How Did Fraudsters Target Polymarket’s U.S. Platform?

Fraudsters attempted to move at least $10 million through Polymarket’s U.S. platform using stolen debit cards in February, exposing weaknesses in payment and withdrawal controls only months after the prediction-market operator began admitting American users.The scheme involved depositing money from compromised debit cards, placing bets and then attempting to withdraw proceeds to different cards or accounts controlled by the attackers. Polymarket’s payment processor, Checkout.com, reportedly rejected more than 80% of deposits it handled at one point during the attack because they appeared fraudulent. Typical fraud levels across comparable payment activity are closer to 1%.The report did not establish how much of the attempted $10 million was successfully withdrawn. One person familiar with the incident said most attempted deposits failed, with roughly seven users responsible for most of the activity. One account reportedly attempted around 4,000 deposits.The attack arrived shortly after Polymarket began opening its U.S. platform to waitlisted users, following its return to the regulated American market through the acquisition of QCEX.CEO Shayne Coplan was reported to have told employees to prioritize growth and deal with potential regulatory fines later. Polymarket has since said it strengthened its infrastructure, risk controls and leadership team. An internal investigation conducted by law firm Sullivan & Cromwell concluded that the company complied with applicable regulations, according to people familiar with its findings.

Why Did Polymarket Change Its Withdrawal Controls?

The fraudulent deposits created a second problem by contributing to a backlog of withdrawal requests from legitimate customers and putting pressure on Polymarket’s compliance operation.Management subsequently removed a safeguard requiring customers to withdraw money through the same payment source used for the original deposit. Such controls can make stolen-card schemes harder because criminals cannot simply fund an account with a compromised card and cash out through a separate “clean” payment method.The restriction was not a specific regulatory requirement for prediction markets. Employees nevertheless reportedly warned that removing it could increase exposure to money laundering and payment fraud, while executives believed other controls were sufficient.Polymarket later limited the number of debit cards that individual users could connect to their accounts. By May, fraud rates had returned to levels closer to industry norms, according to a person familiar with the changes.

Investor Takeaway

The attempted theft matters less because of the $10 million headline than because it tested whether Polymarket’s controls were scaling as quickly as its U.S. business. That question becomes more important as the company seeks fresh capital, expands regulated operations and prepares for a possible public listing.

What Happened in the Separate July Account Attack?

The February debit-card episode was followed by a separate security incident in late July affecting nearly 500 users.Attackers reportedly discovered that stolen personal information, including Social Security numbers, could be used during account registration to gain access to an existing customer’s account without knowing the established username or password. Linked bank accounts and debit cards could then become accessible.The total amount stolen was described as relatively small, although some users reported losses running into thousands of dollars. Polymarket said it would reimburse affected customers.The two incidents involved different attack methods but point to the same operational challenge: rapid user growth can put pressure on payment controls, identity verification, product testing and customer support at the same time.Polymarket has since added experienced risk-management personnel and upgraded compliance procedures. The company is also operating inside a more closely watched U.S. prediction-market sector, where the CFTC has recently warned Polymarket, Kalshi and other regulated venues about compliance obligations.

Why Does the Timing Matter for Polymarket’s Funding and IPO Plans?

The fraud disclosures arrive while Polymarket is pursuing approximately $1 billion in financing at a valuation of around $21 billion. 1789 Capital is expected to contribute about $300 million to the funding round, following roughly $200 million it had previously invested.The company has also discussed preparing for a potential 2027 initial public offering and has expanded its executive team, including hiring former Amazon finance executive Warren Jenson as its first chief financial officer.At the same time, several senior U.S. compliance and regulatory executives have departed. U.S. chief compliance officer Andrew Clifford resigned in April after preparing a report outlining fraud concerns, while U.S. CEO Justin Hertzberg was later dismissed. Executives overseeing U.S. regulation and anti-money-laundering functions also left.Polymarket says it has continued investing in controls while expanding the business. “We are proud of our key leadership hires and continuous infrastructure upgrades and we have quickly scaled and remain focused on growing responsibly at the frontier of finance, tech, and culture,” a company spokesperson said.For investors, the next issue is whether those upgrades can keep operational risk from rising alongside valuation and transaction volume. A platform seeking a $21 billion valuation and a possible IPO will be judged not only on how quickly it can attract traders, but on whether its fraud, identity and compliance systems can handle them at scale.

Author