The direct takeaway is that this is a supply-chain phishing incident with a reported loss of about $3.1 million in PUSD across 11 wallets. The event matters for ETH and MATIC readers because the supplied route moved funds from Polygon to Ethereum and into ETH. It should be treated as a wallet-security and platform-vendor risk story, not as a trading signal or financial recommendation.
| Primary source | TheDefiant |
|---|---|
| Reported at | 2026-06-27T17:13:43.000Z |
| Topic | ETH |
| Evidence limit | Reported facts are separated from interpretation; current prices and platform terms require independent verification. |
Evaluate BINANCE for your use case
Check regional eligibility, current fees and product availability on the official destination.
Review BINANCEDirect Answer
AMLBot put the Polymarket phishing toll at approximately $3.1 million in PUSD across 11 user wallets. According to the supplied brief, the funds were bridged from Polygon to Ethereum and converted to ETH.
Polymarket pledged full refunds, but the brief does not identify the compromised vendor. That limits what readers can conclude about the exact source of the supply-chain failure or how similar exposure should be assessed elsewhere.
What Happened
The reported incident was a Polymarket supply-chain attack, not a general statement about all Ethereum or Polygon activity. The supplied event says the affected value was about $3.1 million in PUSD across 11 user wallets.
The fund movement described in the brief is specific: assets were bridged from Polygon to Ethereum and converted to ETH. That is why ETH and MATIC appear in the affected-asset context for this guide.
What Readers Can Conclude
The most useful conclusion is operational: wallet exposure can come through services and vendors, not only through obvious fake websites or direct private-key compromise. A user can be careful and still face risk if a trusted workflow is compromised upstream.
The event also shows why tracing across chains matters. In this case, the supplied brief describes movement from Polygon to Ethereum, then conversion to ETH. That helps readers understand the route, but it does not by itself prove recovery status, responsibility, or future asset direction.
Evidence Limits
This article uses only the supplied event and brief as factual source material. It does not add wallet addresses, transaction hashes, vendor identity, refund mechanics, recovery status, legal conclusions, or a full timeline because those details were not included in the brief.
The brief says Polymarket pledged full refunds. It does not say when refunds would be completed, how users would be verified, or whether any funds were recovered. Those points should be checked only through official Polymarket communications or direct account support channels.
Practical Checks
Affected users should verify account notices through official Polymarket channels, review recent wallet approvals, and inspect wallet activity around the incident period. They should avoid acting on unsolicited refund messages, especially messages asking for signatures, seed phrases, or urgent wallet connections.
ETH and MATIC holders who were not involved with Polymarket should avoid treating the incident as a reason to make rushed market moves. A better first step is to check whether they interacted with the affected service flow, review permissions, and keep security actions separate from trading decisions.
Risk Disclosure and Binance Context
This guide is not financial advice and does not recommend buying, selling, or holding ETH, MATIC, or any other asset. A phishing or supply-chain incident can create security risk without creating a reliable market signal.
The supplied brief includes a Binance CTA with referral code 7nfg8123. If a reader chooses to use that commercial route, it should be kept separate from incident response. A trading venue does not identify the compromised vendor, determine refund eligibility, or reduce the need for wallet-security checks.
Evaluate BINANCE for your use case
Check regional eligibility, current fees and product availability on the official destination.
Review BINANCEAffiliate link · Availability varies by region · No guaranteed outcomeQuestions readers ask
What did AMLBot report about the Polymarket phishing incident?
AMLBot reported that the Polymarket supply-chain attack totaled approximately $3.1 million in PUSD across 11 user wallets, according to the supplied brief.
Where were the funds traced?
The supplied brief says the funds were bridged from Polygon to Ethereum and converted to ETH.
Did Polymarket say users would be refunded?
Yes. The supplied brief says Polymarket pledged full refunds, but it does not provide refund timing, process details, or completion status.
Has the compromised vendor been named?
No. The supplied brief says Polymarket has not named the compromised vendor.
Does this incident mean ETH or MATIC should be traded differently?
No conclusion like that can be drawn from the supplied brief. This guide treats the event as a security and risk-management issue, not as financial advice or a market forecast.
What should users check first?
Users should verify official Polymarket communications, review recent wallet approvals, inspect wallet activity, and avoid unsolicited refund or support messages that ask for wallet signatures or sensitive information.