{"id":110571,"date":"2026-05-25T05:08:21","date_gmt":"2026-05-24T20:08:21","guid":{"rendered":"https:\/\/coin.iroirojapon.com\/?p=110571"},"modified":"2026-05-25T05:30:52","modified_gmt":"2026-05-24T20:30:52","slug":"polymarket-hit-with-520k-polygon-contract-exploit","status":"publish","type":"post","link":"https:\/\/coin.iroirojapon.com\/?p=110571","title":{"rendered":"Polymarket hit with $520K+ Polygon contract exploit"},"content":{"rendered":"<div class=\"youtube\"><iframe title=\"Polymarket hit with $520K+ Polygon contract exploit\" src=\"https:\/\/www.youtube.com\/embed\/4OD80AuI-0s?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/div>\n<p>#Polymarket&#8217;s UMA CTF Adapter contract was exploited on #Polygon Friday, with an attacker draining roughly $520,000 to $660,000 through a compromised private key tied to an internal operational wallet used for rewards payouts. On-chain investigator ZachXBT flagged the incident first, with Bubblemaps and PeckShield confirming the drain as automated withdrawals of ~5,000 POL tokens every 30 seconds. The attacker split funds across 15 wallets and routed a portion through ChangeNOW. Polymarket says user funds and market resolution remain safe, since core trading contracts were not affected. The incident lands the same week as Bubblemaps&#8217; $2.4M Polymarket insider trading findings and Congressional pressure to ban prediction markets. #DeFi #security #crypto<\/p>\n<p>CFO take: this is the second high-profile crypto incident in a month tied to compromised admin or operational keys, following Echo Protocol&#8217;s $76M unauthorized eBTC mint via a single-signature admin key on Monad. DeFi protocols should treat segregation of operational wallets, multisig coverage on every internal payout system, key rotation cadence, and monitoring on legacy permission setups as quarterly audit committee items, not annual ones. Audit committees should also revisit ASC 450 loss contingency analysis, disclosure controls around incident communications, ICFR documentation for custody and operational key controls, and SOC reporting expectations as institutional partners and listing venues press for evidence. Insurance coverage limits, smart-contract audit recency, and the scope of past audits (Polymarket&#8217;s 2021-2022 ChainSecurity audit notably did not cover the UMA CTF Adapter) should also be revisited and disclosed where material.<\/p>\n<p>Ridgeway Financial Services helps DeFi protocols and crypto-native platforms with internal controls, incident accounting playbooks, and audit readiness.<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"K0cMcs5igI\"><p><a href=\"https:\/\/www.ridgewayfs.com\/defi-accounting-expert\/\">Financial, Treasury, and Tokenomics Challenges for DeFi Platforms<\/a><\/p><\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"\u201cFinancial, Treasury, and Tokenomics Challenges for DeFi Platforms\u201d \u2014 Ridgeway Financial Services\" src=\"https:\/\/www.ridgewayfs.com\/defi-accounting-expert\/embed\/#?secret=Dx0xGx57sg#?secret=K0cMcs5igI\" data-secret=\"K0cMcs5igI\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>Source: https:\/\/www.coindesk.com\/markets\/2026\/05\/22\/zachxbt-flags-usd520k-polymarket-exploit-on-polygon-team-says-funds-are-safe<\/p>\n<p><!