Polymarket hacked, with vulnerabilities in the off-chain and on-chain transaction result synchronization mechanism

ChainCatcher reports that, according to the GoPlus Chinese community, the prediction market platform Polymarket was hacked due to a design flaw in the synchronization mechanism between off-chain and on-chain transaction results in its order system.

The attacker manipulated nonces to cause on-chain matched transactions to be canceled or invalidated before settlement, while off-chain records remained valid, leading to API false positives, affecting trading bots like Negrisk and causing user losses. The attack process is as follows: 1. The attacker submits or matches large reverse trades with market-making bots on Polymarket’s off-chain order book. 2. The attacker constructs transactions with forged or duplicate nonces or exploits on-chain nonce competition, ensuring the on-chain transaction reverts. 3. Polymarket’s API returns “Trade Successful” to the bot before on-chain confirmation, causing the bot to believe the position has been hedged, while the on-chain state has not yet changed. 4. The attacker then exploits the exposed direction by executing a real on-chain transaction, achieving “risk-free” profit. 5. Since the revert occurs on the blockchain layer, Polymarket’s fees do not explode, making the attack cost manageable and sustainable. GoPlus recommends users pause automated trading tools, verify on-chain transaction statuses, strengthen wallet security, and closely monitor official Polymarket announcements.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

The probability that Bitcoin will decline to $55,000 this year is as high as 73%.

ChainCatcher reports that, according to Polymarket data, the probability of Bitcoin falling below $55,000 by 2026 is as high as 73%, while the probability of reaching $100,000 on the upside is only 38%.

GateNewsBot4h ago

Netherlands imposes heavy penalty on Polymarket! Illegally providing prediction market services, potentially facing a fine of up to 840,000 euros

The Dutch gambling authority Ksa has issued a cease and desist order and fined Polymarket for providing gambling services in the Netherlands without a license, facing a penalty of €420,000 per week, with a maximum of €840,000. This incident has sparked legal controversy over whether prediction markets are considered gambling. Ksa emphasizes that unlicensed platforms are not allowed to operate in the market and that prediction markets may pose social risks, which could influence future regulatory trends.

ChainNewsAbmedia6h ago

The Netherlands bans Polymarket, deeming it illegal gambling. Prediction markets are facing setbacks across Europe.

The Dutch gambling regulatory authority KSA has classified Polymarket as illegal gambling, requiring it to cease operations locally and imposing a fine of €420,000 per week. The article discusses the legal positioning and regulatory trends of prediction markets, showing that Europe is tightening its stance compared to the more lenient approach in the United States, and emphasizes the regulatory challenges faced by Polymarket and the double-edged sword effect of globalization.

動區BlockTempo7h ago

New Wallet Places $100K Bet on U.S.-Iran Strike in March

Gate News bot message, a newly created wallet has placed a $100K bet on a potential U.S. strike against Iran in March. The timing and amount of the wager have raised questions about whether this represents an informed position or speculative gambling.

GateNewsBot10h ago

The Clarity Act – a Potential ETH Super-Cycle Trigger As Prediction Markets Signal 90% Approval Odds

The crypto market is experiencing some serious sentiment shifts as legislators gain traction. After the Genius Act resulted in significant stablecoin inflows and boosted liquidity into 2025, focus has now shifted to the Digital Asset Market Clarity Act. According to Polymarket, there’s a 90%

BlockChainReporter12h ago

The probability that the court orders Trump to refund tariffs on Kalshi quickly rises to 66%

BlockBeats News, February 20 — According to prediction platform Kalshi, the market currently estimates a 66% probability that a court will order Trump to refund tariffs before July 2026, a significant increase from around 30% previously.

GateNewsBot20h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)