The prediction market platform Polymarket is suspected of a data breach, with over 300,000 records and an exploit toolkit leaked
The decentralized prediction market platform Polymarket is suspected to have been hacked, with the threat actor xorcat posting over 300,000 data records and a corresponding exploit toolkit on a well-known cybercrime forum.
It is reported that the attacker extracted data through undisclosed API endpoints, pagination bypass, and CORS misconfigurations in Polymarket Gamma and CLOB API. The leaked content includes: 10,000 users' complete personal information (including names, proxy wallets, and base addresses), 4,111 comments, 1,000 reports (including 58 ETH addresses and administrator verification address identifiers), 48,536 Gamma market metadata, over 250,000 active CLOB market fixed product market maker addresses, and 9,000 social graph data of followers.
The toolkit contains proof-of-concept code for multiple vulnerabilities, including CVE-2025-62718 (Axios NO_PROXY bypass, CVSS 9.9, which can trigger server-side request forgery), CVE-2024-51479 (Next.js middleware authentication bypass, CVSS 7.5), and CORS misconfigurations. Additionally, the toolkit includes automated continuous pull scripts and a complete red team report.
You may also like

Morning Report | CoinEx becomes a key hub for Iran to evade sanctions, involving over $3.8 billion in funds; Kalshi seeks a new round of financing, with a valuation potentially rising to $40 billion

From the white-haired stock god to the billionaire fund mogul, the smart people shorting Nvidia are all getting rich using the same framework

Why do cryptocurrency projects always like to change their names?

Global Launch: As predictions become the most scarce asset in the AI era, Manadia is defining the next generation of the value internet

Who is footing the bill for the $64 billion accounting frenzy?

I never expected that the first application of AI x Crypto would be in security auditing

What is your view on Binance's competitive advantages?

ETH has entered a non-consensus phase, and the turning point is approaching!

The shift in the cloud of the air: from despising stablecoins a year ago to the high-profile entry of capital today

The survival dilemma of small and medium exchanges behind the withdrawal anomalies exposed by AscendEX

Why Is Bitcoin Falling Below $60K? 5 Key Market Drivers Explained
Bitcoin has dropped sharply amid ETF outflows, Strategy stock weakness, AI stock rallies, and changing Fed expectations. Explore the key forces driving BTC’s latest correction and what traders should watch next.

Bitcoin vs. Gold in 2026: Which Asset Performs Better in Different Markets?

Morning News | The draft amendment to the People's Bank of China Law aims to clarify the legal status of digital renminbi; South Korea will transfer about 40 unregistered virtual asset service providers to law enforcement agencies

The cryptocurrency industry has entered the "Show Me" era: merely relying on vision is no longer enough

Interpreting the Ethereum Foundation's new structure: Reaffirming self-sovereignty amid institutional trends

Former SpaceX engineer reconstructs the financial execution system using first principles

Standard Chartered Bank sings a 50x rhapsody again, aiming for AAVE to reach 3500 USD

