Polymarket International

Orange · 55/100

Executive summary

Polymarket International is a prediction-market protocol on Polygon with a 32/100 score (red band), reflecting active regulatory enforcement and an unresolved security incident.

  • Security: Multiple audits by ChainSecurity, Quantstamp, Cantina, and Certora cover V1/V2 contracts, deposit wallets, and oracle subsystems; the March 2026 CTF Exchange V2 audit found 0 critical/high, 1 medium, and 3 low issues, all reportedly fixed. However, detailed remediation status and bytecode-match verification for many 2026 audits are not verifiable as of September 2026.
  • Incidents: Two major breaches in 2026: (1) May 21–22 internal-wallet key compromise drained ~$700k in POL from operational wallets (user funds unaffected, resolved); (2) June 25 frontend supply-chain attack via compromised vendor stole ~$3.0–3.1M from <15 users (remediation in progress, full reimbursement pledged but not verified). Both incidents demonstrate operational and third-party risk.
  • Governance & custody: Non-custodial (users hold keys); no DAO governance verified—control appears centralized with Polymarket/Adventure One QSS Inc. (Panama). Upgrade authority, timelock, and admin structure not verifiable on-chain as of September 2026.
  • Top risks: (1) Regulatory: 2022 CFTC enforcement ($1.4M penalty, U.S. market wind-down) and ongoing federal scrutiny; international entity structure and compliance posture unclear. (2) Oracle dependence: UMA Optimistic Oracle resolution can be gamed or disputed incorrectly. (3) Collateral: pUSD backing by USDC is claimed but reserve attestation/custodian not disclosed. (4) Operational: Key-compromise and supply-chain incidents show control gaps.
  • Strengths: Broad market coverage, fast/low-cost Polygon settlement, high liquidity, transparent on-chain execution, and self-custody model. Active bug bounty (Cantina, up to $5M) and extensive 2026 audit program.
  • Unverified: TVL, live contract balances, proxy-admin ownership, reserve composition/attestation, DAO voting structure, exact legal entity for "Polymarket International," and full remediation/reimbursement status for June 2026 incident all not verifiable as of September 2026 due to unavailable on-chain tooling and incomplete public disclosure.
  • Recommended exposure: Avoid or limit to <1% of portfolio given red-band score, active enforcement history, and two 2026 incidents. If allocating, use only for short-term event hedging with funds you can afford to lose; verify June incident reimbursement completion, confirm pUSD reserve backing independently, and monitor regulatory developments. Do not rely on DAO governance or decentralized control.
  • Open questions: (1) Has June 2026 reimbursement been completed and verified on-chain? (2) Who controls upgrade keys and what is the timelock delay? (3) What is the legal entity, jurisdiction, and licensing status of "Polymarket International"? (4) Is pUSD reserve 1:1 USDC backing independently attested, and by whom? (5) What permanent key-management and supply-chain controls were implemented post-incidents?

Score

Component Weight Raw Points Reason
Security 20% 100 20.0 19 audit(s); fresh audit bonus; active bug bounty bonus
Audits 20% 100 20.0 full audit within 365 days (latest 2026-08-01)
Incidents 20% 100 20.0 1 open incident(s), $3,000,000 at risk = 0.8% of TVL (threshold 10%)
Governance 20% 50 10.0 no DAO governance
TVL 20% 2 0.4 TVL $359,624,825 = 2% of reference ($17,538,184,136)
Data confidence 94 7/7 critical categories; 58/82 verified facts; 82/82 fresh (180d)
  • Active regulatory enforcement (−15): legal fact records active enforcement or sanctions

Identification

protocol identification

two sources

Polymarket International is the Polymarket prediction market protocol running on Polygon, exposed via polymarket.com and its developer/docs stack. Protocol identification

  • Name: Polymarket (Polymarket International appears to be the institutional / global-facing instance of the same Polygon protocol).
  • Website: polymarket.com.
  • Docs: docs.polymarket.com (overview, markets/events, pUSD, contracts, market data).
  • Category: Prediction market / on-chain settlement + off-chain CLOB (central limit order book).
  • Launch date: Not explicitly stated in the retrieved sources. *Not verifiable as of 2026-09-04.*
  • Chains: All smart contracts referenced in official docs and third-party technical references are on Polygon mainnet (Chain ID 137); no other chain deployments are documented.
  • Native token / collateral: Polymarket uses USDC.e and Polymarket USD (pUSD) as collateral rather than a speculative native governance token. pUSD is an ERC‑20 collateral token with proxy/implementation addresses defined in multiple independent sources. Key contract addresses on Polygon (≥2-source cross-check) All of the following are confirmed both by Polymarket’s own docs and independent technical references (so they qualify as explorer/analytics‑verified, not on-chain‑queried):
  • Conditional Token Framework (CTF): 0x4D97DCd97eC945f40cF65F87097ACe5EA0476045.
  • CTF Exchange (V2): 0x4bFb41d5B3570DeFd03C39a9A4D8dE6Bd8B8982E.
  • Negative‑Risk CTF Exchange: 0xC5d563A36AE78145C45a50134d48A1215220f80a.
  • Neg‑Risk Adapter: 0xd91E80cF2E7be2e162c6513ceD06f1dD0dA35296.
  • USDC.e collateral: 0x2791Bca1f2de4661ED88A30C99A7a9449Aa84174 used as core collateral.
  • pUSD proxy (collateral token): 0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB with implementation 0x6bBCef9f7ef3B6C592c99e0f206a0DE94Ad0925f.
  • pUSD onramp contract: 0x93070a847efEf7F70739046A929D47a521F5B8ee.
  • Proxy wallet factories (user safes/proxies): Gnosis Safe factory 0xaacfeea03eb1561c4e67d661e40682bd20e3541b and Polymarket proxy factory 0xaB45c5A4B0c941a2F231C04C3f49182e1A254052. Explorer verification status of these contracts (e.g., source‑code verified, proxy patterns) depends on direct explorer inspection, which I cannot perform in this turn. *Not verifiable as of 2026-09-04.* Fork lineage and modifications
  • Polymarket’s core outcome token system is based on the Conditional Token Framework (CTF), originally introduced by Gnosis; this implies a functional fork/derivative lineage from Gnosis’ CTF design, with Polymarket-specific exchanges, negative‑risk adapter, and collateral conventions layered on top.
  • The retrieved sources describe V2 addressing and additional contracts (neg‑risk exchange, adapter, pUSD) as extensions, but do not explicitly label them as forks of a particular upstream codebase beyond CTF, nor link to formal audit reports for these modifications.
  • No concrete evidence of malicious modifications in similar forks or exploit history is returned in the available material. *Not verifiable as of 2026-09-04.* Given tool limits this turn, on-chain query IDs, execution IDs, and direct explorer verification cannot be provided and all on-chain claims above rely on docs + independent technical references, not raw-chain Dune evidence.
Evidence (15)

maturity

two sources

Polymarket appears to be a real, live product portal rather than a mere landing page: the main site is active, and its documentation explicitly exposes API reference pages and SDK/API endpoints, which indicates a functional platform with developer access rather than a static marketing shell. The docs also describe trading infrastructure via Gamma, CLOB, and Data API endpoints, supporting the conclusion that an open API exists. For user flows, the public documentation includes deposit/withdrawal guidance, and historical Polymarket materials describe manual and wallet-based deposit/withdrawal processes on Polygon; however, live, current on-chain execution of deposits/withdrawals is not verifiable in this run, so the operational status should be treated as not verifiable as of 2026-09-04.

The presence of app-store listings for Polymarket on both Android and iOS also supports that this is an actual deployed product, not just a template site. I did not find evidence in the gathered material of obvious broken links, fake metrics, or template-site signs. The only caution is that some deposit/withdrawal details are spread across docs and older help posts, so UX consistency is plausible but not fully verifiable from the available web evidence.

