The prediction market platform Polymarket is suspected of a data breach, with over 300,000 records and an exploit toolkit leaked

By: rootdata|2026/04/29 10:42:01
0
Share
copy

The decentralized prediction market platform Polymarket is suspected to have been hacked, with the threat actor xorcat posting over 300,000 data records and a corresponding exploit toolkit on a well-known cybercrime forum.

It is reported that the attacker extracted data through undisclosed API endpoints, pagination bypass, and CORS misconfigurations in Polymarket Gamma and CLOB API. The leaked content includes: 10,000 users' complete personal information (including names, proxy wallets, and base addresses), 4,111 comments, 1,000 reports (including 58 ETH addresses and administrator verification address identifiers), 48,536 Gamma market metadata, over 250,000 active CLOB market fixed product market maker addresses, and 9,000 social graph data of followers.

The toolkit contains proof-of-concept code for multiple vulnerabilities, including CVE-2025-62718 (Axios NO_PROXY bypass, CVSS 9.9, which can trigger server-side request forgery), CVE-2024-51479 (Next.js middleware authentication bypass, CVSS 7.5), and CORS misconfigurations. Additionally, the toolkit includes automated continuous pull scripts and a complete red team report.

-- Price

--

You may also like

Morning Report | Galaxy Digital announces Q1 2026 financial report; Liquid completes $18 million Series A financing; Polymarket plans to bring major exchanges to the U.S

Overview of Important Market Events on April 28

From a banned economist to the new CEO of Xinhua: Fu Peng has figured out the second half of traffic

This uproar in the crypto circle appears to be a cultural conflict between a traditional economist and a crypto OG, but looking deeper, it is merely the new fire leveraging Fu Peng's influence in the traditional financial sector to pry open a batch of client funds that were originally difficult to r...

Why Private Credit Became the First True Bridge from TradFi to DeFi

Unveiling the core logic of private credit leading RWA: it is no longer just simple tokenization, but rather a true reshaping of the practical value of asset on-chain through real returns and deep integration with the DeFi ecosystem.

Senior cryptocurrency investor: Blockchain is showing a siphoning effect on capital

Stablecoins are the first real-world assets on the blockchain, but they will not be the last. Every billion dollars in stablecoins generates $12.2 billion in economic activity and $19 million in protocol revenue annually; once capital is on the blockchain, it gains productivity and does not go back.

When traditional crypto derivatives start to subtract: Insights from Hyper Trade's products

Say goodbye to complex contracts, as crypto derivatives begin to "subtract": This article breaks down how Hyper Trade reduces hardcore risk pricing into "second-level multiple-choice questions," reshaping the trading experience for retail investors.

My view on blockchain has changed

In-depth Reflection on the Value of Blockchain Applications and the Time Dimension

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com