Polymarket Temperature Hacker: Hair Dryer Player Earns $34,000 Through Physical Attack
A trader allegedly used a portable heat source (believed by meteorologists to be a hair dryer) near Charles de Gaulle Airport in Paris to briefly heat Météo France's outdoor temperature sensor, causing readings to spike several degrees Celsius in a very short time. This allowed the trader to manipulate the "Paris Daily Maximum Temperature" prediction market on Polymarket twice, earning a total profit of approximately $34,000. Reports indicate that on April 6 and April 15, isolated high-temperature spikes were recorded at the automatic station near the airport runway, with temperatures rising from about 16–18°C to 22–22.5°C within minutes before dropping back, while surrounding weather stations did not record similar occurrences. Météo France has filed a criminal complaint with the airport gendarmerie regarding the "tampering with data processing system operations."
According to an analysis of on-chain and trading data, the trader had previously bought a large number of contracts at extremely low prices for temperature ranges deemed almost impossible by the market (such as the 21–22°C range) on Polymarket. They then implemented a physical intervention near the sensor, causing that range to become the officially recorded maximum temperature, triggering payouts of over $14,000 and $20,000. After the incident was exposed, Polymarket switched the temperature settlement data source from Charles de Gaulle Airport to Paris-Le Bourget Airport and stated in the community that there would be no refunds for settled markets, emphasizing that "manipulating airport weather data is a serious crime."
Source: Public Information
ABAB AI Insight
This incident of manipulating a weather sensor with a hair dryer is essentially a real-world case of "physical attacks on on-chain markets": the attacker did not compromise smart contracts or hack oracles, but chose to intervene at the intersection of data sources and the real world. Oracles have never been purely a technical issue, but rather a systemic issue of "who do you trust, which sensor do you trust"—when the entire market entrusts the pricing power of Paris's maximum temperature to an isolated, almost unmonitored airport probe, it effectively hands over the settlement rights of hundreds of thousands of dollars to anyone who can approach that probe and is willing to take legal risks.
Structurally, Polymarket's design choice—to use a single Météo France station as the settlement source—greatly simplifies market rules but also creates a single point of failure; from a data governance perspective, this is a typical case of "convenience outweighing security." Once the scale of high-frequency weather betting expands, this "single sensor pricing" model inevitably creates attack surfaces: physical interference, internal tampering, or data delays can create arbitrage opportunities. Conversely, if a multi-site weighted approach, anomaly detection, or manual verification were adopted, although it would sacrifice some real-time responsiveness and simplicity, it could significantly increase the cost and uncertainty of such physical attacks.
This incident also serves as a warning to all "real-world assets" and prediction markets: when financial products reference real-world data for settlement, attackers will prioritize finding the "most vulnerable data sources," rather than the most complex smart contracts. Airport weather stations, sports referee record terminals, election vote counting public interfaces, and off-chain custody systems will become more attractive targets than on-chain contracts when asset scales are large enough. In other words, DeFi and on-chain markets are forcing traditional infrastructures (such as weather systems, sports leagues, election management agencies) to bear adversarial security pressures they have never faced before.
From a longer historical perspective, this incident marks a significant point in the "oracle problem" entering the realms of real politics and criminal justice. In the past, "oracle attacks" were more commonly discussed in white papers and technical discussions, but now they have become criminal cases reported by Météo France and filed by airport gendarmerie. As the scale of on-chain markets pricing real-world events continues to rise, the question of who has the authority to define "official truth" and who operates and protects "the interface of truth" will no longer be an internal structural issue for technical teams, but will evolve into a long-term game of data sovereignty and responsibility boundaries between traditional institutions, regulators, and the crypto market.