Tap to Trade in Gate Square, Win up to 50 GT & Merch!
Click the trading widget in Gate Square content, complete a transaction, and take home 50 GT, Position Experience Vouchers, or exclusive Spring Festival merchandise.
Click the registration link to join
https://www.gate.com/questionnaire/7401
Enter Gate Square daily and click any trading pair or trading card within the content to complete a transaction. The top 10 users by trading volume will win GT, Gate merchandise boxes, position experience vouchers, and more.
The top prize: 50 GT.

(Additional context: How to arbitrage through Polymarket to achieve an annualized 40% return?)
The leading crypto prediction market Polymarket reports funds being stolen, with multiple users furious on X and Reddit in the early hours of December 24, claiming “account balances have been wiped out.”
The platform immediately acknowledged the security breach on its official Discord, pointing to a “third-party service provider.” On-chain tracking tools Lookonchain subsequently identified the wallet service provider Magic Labs, making this incident one of the most concerning crypto market security breaches of late 2025.
The official statement claims the issue has been fixed, but concerns remain
Less than an hour after user reports, Polymarket issued an announcement:
The announcement did not disclose the amount lost or the number of victims, but it sparked greater panic. Based on Polymarket’s platform monthly trading volume in 2025, estimated at tens of billions of dollars, even a “very small” number could mean significant losses.
Unlike common phishing attacks, no suspicious links were circulated at the time of the incident, and many victims had even enabled email 2FA. The key to bypassing defenses was not on the user side but in the backend third-party authentication.
Magic Labs Login Mechanism Became the Breach Point
To lower barriers, Polymarket introduced Magic Labs’ “Email One-Click Non-Custodial Wallet Generation.” Users do not need to manage seed phrases; they can operate Ethereum assets by sending verification codes. Attackers exploited a system vulnerability in Magic Labs’ authentication layer to gain control of wallets, rendering 2FA ineffective.
On-chain flow shows that the hacker quickly split assets and used multiple layers of mixing to complicate tracing. Although the official states “already fixed,” they have yet to respond to community requests for a full post-incident report.
Meanwhile, security firm SlowMist warns of malicious Polymarket copycat bots on GitHub, targeting advanced traders using custom trading scripts. These programs read local configuration files and secretly exfiltrate private keys, which, while not directly related to the Magic Labs vulnerability, also surfaced on the same day.