Polymarket A.I CyberSecurity Scoring
Polymarket
Company Information
Website:http://www.polymarket.com
Employees number:242
Number of followers:34,857
NAICS:5112
Industry Type:Software Development
Homepage:polymarket.com
Polymarket Risk Score (AI oriented)
Between 550 and 599
PolymarketSoftware Development
Updated:
22/05/2026
22/05/2026
570/1000
Very Poor
Ca
Polymarket Global Score (TPRM)
xxxx
PolymarketSoftware Development
Score locked

PolymarketVery Poor
Current Score
570Ca (VERY POOR)
01000
3 incidents
-92.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
574
MAY 2026
666
Breach
22 May 2026 • Polymarket
Polygon and Polymarket: ZachXBT flags $520K Polymarket exploit on Polygon, team says funds are safe
Polymarket Suffers $520K Security Breach Due to Private Key Compromise
570
LOW-96
POLPOL1779460097
Polymarket Suffers $520K Security Breach Due to Private Key Compromise
Blockchain investigator ZachXBT has uncovered a suspected security breach targeting Polymarket, the largest decentralized prediction market platform. According to on-chain data, $520,000 was drained from two smart contracts on the Polygon blockchain on [date not specified]. The compromised addresses 0x871D7c0f9E19001fC01E04e6cdFa7fA20f929082 and 0x91430CaD2d3975766499717fA0D66A78D814E5c5 had funds transferred to the attacker’s address (0x8F98075db5d6C620e8D420A8c516E2F2059d9B91).
Polymarket’s development team acknowledged the incident in an X (formerly Twitter) post, confirming awareness of reports tied to its rewards payout system. The company clarified that user funds and market resolutions remain unaffected, attributing the breach to a private key compromise of an internal operations wallet rather than a smart contract exploit or core infrastructure failure. Further updates are pending.
Polygon Labs CTO Mudit Gupta weighed in, stating that Polymarket’s contracts and user funds are secure, though the platform’s market initializer was compromised. He emphasized that the incident had no direct impact on users or smart contracts.
Polymarket has yet to release an official statement from its primary X account. The breach occurs amid increased scrutiny of decentralized finance (DeFi) platforms, highlighting ongoing security challenges in the sector.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
APRIL 2026
754
Breach
28 Apr 2026 • Polymarket
Polymarket: Polymarket denies data breach, says hacker is selling public data
Polymarket Denies Data Breach After Hacker Claims Theft of 300,000 Records
665
CRITICAL-89
POL1777458829
Polymarket Denies Data Breach After Hacker Claims Theft of 300,000 Records
Prediction markets platform Polymarket has refuted allegations of a data breach after a hacker, operating under the pseudonym xorcat, posted claims on the dark web that they had stolen over 300,000 records, including 10,000 unique user profiles containing full names, profile images, proxy wallets, and base addresses. The screenshots of the post, shared by cybersecurity firm Vecert Analyzer and dark web monitoring accounts on X (formerly Twitter), surfaced on Tuesday.
Polymarket dismissed the claims as "complete and utter nonsense," asserting that the allegedly stolen data was already publicly accessible via its API endpoints and on-chain records. The platform emphasized that its transparency as a blockchain-based service means all data is auditable by design a feature, not a vulnerability. In a follow-up statement, Polymarket mocked the hacker’s attempt to monetize freely available information, questioning whether venture capital funding had backed the stunt.
The hacker, however, argued that the data was obtained through undocumented API endpoints, pagination bypasses, and CORS misconfigurations in Polymarket’s Gamma and CLOB APIs. Xorcat also claimed to have breached other prediction markets and threatened to release additional data in the coming days. The motive, according to the hacker, was Polymarket’s lack of a bug bounty program though the platform has had an active program since April 16, receiving 446 reports as of Wednesday.
Security experts have cast doubt on the breach claims. Vladimir S, Chief Security Officer at Legalblock, suggested the incident appeared to be a case of parsed public data being misrepresented as a database leak.
