Scope, method and what this document is not
What was reviewed, from which sources, and the limits of a desk assessment.
This paper assesses the security surface a professional participant inherits by trading Polymarket through its public interfaces. It covers the settlement chain, the collateral and position primitives, the matching venue, wallet custody, API credentials, the gasless relayer, and outcome resolution. It is written from public primary sources only: Polymarket's published developer documentation, the two ChainSecurity audit reports Polymarket has made public, CFTC filings and orders, and dated reporting on the incidents discussed.
- Desk review of public documentation and published audit reports — not a penetration test, code review, or independent verification of deployed bytecode.
- No non-public material, no vendor questionnaire response, and no privileged communication was used.
- Audit findings are reported exactly as the auditor classified and resolved them; no severity has been re-rated here.
- Where a control is undocumented publicly, this paper says so rather than assuming it exists.