🎉 Share Your 2025 Year-End Summary & Win $10,000 Sharing Rewards!
Reflect on your year with Gate and share your report on Square for a chance to win $10,000!
👇 How to Join:
1️⃣ Click to check your Year-End Summary: https://www.gate.com/competition/your-year-in-review-2025
2️⃣ After viewing, share it on social media or Gate Square using the "Share" button
3️⃣ Invite friends to like, comment, and share. More interactions, higher chances of winning!
🎁 Generous Prizes:
1️⃣ Daily Lucky Winner: 1 winner per day gets $30 GT, a branded hoodie, and a Gate × Red Bull tumbler
2️⃣ Lucky Share Draw: 10
Polymarket Confirms User Account Hacks Tied to Third-Party Vulnerability – Funds Drained Despite 2FA
Decentralized prediction market platform Polymarket acknowledged on December 25, 2025, that several user accounts were compromised due to a security vulnerability in a third-party authentication provider.
Affected users reported unauthorized logins and drained balances—despite enabling two-factor authentication (2FA) and no evidence of personal device compromise—prompting speculation on X and Reddit that the issue may involve Magic Labs, a common wallet connection service. While Polymarket has not named the provider, the incident highlights ongoing third-party risks in Web3 platforms, even for non-custodial services. No official loss figures have been disclosed, but individual reports describe significant fund withdrawals after suspicious login attempts.
Details of the Polymarket Account Hacks
Users began surfacing complaints earlier in the week:
Polymarket’s statement confirmed the third-party root cause but provided limited specifics on scope or remediation timeline.
Why Third-Party Vulnerabilities Pose Risks to DeFi Users
Even decentralized platforms rely on external services for UX:
This incident echoes past breaches where third-party tools (e.g., Ledger Connect kit) exposed users despite strong individual security.
Implications for Polymarket and Prediction Market Users
Polymarket—known for high-volume event betting—faces reputational pressure:
No evidence of on-chain exploits; losses tied to account takeovers.
In summary, Polymarket’s December 25, 2025, confirmation of user account hacks via a third-party vulnerability—resulting in drained funds despite 2FA—underscores persistent supply-chain risks in Web3. With speculation centering on Magic Labs and reports of unauthorized access, the incident serves as a reminder for users to review connected services and enable advanced security options. Monitor official Polymarket channels for updates on affected accounts and resolution steps in this developing situation.