Skip to content
Polymarket Resolves Security Incident with Key Rotation and KMS Migration

Polymarket Resolves Security Incident with Key Rotation and KMS Migration

First seen 23 May 2026, 22:04 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 24, 2026 at 21:01 UTC
  • A private key compromised for six years led to a security incident at Polymarket.
  • The platform has completed private key rotation and plans to migrate to a Key Management Service.
  • All user funds are secure, and there was no compromise of Polymarket's UMA contracts.

Polymarket, a prediction market platform, experienced a security incident due to a private key that had been compromised for six years. This key was utilized for internal deposit configurations, leading to some funds being sent to related addresses. The company has successfully completed a private key rotation and revoked all production environment permissions. Furthermore, Polymarket plans to migrate all private keys to a Key Management Service (KMS) to enhance security. Importantly, neither Polymarket nor its UMA contracts were compromised, ensuring that all user funds remain secure and the platform continues to operate normally. The incident highlights the risks associated with long-term key management practices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 120d ago How this analysis works

Timeline

2026-05-23
Polymarket announces private key rotation
Polymarket confirmed the completion of private key rotation and plans to migrate keys to a KMS after a security incident.
Kucoin
2026-05-23
Details of the security incident revealed
A representative disclosed that a private key used for six years was compromised, affecting internal deposit configurations.
Panewslab

More articles in this cluster (2)

Following this threat?

Track Polymarket in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed