Gate News message, April 29 — Decentralized prediction market platform Polymarket appears to have suffered a data breach, with threat actor xorcat releasing over 300,000 data records and accompanying exploit tools on a known cybercriminal forum. According to reports, attackers exploited undisclosed API endpoints, pagination bypasses, and CORS misconfigurations in Polymarket’s Gamma and CLOB APIs to extract the data.
The leaked data includes complete personal information for 10,000 users (names, proxy wallets, and base addresses), 4,111 comments, 1,000 report records (containing 58 ETH addresses and admin authentication identifiers), 48,536 Gamma market metadata entries, over 250,000 active CLOB market automated market maker addresses, and 9,000 follower social graph data points.
The exploit toolkit contains proof-of-concept code for multiple vulnerabilities: CVE-2025-62718 (Axios NO_PROXY bypass, CVSS 9.9, enabling server-side request forgery), CVE-2024-51479 (Next.js middleware authentication bypass, CVSS 7.5), and CORS misconfigurations. The package also includes automated data extraction scripts and a complete red team assessment report.
Related News
CFTC Sues Wisconsin Over Prediction Market Jurisdiction
SSRN Research Paper: Polymarket’s Pricing Accuracy Comes From 3.14% Informed Traders
Research reveals: Polymarket players take home 30% of profits by winning 3% of the positions—more than 70% of players absorb all losses