Web Analytics
Coinpaper
2026-04-29 09:30:00

Polymarket Rejects Dark Web Claims of Massive Data Breach

The platform said the information mentioned by the so-called attacker was already publicly available through its APIs and on-chain blockchain data, not the result of unauthorized access. Polymarket also rejected claims that it lacked a bug bounty program. Security researchers also questioned the breach allegations, with some suggesting the data may have been scraped from public sources rather than leaked from internal systems. Polymarket Denies Leak Prediction markets platform Polymarket denied allegations that it suffered a customer data breach after claims surfaced on dark web forums that a hacker stole private user information. The controversy began when cybersecurity monitoring accounts and security researchers shared screenshots from DarkForums showing a user operating under the pseudonym “xorcat” claiming responsibility for the supposed breach. According to the post, the hacker alleged that more than 300,000 records were obtained, including around 10,000 unique user profiles. The claimed data reportedly included full names, profile images, proxy wallet information, and base addresses. These claims quickly attracted attention from the crypto community, particularly because the industry recently experienced an increase in cyberattacks, scams, and exploits. Polymarket responded publicly and dismissed the allegations, calling the breach claims “complete and utter nonsense.” The company stated that the information referenced by the hacker was not stolen private data, but instead consisted of information that was already publicly accessible through its open APIs and on-chain blockchain records. Polymarket argued that transparency is a core feature of blockchain-based systems, where transaction and market data can be openly audited by anyone. In a response on social media, the platform mocked the hacker’s claims by suggesting that publicly available data was simply collected and repackaged as if it were a leak. Polymarket explained that developers and users can already access a lot of this information for free through official endpoints. This means that no unauthorized breach of internal systems actually took place. The hacker also claimed the data was being released because Polymarket allegedly lacked a bug bounty program. However, this claim was contradicted by Polymarket as it launched an active bug bounty initiative on April 16 and already received hundreds of submissions by Wednesday. This weakened the credibility of the hacker’s narrative. Other claims from xorcat suggested that undocumented API endpoints, pagination bypass techniques, and CORS misconfigurations in Polymarket’s Gamma and CLOB APIs were used to gather the data. The hacker also said other prediction market platforms were compromised and threatened to release more information in the coming days. Despite the dramatic claims, several cybersecurity experts also expressed their skepticism. Vladimir S, a threat researcher and chief security officer at Legalblock, said the situation looked more like someone scraping publicly available information and falsely presenting it as a database leak rather than exposing any genuine compromise.

Crypto 뉴스 레터 받기
면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.