Mars Finance reports that the Polymarket platform has detected and resolved a security issue affecting “a small number of users,” caused by a vulnerability introduced by a third-party authentication provider. Previously, several Polymarket users reported abnormal login activity on Reddit and X platforms, with funds being drained and trading positions forcibly closed. The affected users mainly consist of those who log in via email through Magic Labs. Some victims stated that despite enabling two-factor authentication (2FA) and not having their devices illegally accessed, their accounts were still compromised after multiple abnormal login attempts. Polymarket officials confirmed that the vulnerability has been fixed, and there is currently no ongoing risk. The platform is directly contacting affected users. Earlier in late 2024, the platform also experienced asset theft for some users who logged in via Google due to a third-party plugin vulnerability.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Polymarket: Third-party authentication vulnerability leads to a small number of user accounts being compromised
Mars Finance reports that the Polymarket platform has detected and resolved a security issue affecting “a small number of users,” caused by a vulnerability introduced by a third-party authentication provider. Previously, several Polymarket users reported abnormal login activity on Reddit and X platforms, with funds being drained and trading positions forcibly closed. The affected users mainly consist of those who log in via email through Magic Labs. Some victims stated that despite enabling two-factor authentication (2FA) and not having their devices illegally accessed, their accounts were still compromised after multiple abnormal login attempts. Polymarket officials confirmed that the vulnerability has been fixed, and there is currently no ongoing risk. The platform is directly contacting affected users. Earlier in late 2024, the platform also experienced asset theft for some users who logged in via Google due to a third-party plugin vulnerability.