← PolyArb1 decision on this page
Audit log
Every state-changing event for PolyArb: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-23 03:38:33ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 449,583,504
- sig
4MU5F9ND3bVE…zu3G3LQXexplorer ↗- hash
CdZyqBGcpNMB…VgYgbpHqsha256 → base58
verifying row…full verify ↗canonical bytes (9210 B) ▸
{"actor":"system:backfill","investigation_id":"bd06de19-e001-4b28-9227-fdcd75358535","kind":"publish","page_slug":"polyarb","published_at":"2026-09-23T03:38:33.142Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"PolyArb","sections":[{"content":"On May 4, 2026, blockchain investigator ZachXBT publicly identified PolyArb as a deceptive prediction-market product whose website allegedly contains a wallet drainer (referred to in some coverage as a \"wallet swapper\") designed to steal funds from users who connect their wallet. ZachXBT's warning followed an interaction between tech investor William LeGate and the PolyArb account on X, which ZachXBT said risked giving the alleged scam exposure to a wider pool of potential victims. Security researcher \"bbsz\" reportedly characterized the operation as part of a cluster run by an individual associated with both wallet drainers and occasional malware campaigns operated across different front-end products, describing it as a longer-running, credibility-building operation rather than a typical hit-and-run drainer. These allegations originate primarily from social-media statements by named security researchers relayed through crypto news outlets; no independent confirmation from a law-enforcement or regulatory body has been identified.","heading":"ZachXBT Fraud Allegation and Wallet Drainer","severity":"critical","sources":[{"credibility":2,"name":"ZachXBT: PolyArb for Fake Prediction Market Product with Wallet Swapper — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605395916"},{"credibility":3,"name":"ZachXBT Flags Polyarb as Fake Prediction Market With an Active Wallet Drainer — CryptoBreak.net","type":"news_article","url":"https://www.cryptobreak.net/cryptocurrencies/bitcoin-btc/zachxbt-flags-polyarb-as-fake-prediction-market-with-an-active-wallet-drainer.html"},{"credibility":2,"name":"Beware of wallet draining products on Polymarket, prediction markets, analysts warn — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/32805424/"}]},{"content":"According to the reporting cited above, the PolyArb account allegedly engaged in reply-based marketing under posts from well-known prediction-market-related accounts, a tactic described as intended to drive traffic and lend the product an appearance of credibility. This is characterized as distinguishing PolyArb from typical short-lived, low-effort drainer scams, since the operation reportedly built an ongoing social-media presence rather than relying on a single viral push. This claim rests on secondary reporting summarizing researcher commentary rather than a primary document, and should be treated as alleged.","heading":"Marketing and Traffic-Generation Tactics","severity":"high","sources":[{"credibility":2,"name":"ZachXBT: PolyArb for Fake Prediction Market Product with Wallet Swapper — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605395916"},{"credibility":2,"name":"Beware of wallet draining products on Polymarket, prediction markets, analysts warn — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/32805424/"}]},{"content":"The domain polyarb.io has been catalogued by the phishing-tracking service PhishDestroy, which recorded it as first identified and registered on April 8, 2026, hosted on IP 172.67.153.181 and registered through Name.com. PhishDestroy's listing indicates the domain was flagged by 4 of 91 security vendors on VirusTotal and appears on blocklists maintained by MetaMask and SEAL, and it associates the site with impersonation of the Jupiter brand (a Solana-based trading protocol) rather than Polymarket or Kalshi directly. A separate related domain, polyarb.bot, is also tracked by the same service with at least one detection as of the source's 2026 report. These technical indicators corroborate the wallet-drainer allegation but come from an automated/community threat-intelligence aggregator rather than a named forensic investigation, so specifics (e.g., total funds stolen, exact drainer mechanism) remain unverified.","heading":"Domain and Technical Indicators","severity":"high","sources":[{"credibility":2,"name":"polyarb.io — Active Crypto Wallet Theft Phishing domain profile — PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/polyarb.io/"},{"credibility":2,"name":"Is polyarb.bot Legit or Scam? — PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/polyarb.bot/"}]},{"content":"PolyArb's exposure occurred amid a broader increase in phishing activity targeting prediction-market users during 2026, as prediction-market open interest reportedly reached a record $1.3 billion in April 2026 across platforms including Kalshi (approximately $636.4 million) and Polymarket (approximately $589.8 million), a growth in user base and funds that reporting suggests made the sector an attractive phishing target. Separately from PolyArb, multiple outlets reported that a distinct phishing campaign used Polymarket's own comment sections to post links advertising fake \"private markets\" with better odds, directing victims to sites that mimicked Polymarket's interface and used a fake Cloudflare verification pop-up to execute malicious code and drain wallets; this campaign was reported to have cost users over $500,000 and was first flagged publicly by a trader using the handle \"25usdc.\" These are reported as related but separate schemes exploiting the same user base and general phishing pattern (fake tools/links preying on prediction-market traders), not the same operation as PolyArb.","heading":"Broader Context: Wave of Prediction-Market Phishing","severity":"medium","sources":[{"credibility":2,"name":"Beware of wallet draining products on Polymarket, prediction markets, analysts warn — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/32805424/"},{"credibility":2,"name":"Polymarket Users Face Phishing Campaign That Has Stolen Over $500,000 — BingX","type":"news_article","url":"https://bingx.com/en/news/post/polymarket-users-warned-of-phishing-scheme-that-has-stolen-over-k"},{"credibility":2,"name":"Phishing Link in Polymarket Comment Section Ends up Losing User $90,000 — GamblingNews","type":"news_article","url":"https://www.gamblingnews.com/news/phishing-link-in-polymarket-comment-section-ends-up-losing-user-90000/"}]}],"sources_used":[{"credibility":2,"name":"ZachXBT: PolyArb for Fake Prediction Market Product with Wallet Swapper — Bitget News","type":"news_article","url":"https://www.bitget.com/news/detail/12560605395916"},{"credibility":3,"name":"ZachXBT Flags Polyarb as Fake Prediction Market With an Active Wallet Drainer — CryptoBreak.net","type":"news_article","url":"https://www.cryptobreak.net/cryptocurrencies/bitcoin-btc/zachxbt-flags-polyarb-as-fake-prediction-market-with-an-active-wallet-drainer.html"},{"credibility":2,"name":"Beware of wallet draining products on Polymarket, prediction markets, analysts warn — CryptoNews.net","type":"news_article","url":"https://cryptonews.net/news/security/32805424/"},{"credibility":2,"name":"polyarb.io — Active Crypto Wallet Theft Phishing domain profile — PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/polyarb.io/"},{"credibility":2,"name":"Is polyarb.bot Legit or Scam? — PhishDestroy","type":"research","url":"https://phishdestroy.io/domain/polyarb.bot/"},{"credibility":2,"name":"Polymarket Users Face Phishing Campaign That Has Stolen Over $500,000 — BingX","type":"news_article","url":"https://bingx.com/en/news/post/polymarket-users-warned-of-phishing-scheme-that-has-stolen-over-k"},{"credibility":2,"name":"Phishing Link in Polymarket Comment Section Ends up Losing User $90,000 — GamblingNews","type":"news_article","url":"https://www.gamblingnews.com/news/phishing-link-in-polymarket-comment-section-ends-up-losing-user-90000/"}],"summary":"PolyArb is a crypto product marketed as a prediction-market arbitrage bot for platforms like Polymarket, but was publicly identified by on-chain investigator ZachXBT on May 4, 2026 as a fraudulent front containing an active wallet drainer. Independent phishing-domain trackers separately flagged associated domains (including polyarb.io) as malicious. The operation surfaced amid a broader wave of phishing targeting prediction-market users in 2026, though PolyArb itself is a distinct scheme from the unrelated Polymarket comment-section phishing campaign that cost users over $500,000.","timeline":[{"date":"2026-04-08","event":"The domain polyarb.io was registered and subsequently flagged as a phishing/wallet-theft domain by threat-intelligence tracker PhishDestroy.","source":"PhishDestroy domain profile for polyarb.io","source_url":"https://phishdestroy.io/domain/polyarb.io/"},{"date":"2026-05-04","event":"Blockchain investigator ZachXBT publicly flagged PolyArb as a fake prediction-market product containing an active wallet drainer, after tech investor William LeGate interacted with the PolyArb account on X.","source":"Bitget News / CryptoBreak.net","source_url":"https://www.bitget.com/news/detail/12560605395916"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision a30ed6f0-9ec4-427e-9314-e23647f90488
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.