Operational Security
Incident response speed, deployment hygiene, key management, monitoring infrastructure, and emergency history.
How This Score Is Built
Incident response speed, deployment hygiene, key management, monitoring infrastructure, and emergency history.
Scoring Tree
Sub-Score Breakdown
Score Composition
Attack pattern: 5,000 POL transfers every ~30 seconds at 415+ gwei priority — single private-key, no multisig, no MPC, no velocity circuit breaker
Pre-hack key factors carried over: no branch protection, minimal dev activity, default key_management sub-score (70 was overstated)
EXPLOITED HACK-POLYMARKET-2026-001 (2026-05-22): private-key compromise of two operational hot wallets on Polygon
Drained: 0x871D7c0f...929082 (POL reward wallet) and 0x91430CaD...14E5c5 (UMA CTF Adapter Admin, tagged COMPROMISED on Polygonscan)
No HSM/MPC custody on operational wallets controlling protocol-adjacent value (~$700K lost)
External detection (ZachXBT) preceded internal detection — no realtime outflow alerting
EIP-7702 delegation on drained wallet was Polymarket's own pre-installed scaffolding, not the attack vector
Evidence Chain (10 files)
Score History
No dimension-level score changes recorded yet.