The incident comes amid a surge in crypto-related exploits, with blockchain security firm Hacken reporting $482 million in losses across 44 Web3 incidents in Q1 2026. Polymarket’s denial highlights the ongoing tension between transparency in decentralized platforms and the risks of data exposure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
754
FEBRUARY 2026
754
JANUARY 2026
754
DECEMBER 2025
754
NOVEMBER 2025
754
OCTOBER 2025
754
SEPTEMBER 2025
754
AUGUST 2025
754
JULY 2025
754
OCTOBER 2008
754
Cyber Attack
16 Oct 2008 • Polymarket
Kalshi and Polymarket: Betting on Cybercrime – Prediction Markets and Hacking
Cybercriminals Exploit Prediction Markets to Profit from Insider Knowledge
736
HIGH-18
KALPOL1777451477
Cybercriminals Exploit Prediction Markets to Profit from Insider Knowledge
Cybercrime has long revolved around monetizing unauthorized access from credit card theft to ransomware. Now, attackers are leveraging prediction markets like Kalshi and Polymarket to profit from foreknowledge of real-world events, turning future outcomes into tradable assets.
These platforms allow users to bet on everything from corporate data breaches to regulatory decisions, but hackers are no longer just passive observers. By gaining early access to nonpublic information or manipulating systems, they can predict or even control the outcomes they bet on.
### How Attackers Could Game the System
- Data Breach Betting: A hacker breaches a company, discovers an undisclosed incident, and places a bet on its public disclosure profiting when the breach is reported.
- DeFi Exploits: An attacker identifies a vulnerability in a decentralized finance project, bets on its compromise, then executes the hack earning twice.
- Regulatory Insider Trading: Similar to the EDGAR hack, attackers access embargoed corporate or government filings and bet on outcomes tied to that information.
- Sensor Manipulation: In markets tied to physical data (e.g., temperature readings), hackers alter sensor feeds to skew results in their favor.
- Oracle & Voting Exploits: In decentralized markets, attackers influence outcome-determining mechanisms (e.g., oracles or votes) to rig results.
- Disinformation + Betting: Attackers take a position on a negative event (e.g., a company’s stock drop) and amplify false narratives to ensure the outcome.
- Legal Filing Exploits: Early access to court documents (via systems like PACER) allows betting on lawsuit disclosures before they become public.
- Ransomware + Market Manipulation: After breaching a company, attackers could bet on breach disclosures or operational disruptions, then adjust tactics (e.g., data leaks) to guarantee payouts.
### Why This Is Different
While insider trading and market manipulation aren’t new, prediction markets introduce a financial layer where events themselves become tradable commodities. Existing laws such as data breach disclosure requirements can inadvertently create exploitable windows, giving attackers a predictable timeline to act.
Though no major prosecutions have yet targeted this specific scheme, the building blocks are already in place. Cybercriminals have long stolen early information, manipulated systems, and profited from timing. Prediction markets simply connect these tactics into a new revenue stream.
The core risk? These markets assume participants are passive predictors but attackers are anything but. With the ability to see behind the curtain or pull the strings, betting on the future becomes a far more dangerous game.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Polymarket ??
What was Polymarket's A.I Rankiteo Cyber Score in May 2026 ??
What was Polymarket's A.I Rankiteo Cyber Score in April 2026 ??
What was Polymarket's A.I Rankiteo Cyber Score in March 2026 ??
What was Polymarket's A.I Rankiteo Cyber Score in February 2026 ??
What was Polymarket's A.I Rankiteo Cyber Score in January 2026 ??
What was Polymarket's A.I Rankiteo Cyber Score in December 2025 ??
What was Polymarket's A.I Rankiteo Cyber Score in November 2025 ??
What was Polymarket's A.I Rankiteo Cyber Score in October 2025 ??
What was Polymarket's A.I Rankiteo Cyber Score in September 2025 ??
What was Polymarket's A.I Rankiteo Cyber Score in August 2025 ??
What was Polymarket's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Polymarket's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Polymarket ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Polymarket's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?