~35% · $280K/day
Will a ransomware attack cause a US critical infrastructure outage lasting 24h+ in 2026?
Colonial Pipeline-scale attack — $580K/day during incidents
Macro Prediction Markets
Infrastructure ransomware at 35%, federal data breach at 42%, AI malware confirmed at 58%, crypto hack $1B+ at 28%. Cybersecurity prediction markets on Polymarket price every major attack and policy scenario — compare cross-venue cyber odds in one search.
~35% · $280K/day
Colonial Pipeline-scale attack — $580K/day during incidents
~42% · $220K/day
OPM/SolarWinds precedent — nation-state threat persistent
~58% · $180K/day
AI offensive capability market — frontier concern
~28% · $240K/day
Bybit $1.5B hack in 2025 reset expectations
~18% · $160K/day
ADPPA momentum stalled — still possible
The forces behind the attack and policy markets — each reprices on a major incident or regulatory move.
DPRK (Lazarus), Russia, and China APTs drive the largest hacks — the $1.5B Bybit theft reset the crypto-hack market.
LLMs lower the bar for novel malware and phishing; the AI-malware-confirmed market sits near 58%.
Ransomware-as-a-service keeps critical-infrastructure outages a persistent base-rate risk.
Breach-notification rules and the long-run quantum threat to RSA shape the policy and tail-risk markets.
Politics
DPRK Lazarus Group — state-sponsored crypto hacking
AI
The RSA-2048 "Q-Day" tail — the long-run cryptography threat
AI
AI-powered cyberattacks connect to AI capability timeline
Active cybersecurity prediction markets include: critical infrastructure ransomware outage (~35%), federal data breach at scale (~42%), AI-generated malware confirmed in the wild (~58%), major crypto exchange hack above $1B (~28%), and US federal data privacy legislation (~18%). These markets are highly correlated with actual cyber incident news — a major attack can move prediction market prices significantly on Polymarket within hours.
Prediction markets price major security vendors publishing confirmed evidence of AI-generated malware at ~58% in 2026. The concern: AI tools (including LLMs) can be used to write novel malware variants that evade signature-based detection. CrowdStrike, Microsoft Security, and other vendors track this actively. The 58% probability reflects that AI-assisted cyberattacks are already occurring — the market question is whether vendors will confirm sophisticated AI-generated (not just AI-assisted) campaigns.
The $1.5B Bybit hack in 2025 was the largest crypto theft in history, executed by North Korean state hackers (Lazarus Group). This reset prediction market expectations for 2026 crypto exchange hacks — the probability of a $1B+ hack rose from ~15% to ~28% after Bybit, reflecting that state-sponsored actors now have proven capabilities at this scale. Mantis tracks crypto security markets alongside exchange price markets.
Yes. Active US cyber policy prediction markets include: CISA budget changes, federal data privacy law passage (~18%), mandatory breach notification timeline changes, and National Cyber Director authority expansion. These policy markets are less liquid than attack probability markets but are actively traded on Kalshi (regulatory outcomes are Kalshi's specialty). Mantis aggregates all venues.
The long-run tail risk is "Q-Day" — a quantum computer powerful enough to break RSA-2048 encryption, which underpins much of today’s security. Prediction markets price that at only ~2-3% for 2026 (see the Quantum Computing hub), but it drives the post-quantum cryptography migration narrative. The cybersecurity and quantum hubs are two views of the same threat horizon, and Mantis cross-links them.
The $1.5B Bybit theft (DPRK’s Lazarus Group) proved state actors can execute nine-figure-plus crypto heists, so the market’s prior for a $1B+ hack in 2026 jumped from ~15% to ~28%. It linked the cybersecurity hub tightly to the North Korea hub (the attacker) and crypto-exchange security broadly. Mantis tracks the cyber, NK, and crypto hubs together to capture that chain.