Polymarket bug let thieves access nearly 500 US accounts without passwords
A bug on Polymarket allowed attackers to access nearly 500 US user accounts in late July without needing passwords, usernames, or compromised phones, according to a Wall Street Journal report covered by Gizmodo on September 20. The flaw exposed existing accounts and card information. It is unclear how long the vulnerability remained open or what data the attackers extracted beyond account access. Polymarket has not publicly confirmed the incident beyond the original reporting.
The attack hit exactly the trust layer that Polymarket is leaning on to grow beyond crypto-natives into mainstream retail finance. Its perpetual futures launch already blocks US users, but the account bug struck domestic customers directly and required no social engineering to exploit. That combination — trivial execution, large target pool — is what triggers state AG inquiries and CFTC compliance reviews.
For a CFTC-registered exchange scaling into election and pharma verticals, even a contained breach reshapes regulator appetite for enforcement. Rivals like Kalshi, which just landed brokerage distribution across Robinhood and Coinbase, will use the incident in competitive pitches about platform resilience. The metric that matters now is whether Polymarket's remediation satisfies federal examiners before its next product cycle, because a consent order would slow launches that Kalshi and ForecastEx are racing to match.