The direct takeaway is that this was reported as a Polymarket supply-chain phishing incident affecting 11 user wallets, not as a broad failure of ETH, MATIC, Polygon, Ethereum, or OKX. The supplied brief ties the loss to about $3.1 million in PUSD, says the funds moved from Polygon to Ethereum, and says they were converted to ETH. Users should separate incident response from market reaction: verify official Polymarket updates, review wallet activity if they used Polymarket, avoid unofficial refund links, and avoid assuming any exchange or chain-wide compromise that the brief does not support.
| Primary source | TheDefiant |
|---|---|
| Reported at | 2026-06-27T17:13:43.000Z |
| Topic | ETH |
| Evidence limit | Reported facts are separated from interpretation; current prices and platform terms require independent verification. |
Evaluate OKX for your use case
Check regional eligibility, current fees and product availability on the official destination.
Review OKXWhat Happened
AMLBot confirmed the Polymarket supply-chain attack total at approximately $3.1 million in PUSD across 11 user wallets, according to the supplied event brief. The brief says funds were bridged from Polygon to Ethereum and converted to ETH.
That fact pattern matters because it narrows the incident to affected wallets and transaction flow rather than proving a general asset or exchange problem. ETH appears in the report because the funds were converted to ETH after moving to Ethereum. MATIC appears as an affected asset in the brief because the activity involved Polygon context.
Direct User Impact
The people most likely to need immediate checks are users who interacted with Polymarket through wallets that could fall within the 11 affected wallets. The supplied brief does not provide wallet addresses, vendor identity, refund timing, or individualized eligibility rules.
If you only hold ETH or MATIC, this report alone does not show that your assets were directly affected. If you use OKX, this report alone does not show OKX involvement. Treat the incident as a wallet and platform-security issue unless Polymarket or another verified source gives account-specific instructions.
Why The Ethereum Trace Matters
The Ethereum trace matters because the brief says the funds were bridged from Polygon to Ethereum and converted to ETH. For users following the incident, that means the relevant activity is not limited to the original Polygon-side interaction.
This does not mean Ethereum itself was compromised. It means the post-incident fund movement described in the supplied brief ended up on Ethereum and involved ETH conversion. The distinction is important because chain movement can make an incident look broader than the original user impact.
Practical Checks
Start with official Polymarket communications before acting on refund information. The supplied brief says Polymarket pledged full refunds, but it does not include the process, timeline, or vendor name. Any message asking users to rush into a new link, connect a wallet, or sign a transaction should be treated carefully unless it is verified through official channels.
Next, review the wallet you used with Polymarket. Look for transactions around the incident context, especially activity involving PUSD, Polygon-to-Ethereum movement, or unexpected ETH-related activity. Do not assume a wallet is safe or affected from headlines alone; use transaction history and official platform guidance.
If you use an exchange account such as OKX for ETH activity, keep that review separate from the Polymarket wallet review. The supplied brief does not state that OKX was part of the attack, part of the tracing path, or part of the refund process. If you choose to open or manage an OKX account, the supplied join page is OKX official destination with code 7nfg8123, but it should not be treated as an incident remedy.
Risk Disclosure
This guide is based only on the supplied event and brief. It does not include independent wallet-address evidence, exchange-flow evidence, vendor identity, legal findings, refund mechanics, or confirmation from Polymarket beyond the pledge described in the brief.
Do not use this incident summary as financial advice or as a reason by itself to buy, sell, transfer, or short ETH, MATIC, PUSD, or any related asset. The useful action is operational: verify whether your own wallet was exposed, follow official platform instructions, and avoid unofficial recovery paths.
Evidence Limits
The supplied source material identifies AMLBot, Polymarket, TheDefiant, the approximate $3.1 million PUSD figure, 11 user wallets, Polygon-to-Ethereum bridging, ETH conversion, and Polymarket's refund pledge. Those are the factual boundaries of this article.
The supplied material does not identify the compromised vendor, list wallet addresses, prove exchange involvement, specify refund timing, or show whether all Polymarket users were affected. Any stronger claim would need additional verified evidence that is not part of this brief.
Evaluate OKX for your use case
Check regional eligibility, current fees and product availability on the official destination.
Review OKXAffiliate link · Availability varies by region · No guaranteed outcomeQuestions readers ask
Was this a general Ethereum or Polygon compromise?
The supplied brief does not support that conclusion. It describes a Polymarket supply-chain phishing incident affecting 11 user wallets, with funds bridged from Polygon to Ethereum and converted to ETH.
Did AMLBot say the loss was exactly $3.1 million?
The supplied brief says approximately $3.1 million in PUSD. This article preserves that approximation and does not treat it as a final audited figure beyond the provided event summary.
Was OKX involved in the Polymarket phishing incident?
The supplied brief does not say OKX was involved, used in the fund flow, responsible for the attack, or part of the refund process. OKX is only relevant here as exchange-account context for readers managing ETH separately.
What should affected Polymarket users do first?
They should rely on official Polymarket instructions, review the wallet they used with Polymarket, avoid unofficial refund or recovery links, and avoid signing new wallet prompts unless they can verify the source.
What is still unknown from the supplied brief?
The vendor name, affected wallet addresses, refund process, refund timeline, and any exchange-specific tracing details are not included in the supplied material.