News listPolymarket wallet hacked! 5,000 POL drained every 30 seconds, over $600k evaporated.
動區 BlockTempo2026-05-22 08:41:28

Polymarket wallet hacked! 5,000 POL drained every 30 seconds, over $600k evaporated.

ORIGINAL預測市場 Polymarket 錢包遭駭!每 30 秒被抽走 5,000 POL,已超過 60 萬鎂蒸發
AI Impact AnalysisGrok analyzing...
📄Full Article· Automatically extracted by trafilaturaGemini 翻譯1596 words
On-chain analysis platform Bubblemaps has issued an alert that one of the wallets for Polymarket's UMA CTF Adapter has been compromised. The attacker is draining 5,000 $POL every 30 seconds, with losses exceeding $600,000 as of the time of writing. On-chain sleuth ZachXBT also issued a warning, noting that the attacker has already dispersed the funds across 15 addresses. (Previous coverage: Polymarket submits "parlay contract" self-certification to CFTC! SEC Commissioner Atkins seeks comments on prediction market ETFs) (Background: THORChain launches recovery proposal after hack: protocol to absorb $10M loss, burn attacker's RUNE) Key Highlights - Polymarket's UMA CTF Adapter contract exploited; attacker draining 5,000 POL every 30 seconds - Over $600,000 lost as of Bubblemaps' post; ZachXBT confirms the ongoing attack - Attacker's address identified; stolen funds dispersed to 15 addresses, suspected money laundering in progress On-chain analysis platform Bubblemaps issued an urgent alert on X today (May 22), stating that the UMA CTF Adapter wallet used by Polymarket to settle prediction markets is under continuous attack. The attacker is draining funds from the contract at a rate of 5,000 $POL every 30 seconds. As of the time of writing, cumulative losses have exceeded $600,000 and the figure continues to rise. ALERT: 🚨 Polymarket contract exploited Attackers are removing 5,000 $POL every 30 seconds – $600k stolen so far Pause all Polymarket activity for now pic.twitter.com/DpqOp5ggVj — Bubblemaps (@bubblemaps) May 22, 2026 Bubblemaps directly urged all users to "pause all Polymarket activity for now." On-chain sleuth ZachXBT also issued a warning, confirming that the attack is ongoing. Attacker's address identified, funds dispersed to 15 wallets According to on-chain data, the attacker's primary address has been identified as 0x8F98…9B91. The stolen funds were immediately dispersed into 15 different addresses, a typical precursor to on-chain money laundering: splitting, mixing, and eventually cashing out via cross-chain bridges or centralized exchanges. The UMA CTF Adapter is the core settlement component of Polymarket's prediction markets, responsible for verifying and settling market results via UMA's Optimistic Oracle. A breach of this contract indicates a vulnerability in the settlement layer of the entire prediction market, and the scope of impact may extend beyond the currently known losses. DeFi hack wave continues in May This is the third security incident Polymarket has faced recently. Previously, the platform experienced some user account compromises due to a vulnerability in a third-party login service provider and faced allegations of data leaks (which were later denied by the official team). The entire DeFi ecosystem has faced a wave of intensive attacks in May, with five independent hacking incidents occurring in a single week and 19 cumulative incidents for the month, totaling approximately $38.2 million in losses. Just yesterday, THORChain launched the ADR028 recovery proposal following its own $10.7 million hack. Polymarket has not yet released an official response as of press time. With funds bleeding at a rate of 5,000 POL every 30 seconds, the final loss figure from this attack may far exceed $600,000. FAQ What is the UMA CTF Adapter? The UMA CTF Adapter is the settlement contract for Polymarket's prediction markets, which verifies market results and completes settlements through UMA's Optimistic Oracle. This breach indicates a vulnerability in the settlement layer, and the scope of impact may expand. What should Polymarket users do now? Bubblemaps urges users to immediately pause all Polymarket operations, including opening new positions and withdrawals. The attack is still ongoing, and users should wait for official confirmation that the vulnerability has been patched before resuming use.
Data Status✓ Full text extractedRead Original (動區 BlockTempo)
🔍Historical Similar Events· Keyword + Asset Matching6 items
💡 Currently matching via keywords + symbols (MVP) · Will be upgraded to embedding semantic search later
Raw Information
ID:c457278e0d
Source:動區 BlockTempo
Published:2026-05-22 08:41:28
Category:zh_news · Export Category zh
Symbols:Unspecified
Community Votes:+0 /0 · ⭐ 0 Important · 💬 0 Comments