Spheric News Blog Crypto Polymarket hit by alleged $10M stolen-card fraud
Crypto

Polymarket hit by alleged $10M stolen-card fraud



Polymarket has come under renewed scrutiny after a Sept. 19 report said fraudsters used stolen debit cards on its U.S. platform in February to attempt at least $10 million in illicit withdrawals and wagers.

Summary

  • Polymarket reportedly faced at least $10 million in attempted stolen-card fraud during February this year.
  • Checkout.com reportedly rejected more than 80% of Polymarket US deposits as fraudulent during February’s peak.
  • Polymarket says fraud rates later returned to industry norms after stronger card controls were introduced.
  • Polymarket US operates through QCX, a CFTC-designated contract market subject to federal derivatives oversight today.
  • Polymarket recently hired Warren Jenson as CFO while expanding compliance, investigations and risk management staffing.

The Wall Street Journal reported that criminals connected stolen cards to thousands of Polymarket US accounts, funded them and then tried to move the money through trading before withdrawing it to cards or accounts they controlled.

Polymarket reportedly saw fraud rejection rates top 80%

At the peak of the February attack, payment processor Checkout.com rejected more than 80% of deposits it handled for Polymarket as fraudulent, according to the Journal. The newspaper compared that rate with an industry level of roughly 1%.

The 80% figure has not been independently confirmed by Checkout.com in a public statement reviewed for this report. Checkout.com does provide merchants with fraud-scoring, transaction-filtering and authentication tools, while its current service terms state that merchants remain responsible for deciding whether transactions are accepted or canceled.

Current and former employees told the Journal that compliance workers escalated concerns about the surge to Polymarket CEO Shayne Coplan. According to people cited by the newspaper, Coplan responded: “Just keep growing and pay a fine if regulators ever find out.”

Polymarket has not publicly confirmed that Coplan made the remark. The company told the Journal that it maintains procedures to identify and respond to suspicious activity and remains committed to cooperating with regulators and law enforcement.

The $10 million figure represents the amount fraudsters allegedly tried to move, not a confirmed loss suffered by customers or Polymarket. Public reporting reviewed for this article does not provide a final amount successfully withdrawn through the February scheme.

Card restrictions helped bring fraud rates down by May

The Journal reported that elevated fraud continued for several months after February, though rejection rates did not return to the peak recorded during the first wave. By May, fraud rates had reportedly moved back toward normal industry levels after Polymarket limited how many debit cards users could connect to their accounts and brought in Riskified as an outside antifraud provider.

An earlier report from The Information had separately described prediction-market operators, including Polymarket, strengthening card-fraud controls after criminals used stolen payment credentials and fake identities to create accounts. Visa reportedly pushed payment processors to tighten screening as disputed transactions increased.

Riskified provides automated fraud-decision systems used to identify suspicious card activity before merchants approve transactions. Public material from the company describes its service as combining machine-learning risk scoring with merchant transaction controls, but Riskified has not publicly disclosed Polymarket-specific fraud numbers.

The Journal further reported that Polymarket initially required some withdrawals to return to the same payment source that had funded an account. The platform later loosened that restriction, according to the report, which cited employees who raised concerns about financial-crime risks.

Polymarket’s current U.S. rulebook gives the exchange authority to restrict accounts, place customers into liquidation-only status and take other steps to protect customers and market integrity. The CFTC filing containing the March 20 version was certified in April.

Polymarket US operates under CFTC-regulated QCX

Polymarket US is legally separate from the company’s international blockchain-based prediction market.

The Commodity Futures Trading Commission’s current register lists QCX LLC, doing business as Polymarket US, as a designated contract market. QCX received its designation in July 2025 before operating under the Polymarket US name.

As previously explained in Polymarket’s two-platform structure, U.S. customers trade through the federally regulated exchange, while the international product uses separate blockchain infrastructure and access rules.

The regulatory status differs from Polymarket’s position in 2022, when the CFTC ordered the company to pay a $1.4 million civil penalty for offering event-based binary options without operating through a registered market. The settlement required Polymarket to wind down noncompliant markets and cease the violations cited in the order.

The Journal reported that the CFTC is now investigating issues connected with Polymarket and that employees were instructed to preserve documents involving the February fraud incident and other matters.

No new public CFTC enforcement release specifically addressing the February stolen-card episode was located as of Sept. 20. The reported investigation should therefore be treated as an ongoing inquiry described by the Journal, not a finding that Polymarket violated federal law.

Separate congressional scrutiny was already underway. On May 22, the House Committee on Oversight and Government Reform requested records from Polymarket concerning identity verification, suspicious activity, geographic restrictions and referrals to U.S. authorities.

The committee specifically requested documents showing the number and disposition of suspicious-activity referrals since Jan. 1, 2024. That inquiry centered on insider trading and sensitive information, not the stolen-card scheme reported this weekend.

Polymarket has expanded investigations and finance teams

Since the February incident, Polymarket has built out its internal investigation and management functions. Shana Bautista, a former FBI investigator, joined as global head of investigations and intelligence. Reuters reported in August that the company uses blockchain analytics, machine learning and trading surveillance to identify anomalous behavior.

Polymarket’s own market-integrity page says the company has referred more than 90 accounts to law enforcement and supplied authorities with details involving more than 315 wallets. The figures are company-reported and do not relate exclusively to payment-card fraud.

Federal authorities have publicly acknowledged cooperation in at least one separate case. In April, the U.S. Attorney’s Office for the Southern District of New York said Polymarket cooperated with investigators in the case of an Army service member accused of using classified information to trade event contracts.

The CFTC filed a parallel insider-trading complaint alleging that the defendant earned more than $404,000 trading a market related to the capture of Nicolás Maduro. The case remains separate from the February payment-card allegations.

Polymarket added another senior executive on Sept. 10 when it named Warren Jenson its first chief financial officer. The CFO appointment, Jenson previously served in senior finance roles at Amazon, Electronic Arts, Delta Air Lines and Nielsen.

The company said Jenson will oversee finance, capital strategy and long-range planning. Polymarket did not announce an IPO timetable when it appointed him, although the Journal reported that the company is preparing itself for a potential public listing.

Polymarket has been raising large amounts of private capital in parallel. ICE, the parent of the New York Stock Exchange, disclosed a further $600 million cash investment in March after investing $1 billion in 2025.

As recent Polymarket funding coverage reported, the company has separately been seeking roughly $1 billion in new capital at a valuation near $21 billion. The financing has not been presented by Polymarket as a formal IPO filing.

Separate security incidents added pressure during 2026

Payment fraud has not been the company’s only security issue this year. In June, Polymarket confirmed that a compromised third-party vendor injected malicious code into its frontend for some users. The company said it removed the affected dependency, contained the incident and would reimburse affected customers.

Blockchain investigators later estimated losses at roughly $3.1 million across 11 wallets. AMLBot said stolen assets were moved from Polygon to Ethereum after the malicious activity.

The June event was technically separate from the February stolen-card activity. It involved compromised web infrastructure and wallet interactions, while the earlier scheme reportedly relied on stolen debit-card credentials and account funding.

The Journal reported another account-security episode in July involving nearly 500 users. According to its account, attackers used stolen personal information to access existing accounts and linked payment methods through an engineering weakness. Polymarket reportedly agreed to cover affected losses.

No public Polymarket notice reviewed for this report provides an independently confirmed loss total from that July incident.

The company’s current position is that its fraud controls have been strengthened and that it works with law enforcement on suspicious activity. The Journal’s report says February’s payment-fraud rate had returned to industry norms by May after debit-card restrictions and the Riskified deployment.



Source link

Exit mobile version