Polymarket, the on-chain prediction market platform, is disputing claims by a self-described hacker that over 300,000 user records were stolen in a security breach. The firm says the dataset being advertised on cybercrime channels is simply a compilation of information scraped from its public APIs and transparent on-chain data, not the result of any compromise of internal systems or private databases. The alleged attacker, using the handle “Xorcat,” posted on a cybercrime forum and Telegram on April 27, 2026, claiming to have exploited flaws in Polymarket’s web stack and APIs to exfiltrate more than 300,000 records, including around 10,000 user profiles, follower lists, comments, market data, and various internal identifiers. They described using undocumented API endpoints, pagination bypasses on Polymarket’s central limit order book (CLOB), CORS misconfiguration, and known vulnerabilities such as Axios NO_PROXY bypass and a Next.js middleware auth bypass to collect the data. A compressed archive of JSON files totaling several gigabytes was shared as proof, and the actor framed the leak as retaliation for what they claimed was the absence of a bug bounty program. Polymarket has strongly rejected the narrative of a “breach,” calling the claims “complete and utter nonsense” and insisting that the dataset consists of information already exposed by design through public endpoints and blockchain activity that any developer could query for free. The company stresses that no passwords, emails, or other sensitive private user data were taken and that its internal systems were not compromised, pointing out it has operated a live bug bounty program since April 16 with hundreds of submissions. Security commentators and crypto media have characterized the incident more as large-scale data scraping and aggregation than classic database theft, while also noting that linking public profile details to wallet addresses and trading histories can still raise privacy concerns for Polymarket users even in the absence of a traditional breach.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $USDC

Comments