Polymarket can predict the future. So how did it miss this hack? artwork

Polymarket can predict the future. So how did it miss this hack?

Smashing Security

July 1, 2026

Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer.
Speakers: Quentyn Taylor, Graham Cluley
**Quentyn Taylor** (0:03)
Well, permanent means permanent.

**Graham Cluley** (0:05)
You would think so.

**Quentyn Taylor** (0:06)
So surely you could take the bet, but you could never pay out.

**Graham Cluley** (0:08)
No.

**Quentyn Taylor** (0:09)
You'd have to wait till the heat death of the universe before you could pay out.

**SPEAKER_3** (0:23)
Smashing Security, Episode 474, Polymarket Can Predict the Future. So how did it miss this hack? With Graham Cluley and special guest Quentyn Taylor.

**Graham Cluley** (0:34)
Hello, hello, and welcome to Smashing Security, Episode 474 My name's Graham Cluley.

**Quentyn Taylor** (0:39)
And I'm Quentyn Taylor.

**Graham Cluley** (0:40)
Quentyn, welcome to the show. First time on Smashing Security. Great to have you here.

**Quentyn Taylor** (0:45)
No, thank you for having me. I am doing the representation for all the people called Quentyn, of which there aren't many.

**Graham Cluley** (0:51)
Well, there aren't many. I don't think there's been anybody with the letter Q ever on Smashing Security at all. So you are the Q of Cybersecurity, aren't you?

**Quentyn Taylor** (0:59)
Indeed, indeed. There's a nickname that I pretty much go by because no one can spell my name. So I answer to many things, Q being one of them.

**Graham Cluley** (1:07)
Yeah. So aside from potentially being the person who can give us a spy gadgetry and the likes of that, why else might people know you? You've got a pretty important job at a big company, haven't you?

**Quentyn Taylor** (1:19)
Yeah, sure. I look after information security at Canon. I've been there for quite some time now.
I know in this world of everyone leaving and changing jobs every three to five years, I've been in Canon for 25 years, which is really unusual to be in a similar role. And now I head up information security. I also now, which is really weird, I head up product security, and I also head up global response as well. So having product security and cyber security under the same hat, I think it's unique in Canon. But I do think, though, that this will be the way that information security teams of the future will be formed. I think we're kind of setting a trend here. I think this is the way things will work in the future.

**Graham Cluley** (2:01)
And what's the benefit of that, do you think?

**Quentyn Taylor** (2:02)
Well, it means, especially given the fact that we're thinking about the products that we have, and obviously this isn't sponsored, but obviously we've got the camera side, we've got the CCTV side, we've got medical as well, but that's somebody slightly different. And then we've also got the printer side, and the office and the scanner, so all the stuff that goes into the office. So we both use our own products, which means I have to secure our own product, which means I can then be the best person to suggest to our customers how to secure it, because we've also had to do it ourselves.

**Graham Cluley** (2:28)
Yes.

**Quentyn Taylor** (2:28)
So we can turn around and go, not only do I recommend that this is the way you harden it, I can also demonstrate that that hardening guide is very, very, very similar to our internal hardening guide. And the first version of the hardening guide that we wrote for customers, we didn't write for customers, we wrote for ourselves and then gave to customers. And that's kind of how product security started, because we were doing testing internally, because we had to for our own deployment. Yes. And then people say, well, could we give that to a customer? And I went, of course we can.

**Graham Cluley** (2:53)
Yeah.

**Quentyn Taylor** (2:54)
I mean, this is us proving that the product's good, the product's solid enough to work inside our network, so it's good enough for their network as well.

**Graham Cluley** (3:00)
And of course, you meant you could give feedback as well to your own product team when they're building the cameras, the printers, the scanners and so forth.

**Quentyn Taylor** (3:07)
Now that's actually part of what we do. In the past, it was very much ad hoc and we would pass in tidbits through. And now it's actually a proper defined process that we sit down and we say, right, well, we tested this. This is what we think about in our market and this is how we would improve it. And a great example of that is things like ubiquitous encryption on the device, on the printer device. That used to be an option and now it's just there by default.

**Graham Cluley** (3:30)
Oh, fantastic.

**Quentyn Taylor** (3:31)
Disabling access to certain things that were good from an engineering perspective, but really just opened up an attack surface that we didn't think should be there. Well, that was a change that we and several other people pushed for simultaneously and said, no, just just make this change.

34 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000774767620