The direct takeaway is that AMLBot confirmed the Polymarket phishing toll at about $3.1 million in PUSD across 11 wallets, with the stolen funds traced from Polygon to Ethereum and converted into ETH. For ETH and MATIC watchers, the event is less about market direction and more about wallet hygiene, bridge monitoring, and third-party vendor risk.

Primary sourceTheDefiant
Reported at2026-06-27T17:13:43.000Z
TopicETH
Evidence limitReported facts are separated from interpretation; current prices and platform terms require independent verification.
Official platform access

Evaluate BYBIT for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review BYBIT
01

What Happened

Blockchain intelligence firm AMLBot confirmed the Polymarket supply-chain attack total at approximately $3.1 million in PUSD across 11 user wallets, according to the supplied event brief from TheDefiant.

The reported laundering path matters because the funds were bridged from Polygon to Ethereum and converted to ETH. That links the incident to both MATIC infrastructure exposure and ETH settlement visibility, even though the original user losses were described in PUSD.

02

Why ETH and MATIC Are Involved

ETH is central to the final leg of the reported trail because the funds were converted to ETH after reaching Ethereum. MATIC is relevant because the funds were bridged from Polygon before that conversion.

This does not mean Ethereum or Polygon caused the phishing attack. The supplied brief frames the event as a Polymarket supply-chain compromise, with the affected assets listed as ETH and MATIC because of the traced movement across chains.

03

What Users Should Check

Users should review recent wallet approvals, bridge activity, and any unexpected interactions connected to Polymarket-related workflows. The practical concern is whether a wallet signed a malicious approval or interacted with a compromised front-end or vendor-linked component.

A careful check should focus on transaction history, approval permissions, destination addresses, and whether any funds moved from Polygon toward Ethereum without the user’s intent. The brief does not provide victim addresses, so checks must be based on each user’s own wallet records.

04

Evidence Limits

The available facts are limited to the supplied event brief: AMLBot confirmed the approximate loss amount, the number of wallets, the Polygon-to-Ethereum path, ETH conversion, Polymarket’s refund pledge, and the fact that the compromised vendor was not named.

The brief does not supply wallet addresses, transaction hashes, vendor identity, refund timing, law-enforcement status, or any market-impact data. Any claim beyond those points would be speculation and should not be treated as confirmed.

05

Risk Disclosure

This incident shows how supply-chain compromise can create losses even when users believe they are interacting with a familiar crypto product. The risk is not limited to private-key theft; malicious approvals, compromised interfaces, and vendor-side exposure can also create asset loss.

Nothing in the supplied brief supports a price forecast for ETH or MATIC. Traders should separate security analysis from market direction and avoid treating a phishing report as a standalone buy, sell, or hold signal.

06

Exchange Context

For users comparing exchange workflows after an incident like this, the useful question is not whether an exchange can remove on-chain risk. It cannot. The more practical question is how users manage custody, approvals, deposits, withdrawals, and account security around any venue they use.

Bybit-related readers can use this event as a prompt to review their own security checklist before moving funds: confirm destination addresses, keep exchange-account protections enabled, and separate active trading wallets from wallets used for experimental dapps. Any signup or referral context should be secondary to that security review.

Official platform access

Evaluate BYBIT for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review BYBITAffiliate link · Availability varies by region · No guaranteed outcome
FAQ

Questions readers ask

How much did AMLBot say was lost in the Polymarket phishing incident?

AMLBot put the confirmed toll at approximately $3.1 million in PUSD across 11 user wallets, based on the supplied event brief.

Where were the funds traced?

The funds were reportedly bridged from Polygon to Ethereum and then converted to ETH.

Has Polymarket named the compromised vendor?

No. The supplied brief says Polymarket has pledged full refunds but has not named the compromised vendor.

Does this incident prove anything about ETH or MATIC price direction?

No. The brief supports a security-risk analysis, not a market forecast. It does not provide price, liquidity, or trading-impact evidence.

What is the most practical user response?

Users should review wallet approvals, transaction history, bridge activity, and any unexpected Polymarket-related interactions. The goal is to identify exposure, not to infer a trading signal.

Independent educational content. Last updated 2026-07-13. This page is not investment, legal or tax advice.