#News
Polymarket refutes 300k record breach claim as hacker sells public API data
WooFun2026-04-29 14:10
Key Takeaways
Polymarket rejects allegations of a 300,000 record breach, asserting the hacker is monetizing publicly accessible on-chain data. This incident highlights ongoing confusion between open data features and security vulnerabilities in Web3.
Prediction market platform Polymarket has formally denied allegations of a customer data breach following a dark web post by a hacker using the pseudonym xorcat. On Tuesday, cybersecurity firm Vecert Analyzer and various X accounts monitoring illicit forums shared screenshots from DarkForums where xorcat claimed to have exfiltrated over 300,000 records. The alleged trove reportedly included 10,000 unique user profiles containing full names, profile images, proxy wallets, and base addresses. Polymarket immediately characterized these claims as complete and utter nonsense, stating that the information exposed is already publicly available through standard channels. This denial comes amidst a broader surge in crypto-related exploits during April, which has placed the entire industry on high alert. Data compiled by Woofun AI indicates that blockchain security firm Hacken reported Web3 projects lost $482 million to hacks and scams in the first quarter of 2026 across 44 incidents, underscoring the heightened sensitivity to such threats.
The core of the dispute lies in the nature of the data accessed. Polymarket argued that the attacker merely accessed publicly accessible API endpoints and on-chain data, which are inherently open by design. In a direct response, the platform questioned the hacker's motives, asking which venture capitalist paid them to post data that developers can access for free. The platform emphasized that the ability to audit all data on-chain is a feature, not a bug, and explicitly stated that no private data was leaked. Instead of paying for the information, the hacker could have accessed it freely via public APIs. Woofun AI notes that this distinction between public data exposure and a genuine breach is a critical nuance often misunderstood in the current threat landscape.
The hacker, xorcat, justified the release of the data by claiming Polymarket lacked a bug bounty program, a common grievance among white-hat researchers.
However, this assertion contradicts the platform's current security posture. Polymarket launched a live bug bounty program on April 16, which had already received 446 reports as of Wednesday. The hacker further alleged that the data was extracted through undocumented API endpoints, pagination bypasses, and CORS misconfigurations on Polymarket's Gamma and CLOB APIs. Despite these technical claims, the platform maintains that the data remains public and that the methods used do not constitute a security breach of private user information.
Xorcat also claimed to have breached other prediction markets and indicated plans to release additional data over the coming days. This aggressive stance has drawn skepticism from security professionals who view the situation as a misrepresentation of open data. Vladimir S, a threat researcher and chief security officer at Legalblock, expressed doubt regarding the severity of the incident. He suggested that the actor likely parsed public data and is attempting to present it as a database leak, a scenario he deemed improbable given the transparency of the underlying blockchain infrastructure. Woofun AI analysis suggests that as on-chain transparency increases, the line between legitimate data scraping and malicious exploitation will continue to blur, requiring more sophisticated attribution frameworks.
Comments
No comments yet.