AMLBot put the Polymarket supply-chain phishing loss at approximately $3.1 million in PUSD across 11 wallets. The brief says the funds moved from Polygon to Ethereum and were converted to ETH. Polymarket has pledged full refunds, but the compromised vendor has not been named.
| Primary source | TheDefiant |
|---|---|
| Reported at | 2026-06-27T17:13:43.000Z |
| Topic | ETH |
| Evidence limit | Reported facts are separated from interpretation; current prices and platform terms require independent verification. |
Evaluate BINANCE for your use case
Check regional eligibility, current fees and product availability on the official destination.
Review BINANCEWhat happened
The supplied event says blockchain intelligence firm AMLBot confirmed a Polymarket supply-chain attack total of approximately $3.1 million in PUSD across 11 user wallets.
The same brief says the funds were bridged from Polygon to Ethereum and converted to ETH. That makes the incident relevant to users watching both Ethereum activity and Polygon-linked wallet exposure.
Why it matters
The practical issue is not only the dollar amount. A supply-chain phishing event can put ordinary wallet actions under suspicion, especially when users are asked to approve movement across networks or asset conversion.
For ETH and MATIC users, the key decision is whether a wallet prompt matches the action they intended. A transaction involving Polygon-to-Ethereum movement or ETH conversion should be checked carefully before approval.
Evidence limits
This article uses only the supplied event brief as factual source material. It does not independently verify AMLBot’s analysis, the wallet count, the PUSD amount, the bridge path, or the conversion into ETH.
The brief says Polymarket has pledged full refunds, but it does not name the compromised vendor. It also does not provide refund timing, eligibility details, recovery status, or final attribution beyond the supplied source material.
Practical checks
Before approving wallet activity connected to Polymarket-like apps, prediction markets, Polygon bridging, or Ethereum conversion, compare the transaction request with the action you actually intended to take.
If a wallet may be affected, preserve transaction details, avoid repeating the same approval path, and wait for official refund instructions from the platform involved. Do not assume a refund pledge removes the need to secure the wallet.
Risk disclosure
This is a security-context article, not financial advice. The brief does not support any claim about ETH or MATIC price direction, exchange flows, rankings, rewards, registration results, or recovery outcomes.
A refund pledge is not the same as confirmed reimbursement. Until details are published by the relevant platform, users should separate asset-security decisions from trading decisions.
Binance context
The supplied brief includes a Binance CTA link and code, but it does not say Binance was part of the fund path or the attack. The reported path in the event is Polygon to Ethereum, followed by conversion to ETH.
If you choose to use the supplied Binance entry point, the provided URL is BINANCE official destination and the code is 7nfg8123. Treat it as optional account context, not as a guarantee of safety, refunds, rewards, or outcomes.
Evaluate BINANCE for your use case
Check regional eligibility, current fees and product availability on the official destination.
Review BINANCEAffiliate link · Availability varies by region · No guaranteed outcomeQuestions readers ask
What did AMLBot report about the Polymarket phishing incident?
The supplied brief says AMLBot confirmed the Polymarket supply-chain attack total at approximately $3.1 million in PUSD across 11 user wallets.
Which networks and assets are named in the brief?
The brief names Polygon, Ethereum, PUSD, ETH, and the affected assets ETH and MATIC. It says funds were bridged from Polygon to Ethereum and converted to ETH.
Has the compromised vendor been named?
No. The supplied brief says Polymarket has not named the compromised vendor.
Does Polymarket’s refund pledge settle the risk?
No. The brief says Polymarket pledged full refunds, but it does not provide timing, eligibility, recovery status, or final refund mechanics.
Is this a Binance tracing report?
No. The supplied event says funds were traced from Polygon to Ethereum and converted to ETH. Binance appears only as the provided CTA context in the brief.