security
Polymarket Bot Security: How Traders Lose Funds to Bots, and How to Avoid It (2026)
Real 2026 incidents (key-stealing GitHub bots, fake npm packages, a $230K custodial bot loss) and a practical checklist for running any Polymarket trading bot safely: custody models, dedicated wallets, session keys and code review.
The fastest way to lose money with a Polymarket bot isn't a bad trade. It's handing your wallet to the wrong code or the wrong company. In 2026 alone, security researchers documented trading-bot repositories on GitHub that steal private keys, fake npm packages that pose as Polymarket tools, and a Telegram copy-trading bot that reported about $230,000 of user funds lost.
This guide covers what happened, the three custody models every bot uses, and a checklist you can apply to any tool, including ours.
What actually happened in 2026
1. A "copy-trading bot" on GitHub that steals keys
In March 2026, StepSecurity reported that a hijacked, verified GitHub organisation was distributing a polished Polymarket copy-trading bot with hundreds of stars. The bot really did connect to Polymarket's APIs and trade. Hidden in its npm dependencies were two typosquatted packages (ts-bign, big-nunber) that sent the user's .env file, including the wallet private key, to attacker servers. They also opened an SSH backdoor on the machine. The researchers found 20+ similar repositories with slight name variations and star counts inflated by bot accounts (StepSecurity).
Lesson: stars, a verified badge and working code prove nothing. The malware ran during npm install, before the bot even started.
2. Fake Polymarket packages on npm
In May 2026, SafeDep found nine npm packages published within 30 seconds by one account, with names like polymarket-bot, polymarket-copy-trading, polymarket-terminal and polymarket-claude-code. On install they asked the user to "paste your wallet key — it stays encrypted" and sent it in plain text to an attacker's server. They also silently read PRIVATE_KEY from any .env file. The packages wrapped a working trading CLI, with a "paper mode by default" feature, around the theft (SafeDep).
Lesson: generic, official-sounding package names are a target. Some were aimed at people whose AI coding assistant suggests a package.
3. A custodial Telegram bot losing user funds
In January 2026, the team behind Polycule, a Telegram-based Polymarket trading bot where users deposited funds into bot-managed wallets, said it had been hacked, affecting about $230,000 of user funds. It took the bot offline and promised fixes and audits (Odaily). Polymarket said it had no relationship with the bot (OAK incident summary).
Lesson: whatever the cause, when a third party holds your funds or keys, its security failure becomes your loss.
The three custody models
Every Polymarket bot falls into one of these:
| Model | Who holds the key | Typical examples | Main risk |
|---|---|---|---|
| Custodial | The service: you deposit into its wallet | Many Telegram bots | The service is hacked, fails or disappears with your funds |
| Delegated / hosted signing | The service holds a key or signer that can trade for you | Some hosted copy-trading apps | A compromised server can trade (and sometimes withdraw) your funds |
| Self-custody, local signing | You: the bot runs on your machine and signs locally | Open-source scripts, self-hosted runners (including Ghost Trader) | Malware on your machine, or malicious code in the bot itself |
No model is risk-free. Self-custody takes away the operator risk but moves the responsibility to you and the code you run. That's why the checklist below matters most for self-hosted bots.
A practical security checklist
Before you install anything
- Find the official source. Get the bot from the vendor's own website or the repo it links to. Don't trust a search result or a Telegram DM. Check the exact spelling of the org and package name.
- Distrust star counts. In the cases above, stars were bought or botted. Look for real issue discussions, a commit history over time and maintainers with real identities.
- Read the dependency list. Look for misspelled versions of popular libraries (
big-nunber,ts-bign) and packages with no history. For npm, install withnpm install --ignore-scriptsfirst and inspect what would run. - Never paste a private key into a prompt, chat or web form that asks for it "to connect". Legitimate tools read keys from a local file or a hardware or remote signer that you control.
- Check any affiliation claim. Polymarket doesn't endorse third-party bots by default. A tool that implies it's "official" without evidence is a warning sign.
