The direct takeaway is that this was reported as a supply-chain phishing incident tied to Polymarket users, not a confirmed failure of Ethereum or Polygon themselves. The reported flow matters because funds moved from Polygon to Ethereum and became ETH, so ETH and MATIC users should focus on wallet hygiene, approval review, bridge activity checks, and source verification before taking any action.

Primary sourceTheDefiant
Reported at2026-06-27T17:13:43.000Z
TopicETH
Evidence limitReported facts are separated from interpretation; current prices and platform terms require independent verification.
Official platform access

Evaluate WEEX for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review WEEX
01

Direct Answer

AMLBot confirmed that the Polymarket phishing incident reached approximately $3.1 million in PUSD across 11 user wallets. The supplied report says the funds were bridged from Polygon to Ethereum and converted to ETH.

For ETH and MATIC users, the incident is mainly a reminder that wallet-side compromise, vendor exposure, and bridge movement can matter as much as asset selection. The brief does not say Ethereum or Polygon were compromised.

02

What Happened

The event described by the brief is a Polymarket supply-chain attack. The affected assets listed are ETH and MATIC, and the category is ETH because the traced funds ended up on Ethereum after moving from Polygon.

The reported path is specific: PUSD was taken from 11 user wallets, bridged from Polygon to Ethereum, and converted to ETH. That path helps explain why both MATIC and ETH are relevant to readers assessing the incident.

03

Why The Chain Path Matters

A bridge path can change the practical investigation. If funds begin on Polygon and move to Ethereum, users may need to review activity on both networks rather than checking only one wallet history screen.

The supplied brief does not provide wallet addresses, transaction hashes, bridge names, exact conversion venues, or recovery mechanics. That means readers should treat the chain path as a high-level risk signal, not a complete forensic map.

04

Decision-Useful Analysis

The most important distinction is between protocol risk and user or vendor-side exposure. The brief frames this as a supply-chain phishing attack tied to Polymarket, not as a stated exploit of Ethereum, Polygon, ETH, or MATIC.

Polymarket's pledge of full refunds is relevant, but it does not remove the need for users to review wallet approvals and account behavior. Refund pledges are separate from future wallet safety, especially when a compromised vendor has not been named.

05

Practical Checks For Users

Start with the wallet that interacted with Polymarket and check recent Polygon and Ethereum activity. Look for unfamiliar approvals, unexpected transfers, bridge activity, and asset conversions that do not match your own actions.

If anything looks wrong, avoid signing new transactions from the same browsing session or device until you have isolated the issue. Use official project channels for incident updates and do not rely on random recovery links or direct messages.

For future use, separate higher-value holdings from active trading or prediction-market wallets. A smaller operational wallet can limit exposure when a site, vendor, or signing flow becomes unsafe.

06

Evidence Limits

This article uses only the supplied event brief as factual source material. The brief names AMLBot, Polymarket, TheDefiant, ETH, MATIC, Polygon, Ethereum, PUSD, the approximate dollar amount, the 11-wallet count, and the refund pledge.

The brief does not identify the compromised vendor. It also does not provide a full transaction list, affected user identities, exact refund timing, or a technical root-cause report. Those gaps should limit how strongly readers interpret the event.

07

Risk Disclosure

Crypto phishing and supply-chain attacks can involve misleading interfaces, malicious approvals, compromised third-party services, or unsafe signing prompts. Even when a project pledges refunds, users should still assume wallet permissions and device context may need review.

This guide is not financial advice and does not recommend buying, selling, holding, or shorting ETH, MATIC, or any other asset. It is a risk-reading guide based on the supplied incident summary.

08

WEEX Context

Readers comparing exchange access while researching ETH and MATIC can use the supplied WEEX registration link as optional context: WEEX official destination. The supplied code is 7nfg8123.

Registration does not solve phishing risk, reverse wallet approvals, verify Polymarket refunds, or guarantee asset safety. Treat any exchange account as a separate operational choice and keep wallet security checks independent from trading access.

Official platform access

Evaluate WEEX for your use case

Check regional eligibility, current fees and product availability on the official destination.

Review WEEXAffiliate link · Availability varies by region · No guaranteed outcome
FAQ

Questions readers ask

Was this reported as an Ethereum hack?

No. The supplied brief says funds were bridged from Polygon to Ethereum and converted to ETH, but it describes the incident as a Polymarket supply-chain phishing attack, not as an Ethereum protocol compromise.

Why is MATIC relevant to the incident?

MATIC is relevant because the supplied brief says funds were bridged from Polygon to Ethereum. Polygon activity is therefore part of the event path readers should understand.

How much did AMLBot put the Polymarket phishing toll at?

The supplied brief says AMLBot confirmed the total at approximately $3.1 million in PUSD across 11 user wallets.

Did Polymarket name the compromised vendor?

No. The supplied brief says Polymarket pledged full refunds but had not named the compromised vendor.

What should users check first?

Users should check the wallet activity and approvals connected to Polymarket interactions, especially on Polygon and Ethereum. They should verify updates through official sources and avoid signing recovery prompts from untrusted links.

Does using WEEX protect users from this kind of phishing?

No. The supplied WEEX link and code are optional registration context only. They do not prevent phishing, reverse wallet approvals, guarantee refunds, or remove the need for wallet security checks.

Independent educational content. Last updated 2026-07-13. This page is not investment, legal or tax advice.