-- Video Blogster Pro --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>#Polymarket&#8217;s UMA CTF Adapter contract was exploited on #Polygon Friday, with an attacker draining roughly $520,000 to $660,000 through a compromised private key tied to an internal operational  [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":110572,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[12],"tags":[],"class_list":["post-110571","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-polygon"],"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Polymarket-hit-with-520K-Polygon-contract-exploit.jpg?fit=1280%2C720&ssl=1","jetpack-related-posts":[{"id":108237,"url":"https:\/\/coin.iroirojapon.com\/?p=108237","url_meta":{"origin":110571,"position":0},"title":"Bitcoin Above $70K? JPMorgan Warning, Iran Hormuz Crypto Tolls, Polygon Payments Push","author":"coin.iroirojapon.com","date":"2026\u5e744\u67089\u65e5","format":false,"excerpt":"https:\/\/kraken.pxf.io\/c\/6563010\/687155\/10583 https\u2026","rel":"","context":"\u30dd\u30ea\u30b4\u30f3\uff08MATIC\uff09","block_context":{"text":"\u30dd\u30ea\u30b4\u30f3\uff08MATIC\uff09","link":"https:\/\/coin.iroirojapon.com\/?cat=12"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Bitcoin-Above-70K-JPMorgan-Warning-Iran-Hormuz-Crypto-Tolls-Polygon-Payments-Push.jpg?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Bitcoin-Above-70K-JPMorgan-Warning-Iran-Hormuz-Crypto-Tolls-Polygon-Payments-Push.jpg?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Bitcoin-Above-70K-JPMorgan-Warning-Iran-Hormuz-Crypto-Tolls-Polygon-Payments-Push.jpg?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Bitcoin-Above-70K-JPMorgan-Warning-Iran-Hormuz-Crypto-Tolls-Polygon-Payments-Push.jpg?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Bitcoin-Above-70K-JPMorgan-Warning-Iran-Hormuz-Crypto-Tolls-Polygon-Payments-Push.jpg?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":110475,"url":"https:\/\/coin.iroirojapon.com\/?p=110475","url_meta":{"origin":110571,"position":1},"title":"Video Short \ud83d\udea8 C\u1ea3nh b\u00e1o: ZachXBT cho bi\u1ebft m\u1ed9t b\u1ed9 \u0111i\u1ec1u ch\u1ec9nh UMA 2026-05-22 18:06","author":"coin.iroirojapon.com","date":"2026\u5e745\u670823\u65e5","format":false,"excerpt":"Automated YouTube Short \ud83d\udccc \ud83d\udea8 C\u1ea3nh b\u00e1o: ZachXBT cho \u2026","rel":"","context":"\u30dd\u30ea\u30b4\u30f3\uff08MATIC\uff09","block_context":{"text":"\u30dd\u30ea\u30b4\u30f3\uff08MATIC\uff09","link":"https:\/\/coin.iroirojapon.com\/?cat=12"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Video-Short-Canh-bao-ZachXBT-cho-biet-mot-bo-dieu-chinh-UMA-2026-05-22-1806.jpg?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Video-Short-Canh-bao-ZachXBT-cho-biet-mot-bo-dieu-chinh-UMA-2026-05-22-1806.jpg?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Video-Short-Canh-bao-ZachXBT-cho-biet-mot-bo-dieu-chinh-UMA-2026-05-22-1806.jpg?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Video-Short-Canh-bao-ZachXBT-cho-biet-mot-bo-dieu-chinh-UMA-2026-05-22-1806.jpg?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Video-Short-Canh-bao-ZachXBT-cho-biet-mot-bo-dieu-chinh-UMA-2026-05-22-1806.jpg?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":109957,"url":"https:\/\/coin.iroirojapon.com\/?p=109957","url_meta":{"origin":110571,"position":2},"title":"Analyst Targets &#8220;$2.91 ADA.&#8221; Pyth Pro Now LIVE On Cardano! Angry Crypto Reacts","author":"coin.iroirojapon.com","date":"2026\u5e745\u670813\u65e5","format":false,"excerpt":"Cardano $ADA 24h trade volume reached as high as $\u2026","rel":"","context":"\u30a8\u30a4\u30c0\u30b3\u30a4\u30f3(ADA)\u3000","block_context":{"text":"\u30a8\u30a4\u30c0\u30b3\u30a4\u30f3(ADA)\u3000","link":"https:\/\/coin.iroirojapon.com\/?cat=15"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Analyst-Targets-2.91-ADA.-Pyth-Pro-Now-LIVE-On-Cardano-Angry-Crypto-Reacts.jpg?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Analyst-Targets-2.91-ADA.-Pyth-Pro-Now-LIVE-On-Cardano-Angry-Crypto-Reacts.jpg?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Analyst-Targets-2.91-ADA.-Pyth-Pro-Now-LIVE-On-Cardano-Angry-Crypto-Reacts.jpg?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Analyst-Targets-2.91-ADA.-Pyth-Pro-Now-LIVE-On-Cardano-Angry-Crypto-Reacts.jpg?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/05\/Analyst-Targets-2.91-ADA.