Set up a blast radius
- Use a dedicated trading wallet. Fund it with only what the bot should trade. Keep long-term savings in a different wallet, ideally a hardware wallet.
- Use scoped keys where you can. Polymarket's Session Keys (beta, for its newer Deposit Wallets) let you authorise a separate signer that can trade but cannot withdraw, for a limited time and scope (Polymarket docs). Where a tool supports something similar, use it.
- Use a separate machine or VPS. Don't run trading bots on the laptop where you keep other wallets, browser sessions and SSH keys. A small VPS or a separate user account limits what malware can reach.
- Store the key with tight permissions.
chmod 600on the key file, never commit it to git, and never put it in a shared folder.
While it runs
- Watch the network. A trading bot should only talk to Polymarket's endpoints, your RPC provider, price feeds and (for hosted dashboards) the vendor's API. Unexpected outbound connections are a red flag.
- Set limits in the bot and in the wallet. A max trade size, a daily-loss kill switch and a cap on open positions limit the damage from bugs as well as bad markets (see Kelly sizing).
- Run paper mode first. A bot that trades on paper shows you its behaviour without putting a funded key at risk.
- Review onchain activity. Your Polymarket wallet is public. Check its transfers regularly, not just the bot's own dashboard.
If you think you've been compromised
- Move funds to a fresh wallet immediately, from a clean device. Don't reuse the old key.
- Revoke Polymarket API credentials and any session keys.
- Check
~/.ssh/authorized_keysand firewall rules for changes (the March 2026 malware opened SSH). - Remove the package or repo and scan for the known malicious package names.
- Report the repo or package to GitHub or npm.
Questions to ask any bot vendor
Use these for any product, including Ghost Trader:
- Who holds my private key, and where does signing happen?
- Can your servers move or withdraw my funds? Under what circumstances?
- What do your servers store about me? Keys, API credentials, trade history?
- What happens if your service goes offline? Do my positions stay in my wallet?
- How do I verify the software I'm running is the one you shipped?
- What fees apply per trade? Builder fees show up on Polymarket orders (see fees).
- Do you enforce Polymarket's geographic restrictions? A vendor that helps you bypass them puts your account at risk (see legality and geo-restrictions).
How Ghost Trader answers them
So you can compare like for like:
- Key custody: Ghost Trader's runner runs on your own machine or server with your wallet. It signs orders locally, and the private key stays in a config file only you can read. Never share it with anyone, including us.
- Withdrawals: we never hold your funds. Positions live in your own Polymarket wallet.
- What the dashboard is for: signals, settings, status and Telegram alerts. It's designed so it doesn't need your private key.
- If we're offline: your funds and positions stay in your wallet, under your control.
- Limits: min and max trade size, open-position cap, fractional Kelly, daily-loss kill switch and max drawdown, plus paper mode.
- Restrictions: Ghost Trader isn't offered where Polymarket restricts trading, including the US.
That's a description of the design, not a guarantee. Apply the same checklist to us that you'd apply to anyone.
FAQ
Are Polymarket trading bots safe? Some are, some aren't. The risk depends on who holds your key, what code you run and how much you fund the wallet. Self-custody with a dedicated, limited wallet and reviewed code is the safest common setup.
Is it safe to clone a Polymarket bot from GitHub? Only after you've checked the source, the maintainers and the dependencies. In 2026, researchers found working Polymarket bots on GitHub that stole keys during installation.
Should I give a Telegram bot my private key? Doing so gives the bot operator full control of that wallet. If you use one, fund that wallet with only what you can afford to lose.
What's the single most important step? Use a dedicated trading wallet holding only what the bot should trade.
Ghost Trader keeps your key on your own machine. A license-locked runner signs locally, a hosted dashboard sends Telegram alerts, and paper mode lets you test before funding anything. $199/month. See pricing.
Not financial or security advice. Trading can lose money. Ghost Trader isn't available where Polymarket restricts trading, including the US, and is not affiliated with Polymarket.
This article is general information, not financial advice. Prediction markets are risky, and Polymarket isn’t available everywhere.