Polymarket's UMA CTF Adapter contract on Polygon exploited for over $520k via compromised smart contract.
Security & Exploits ·
A suspected exploit of Polymarket's UMA CTF Adapter contract on Polygon has resulted in losses exceeding $520k, according to a ZachXBT community alert. Two smart contracts were affected: 0x871D7c0f9E19001fC01E04e6cdFa7fA20f929082 and 0x91430CaD2d3975766499717fA0D66A78D814E5c5, with the attacker's address identified as 0x8F98075db5d6C620e8D420A8c516E2F2059d9B91.
The incident highlights dependencies in Polymarket's market resolution infrastructure. UMA's CTF Adapter serves as a bridge for conditional token settlement on the prediction market platform, and the compromise of this contract component allowed unauthorized fund transfers. The attack mechanism and whether the breach stemmed from compromised credentials or a smart contract vulnerability remain under examination across multiple reports covering the incident.
The immediate scope of the loss is quantified at $520k, though full recovery details and any subsequent protocol changes have not yet been disclosed. Polymarket's operational status and whether additional safeguards have been implemented in response to the incident are not addressed in the available reporting.