-Pyth-Pro-Now-LIVE-On-Cardano-Angry-Crypto-Reacts.jpg?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":107984,"url":"https:\/\/coin.iroirojapon.com\/?p=107984","url_meta":{"origin":110571,"position":3},"title":"Solana Stories: BAXUS","author":"coin.iroirojapon.com","date":"2026\u5e744\u67084\u65e5","format":false,"excerpt":"BAXUS is a global marketplace that tokenizes fine \u2026","rel":"","context":"\u30bd\u30e9\u30ca(SOL)\u3000","block_context":{"text":"\u30bd\u30e9\u30ca(SOL)\u3000","link":"https:\/\/coin.iroirojapon.com\/?cat=14"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Solana-Stories-BAXUS.jpg?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Solana-Stories-BAXUS.jpg?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Solana-Stories-BAXUS.jpg?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Solana-Stories-BAXUS.jpg?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2026\/04\/Solana-Stories-BAXUS.jpg?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":100630,"url":"https:\/\/coin.iroirojapon.com\/?p=100630","url_meta":{"origin":110571,"position":4},"title":"5 Years of Solana","author":"coin.iroirojapon.com","date":"2025\u5e7412\u670811\u65e5","format":false,"excerpt":"5 years of Solana. 5 years of Breakpoint. 5 years \u2026","rel":"","context":"\u30bd\u30e9\u30ca(SOL)\u3000","block_context":{"text":"\u30bd\u30e9\u30ca(SOL)\u3000","link":"https:\/\/coin.iroirojapon.com\/?cat=14"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/5-Years-of-Solana.jpg?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/5-Years-of-Solana.jpg?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/5-Years-of-Solana.jpg?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/5-Years-of-Solana.jpg?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/5-Years-of-Solana.jpg?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":100739,"url":"https:\/\/coin.iroirojapon.com\/?p=100739","url_meta":{"origin":110571,"position":5},"title":"Solana Breakpoint 2026 Will Be Hosted in London","author":"coin.iroirojapon.com","date":"2025\u5e7412\u670812\u65e5","format":false,"excerpt":"For the first time, Solana Breakpoint 2026 will be\u2026","rel":"","context":"\u30bd\u30e9\u30ca(SOL)\u3000","block_context":{"text":"\u30bd\u30e9\u30ca(SOL)\u3000","link":"https:\/\/coin.iroirojapon.com\/?cat=14"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/Solana-Breakpoint-2026-Will-Be-Hosted-in-London.jpg?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/Solana-Breakpoint-2026-Will-Be-Hosted-in-London.jpg?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/Solana-Breakpoint-2026-Will-Be-Hosted-in-London.jpg?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/Solana-Breakpoint-2026-Will-Be-Hosted-in-London.jpg?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/coin.iroirojapon.com\/wp-content\/uploads\/2025\/12\/Solana-Breakpoint-2026-Will-Be-Hosted-in-London.jpg?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"publishpress_future_action":{"enabled":true,"date":"2028-05-23 20:30:51","action":"delete","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/posts\/110571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=110571"}],"version-history":[{"count":1,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/posts\/110571\/revisions"}],"predecessor-version":[{"id":110575,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/posts\/110571\/revisions\/110575"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=\/wp\/v2\/media\/110572"}],"wp:attachment":[{"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=110571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=110571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coin.iroirojapon.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=110571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}