Report: Polymarket Ignored Warnings During $10M Fraud Attack

1 hour ago 18

Bad actors targeted Polymarket’s U.S. platform in a $10 million fraud scheme using stolen debit cards, pushing payment processor Checkout.com to reject over 80% of deposits as fraudulent.

Key Takeaways

  • Polymarket faced a $10 million stolen debit card attack in February 2026 as executives prioritized growth over risk.
  • Payment processor Checkout.com rejected over 80% of deposits, exposing compliance flaws across prediction markets.
  • The CFTC is probing the platform as it hires former FBI and Amazon leaders to pursue a $1 billion funding round.

High Rejection Rates Trigger Payment Processor Crackdown

Prediction-market startup Polymarket faces accusations of prioritizing user expansion and aggressive growth over compliance safeguards when bad actors targeted its U.S. platform in an attempt to siphon off at least $10 million using stolen debit cards.

Attackers linked stolen payment cards to accounts, placed bets, and attempted to withdraw cash to clean accounts or separate cards under their control. In one instance, a single user account made roughly 4,000 separate deposit attempts.

The surge in illicit activity prompted automated intervention by payment processor Checkout.com, which began rejecting deposits. At the height of the crisis, Checkout.com rejected more than 80% of Polymarket’s processed deposits as fraudulent, far exceeding standard industry fraud levels of roughly 1%.

According to a Wall Street Journal report, Polymarket employees raised urgent red flags with CEO Shayne Coplan as the payment rejections mounted. Rather than slowing operations to shore up anti-money laundering controls, Coplan reportedly instructed compliance staff to focus on growth, suggesting the firm could simply pay a fine if regulators ever intervened.

Executives then removed a standard fraud-prevention policy requiring withdrawals to be returned to the same payment source used for deposits. Despite staff warnings that dropping the restriction invited money laundering, the rule change proceeded.

The incident triggered the departure of the platform’s senior risk leadership, including U.S. Chief Compliance Officer Andrew Clifford, who resigned in April after submitting a formal memo outlining compliance deficiencies. Justin Hertzberg, CEO of Polymarket US, was terminated, while the heads of U.S. regulation and anti-money laundering also left the company.

Security Flaws and Investigations

The February debit card attack was accompanied by additional security lapses later in the year. In June, hackers exploited a third-party vendor to inject malicious code into Polymarket’s website, directly compromising certain user balances. A month later, a flaw in account registration allowed attackers armed with stolen personal data to breach nearly 500 existing accounts without login passwords. Polymarket later agreed to reimburse affected users.

Federal authorities are increasing pressure on the platform. The Commodity Futures Trading Commission (CFTC) has launched an investigation, instructing employees to preserve records tied to the fraud attacks and internal compliance handling. Polymarket also faces inquiries into its marketing practices from the New York City Council, alongside lawsuits in more than a dozen states alleging it operates as an unlicensed gambling enterprise.

Polymarket maintained that its internal controls eventually contained the problem. By May, after capping the number of debit cards a single user could attach to an account, the company brought fraud rates down to industry averages. A subsequent investigation by law firm Sullivan & Cromwell concluded the company complied with applicable rules.

In a public statement, a Polymarket spokesperson defended the platform’s protocols: “Our market integrity framework includes processes to detect, review, and respond to suspicious activity. Polymarket remains committed to maintaining accurate, fair, and transparent markets while cooperating fully with regulators and law enforcement.”

To reinforce internal governance, Polymarket hired former FBI agent Shauna Batista to lead its investigative arm, brought on former Amazon CFO Warren Jenson, and appointed former Uber executive Travis Vanderzanden as chief growth officer.

The regulatory scrutiny comes as Polymarket seeks to raise $1 billion in funding at a $21 billion valuation, led in part by a $300 million commitment from Donald Trump Jr.’s 1789 Capital, as it lays the groundwork for a potential initial public offering.

Read Entire Article