No polymarket or UMA contracts have been exploited. All user funds are safe, and using is safe, so business as usual.
We had a 6-year-old private key that was compromised. This was in the internal top-up config, which is why funds were being sent to it. We have rotated this key, revoked all prod permissions and are moving all PKs to KMS keys from now on.