Polymarket Hack Drains $600K in $POL Tokens
The Polymarket hack has triggered major discussion across the crypto industry after attackers drained more than $600,000 in POL tokens from an operational contract connected to Polymarket.
The incident unfolded on May 22, 2026, after hackers compromised a private key tied to the platform’s UMA CTF Adapter on the Polygon network. Despite the exploit, Polymarket says user funds, active prediction markets, and trading positions remain safe.
How the Polymarket Hack Happened
Blockchain investigators ZachXBT and Bubblemaps reported that the attacker repeatedly withdrew around 5,000 POL tokens every 30 seconds from the affected contract.
The stolen funds moved across more than 15 wallet addresses. Some transfers reportedly passed through swap and obfuscation services, including ChangeNOW.
The compromised contract was the UMA CTF Adapter, which connects Polymarket’s prediction markets to UMA’s oracle infrastructure.
Attacker Wallet Address
0x8F98075db5d6C620e8D420A8c516E2F2059d9B91
Polymarket Says User Funds Are Safe
Polymarket clarified that the Polymarket hack did not originate from a flaw in its smart contracts or prediction market infrastructure.
According to company representatives, attackers gained access to a legacy operational private key used for internal wallet management and rewards distribution.
The platform stated:
- User balances remain secure
- Open positions are unaffected
- Market resolution systems continue operating normally
- The affected adapter contract is isolated from core trading infrastructure
Community trackers later reported that the draining activity slowed significantly after the initial exploit.
Why the Polymarket Hack Matters
The Polymarket hack highlights a growing problem in decentralized finance: operational security failures.
Many recent crypto attacks have targeted private keys, admin wallets, and internal operational systems instead of exploiting smart contract code directly.
Although this incident caused smaller losses compared to major DeFi breaches, it still raises concerns about wallet management and access controls across crypto platforms.
For more on crypto security:
- Read our guide to protecting crypto wallets
- Learn how decentralized oracles work
- Explore the biggest DeFi hacks of 2026
Could the Stolen Funds Be Recovered?
Investigators continue tracking the stolen POL tokens across the Polygon ecosystem.
If attackers attempt to move funds through centralized exchanges, blockchain analysts and law enforcement agencies may still have opportunities to freeze or recover part of the assets.
The crypto community will likely monitor:
- Exchange deposit activity
- Cross-chain bridge transfers
- Mixer transactions
- Wallet clustering analysis
Final Thoughts on the Polymarket Hack
The Polymarket hack serves as another reminder that crypto security depends heavily on operational practices, not just audited smart contracts.
While Polymarket appears to have contained the incident quickly, the exploit shows how compromised legacy keys can still expose critical infrastructure to attackers.
As prediction markets continue growing, platforms across the industry will likely face increased pressure to strengthen wallet security, internal access controls, and operational safeguards.

