Gate Square “Creator Certification Incentive Program” — Recruiting Outstanding Creators!
Join now, share quality content, and compete for over $10,000 in monthly rewards.
How to Apply:
1️⃣ Open the App → Tap [Square] at the bottom → Click your [avatar] in the top right.
2️⃣ Tap [Get Certified], submit your application, and wait for approval.
Apply Now: https://www.gate.com/questionnaire/7159
Token rewards, exclusive Gate merch, and traffic exposure await you!
Details: https://www.gate.com/announcements/article/47889
Polymarket Confirms User Account Hacks Tied to Third-Party Vulnerability – Funds Drained Despite 2FA
Decentralized prediction market platform Polymarket acknowledged on December 25, 2025, that several user accounts were compromised due to a security vulnerability in a third-party authentication provider.
Affected users reported unauthorized logins and drained balances—despite enabling two-factor authentication (2FA) and no evidence of personal device compromise—prompting speculation on X and Reddit that the issue may involve Magic Labs, a common wallet connection service. While Polymarket has not named the provider, the incident highlights ongoing third-party risks in Web3 platforms, even for non-custodial services. No official loss figures have been disclosed, but individual reports describe significant fund withdrawals after suspicious login attempts.
Details of the Polymarket Account Hacks
Users began surfacing complaints earlier in the week:
Polymarket’s statement confirmed the third-party root cause but provided limited specifics on scope or remediation timeline.
Why Third-Party Vulnerabilities Pose Risks to DeFi Users
Even decentralized platforms rely on external services for UX:
This incident echoes past breaches where third-party tools (e.g., Ledger Connect kit) exposed users despite strong individual security.
Implications for Polymarket and Prediction Market Users
Polymarket—known for high-volume event betting—faces reputational pressure:
No evidence of on-chain exploits; losses tied to account takeovers.
In summary, Polymarket’s December 25, 2025, confirmation of user account hacks via a third-party vulnerability—resulting in drained funds despite 2FA—underscores persistent supply-chain risks in Web3. With speculation centering on Magic Labs and reports of unauthorized access, the incident serves as a reminder for users to review connected services and enable advanced security options. Monitor official Polymarket channels for updates on affected accounts and resolution steps in this developing situation.