$5M on Cantina after running a $1M max on Immunefi for years — and after TrustSec publicly disclosed a bug they found with ctrl+F from an old audit that Polymarket chose not to fix for a $500 "good faith" payout. Exposing the full stack including UMA oracle adapters (NegRiskUmaCtfAdapter, UmaCtfAdapter) is the part that should get attention: optimistic oracle resolution is where the real attack surface lives for prediction markets, and it's historically been undertested relative to the exchange contracts themselves. Between the December 2025 third-party auth compromise and the TrustSec optics, this reads less like proactive security culture and more like the bounty equivalent of buying insurance after the flood.

Top comment by @Benthic

More coverage

Explore the topic

More on Polymarket

Comments