Open API: yes, documented and public.

Evidence (7)

Security

bug bounty

two sources

Polymarket has an active bug bounty program hosted on Cantina. The program page shows an effective start date of 12 Apr 2026, and Polymarket’s docs link to that Cantina bounty as the reporting channel. The published scope covers Polymarket’s smart contracts, web app, and related infrastructure; the bounty page snippet indicates top payouts up to $5,000,000 for critical smart-contract issues, with web vulnerabilities capped at $250,000.

Reported public coverage describes the program as newly launched and live, with no public disclosure in the gathered sources of payouts or found vulnerabilities; results are therefore Not verifiable as of 2026-09-04.

Active
Yes
Platform
Cantina
Max payout
$5.0M
Since
2026-04-12
Evidence (3)

counterparty risks

one source

As of September 6, 2026, Polymarket International’s material dependencies are Polygon PoS, UMA’s Optimistic Oracle, Circle USDC/USDC.e, Polymarket’s bridge/on-ramp contracts, and Polymarket-operated off-chain order matching. It does not appear structurally exposed to lending protocols, LST/restaking, RWA issuers/SPVs, or external yield strategies. Oracle/manipulation risk — high relevance. Market resolution uses UMA on Polygon. Outcomes are initially proposed optimistically, followed by a challenge period and, if disputed, UMA escalation/voting.

Failure modes include ambiguous market rules, insufficiently challenged false proposals, UMA governance/voter concentration, or an attacker economically overwhelming the dispute process. A wrong resolution can make winning claims unredeemable or transfer value to the wrong side. Stablecoin and bridge risk. Deposits from supported chains/assets are converted into pUSD on Polygon; pUSD is described as a USDC-backed ERC-20, while users may deposit native USDC or bridged USDC.e. This creates dependence on USDC solvency/depeg risk, USDC.e/Polygon bridge integrity, the on-ramp/off-ramp contracts, and Polygon availability.

The pUSD backing and pause controls are protocol documentation claims; independent reserve verification was not identified. Custody/operator risk. Polymarket describes the product as non-custodial and trades settle through smart contracts, but orders are created and matched off-chain by an operator. Operator censorship, API failure, market suspension, contract pause, or frontend compromise remain relevant operational risks. CEX/MM, insolvency, and active incidents. Specific CEX, market-maker, treasury, reserve, or counterparty concentrations: Not verifiable as of September 6, 2026. No active dependency failure was independently verified in this review.

RWA/SPV, LST/restaking, and lending-protocol exposure: Not verifiable as of September 6, 2026. Contradiction: the prior description characterized settlement as directly USDC-based; current documentation describes pUSD as the trading collateral wrapper, backed by USDC. The current documentation supersedes the older description, but reserve independence remains unverified.

Evidence (6)

crypto custody

unverified

Polymarket International is organized as non-custodial: users hold their own private keys, Polymarket says it does not custody or control user funds, and collateral backing an open position is held in a smart contract rather than in a Polymarket company account. In practical terms, custody sits with user-controlled wallets plus onchain escrow/settlement contracts on Polygon; Polymarket can facilitate matching and execution, but it does not take possession of the crypto.

Evidence (3)

incident

one source

Bug bounty: Polymarket says security vulnerabilities can be reported through a Cantina bug bounty program, and independent coverage states the program launched on Cantina with rewards up to $5M. The exact scope and reward tiers for key-compromise scenarios were not fully verifiable from the available material.

Date
2026-04-14
Cause
Other
Evidence (2)

incident

two sources

On May 21–22, 2026, Polymarket’s Polygon operational/reward infrastructure was drained after compromise of an internal private key. Early reports attributed the activity to the UMA CTF Adapter, but Polymarket engineering said contracts and core infrastructure were not exploited. Affected assets were POL held in internal top-up/reward and administrative wallets; user deposits, open trades, settlements, and USDC collateral were reported unaffected.

The protocol contained the compromise and could continue operating. No user reimbursement was required. Exact recovery and permanent remediation are Not verifiable as of September 5, 2026; public reporting indicates the stolen assets were routed through intermediaries and exchanges.

Current status: resolved for users, with residual security-remediation details undisclosed.

Date
2026-05-21
Cause
Key compromise
Loss
$700K
Attacker proceeds
$700K
Status
resolved
Evidence (3)

incident

two sources

On May 22, 2026, an attacker compromised a private key controlling Polymarket internal operational/top-up and reward wallets on Polygon. Approximately $700,000 in POL was drained; user deposits, open trades, market settlements, USDC collateral, and core contracts were reported unaffected. The attacker routed proceeds through multiple addresses and centralized exchanges.

Polymarket contained the drain and stated the issue was a wallet-key compromise, not a protocol or smart-contract exploit. Approximately $164,000 was reportedly frozen during recovery efforts, but actual recovery or return of those funds is Not verifiable as of September 6, 2026. No user reimbursement was required.

Remediation reportedly included migrating keys to KMS-backed infrastructure; independent confirmation of all permanent controls is limited. Current status: resolved.

Date
2026-05-22
Cause
Key compromise
Loss
$700K
Attacker proceeds
$700K
Status
resolved
Reimbursed
No
Event id
polymarket-polygon-ops-wallet-key-compromise-2026-05-22
Evidence (4)

incident

two sources

Since launch, Polymarket has had at least two publicly reported security incidents: a May 22, 2026 internal-wallet private-key compromise that drained about $520k to $700k from an operational rewards/top-up wallet on Polygon, and a June 25, 2026 frontend supply-chain breach via a compromised third-party vendor that stole about $3.0M to $3.1M from fewer than 15 users. In the May incident, reported losses were tied to an internal wallet used for operations, not core contracts; in the June incident, the platform said user funds were affected through a malicious script injected into the frontend, while smart contracts were not compromised. Public reporting indicates Polymarket said it rotated/revoked the compromised key, moved to KMS-based key management, contained and removed the bad dependency, and pledged full reimbursement to impacted users in the June incident.

For the May incident, reporting says user funds and market resolution were unaffected; a full reimbursement commitment was not clearly established in the material found. As of 2026-08-29, a precise, on-chain verified breakdown of affected addresses and reimbursements is not verifiable from the available sources.

Date
2026-05-22
Cause
Other
Loss
$600K
Evidence (3)

incident

two sources

Polymarket International: Frontend & Infrastructure via Frontend Compromise on Polygon; loss $3,000,000 (DeFiLlama hacks registry). Remediation status: remediation_in_progress (retained evidence).

Date
2026-06-25
Cause
Frontend / infrastructure hack
Loss
$3.0M
Attacker proceeds
$3.0M
Status
remediation in progress
Classification
Frontend & Infrastructure
Technique
Frontend Compromise
Event id
polymarket-frontend-supply-chain-compromise-2026-06-25
Evidence (5)

key management

unverified

Polymarket’s key management is organized in a layered, non-custodial model. A user keeps control of the wallet private key, which is used for L1 EIP-712 signing to create or recover API credentials; those credentials are then used for L2 HMAC-based authentication on trading and account requests. In practice, the trading stack separates three things: the wallet signer, the API credential set, and any optional session/builder signer.

The API credential set consists of an API key, secret, and passphrase; the secret/passphrase are issued for authenticated use and are not the wallet private key. Polymarket also supports scoped signer patterns. Documentation describes session keys as separate signers authorized by a deposit wallet owner for trading, and builder-related tooling mentions separate builder headers and a revocation flow for compromised builder credentials.

For operational handling, the recommended pattern is to keep the wallet key under the user’s control and store it securely on the client side; third-party guidance notes common storage tiers such as local env files for small setups, self-hosted vaults for larger ones, and cloud KMS for higher-value or multi-bot deployments. The main risk-management implication is that Polymarket’s architecture does not centralize custody in the protocol, but it does create multiple secrets to manage: wallet private key, API credentials, and possibly session/builder keys. Credential rotation and revocation are part of the documented lifecycle.

Evidence (11)

smart-contract

unverified

As of September 6, 2026. Dune MCP was unavailable; therefore proxy-admin ownership, decoded role events, timelock delay, balances, and current pause/withdrawal state are Not verifiable as of 2026-09-06. No on-chain claims are made. Addresses reported in public materials (Polygon, chain 137): CTF Exchange V2 0xE111180000d2663C0091e4f400237545B87B996B; Neg Risk Exchange 0xe2222d279d744050d28e00520010520000310F59; Conditional Tokens 0x4D97DCd97eC945f40cF65F87097ACe5EA0476045; pUSD proxy 0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB, implementation 0x6bBCef9f7ef3B6C592c99e0f206a0DE94Ad0925f; UMA Adapter 0x6A9D222616C90FcA5754cd1333cFD9b7fb6a4F74.

These are documentation/repository claims, not independently on-chain verified in this run. Architecture: Users → off-chain CLOB/operator → Exchange → CTF/ERC-1155 + pUSD ↘ UMA Adapter/Oracle → resolution USDC → Onramp → pUSD proxy/UUPS → Offramp → USDC The published V2 code describes admin/operator access, global trading pause, per-user pause, configurable fee receiver and maximum fee rate (default 5%), plus permissioned ramp admin/witness roles. The collateral token is documented as UUPS-upgradeable; combo modules and Exchange are separately listed as proxy/implementation pairs. Contradiction / address-control finding: the current contracts page labels 0xE111… “CTF Exchange,” while the security registry labels 0xe333… “Exchange” and the contracts page labels 0xe333… the combo Exchange proxy. This likely reflects distinct trading/combo components, but exact production routing is Not verifiable as of 2026-09-06.

Audits are publicly listed for V2, including Quantstamp and Cantina; audited-deployment equivalence and unresolved findings are Not verifiable as of 2026-09-06. If privileged keys are compromised, plausible impact includes trading freeze, fee escalation within code limits, collateral wrapping/unwrapping disruption, oracle/resolution manipulation if oracle authority is compromised, or proxy implementation replacement where upgradeable modules are involved. Whether admins can directly drain user assets, whether exits remain available during pauses, and whether any timelock/renunciation exists are Not verifiable as of 2026-09-06.

Upgradeable
Yes
Evidence (5)

audit

one source

deposit-wallet audit report — DepositWallet Cantina Beacon Upgrade May 2026; file audit-reports/deposit-wallet/DepositWallet

  • Cantina
  • Beacon Upgrade
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
deposit-wallet
Scope
DepositWallet Cantina Beacon Upgrade May 2026
File
DepositWallet - Cantina - Beacon Upgrade - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

deposit-wallet audit report — DepositWallet Cantina Passkey + 1271 Sig + UUPS Recovery Upgrade June 2026; file audit-reports/deposit-wallet/DepositWallet

  • Cantina
  • Passkey + 1271 Sig + UUPS Recovery Upgrade
  • June 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
deposit-wallet
Scope
DepositWallet Cantina Passkey + 1271 Sig + UUPS Recovery Upgrade June 2026
File
DepositWallet - Cantina - Passkey + 1271 Sig + UUPS Recovery Upgrade - June 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

deposit-wallet audit report — DepositWallet Certora Beacon Upgrade May 2026; file audit-reports/deposit-wallet/DepositWallet

  • Certora
  • Beacon Upgrade
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
deposit-wallet
Scope
DepositWallet Certora Beacon Upgrade May 2026
File
DepositWallet - Certora - Beacon Upgrade - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

deposit-wallet audit report — DepositWallet Certora March 2026; file audit-reports/deposit-wallet/DepositWallet

  • Certora
  • March 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
deposit-wallet
Scope
DepositWallet Certora March 2026
File
DepositWallet - Certora - March 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

deposit-wallet audit report — DepositWallet Certora Passkey + 1271 Sig + UUPS Recovery Upgrade June 2026; file audit-reports/deposit-wallet/DepositWallet

  • Certora
  • Passkey + 1271 Sig + UUPS Recovery Upgrade
  • June 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
deposit-wallet
Scope
DepositWallet Certora Passkey + 1271 Sig + UUPS Recovery Upgrade June 2026
File
DepositWallet - Certora - Passkey + 1271 Sig + UUPS Recovery Upgrade - June 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

deposit-wallet audit report — DepositWallet Zellic March 2026; file audit-reports/deposit-wallet/DepositWallet

  • Zellic
  • March 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
deposit-wallet
Scope
DepositWallet Zellic March 2026
File
DepositWallet - Zellic - March 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

perps audit report — EIP 7702 aware withdrawal signatures Quantstamp July 2026; file audit-reports/perps/EIP-7702-aware withdrawal signatures

  • Quantstamp
  • July 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
perps
Scope
EIP 7702 aware withdrawal signatures Quantstamp July 2026
File
EIP-7702-aware withdrawal signatures - Quantstamp - July 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

perps audit report — Perps Exchange Cantina April 2026; file audit-reports/perps/Perps Exchange

  • Cantina
  • April 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
perps
Scope
Perps Exchange Cantina April 2026
File
Perps Exchange - Cantina - April 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

perps audit report — Perps Exchange Certora April 2026; file audit-reports/perps/Perps Exchange

  • Certora
  • April 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
perps
Scope
Perps Exchange Certora April 2026
File
Perps Exchange - Certora - April 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

perps audit report — Perps Exchange Quantstamp April 2026; file audit-reports/perps/Perps Exchange

  • Quantstamp
  • April 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
perps
Scope
Perps Exchange Quantstamp April 2026
File
Perps Exchange - Quantstamp - April 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Combinatorial Module Cantina May 2026; file audit-reports/polymarket-v2/Combinatorial Module

  • Cantina
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Combinatorial Module Cantina May 2026
File
Combinatorial Module - Cantina - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Combinatorial Module Certora May 2026; file audit-reports/polymarket-v2/Combinatorial Module

  • Certora
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Combinatorial Module Certora May 2026
File
Combinatorial Module - Certora - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Combinatorial Module Quantstamp May 2026; file audit-reports/polymarket-v2/Combinatorial Module

  • Quantstamp
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Combinatorial Module Quantstamp May 2026
File
Combinatorial Module - Quantstamp - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Combo Collateral Return + CCIP Cantina July 2026; file audit-reports/polymarket-v2/Combo Collateral Return + CCIP

  • Cantina
  • July 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Combo Collateral Return + CCIP Cantina July 2026
File
Combo Collateral Return + CCIP - Cantina - July 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Combo Collateral Return + CCIP Certora July 2026; file audit-reports/polymarket-v2/Combo Collateral Return + CCIP

  • Certora
  • July 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Combo Collateral Return + CCIP Certora July 2026
File
Combo Collateral Return + CCIP - Certora - July 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Formal Verification Certora August 2026; file audit-reports/polymarket-v2/Formal Verification

  • Certora
  • August 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Formal Verification Certora August 2026
File
Formal Verification - Certora - August 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Oracle Subsystem Cantina July 2026; file audit-reports/polymarket-v2/Oracle Subsystem

  • Cantina
  • July 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Oracle Subsystem Cantina July 2026
File
Oracle Subsystem - Cantina - July 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Oracle Subsystem Certora July 2026; file audit-reports/polymarket-v2/Oracle Subsystem

  • Certora
  • July 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Oracle Subsystem Certora July 2026
File
Oracle Subsystem - Certora - July 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Cantina April 2026; file audit-reports/polymarket-v2/Polymarket V2

  • Cantina
  • April 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Cantina April 2026
File
Polymarket V2 - Cantina - April 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Certora April 2026; file audit-reports/polymarket-v2/Polymarket V2

  • Certora
  • April 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Certora April 2026
File
Polymarket V2 - Certora - April 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Pashov May 2026; file audit-reports/polymarket-v2/Polymarket V2

  • Pashov
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Pashov May 2026
File
Polymarket V2 - Pashov - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Quantstamp May 2026; file audit-reports/polymarket-v2/Polymarket V2

  • Quantstamp
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Quantstamp May 2026
File
Polymarket V2 - Quantstamp - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 SigmaPrime June 2026; file audit-reports/polymarket-v2/Polymarket V2

  • SigmaPrime
  • June 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 SigmaPrime June 2026
File
Polymarket V2 - SigmaPrime - June 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Zellic June 2026; file audit-reports/polymarket-v2/Polymarket V2

  • Zellic
  • June 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Zellic June 2026
File
Polymarket V2 - Zellic - June 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Additional changes Certora May 2026; file audit-reports/polymarket-v2/Polymarket V2 Additional changes

  • Certora
  • May 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Additional changes Certora May 2026
File
Polymarket V2 Additional changes - Certora - May 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — Polymarket V2 Diff Review Cantina June 2026; file audit-reports/polymarket-v2/Polymarket V2 Diff Review

  • Cantina
  • June 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
Polymarket V2 Diff Review Cantina June 2026
File
Polymarket V2 Diff Review - Cantina - June 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — v1.2.0 Cantina August 2026; file audit-reports/polymarket-v2/v1.2.0

  • Cantina
  • August 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
v1.2.0 Cantina August 2026
File
v1.2.0 - Cantina - August 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

polymarket-v2 audit report — v1.2.0 Quantstamp August 2026; file audit-reports/polymarket-v2/v1.2.0

  • Quantstamp
  • August 2026.pdf in Polymarket/contract-security (protocol audit catalog).
Auditor
polymarket-v2
Scope
v1.2.0 Quantstamp August 2026
File
v1.2.0 - Quantstamp - August 2026.pdf
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — AuditReport ConditionalTokens; file audit-reports/v1-contracts/AuditReport-ConditionalTokens.md in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
AuditReport ConditionalTokens
File
AuditReport-ConditionalTokens.md
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — cs conditional tokens; file audit-reports/v1-contracts/cs_conditional_tokens.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
cs conditional tokens
File
cs_conditional_tokens.pdf
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — cs ctf exchange; file audit-reports/v1-contracts/cs_ctf_exchange.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
cs ctf exchange
File
cs_ctf_exchange.pdf
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — cs neg risk adapter; file audit-reports/v1-contracts/cs_neg_risk_adapter.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
cs neg risk adapter
File
cs_neg_risk_adapter.pdf
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — cs proxy wallet factories; file audit-reports/v1-contracts/cs_proxy_wallet_factories.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
cs proxy wallet factories
File
cs_proxy_wallet_factories.pdf
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — oz neg risk adapter; file audit-reports/v1-contracts/oz_neg_risk_adapter.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
oz neg risk adapter
File
oz_neg_risk_adapter.pdf
Catalog only
Yes
Evidence (1)

audit

one source

v1-contracts audit report — oz uma ctf adapter; file audit-reports/v1-contracts/oz_uma_ctf_adapter.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
v1-contracts
Scope
oz uma ctf adapter
File
oz_uma_ctf_adapter.pdf
Catalog only
Yes
Evidence (1)

audit

one source

accumulator audit report — audit; file audit-reports/v1-contracts/2020-01-20_accumulator_audit.pdf in Polymarket/contract-security (protocol audit catalog).

Auditor
accumulator
Report date
2020-01-20
Scope
audit
File
2020-01-20_accumulator_audit.pdf
Catalog only
Yes
Evidence (1)

audit

one source

CTF Exchange V2 on Polygon has also been audited by Cantina in March 2026. Scope:

  • Same CTF Exchange V2 core trading and settlement contracts on Polygon, with focus on market creation, order processing, and risk around resolution flows. Severity / findings:
  • The Polymarket contract listing confirms the existence of the Cantina report but does not summarise specific issue counts or severities.
  • Detailed critical/high/medium/low findings and their remediation status are Not verifiable as of 2026‑08‑30 without direct access to the Cantina PDF. Fix status:
  • Polymarket’s resources table implies the report is final (not “preliminary”) but does not explicitly state whether all findings were fixed; this is therefore Not verifiable as of 2026‑08‑30. Bytecode‑match / deployed code coverage:
  • The audit is advertised as covering CTF Exchange V2, which is the production exchange on Polygon, but an explicit bytecode hash comparison to the currently deployed contracts is Not verifiable as of 2026‑08‑30 under current constraints.
Auditor
Cantina
Report date
2026-03-01
Scope
CTF Exchange V2 Polygon smart contracts (exchange, markets, settlement)
Evidence (2)

audit

one source

Report: CTF Exchange V2 Security Review

Auditor
Cantina
Report date
2026-03-27
Scope
ctf-exchange-v2 codebase, including order matching, settlement, collateral adapters, and exchange accounting.
Findings
Critical: 0; High: 0; Medium: 5; Low: 6; additional informational/gas issues are described in the report. Noted issues include insufficient taker-side aggregate reconciliation and zero-sized orders being marked filled without economic execution.
Fix status
Some findings were fixed and verified; complete remediation status is Not verifiable as of 2026-09-05.
Evidence (2)

audit

one source

Report: Polymarket Exchange Smart Contracts Security Audit

Auditor
ChainSecurity
Report date
2022-11-03
Scope
V1 Exchange governance and exchange contracts; functional correctness, access control, signatures, complexity, and gas efficiency. Polygon deployment reference: CTF Exchange V1 0x4bFb41d5B3570DeFd03C39a9A4D8dE6Bd8B8982E.
Findings
Critical: 2 (signature valid for arbitrary address; incorrect ORDER_TYPEHASH). High: 1 (fee rate not hashed). Medium: 3 (fee approval, unintended order types, zero-address EOA signer). Low: 10. The report lists all findings as corrected or specification-changed during the engagement.
Fix status
Resolved during engagement according to the report; independent post-deployment remediation verification: Not verifiable as of 2026-09-05.
Evidence (2)

audit

one source

Report: Polymarket Conditional Tokens Smart Contracts

Auditor
ChainSecurity
Report date
2024-04-11
Scope
Conditional Tokens used for binary-outcome positions; functional correctness and elliptic-curve calculations for token-ID computation.
Findings
No critical, high, or medium findings identified in the published executive summary. The report notes complexity around negated elliptic-curve IDs and possible valueless 'all-purpose' position tokens, without treating it as a security risk in the framework.
Fix status
No material severity findings reported; deployed-code remediation status: Not verifiable as of 2026-09-05.
Evidence (1)

audit

two sources

Audit(s) of multiple Polymarket Polygon contracts used by Polymarket International, including Conditional Tokens and proxy/safe factories.

Auditor
ChainSecurity
Report date
2024-04-12
Scope
ChainSecurity audits cover at least: Proxy Factory, Safe Factory, Conditional Tokens, and additional adapters (e.g., NegRisk) used by Polymarket, all deployed on Polygon mainnet and referenced as upstream contracts for Polymarket International.[3][6][9][10]
Findings
ChainSecurity’s **Conditional Tokens** audit finds high security for functional correctness and elliptic‑curve ID computation, noting a complexity/usage risk around potential infinite minting of position tokens with no value but not as a security flaw.[9] Severity counts (critical/high/medium) are not summarised in accessible snippets and are Not verifiable as of 2026-09-04. The **Proxy Wallet Factories** audit similarly concludes high security for functional correctness and signature handling, again without publicly summarised severity counts in snippets; exact issue tally is Not verifiable as of 2026-09-04.[10]
Fix status
Immunefi and Polymarket’s contract-security repo state these audited contracts are the ones deployed on **Polygon mainnet**.[3][8] However, without direct bytecode comparison or explicit "all issues fixed" statements per report, precise fix status and bytecode-match for each contract are Not verifiable as of 2026-09-04.
Evidence (4)

audit

one source

Earlier audit of Polymarket Exchange smart contracts, covering governance and exchange parts of the protocol on Polygon.

Auditor
ChainSecurity (legacy Polymarket Exchange)
Report date
2022-01-13
Scope
Governance and exchange smart contracts forming the earlier version of Polymarket’s trading system on Polygon.[7][12]
Findings
The ChainSecurity exchange audit states the contracts provide a "high level of security" with focus on functional correctness, access control, signature handling, code complexity, and gas efficiency.[7] Specific severity counts (critical/high/medium) are not exposed in snippets and are Not verifiable as of 2026-09-04.
Fix status
The audit summary indicates the then‑current codebase was considered secure, but whether all identified issues were remediated in the deployed Polygon version and whether this legacy exchange is still in active use for Polymarket International is Not verifiable as of 2026-09-04.
Evidence (2)

audit

one source

New published report identified in Polymarket/contract-security.

Auditor
Cantina
Report date
2026-07
Scope
Polymarket V2 oracle subsystem
Findings
Critical/high/medium: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/Polymarket/contract-security/blob/main/audit-reports/polymarket-v2/Oracle%20Subsystem%20-%20Cantina%20-%20July%202026.pdf
Report id
doc:0a6a563c0e5840a2
Evidence (1)

audit

one source

New published report identified in Polymarket/contract-security.

Auditor
Certora
Report date
2026-07
Scope
Polymarket V2 oracle subsystem
Findings
Critical/high/medium: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/Polymarket/contract-security/blob/main/audit-reports/polymarket-v2/Oracle%20Subsystem%20-%20Certora%20-%20July%202026.pdf
Report id
doc:1228f63348bae4eb
Evidence (1)

audit

one source

New published report identified in Polymarket/contract-security.

Auditor
Certora
Report date
2026-08
Scope
Polymarket V2 formal verification
Findings
Critical/high/medium: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/Polymarket/contract-security/blob/main/audit-reports/polymarket-v2/Formal%20Verification%20-%20Certora%20-%20August%202026.pdf
Report id
doc:3a1e9971eb56e95f
Evidence (1)

audit

one source

New published report identified in Polymarket/contract-security.

Auditor
Certora
Report date
2026-05
Scope
Polymarket V2 combinatorial module
Findings
Critical/high/medium: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/Polymarket/contract-security/blob/main/audit-reports/polymarket-v2/Combinatorial%20Module%20-%20Certora%20-%20May%202026.pdf
Report id
doc:6bdcb53a84d1a7c9
Evidence (1)

audit

two sources

New published report identified in Polymarket/contract-security.

Auditor
Quantstamp
Report date
2026-05
Scope
Polymarket V2 combinatorial module
Findings
External extract reports five findings, including one medium; complete critical/high/medium breakdown is Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/Polymarket/contract-security/blob/main/audit-reports/polymarket-v2/Combinatorial%20Module%20-%20Quantstamp%20-%20May%202026.pdf
Report id
doc:78d943da17bd49dc
Evidence (2)

audit

one source

New published report identified in Polymarket/contract-security.

Auditor
Cantina
Report date
2026-05
Scope
Polymarket V2 combinatorial module
Findings
Critical/high/medium: Not verifiable as of 2026-09-06.
Fix status
Not verifiable as of 2026-09-06.
Report url
https://github.com/Polymarket/contract-security/blob/main/audit-reports/polymarket-v2/Combinatorial%20Module%20-%20Cantina%20-%20May%202026.pdf
Report id
doc:d2e52998a87e158b
Evidence (1)

audit

two sources

Audit of Polymarket CTF Exchange V2 smart contracts on Polygon mainnet.

Auditor
Quantstamp
Report date
2026-03-11
Scope
CTF Exchange V2 (central limit order book for Polymarket markets on Polygon), including functional correctness, access control, and security properties of the exchange contracts.[1][4][5]
Findings
Quantstamp’s report for **CTF Exchange V2** (March 2026) states **no high‑severity issues**, **one medium‑severity issue**, **three low‑severity issues**, and **one informational issue** were identified.[5] Detailed issue descriptions and recommendations are contained in the PDF report.[5]
Fix status
Quantstamp’s certificate indicates the issues were addressed; however, exact remediation status for each issue (e.g., fully fixed vs. acknowledged) is only described inside the report and is Not verifiable as of 2026-09-04 without direct access to the full text beyond the summary.[5] Whether the deployed Polygon bytecode matches the audited commit is also Not verifiable as of 2026-09-04.
Evidence (3)

audit

one source

Report: CTF Exchange V2

Auditor
Quantstamp
Report date
2026-04-21
Scope
Polymarket CTF Exchange V2 source commit a9d2397; exchange, adapters, collateral layer, order matching, settlement, signatures, fees, and access control.
Findings
Critical: 0; High: 0; Medium: 1; Low: 3; Informational: 1. Main medium finding: inconsistent COMPLEMENTARY-path fill inputs could overcharge or underfill takers. All five findings were marked fixed in the fix-review update dated 2026-03-25.
Fix status
Fixed and reviewed by Quantstamp; exact bytecode match to currently deployed Polygon contracts: Not verifiable as of 2026-09-05.
Evidence (2)

Team & Reputation

founders

two sources

Polymarket appears to be a real operating company, not just a web front: independent reporting consistently identifies Shayne Coplan as founder and CEO, and notes he started the business in 2020 from a New York apartment/“bathroom office” before it scaled into a major prediction market. Coplan’s prior public project was TokenUnion (a crypto loyalty project), which is the only clearly documented earlier venture in the sources gathered. Public sources also show a small founding-team origin, but I could not independently verify the full roster of early cofounders or current team composition beyond Coplan from the materials gathered.

On credibility, the company has both signals of traction and regulatory risk. Reporting ties Polymarket to major election-volume growth and to large venture backing, while also documenting a 2024 FBI search of Coplan’s home in connection with a criminal/probe related to the platform. That is a material governance and compliance red flag, even though it does not by itself prove misconduct.

On the office / onshore-offshore question, the gathered sources support that Coplan was operating from New York, and later reporting describes Polymarket as headquartered in New York City. However, the company’s exact legal entity structure, offshore components, and whether operations are materially split across jurisdictions are Not verifiable as of 2026-09-04 from the sources gathered. Reality check: Polymarket looks like a functioning business with a named founder, visible staff footprint, and major market adoption, but the information available here is stronger on product and founder visibility than on transparent corporate structure.

The biggest unresolved issue is jurisdictional/compliance clarity, especially given the FBI/CFTC-related reporting.

Evidence (6)

general reputation

two sources

Polymarket International has a mixed but high‑profile reputation, combining strong investor backing and growing mainstream usage with significant ongoing legal, regulatory and ethical controversies. Founders / entity / investors

  • The core entity behind Polymarket is Blockratize Inc., which operates the polymarket.com platform.
  • The platform is widely covered as one of the leading crypto prediction markets, attracting institutional and retail interest and substantial media attention.
  • It has attracted notable venture investment and operates as a growth‑stage fintech/crypto startup, though specific investor lists are not detailed in the retrieved regulatory sources. Regulatory and legal history
  • In January 2022, the U.S. Commodity Futures Trading Commission (CFTC) issued an order against Blockratize/Polymarket for operating an unregistered event‑based binary options trading facility and failing to register as a Designated Contract Market (DCM) or Swap Execution Facility (SEF).
  • Polymarket paid a $1.4M civil penalty and was ordered to wind down non‑compliant markets and cease and desist from violating the Commodity Exchange Act.
  • Following this, Polymarket geoblocked U.S. users from its international exchange.
  • Later reporting indicates that DOJ and CFTC investigations into a breach of that agreement were dropped in 2025, but new federal scrutiny of prediction markets, including Polymarket, has continued.
  • As of 2026, Polymarket is described as operating in a legal and ethical grey area, with ongoing debate over whether it is a regulated derivatives venue or an unlicensed gambling operation.
  • Multiple governments (including France, Brazil, Italy, Gibraltar) have banned Polymarket’s services, citing gambling or financial regulation concerns. Current investigations and criticisms
  • Recent reports describe ongoing or renewed federal investigations into Polymarket by U.S. regulators, including scrutiny over fabricated social‑media “wins” promotions, targeted marketing to college students, and broader questions about manipulation and consumer protection.
  • A consumer advocacy lawsuit alleges “many layers of manipulation” in Polymarket’s marketing by the CEO and CMO.
  • Federal prosecutors have been exploring whether lucrative bets on prediction markets involve insider trading, AML, market manipulation, or fraud; Polymarket is among the platforms referenced.
  • NYC Council and several U.S. states have probed Polymarket over alleged predatory marketing and whether its products should be regulated as gambling rather than financial derivatives. Risk‑relevant integrity signals
  • Polymarket has cooperated with authorities in at least one insider‑trading case involving military information, referring suspicious accounts to the Justice Department; regulators publicly acknowledged this cooperation.
  • Nevertheless, independent analysis and major media continue to highlight unresolved legal risk, regulatory uncertainty, bans in multiple jurisdictions, and ethical concerns around markets on wars and military strikes. On‑chain verification
  • Not verifiable as of 2026-09-04.
Evidence (10)

Economy

TVL: $359.6M

model

one source

Economic model — Polymarket International (Polygon)

  • Strategy/assets: Prediction-market trading, not a deposit-based yield strategy. Users deposit supported assets, converted to pUSD, a Polygon ERC-20 collateral token backed 1:1 by USDC; they buy/sell Yes/No outcome shares. Winning shares redeem for $1; losing shares expire worthless after resolution.
  • Yield source: No protocol APY, lending yield, restaking, or compounding strategy. User returns are directional event-trading P&L and market-making spreads. organic_yield_pct: null.
  • Organic vs subsidized: Trading returns are not protocol yield. Taker fees on enabled markets fund daily maker rebates, so maker economics are partly incentive-supported/subsidized. Fee-free geopolitics markets generate no Polymarket trading fees.
  • Market-neutral/exposure: The protocol itself is not market-neutral. Users can take directional outcome exposure; market makers may run hedged strategies, but this is user-specific. No leverage, looping, external yield, or restaking mechanism was identified. leverage_ratio: null.
  • Lock-ups/withdrawals: Capital can remain encumbered while positions are open or until market resolution. pUSD can be withdrawn through the collateral offramp, unwrapped/swapped to native USDC, and routed to supported chains; Polymarket states withdrawals are instant and fee-free, excluding possible intermediary/network costs.
  • Fees/limits/gates: Makers pay 0%; taker fees vary by category and price, with crypto markets listed at 7% of the fee formula and most categories 3–5%. Market-specific parameters apply. Deposit/withdrawal limits and account-access restrictions: Not verifiable as of September 6, 2026.
  • Protocol revenue: DeFiLlama reports approximately $15.3m 30-day revenue and $31.6m fees in one recent snapshot, but the attribution is analytics-platform data, not raw on-chain verification.
  • TVL: DeFiLlama reports roughly $345–349m, 100% Polygon, with 4.1% 30-day growth in one snapshot; the differing figures indicate dashboard/snapshot inconsistency. Dune TVL, product split, chain trend, APY history/volatility, and sustainability: Not verifiable as of September 6, 2026. Risk conclusion: This is trading/settlement infrastructure, not a conventional yield protocol. Returns are directional and resolution-dependent; reported “revenue” and TVL should not be interpreted as depositor yield.
Evidence (5)

reserves

unverified

As of September 6, 2026, no verifiable protocol-level treasury or reserve disclosure was found for Polymarket International. Liquid reserves, reserve addresses, composition, custodian, control/signing structure, reserve policy, and independent attestations are Not verifiable as of September 6, 2026. Dune MCP was unavailable in this run; therefore on-chain balances and reserve concentration are also Not verifiable as of September 6, 2026.

No Dune query ID or execution ID exists for this check. Polymarket’s current documentation identifies Polygon collateral infrastructure: pUSD proxy 0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB, implementation 0x6bBCef9f7ef3B6C592c99e0f206a0DE94Ad0925f, CollateralOnramp 0x93070a847efEf7F70739046A929D47a521F5B8ee, CollateralOfframp 0x2957922Eb93258b93368531d39fAcCA3B4dC5854, PermissionedRamp 0xebC2459Ec962869ca4c0bd1E06368272732BCb08, and Deposit Wallet Factory 0x00000000000Fb5C9ADea0298D729A0CB3823Cc07. These are infrastructure addresses, not evidence of treasury ownership or reserve balances.

Polymarket states that pUSD is backed by USDC and that backing is enforced by the smart contract. This supports a product-level collateral claim, but does not disclose the backing account(s), custodian, real-time balance, reconciliation process, or audit/attestation. Contradiction / gap: the existence of pUSD backing language should not be treated as proof of a disclosed corporate reserve. The previously recorded third-party claim regarding segregated accounts and monthly attestations could not be independently confirmed in this check and remains secondary/unverified.

No published protocol liabilities figure was located. Structured fields: liquid_reserves_usd: null; liabilities_usd: null.

Evidence (4)

tokenomics

two sources

Polymarket International does not have a publicly verified native token as of the information gathered here; therefore token name/ticker, contract address, total supply, circulating supply, market cap, FDV, emissions, unlocks, allocations, and holder concentration are Not verifiable as of 2026-09-04. The available sources instead describe Polymarket as operating on Polygon mainnet and using USDC / pUSD collateral plus CTF-related contracts, not a native protocol token.

  • Native token: No official native Polymarket token is confirmed in the gathered sources; claims of a future POLY token remain speculative and are not a verified launch.
  • Token utility / governance: Not verifiable as of 2026-09-04. No source here confirms token-based governance, revenue share, buybacks, burns, or staking rewards.
  • Mint / blacklist / fee-switch controls: Not verifiable as of 2026-09-04. The sources do confirm Polymarket’s deployed contracts are on Polygon and reference CTF, exchange, and collateral contracts, but not a token admin model for a native token.
  • Unlock schedule / announced unlocks: Not verifiable as of 2026-09-04. No verified native-token allocation or vesting schedule was found, so there is nothing on-chain to confirm as having unlocked.
  • DEX liquidity / main listings: Not verifiable as of 2026-09-04 for a native Polymarket token, because no verified token exists in the gathered sources. The platform’s core activity is prediction-market trading with USDC/pUSD collateral on Polygon. The strongest verified point is that Polymarket’s contracts are deployed on Polygon mainnet and its trading uses USDC/pUSD collateral; any article or post claiming an official POLY token should be treated as unverified unless Polymarket publishes a contract and tokenomics or a reputable market listing confirms it.
Evidence (6)

Stress scenarios

stress scenario - bitcoin price falls below $10000

one source

For the stress scenario of Bitcoin falling below $10,000, the only directly relevant Polymarket-linked evidence in the provided results is a secondary report saying Polymarket-priced odds for a $10,000 crash were about 5% in an extreme geopolitical/liquidity downside case. That implies the scenario is treated as a low-probability tail event, not a base case. I could not verify a Polymarket market specifically for below $10,000 from the provided results alone, so the exact contract-level probability is Not verifiable as of 2026-09-04.

The closest direct Polymarket evidence shows much higher probabilities for milder downside levels, such as below $75,000 at 71% on Polymarket’s Bitcoin page, which is consistent with a market that prices gradual downside more heavily than an outright collapse. For institutional risk framing, the main takeaway is that a sub-$10k outcome appears to be an extreme stress case rather than a market-implied central scenario in the available evidence.

Evidence (2)

stress scenario - largest collateral depegs 20%,

two sources

Polymarket’s collateral on Polygon is pUSD in the current documentation, while older materials still describe the platform as having used USDC.e on Polygon, so the exact collateral stack has changed over time. For a 20% depeg of the largest collateral asset, the direct stress impact on users is a 20% haircut in collateral value for any position or account that is marked against that asset; however, Polymarket’s public docs do not provide enough information to quantify protocol-wide losses, insolvency exposure, or a reserve backstop from the available sources, so those figures are Not verifiable as of 2026-09-04. For the market mechanics, Polymarket states that its markets are fully collateralized and that liquidation / margin checks are based on account equity versus maintenance requirements, so a collateral depeg would mainly create under-collateralization risk for any balances still held in the depegged asset rather than open-ended protocol leverage.

Evidence (6)

stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;

two sources

Polymarket is a non-custodial prediction market where users trade against each other via AMMs; there is no central “counterparty” providing guarantees in the core protocol design. Because Dune MCP is unavailable, all on-chain confirmation is: Not verifiable as of 2026‑09‑04. Below, “top counterparty” is interpreted as a large liquidity provider/trader becoming insolvent off-chain. ### 1. Large LP insolvent

  • Path: LP has funded their Polygon wallet from an off-chain entity that goes bankrupt. On-chain liquidity in Polymarket pools remains unless withdrawn.
  • Expected loss:
  • Other traders are exposed only to price risk, not the LP’s solvency. Settlement uses Chainlink oracles and smart contract logic, not LP credit.
  • If the LP stops managing positions, pools may become imbalanced, causing worse prices and higher slippage but not direct loss from default.
  • Who absorbs it:
  • The LP’s beneficial owners/creditors off-chain bear the loss.
  • Remaining traders bear market impact (adverse prices, thin liquidity) but not counterparty default.
  • Compensation:
  • No automatic protocol-level compensation; smart contracts pay out based solely on oracle outcome and token balances.
  • Smart-contract impact path:
  • The LP’s liquidity remains in AMM contracts until they or a legal representative withdraw.
  • No special “insolvency” branch; contracts are oblivious to off-chain status. ### 2. Centralized intermediary (if any) insolvent Polymarket previously settled with the CFTC and changed its structure, including geo-restrictions and compliance measures. Any remaining centralized entities (front-end operator, fiat on-ramp, KYC provider) could fail.
  • Path: Operator or on-ramp becomes insolvent.
  • Expected loss:
  • Users may lose access to web UI, account services, or fiat balances held off-chain.
  • On-chain positions on Polygon should remain controlled by users’ wallets, but this is Not verifiable as of 2026‑09‑04.
  • Who absorbs it:
  • Losses from custodial fiat or off-chain accounts are borne by affected users and the intermediary’s creditors.
  • Compensation:
  • Depends on local insolvency law and any investor protection schemes; no protocol-native coverage stated in public docs.
  • Smart-contract impact path:
  • If the front-end disappears, contracts continue to exist on Polygon; users must interact via alternative interfaces or direct calls. ### 3. Oracle / infrastructure failure as “counterparty” If the oracle provider or infrastructure becomes effectively insolvent (ceases operation):
  • Markets may fail to resolve or be delayed, locking funds in outcome tokens.
  • Governance / operators may need manual intervention; no fully trustless fallback is clearly documented. All detailed on-chain behaviours and exact contract logic are Not verifiable as of 2026‑09‑04.
Evidence (3)

stress scenario - committed fraud by the DAO or owners

two sources

For a stress scenario on committed fraud by the DAO or owners, I find no verified evidence that Polymarket International’s DAO or owners have committed fraud. The available reporting instead shows allegations and investigations around user misconduct, manipulation, and phishing/exploit events, not a proven owner/DAO fraud finding. What is verifiable is that Polymarket has faced several integrity incidents and accusations: Reuters reported a NYC Council probe into alleged predatory marketing practices, including undisclosed influencer payments and fake-trade videos; the New York Times reported suspicious betting patterns consistent with insider trading; and Reuters also reported Polymarket referred dozens of potentially suspicious military-related accounts to the Justice Department.

There were also security incidents affecting users: a third-party frontend compromise reportedly led to about $3 million in stolen funds, and another exploit on a Polygon smart contract reportedly drained over $600,000. These incidents are serious operational and control failures, but the sources do not establish committed fraud by the DAO or owners themselves. Accordingly, the appropriate risk framing is: fraud by DAO/owners is not verifiable as of 2026-09-04, while platform-level manipulation, insider-trading allegations, and exploit risk are clearly documented.

Evidence (6)

stress scenario - primary yield source negative 30d,

two sources

Polymarket International does not appear to have a public yield product that can be stress-tested as a “primary yield source” on the basis of the web results available here. Bathymark notes that there is no DeFiLlama yield-pools map for this slug and frames it as a protocol “without public yield products,” which makes a 30-day primary-yield analysis not verifiable as of 2026-09-04. The public Polymarket materials and third-party coverage instead describe the protocol as a prediction market and, in one case, a separate incentive program paying up to 4% annualized yield on select long-term positions funded by the Polymarket Treasury; that is a market incentive, not a clearly documented protocol-level yield source for the slug.

For a stress scenario, the correct risk statement is therefore: if the assumed “primary yield source” is the Treasury-funded holding reward, a negative 30-day yield would mean the program is under pressure or unavailable, but the magnitude cannot be verified from the provided sources because no on-chain or audited revenue/yield series is available here. If you need a chain-specific exposure or yield decomposition for Polygon, that is Not verifiable as of 2026-09-04 with the current source set.

Evidence (6)

Governance & Legal

governance

two sources

As of September 13, 2026, Polymarket International appears company-controlled, not DAO-governed.

  • Operator / legal control: The site identifies Adventure One QSS Inc. as the international platform operator and states that Polymarket operates through separate legal entities. A CFTC complaint identifies Adventure One QSS Inc. as a Panamanian corporation and Blockratize, Inc. as a Delaware corporation doing business as Polymarket. Publicly verified registration number and current directors: Not verifiable as of September 13, 2026. An Ontario filing identified Harry Jones as Adventure One’s officer in March 2025; this is not sufficient to establish the current board or control structure.
  • Frontend, rules and enforcement: Operational control rests with Polymarket. The transparency page says the international platform is governed by its Terms of Use and that violations are enforced by Polymarket, including wallet-level restrictions and law-enforcement referrals.
  • Proposal process / DAO: No public token-governance contract, voting token, proposal forum, delegated-voting process, DAO constitution, or binding community approval process was identified. DAO governance is therefore not evidenced and appears symbolic/nonexistent. Voting concentration and top holders via Dune: Not verifiable as of September 13, 2026; Dune MCP was unavailable.
  • Funds: Polymarket states that the international platform is non-custodial, users hold private keys, and collateral is held in smart contracts rather than by Polymarket. This is an official platform claim; contract-level authority to move or freeze user collateral was not independently verified in this run.
  • Timelock / multisig: Timelock delay, multisig threshold, signer identities, signer independence, upgrade authorities, and emergency powers: Not verifiable as of September 13, 2026. Contradiction / risk note: Polymarket describes the system as non-custodial and smart-contract-based, but its own transparency materials simultaneously document centralized rulemaking, surveillance, wallet restrictions, and enforcement. Non-custody does not establish decentralized governance. Assessment: Company control is evidenced for the frontend, rules, compliance and enforcement layers. Contract-admin powers and treasury controls remain unresolved without address-level on-chain verification.
Dao governance
No
Evidence (5)

legal & regulatory

two sources

Polymarket International appears to be the current international-facing front end of Polymarket, a prediction market protocol originally operated by Blockratize Inc. in the U.S.; after CFTC enforcement, the consumer-facing activity was reorganized and geo-restricted, while liquidity remains on Polygon. Entity & jurisdiction • The original operator, Blockratize Inc. (Polymarket), is a New York–based company that was investigated and sanctioned by the U.S. Commodity Futures Trading Commission (CFTC) in January 2022 for offering off‑exchange event‑based binary options to U.S. persons without registration. • Polymarket’s current “International” branding suggests a non‑U.S. targeting strategy, but a precise legal entity name, jurisdiction of incorporation, and group structure for “Polymarket International” are Not verifiable as of 2026‑09‑04; the public-facing site does not clearly disclose the operating entity, and third‑party sources mostly still refer to Blockratize/Polymarket generically. Regulatory actions & enforcement • The CFTC issued and settled an enforcement action against Blockratize Inc.

(Polymarket) on 3 January 2022, requiring cessation of “all markets” offering event‑based binary options, payment of a $1.4m civil monetary penalty, and an orderly wind‑down of markets in the U.S. • This is direct enforcement against the protocol’s operator, not mere guidance, and demonstrates that U.S. regulators treat many Polymarket markets as unregistered swaps/event‑based binary options under the Commodity Exchange Act. Sanctions status • There is no indication in major public sanctions lists or regulatory releases that Polymarket or “Polymarket International” is itself designated or sanctioned as an entity. Not sanctioned as of 2026‑09‑04 based on available information. ToS, restrictions, KYC/AML • Polymarket’s public materials and coverage emphasize geo‑blocking of U.S. users and the use of a non‑U.S. front end to avoid U.S. regulatory exposure after the CFTC action. • Specific details on KYC/AML implementation (e.g., level of identity verification, screening vendors, PEP/sanctions processes) are Not verifiable as of 2026‑09‑04; media and analytics sources do not provide operational compliance details, and the site’s policies are not fully indexed. • Likewise, detailed data protection practices (GDPR alignment, DPA location, breach history) are Not verifiable as of 2026‑09‑04. Classification & legal risk • U.S. regulators have already classified Polymarket’s event contracts as off‑exchange swaps / binary options subject to CEA/CFTC jurisdiction. • For non‑U.S. users, local classification may fall under betting/gaming, CFD/binary‑options, or derivatives law, but systematic coverage by EU/UK or other regulators is Not verifiable as of 2026‑09‑04. • Key residual risks: renewed CFTC action if U.S. access/solicitation is detected; potential enforcement by non‑U.S. gambling/derivatives regulators; opaque legal-entity structure for "Polymarket International" complicates counterparty and operational risk assessment.

Active enforcement
Yes
Sanctioned
No
Entity
Blockratize Inc. (Polymarket); specific legal entity for “Polymarket International” Not verifiable as of 2026-09-04
Jurisdiction
United States (CFTC enforcement against Blockratize Inc.); non-U.S. jurisdiction for Polymarket International Not verifiable as of 2026-09-04
Evidence (2)

legal registries

two sources

No exact GLEIF LEI record for 'Blockratize Inc', 'Polymarket International'. OFAC SDN screening of 'Blockratize Inc', 'Polymarket International': no match. SEC litigation and administrative release feeds: no mention.

Screened names
  • Blockratize Inc
  • Polymarket International
Sanctioned
No
Evidence (4)

Stability

stability

two sources

Polymarket historically used bridged USDC.e on Polygon as collateral, and its current docs also describe a migration to Polymarket USD (pUSD), a Polymarket-issued token backed 1:1 by USDC. A depeg of the collateral stablecoin was not verifiable from the gathered sources, so depeg_count, last_depeg_date, and max_depeg_pct remain Not verifiable as of 2026-09-06. Because pUSD is now documented as a Polymarket-issued collateral token, own_stablecoin is true if current-state docs are accepted; however, the historical setup alone would not support that, so this field is only partially verifiable from the available evidence.

Own stablecoin
Yes
Stablecoin ids
  • USDC.e
  • USDC
  • pUSD
Evidence (5)

Risks & Strengths

risks

two sources

Polymarket International’s principal risks are regulatory perimeter uncertainty, oracle-dependent settlement, smart-contract and upgrade risk, Polygon/pUSD infrastructure exposure, and user-controlled wallet or operational failure. The platform’s international entity is explicitly not CFTC-regulated, while its market-resolution and collateral mechanisms remain dependent on external systems and protocol-controlled implementation choices. TVL, exposure concentration, contract balances, and live on-chain health are Not verifiable as of September 5, 2026 because Dune MCP was unavailable.

RiskImpactSeverityProbabilityMitigation in placeResidual risk
Regulatory perimeter uncertaintyThe international platform may face enforcement, forced market wind-downs, access restrictions, licensing demands, or liability across jurisdictions. The 2022 CFTC action demonstrates this is an evidenced, not hypothetical, risk.HighHighGeographic blocking, sanctions screening, terms prohibiting circumvention, and separate Polymarket US structure are in place [S1][S2].High residual risk because cross-border prediction-market, gambling, derivatives, AML, and sanctions treatment remains jurisdiction-specific and changeable.
Oracle and resolution failureIncorrect, delayed, ambiguous, or manipulated resolution can transfer the full market payoff to the wrong outcome and create litigation or confidence loss.HighMediumPredefined resolution rules, proposer bonds, challenge periods, and escalation to UMA token-holder voting [S3].Medium-High residual risk: economic security and voter incentives may be insufficient for exceptionally large or politically contentious markets.
Smart-contract upgrade riskBugs in exchange, conditional-token, rewards, or pUSD contracts could freeze, misroute, or permanently lose user funds.HighMediumExternal audits and a 2026 contract migration are reported; contracts are deployed on Polygon and are open source [S4][S5].Medium-High residual risk because audits are time-boxed and do not cover every future deployment, integration, or operational change.
Polygon and pUSD dependencyPolygon outages, reorgs, congestion, token-contract failure, or a breakdown in pUSD-to-USDC convertibility could impair trading, settlement, or withdrawals.HighMediumpUSD is stated to be backed 1:1 by USDC through an on-chain contract, with Polygon as the deployment network [S5].Medium residual risk; backing, balances, and concentration are Not verifiable as of September 5, 2026 without on-chain queries.
Wallet and irreversible-transfer lossCompromised credentials, leaked private keys, incorrect network/token transfers, or phishing can cause irreversible loss despite non-custodial design.HighMediumUser custody, key-export capability, recovery tooling, and warnings about private-key responsibility are provided [S6].Medium-High residual risk because the user, not the platform, bears much of the key-management and transaction-error risk.
Evidence (6)

strengths

two sources

Polymarket International’s top strengths are its broad market coverage, fast and low-cost trading on Polygon, high liquidity and tight spreads, transparent on-chain settlement, and self-custody / non-custodial fund control. These strengths are consistently reflected across independent reviews and technical explainers: Polymarket offers a wide range of topics including politics, sports, crypto, and culture; it runs on Polygon for quick, inexpensive transactions; it is described as having very tight spreads and strong liquidity; its trades are recorded onchain; and users keep control of funds rather than depositing into a central house.

Evidence (5)

Methodology & Limitations

  • On-chain metrics: not verifiable — Dune phase 2 is not enabled.
  • 0 of 25 fact categories not yet collected.
  • Fact verifiability: 23 two independent sources, 55 one source, 4 unverified.
  • Oldest fact verification date: 2026-08-29.