AMLBot says the Polymarket phishing incident affected 11 user wallets for about $3.1 million in PUSD. The funds were bridged from Polygon to Ethereum and converted to ETH. For users, the practical response is to verify wallet approvals, review Polygon and Ethereum activity, avoid assuming the vendor identity, and wait for Polymarket’s refund process details.

Primary sourceTheDefiant
Reported at2026-06-27T17:13:43.000Z
TopicETH
Evidence limitReported facts are separated from interpretation; current prices and platform terms require independent verification.
Official platform access

Evaluate BACKPACK for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review BACKPACK
01

What Happened

According to the supplied event brief, blockchain intelligence firm AMLBot confirmed the Polymarket supply-chain attack total at approximately $3.1 million in PUSD. The affected set is described as 11 user wallets.

The reported path is specific: funds were bridged from Polygon to Ethereum and converted to ETH. That makes the incident relevant to users watching both MATIC-linked Polygon activity and Ethereum wallet exposure.

02

Why ETH and MATIC Users Should Care

The event links Polygon and Ethereum in the same incident. The supplied facts do not say that ETH or MATIC themselves failed; they say the funds moved across chains and ended as ETH after conversion.

That distinction matters. A bridge path can make an incident look broader than the original compromise. Users should separate confirmed fund movement from unconfirmed assumptions about wallet software, exchanges, bridges, or vendors.

03

What Is Still Unknown

The supplied brief says Polymarket pledged full refunds but has not named the compromised vendor. That means vendor identity, precise compromise mechanics, refund timing, and user eligibility details are not established here.

Because those facts are not supplied, this article should not be read as a claim about who caused the attack, whether a specific tool was unsafe, or how fast affected users will be repaid.

04

Practical Wallet Checks

Users can start with simple checks that do not require speculation. Review recent Polygon and Ethereum transactions, look for unfamiliar approvals, and compare wallet activity against the time period surrounding the incident described in the brief.

If a wallet interacted with Polymarket or related flows, the cautious path is to inspect permissions and avoid signing new transactions from unexpected prompts. The supplied facts support vigilance, not panic or broad claims about all ETH and MATIC activity.

05

Risk Disclosure

This incident is a phishing and supply-chain event in the supplied brief, not a market prediction. It does not establish that ETH, MATIC, Polygon, Ethereum, or Polymarket users generally will face the same loss pattern.

Nothing here is financial advice. The decision-useful point is operational: verify wallet state, avoid unconfirmed links, and rely on direct Polymarket communications for refund instructions if you are affected.

06

Backpack Context

If you already use Backpack or are comparing crypto platforms while reviewing ETH-related activity, keep the same standard: check wallet permissions, confirm URLs carefully, and do not treat any referral or exchange link as proof of safety.

For readers who decide independently to visit Backpack, the supplied referral URL is BACKPACK official destination and the supplied code is 7nfg8123. This is context, not a guarantee, ranking claim, or recommendation to trade.

Official platform access

Evaluate BACKPACK for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review BACKPACKAffiliate link · Availability varies by region · No guaranteed outcome
FAQ

Questions readers ask

How much did AMLBot put the Polymarket phishing toll at?

The supplied brief says AMLBot put the total at approximately $3.1 million in PUSD.

How many wallets were affected?

The supplied brief says 11 user wallets were affected.

Where were the funds traced?

The supplied brief says the funds were bridged from Polygon to Ethereum and converted to ETH.

Has Polymarket named the compromised vendor?

No. The supplied brief says Polymarket has not named the compromised vendor.

Did Polymarket promise refunds?

Yes. The supplied brief says Polymarket pledged full refunds, but it does not provide timing, process, or eligibility details.

Does this mean ETH or MATIC are unsafe?

The supplied facts do not support that claim. They describe a Polymarket supply-chain phishing incident and fund movement involving Polygon and Ethereum, not a failure of ETH or MATIC themselves.

Independent educational content. Last updated 2026-07-13. This page is not investment, legal or tax advice.