The prediction market platform Polymarket is suspected of a data breach, with over 300,000 records and an exploit toolkit leaked
The decentralized prediction market platform Polymarket is suspected to have been hacked, with the threat actor xorcat posting over 300,000 data records and a corresponding exploit toolkit on a well-known cybercrime forum.
It is reported that the attacker extracted data through undisclosed API endpoints, pagination bypass, and CORS misconfigurations in Polymarket Gamma and CLOB API. The leaked content includes: 10,000 users' complete personal information (including names, proxy wallets, and base addresses), 4,111 comments, 1,000 reports (including 58 ETH addresses and administrator verification address identifiers), 48,536 Gamma market metadata, over 250,000 active CLOB market fixed product market maker addresses, and 9,000 social graph data of followers.
The toolkit contains proof-of-concept code for multiple vulnerabilities, including CVE-2025-62718 (Axios NO_PROXY bypass, CVSS 9.9, which can trigger server-side request forgery), CVE-2024-51479 (Next.js middleware authentication bypass, CVSS 7.5), and CORS misconfigurations. Additionally, the toolkit includes automated continuous pull scripts and a complete red team report.
You may also like

The other side of Musk's trillion-dollar fortune: 85% cannot be sold

The U.S. government prohibits foreigners from using Fable 5, Anthropic issues a rebuttal

Citibank releases "2030 Asset Tokenization Market Outlook": 6 major trends may create a $8.2 trillion market

The trillion-dollar valuation test: Are the three major super IPOs a celebration for tech stocks or a nightmare for the crypto market?

Morning Report | Digital Asset completes $355 million financing led by a16z Crypto; Meta completes operational separation from Manus

a16z Crypto Partner: Cash flow is the moat

Cryptocurrency market makers collectively seek change as it becomes increasingly difficult to make money

How TradeXYZ, xStocks, and Alpaca break down the SpaceX IPO into three different strategies

$75 billion in risk asset redistribution: How will SpaceX's IPO affect U.S. stocks and Bitcoin?

Why Is BlackRock Investing $5 Billion in the SpaceX IPO?

Morning News | CME Group launches Nasdaq Cryptocurrency Index futures; Asset management giant Janus Henderson strategically invests in Ethena

Bitcoin Layer 2 Network Botanix: Why Did We Choose to Dissolve?

Why did Oracle deliver the strongest financial report in history, yet its stock price fell?

When the P2P illicit funds from ten years ago turned into 60,000 bitcoins

Dialogue with OmenX Founder: Why does the prediction market need an evolution from "spot" to "derivatives"?

Galaxy in-depth report: Is Solana still worth paying attention to?

Young people in South Korea make a "final effort" in the epic bull market

