Polymarket Data Breach Exposes Over 300K Records, Threat Actor Releases Exploit Tools

ETH-0.19%

Gate News message, April 29 — Decentralized prediction market platform Polymarket appears to have suffered a data breach, with threat actor xorcat releasing over 300,000 data records and accompanying exploit tools on a known cybercriminal forum. According to reports, attackers exploited undisclosed API endpoints, pagination bypasses, and CORS misconfigurations in Polymarket’s Gamma and CLOB APIs to extract the data.

The leaked data includes complete personal information for 10,000 users (names, proxy wallets, and base addresses), 4,111 comments, 1,000 report records (containing 58 ETH addresses and admin authentication identifiers), 48,536 Gamma market metadata entries, over 250,000 active CLOB market automated market maker addresses, and 9,000 follower social graph data points.

The exploit toolkit contains proof-of-concept code for multiple vulnerabilities: CVE-2025-62718 (Axios NO_PROXY bypass, CVSS 9.9, enabling server-side request forgery), CVE-2024-51479 (Next.js middleware authentication bypass, CVSS 7.5), and CORS misconfigurations. The package also includes automated data extraction scripts and a complete red team assessment report.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
No comments