Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Polymarket Allegedly Breached, 300K+ Records and Exploit Kit Leaked

The leak reportedly includes user data, market records, and proof-of-concept exploits tied to API flaws, pagination bypass, and CORS misconfiguration.

Written By:
Shubham Soni

Last updated: 23 minutes ago
Published 59 minutes ago
Share
Last updated: 23 minutes ago
Published 59 minutes ago
Polymarket Allegedly Breached, 300K+ Records and Exploit Kit Leaked
Show AI Summary
An alleged large-scale data exposure occurred on April 27, 2026, when an actor exploited Polymarket’s API weaknesses.
The threat actor, identified as xorcat, leaked the dataset on a cybercrime forum on Tuesday, sparking concerns.
Polymarket has yet to confirm the alleged attack, despite being reached out to by Crypto Times for an official response.

Prediction market platform Polymarket is reportedly at the center of a large-scale data exposure, after a threat actor claimed to have leaked more than 300,000 records along with an exploit kit on a cybercrime forum.

The disclosure, flagged by Dark Web Informer in an X post on Tuesday, attributes the incident to an actor identified as “xorcat.” The dataset is said to have been extracted on April 27, 2026, using a combination of undocumented API access points and misconfigurations.

‼️ Polymarket, the decentralized prediction market platform, has allegedly been breached, with 300,000+ records and an exploit kit leaked on a popular cybercrime forum. The actor states Polymarket has no bug bounty program and was not notified.
⠀
‣ Threat Actor: xorcat
‣… pic.twitter.com/UAmCL46pk3

— Dark Web Informer (@DarkWebInformer) April 28, 2026

Crypto Times team reached out to Polymarket for the official confirmation regarding this alleged attack, but hasn’t received any response yet.

Scope of the alleged data leak

According to the claims, the leaked dataset is described as containing over 750 MB of extracted information, later compressed into smaller JSON files. It reportedly spans user profiles, activity logs, and market data tied to the platform’s prediction markets.

Among the exposed information are roughly 10,000 user profiles that include names, pseudonyms, bios, profile images, and wallet-linked addresses. The dataset also allegedly includes thousands of comments linked to user accounts, detailed records from Gamma and central limit order book markets, and event-level data containing Ethereum addresses and internal usernames.

Additional elements reportedly cover follower relationships, reward configurations tied to USDC contracts, and internal identifiers embedded in metadata fields such as “createdBy” and “updatedBy,” potentially allowing deeper mapping of platform activity.

Exploit kit and technical claims

The actor claims the data was obtained by exploiting multiple weaknesses in Polymarket’s API infrastructure. These reportedly include:

  • Use of undocumented endpoints across Gamma and CLOB APIs
  • Pagination bypass allowing unusually large data pulls without rate limits
  • Cross-origin resource sharing (CORS) misconfiguration enabling credentialed requests from any origin
  • Unauthenticated endpoints exposing comments, reports, and follower data

In addition to raw data, the package allegedly contains working proof-of-concept exploits, including scripts designed to automate data extraction until vulnerabilities are patched.

Referenced vulnerabilities

The disclosure references multiple known weaknesses, including an Axios-related proxy bypass enabling server-side request forgery and a middleware authentication bypass affecting Next.js applications. Additional issues cited include insufficient validation on pagination parameters and exposure of API routes that could be queried without proper access controls.

The exploit package is also said to contain a structured report mapping the attack techniques to established threat frameworks, along with additional data dumps.

Questions around disclosure and response

The threat actor claims that no prior disclosure was made to the platform and alleges the absence of a bug bounty program. These assertions have not been independently verified.

As of now, there has been no confirmed public response from Polymarket addressing the claims or verifying the authenticity of the leaked data.

Broader implications

If verified, the incident would highlight risks tied to API security in crypto-native platforms, particularly those handling user-linked wallet data and large-scale market infrastructure.

The exposure of both user profiles and market mechanics could raise concerns about privacy, platform integrity, and potential misuse of on-chain and off-chain data connections.

Also Read: Polymarket Moves to Regain U.S. Access With CFTC Approval Push

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Polymarket
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Shubham Soni Crypto Content Editor
By Shubham Soni
Follow:
Shubham Soni is a veteran content editor and journalist with over three years of experience leading digital editorial strategies across the U.S. and Indian markets. With a background in high-pressure newsrooms, Shubham specializes in the rigorous fact-checking, structural editing, and narrative development of complex news and explainers. Throughout his career at prominent digital publications like Sportskeeda and Opoyi, he has managed fast-paced desks covering global politics, sports, and entertainment. His expertise lies in transforming technical information into accessible, high-impact reporting while maintaining strict adherence to editorial ethics and accuracy. At The Crypto Times, Shubham oversees the editorial workflow, mentoring writers to ensure all cryptocurrency research and analysis meets the highest standards of clarity and journalistic integrity.

Latest News

Czech Central Bank Governor Backs Bitcoin Reserves at Bitcoin 2026
Czech Central Bank Governor Backs Bitcoin Reserves at Bitcoin 2026
WLFI Partnered With Crypto Project Linked to Alleged Scam Network
WLFI Partnered With Crypto Project Linked to Alleged Scam Network
Ostium Labs Unveils Institutional-Backed Onchain Trading System
Ostium Labs Unveils Institutional-Backed Onchain Trading System
CFTC Eyes AI to Accelerate Reviews Amid Rising Crypto Filings
CFTC Eyes AI to Accelerate Reviews Amid Rising Crypto Filings
CFTC Sues Wisconsin to Defend Federal Control Over Prediction Markets
CFTC Sues Wisconsin to Defend Federal Control Over Prediction Markets

Find Us on Socials

You may also like

Polymarket Moves to Regain U.S. Access With CFTC Approval Push

Polymarket Moves to Regain U.S. Access With CFTC Approval Push

Galaxy Digital Stock Rises 14% YTD Despite $216M Q1 Loss

Galaxy Digital Stock Rises 14% YTD Despite $216M Q1 Loss

Visa Taps WeFi to Bring Stablecoins Into Everyday Spending

Visa Taps WeFi to Bring Stablecoins Into Everyday Spending

₹60L Crypto Scam India Cyber Cell Nabs Suspect Linked to Fraud Network

₹60L Crypto Scam: India Cyber Cell Nabs Suspect Linked to Fraud Network

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information