Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    From BitMEX to Leap Wallet 100+ Crypto Projects Have Shut Down in H1 2026
    From BitMEX to Leap Wallet: 100+ Crypto Projects Have Shut Down in H1 2026
    July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
  • Opinion
    OpinionShow More
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Polymarket Rejects Breach Claims Amid 300K Record Leak Reports

The platform denies any hack, while researchers point to API flaws, undocumented endpoints, and exposed datasets shared on a cybercrime forum.

Written By Shubham Soni
Published 2026-04-29·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Polymarket Rejects Breach Claims Amid 300K Record Leak Reports

Key Highlights

  • Polymarket says the reported 300K-record “leak” consists of publicly accessible on-chain and API data, with no private information compromised.
  • The alleged dataset was reportedly compiled using undocumented API endpoints, weak pagination controls, and misconfigurations, alongside an exploit kit shared on a cybercrime forum.
  • While Polymarket calls the claims misleading, critics argue large-scale aggregation of public data, and the methods used, raise security and privacy concerns that remain unaddressed.

Prediction market platform Polymarket has denied claims of a security breach after reports surfaced that more than 300,000 records and an exploit kit were leaked on a cybercrime forum.

The disclosure, flagged by Dark Web Informer in an X post on Tuesday, attributes the incident to an actor identified as “xorcat.” The dataset is said to have been extracted on April 27, 2026, using a combination of undocumented API access points and misconfigurations.

😂 "compromised"?

Part of the beauty of being on-chain is all our data is publicly auditable… this is a feature, not a bug. No data was "leaked" — it's accessible via our public endpoints & on-chain data.

Instead of paying for the data, you can access it for free via our APIs.

— Polymarket (@Polymarket) April 28, 2026

Platform says data is public, not leaked

Polymarket pushed back on the characterization of the incident, stating that the data referenced in the leak is publicly accessible by design.

In a post on X, the platform said its on-chain architecture makes data auditable and available through public endpoints. It added that no private data was compromised and that the same information can be accessed freely through its APIs, framing the claims as a misrepresentation of how its system works.

What the leak allegedly contains

Despite the denial, the dataset described by the threat actor is said to include a large volume of platform data, spanning user profiles, activity records, and market information.

The reported material includes around 10,000 user profiles with associated metadata such as names, pseudonyms, bios, profile images, and wallet-linked addresses. It also references thousands of comments tied to user accounts, extensive records from Gamma and central limit order book markets, and event-level data containing Ethereum addresses and internal usernames.

Other elements in the dataset reportedly map follower relationships, reward configurations linked to USDC contracts, and internal identifiers embedded within platform metadata, which could allow reconstruction of user activity patterns.

Technical claims behind the extraction

The threat actor claims the dataset was assembled by exploiting gaps in Polymarket’s API infrastructure. These include the use of undocumented endpoints, weak pagination controls that allowed large-scale data extraction, and cross-origin resource sharing (CORS) settings that allegedly permitted credentialed requests from unrestricted sources.

Some endpoints were also described as accessible without authentication, including those tied to comments, reports, and follower data. The leak package reportedly includes automated scripts capable of continuously extracting data until such access points are restricted.

Referenced vulnerabilities and exploit kit

The disclosure cites multiple known vulnerabilities, including an Axios-related proxy bypass that could enable server-side request forgery and a middleware authentication bypass affecting Next.js applications.

It also points to insufficient validation of API parameters and exposure of endpoints without proper access controls. The shared package is said to include proof-of-concept exploits, a structured technical report, and additional datasets.

Gaps between claims and response

While Polymarket maintains that the data is public and not the result of a breach, its response does not directly address the specific technical claims related to API misconfigurations or exploit methods outlined by the threat actor.

The actor, for their part, claims no prior disclosure was made to the platform and alleges the absence of a bug bounty program, though these points remain unverified.

Wider context

The episode highlights ongoing tension between transparency in on-chain systems and expectations around data exposure. Even when data is technically public, the aggregation and structuring of large datasets can raise concerns about user privacy and platform safeguards.

The situation remains unresolved, with competing claims over whether the incident reflects a security failure or the reuse of openly accessible data.

Also Read: Polymarket Moves to Regain U.S. Access With CFTC Approval Push

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Polymarket
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Sharplink CEO Says BRCA Could Define CLARITY Act’s DeFi Impact
Sharplink CEO Says BRCA Could Define CLARITY Act’s DeFi Impact
Putin Approves Russia’s Broad Crypto Regulatory Framework
Putin Approves Russia’s Broad Crypto Regulatory Framework
XRP Ledger Adds Axelar Support for Cross-Chain Asset Transfers
XRP Ledger Adds Axelar Support for Cross-Chain Asset Transfers
Senator Lummis Seeks Senate Action on CLARITY Act Before August Break
Senator Lummis Seeks Senate Action on CLARITY Act Before August Break
Senator Bill Hagerty Pushes CLARITY Act Vote Despite Senate Delay
Senator Bill Hagerty Pushes CLARITY Act Vote Despite Senate Delay

Find Us on Socials

You may also like

Dinari Adds 700+ Tokenized U.S. Stocks to Onchain Platform

Dinari Adds 700+ Tokenized U.S. Stocks to Onchain Platform

Circle Upgrades Gateway With ERC-1271 Smart Wallet Support

Circle Upgrades Gateway With ERC-1271 Smart Wallet Support

Wells Fargo Expands Blockchain Payments With Deposit Tokens

Wells Fargo Expands Blockchain Payments With Deposit Tokens

BNY Weighs Crypto Staking Expansion With Galaxy Support

BNY Weighs Crypto Staking Expansion With Galaxy Support

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information