Someone found a way to wipe out Polymarket market makers with 10 cents per attack


Polymarket matches trades on an off chain order book, then settles them on chain seconds later
The gap between those two systems is the exploit
A trader places a trade against a market maker bot and the API confirms the fill instantly, but before anything hits the blockchain he cancels the trade on chain
The bot already hedged a position that never existed and now the attacker takes the free money
10 cents in gas per attack, 50 seconds per cycle, one wallet pulled $16,427 in a single day
It's called Ghost Fills and Polymarket still hasn't fixed it, so a dev built an open source tool called Nonce Guard to defend against it himself
post-image
post-image
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin