Worked example · 2025-10
Polymarket POLY pre-token brand-anticipation phishing — EVM — 2025-10 onward
Summary
In October 2025, Polymarket's Chief Marketing Officer publicly confirmed that the platform planned to launch a POLY token in the future. This public confirmation — made through official Polymarket channels and covered by crypto media — created a structural information asymmetry: the platform had signalled that a token would exist, but had not yet deployed one, published a canonical claim URL, or registered defensive typosquat domains.
Within weeks of the CMO's confirmation, attacker-operated typosquat domains surfaced:
polymarket-claim.com,polymarket-airdrop.io,polymarket-token.app,claim-polymarket.com, and near-miss variants.- dApps hosted on these domains presented a "POLY airdrop claim" interface — a UI that purported to be the official Polymarket token claim portal.
- Users were prompted to connect their wallets and sign transactions that granted token approvals to attacker-controlled drainer contracts (the Inferno / Angel drainer-kit lineage — structurally identical to the drainer-backend pattern documented under T4.008).
The key structural vulnerability was the pre-token information gap: Polymarket's own CMO had created the expectation that a POLY token would exist, but no POLY token existed on-chain. Users searching for "Polymarket token claim" or "POLY airdrop" encountered the attacker's domains as the first concrete "POLY" touchpoints — there was no canonical Polymarket-deployed claim portal to serve as the ground-truth reference.
The campaign is the canonical T4.009 worked example because:
- The platform's own public signalling (CMO confirmation) created the ambiguity.
- No token existed on-chain at the time the phishing infrastructure was active.
- The attacker supplied the claim surface before the platform did — first-mover advantage at the phishing-claim layer.
- The drainer-backend substrate (Inferno / Angel) is the same operational infrastructure observed across T4.008's distribution cohort, confirming the drainer-kit operator-cluster continuity between the two phishing classes.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2025-10 | Polymarket CMO publicly confirms future POLY token plans via official channels | (platform signalling creates ambiguity window) |
| 2025-10 T+weeks | Attacker-operated typosquat domains surface; dApps claiming "POLY airdrop claim" target Polymarket users | T4.009 (pre-token anticipation phishing) |
| 2025-10 onward | Drainer-backend extraction via Inferno / Angel kit lineage; per-incident victim anchors form | T4.008 (drainer-backend substrate) |
| 2025-11 onward | SEAL ISAC / ScamSniffer domain-reputation feeds ingest POLY-anticipation phishing domains | (defender-side detection) |
Realised extraction
Per-incident anchors still forming at v0.1; the class-level calibration anchor is the structural pattern (platform-signalling-creates-ambiguity → attacker-supplies-claim-surface → drainer-backend-extraction). Individual victim losses are aggregated across the Inferno/Angel drainer-kit cohort.
Public references
- Polymarket CMO token-plan confirmation, October 2025 (official Polymarket communications)
- ScamSniffer / SEAL ISAC phishing-domain monitoring feeds (October–November 2025)
- Inferno / Angel / AngelFerno drainer-kit lineage documentation (see T4.008 citations)
- See
techniques/T4.009-pre-token-brand-anticipation-phishing.mdfor full technique characterisation