Polymarket points to third-party login tool after users report account breaches

CN
coindesk
Follow
5 hours ago


What to know : Prediction market Polymarket experienced a series of account breaches, with several users reporting missing funds and suspicious login attempts. The platform attributed the incident to an unidentified third-party login provider. Several users speculated the provider was Magic Labs, a popular tool for email-based logins and wallet creation. Polymarket acknowledged the issue, but did not disclose the number of affected users or the amount of money stolen, highlighting the risks of relying on third-party tools in crypto platforms.

Prediction market Polymarket blamed an unidentified third-party login provider for recent account breaches reported by several users.

The platform confirmed the security incident on its Discord channel after users reported missing funds and suspicious login attempts.

Social media posts on Reddit and X show several users received unexpected login alerts and then discovered their balances had been wiped. One user said their account dropped to just one cent despite not having their devices compromised and no other affected services.

Another user on X said they lost around $2,000, despite having two-factor authentication on. A third user said their “top 1000” Polymarket account was drained, while a fourth said a testing account was drained.

While Polymarket didn’t name the provider in question, several users pointed to Magic Labs, which allows email-based logins and automatically creates wallets for users. The tool is popular and allows newcomers who don’t have crypto wallets to easily access one, making it a common entry point to Polymarket and other platforms.

The company acknowledged the issue but did not disclose how many users were affected or the amount of money stolen.

“We recently identified and resolved a security issue affecting a small number of users. The issue was caused by a vulnerability introduced by a third-party authentication provider," a company spokesperson said on Discord. “Polymarket takes security extremely seriously, and the issue has been remediated. There is no ongoing risk at this time, and we will be in contact with impacted users."

Polymarket and Magic Labs did not respond immediately to emails asking for comment.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink