DATABASE Polymarket.com FULL API BREACH - 10M+ Records, 300k Real Identities, Admin 2026-04

  • Thread starter DBHunter
  • Start date
  • Tagged users None

DBHunter

Infinity Member
Golden Member
Joined
August 23, 2025
Messages
2,122
Reaction score
4,131
Points
113
  • Thread Author
  • #1
Hello DNA Community,
Today I have uploaded the Polymarket.com Full API Dump & Exploit Kit - Decentralized prediction market platform with full user PII, market data and internal API access.

Database Info:
- Target: Polymarket.com (Gamma API + CLOB API)
- Total Records: ~10M+ across all endpoints
- Total Size: ~1GB extracted
- Date: 2026-04-27
- Method: Undocumented API endpoints + pagination bypass + CORS misconfiguration
- Auth: None required for extraction (unauthenticated endpoints)

Vulnerabilities Included (POCs in ZIP):
- CVE-2025-62718 (Axios NO_PROXY Bypass) - CVSS 9.9 - SSRF to internal services
- CORS Misconfiguration on CLOB API - wildcard origin + credentials=true
- CVE-2024-51479 (Next.js Middleware Auth Bypass) - CVSS 7.5
- CLOB Pagination Validation Bypass - limit=999999 accepted silently, no rate limiting
- Unauthenticated /comments/{id} endpoint - brute-forceable, leaks full profiles
- Unauthenticated /reports endpoint - leaks user activity + admin indicator
- Unauthenticated /v1/data/followers/{address} - full social graph enumeration

Compromised Data:
- 10k unique user profiles with full PII (name, pseudonym, bio, profile image, proxy wallet, base address)
- 4111 comments with attached full profile objects
- 1000 report records containing 58 unique ETH addresses + admin_auth_addr indicator
- 48,536 gamma markets with full metadata, condition IDs, token IDs
- 250,000+ active CLOB markets with FPMM addresses
- 292+ events with submitter/resolver ETH addresses and internal usernames
- 100 reward configurations with USDC contract addresses and daily rates
- 9000 follower profiles with names, pseudonyms and proxy wallets
- Internal user IDs exposed in createdBy/updatedBy fields

Sample Data (10 records):



Pack Contents:
- All dumped JSONs (markets, events, profiles, comments, reports, rewards, series)
- 5 working POCs (CORS exploit, Axios SSRF, Next.js bypass, pagination DoS, WebSocket exploit)
- Auto-dump script - runs continuously and pulls fresh data until they patch the endpoints
- Full redteam report with MITRE ATT&CK mapping
Download:
To see this hidden content, you must React with one of the following reactions : Like, Love, Haha, Wow
To see this hidden content, you must React with one of the following reactions : Like, Love, Haha, Wow
 
Reactions: zbnkptz, Aayesha, 3w@nG8PAEXcVDai and 5 others

Similar threads

Replies
0
Views
301
DBHunter
Replies
0
Views
394
DBHunter
Replies
0
Views
373
DBHunter
  • Tags
    addresses and api bypass cloud data dumped endpoints full gofile internal polymarket profiles simple storage the they unauthenticated user with