🎉 Share Your 2025 Year-End Summary & Win $10,000 Sharing Rewards!
Reflect on your year with Gate and share your report on Square for a chance to win $10,000!
👇 How to Join:
1️⃣ Click to check your Year-End Summary: https://www.gate.com/competition/your-year-in-review-2025
2️⃣ After viewing, share it on social media or Gate Square using the "Share" button
3️⃣ Invite friends to like, comment, and share. More interactions, higher chances of winning!
🎁 Generous Prizes:
1️⃣ Daily Lucky Winner: 1 winner per day gets $30 GT, a branded hoodie, and a Gate × Red Bull tumbler
2️⃣ Lucky Share Draw: 10
Polymarket Hit by Third-Party Auth Flaw, Users Lose Funds
Polymarket confirmed a security breach this week after users reported drained accounts and suspicious login activity on the platform. The incident occurred on Polymarket’s prediction market platform, with reports surfacing on Reddit and X on Tuesday. According to the company, a third-party authentication flaw bypassed two-factor protection, enabling unauthorized access and fund withdrawals.
User Reports Trigger Platform Response
Notably, users began flagging the issue after receiving unexpected login alerts tied to their Polymarket accounts. Several users reported multiple login attempts before balances disappeared.
One Reddit user said their account balance dropped to $0.01 overnight, despite no device compromise. Another user on X reported losses of about $2,000, even with two-factor authentication enabled.
However, reports did not remain isolated to one platform. Additional users on X said attackers drained both high-ranking and testing accounts. One user claimed their “top 1000” Polymarket account was fully emptied. As these reports spread, users questioned how attackers bypassed existing security layers.
Third-Party Login Tool Under Scrutiny
As attention shifted to authentication methods, several users pointed to Magic Labs as a possible source. Magic Labs provides email-based login services and automatically generated wallets for users.
The tool allows newcomers without crypto wallets to access platforms like Polymarket. Users claimed affected accounts were created using Magic Labs, despite no phishing emails received.
Meanwhile, Polymarket did not confirm the provider’s identity. However, the company stated the vulnerability originated outside its core infrastructure. Polymarket emphasized that the issue stemmed from a third-party login provider and not internal systems.
Polymarket Confirms Fix, Withholds Details
According to a statement shared on Polymarket’s Discord, the company identified and resolved the vulnerability. The platform said the issue affected a “small number of users” and confirmed no ongoing risk. Polymarket added it would contact impacted users directly.
However, Polymarket did not disclose how many accounts were affected or the total funds lost. Magic Labs also did not respond to media inquiries. Notably, this follows similar user reports in late 2024 involving Google-based logins.