32da76f0d77e82650924d3be702d7858050e4be8efc5521 | 0xe65b1c58...1eD -> 0xea0a80070c38f63c10d7fed95286e83eb415441f |
2026-06-26 20:49:59 | Main capital migration to primary storage vault (Path A - Pt. 1) | 25404301 | 0x62781171eef8748b967d3926c82f5c73cbf2cb40a189443347ad9f276966b086 | 0xe65b1c58...1eD -> 0x975268a2a71e4a7e282b962ec0blee01d3778ac0 |
2026-06-26 20:57:47 | ERC20 state consolidation to primary storage vault (Path A - Pt. 2) | 25404340 | 0xc053a95983965cle0ee39f04c22flaelef65dcea95c0295ebd57145814f59795 | 0xe65b1c58...1eD -> 0x975268a2a71e4a7e282b962ec0blee01d3778ac0 |
Native Token Volume | Layer-1 Token Equivalent | Spot Exchange Valuation | Operational Deployment Status |
|---|---|---|---|
537,526 USDC.e | Bridged via Relay.link | USD 537,526.00 | Siphoned on Polygon via 0xC771A30a...cBaAe2; converted to L1 ETH. |
1,788.516 ETH | Vault Storage Address 1 | USD 2,798,692.50 | Held entirely static inside 0x975268a2...78ac0. Zero outbound movement. |
100.000 ETH | Vault Storage Address 2 | USD 156,624.25 | Held entirely static inside 0xea0a8007...5441f. Zero outbound movement. |
3.400 ETH | Dispersion Wallet | USD 5,320.35 | Stored static inside 0xe3c8c6cf...bd922. No outbound activity. |
1.000 ETH | Laundering Node | USD 1,564.81 | Dispersed through cascading programmatic micro-transactions. |
Total Unliquidated Residue | 1,888.516 ETH | USD 2,960,637.10 | 99.8% of total loot immediately available for targeted blocklisting. |
The initial compromise siphoned user PUSD directly into the threat actor's primary Polygon deployment engine: 0xC771A30a7c1aCA828eeEF7B822ac864a64cBaAe2. To cross standard tracking perimeters, the attacker swapped the pool assets for Polygon-native USDC.e and initiated automated execution calls using the Relay.link cross-chain portal to mint native ETH on the Ethereum Mainnet.

Upon reaching the Ethereum Mainnet consolidation nexus (0xe65b1c58...1EleD), the capital allocation was split across four distinct tracks to test ecosystem resistance and setup long-term holding vaults.

0x113b0cef...20bc0).Target Address Wallet | Network Chain | Forensic Role Designation | Current Token Balance | Technical Observations & Profile Status |
|---|---|---|---|---|
| Polygon | Exploiter Siphon Portal | 0 MATIC | Primary deployment gateway for frontend drainage calls. |
| Polygon | Infrastructure Gas Funder | 0 MATIC | Distributed 1,379 MATIC. Historical logs tie it to Bitfinex/OKX hot wallets. |
| Ethereum | L1 Master Consolidation | 0 ETH | Received 1,893 native ETH via bridge; fully distributed. |
| Ethereum | Primary Deep Storage Vault | 1,788.516 ETH | High-priority target for compliance tracking and blocklisting. |
| Ethereum | Secondary Storage Vault | 100.000 ETH | Static balance. Zero outbound transfers executed. |
| Ethereum | Minor Asset Dispersion Node | 3.400 ETH | Static balance. No activity detected following injection. |
| Ethereum | Tumbler/Laundering Router Hub | 0 ETH | Executed programmatic micro-splits across 6 sub-nodes. |
| Ethereum | Mixer Output Accumulator | 0.090 ETH | Reconciled reverse-flow residual dust from layering loops. |
While no direct cash-out attempts to centralized exchange liquidity pools have been executed from the Ethereum holding vaults, our team uncovered an essential lead within the Polygon gas supply network.
The gas funding infrastructure wallet (0x71d4249079684479f2651745fa2fcd79c9b45f53) exhibits historical transaction markers linked to institutional deposit paths at Bitfinex, Bitget, and OKX on May 30, 2026. Although these actions occurred weeks prior to the supply chain breach, they indicate a persistent operational setup. Subpoena requests targeting the historical account configurations of this gas funder at those specific exchanges represent a high-probability vector for uncovering the attacker's off-chain identity.
Due to the threat actor's choice to keep 99.8% of the siphoned capital entirely stationary, security networks have a critical window to enforce isolation protocols:
0x975268a2a71e4a7e282b962ec0blee01d3778ac0 and 0xea0a80070c38f63c10d7fed95286e83eb415441f) to all Tier-1 centralized exchanges (Binance, Coinbase, OKX, Kraken, Bitfinex). This ensures an immediate asset freeze if any deposit migration is initiated.The Polymarket frontend breach highlights the expanding threat vector of decentralized web application dependencies on third-party software supply chains. By modifying client-side logic, the adversary easily sidestepped standard smart contract access perimeters.
However, the attacker's post-exploit strategy presents a significant operational bottleneck: by locking the overwhelming majority of the siphoned funds inside visible, un-mixed Layer-1 wallets, they have left an accessible trail. Immediate, aggressive asset blocklisting combined with legal sub-surface tracing of the historical gas funding infrastructure gives the Web3 ecosystem a highly viable pathway for attribution and recovery.
ChainBounty Threat Intelligence has locked webhooks onto all associated cluster addresses. Real-time updates will be deployed automatically if any L2 state updates occur.
6 reads