Polymarket Faces Alleged $10M Stolen-Card Fraud Scandal

Polymarket reportedly faced an alleged $10M stolen-debit-card fraud attempt on its U.S. platform. Reports describe elevated payment rejections, controls added with Riskified, regulatory scrutiny under the CFTC and expanded compliance hires.

.1 Comments
Polymarket Faces Alleged $10M Stolen-Card Fraud Scandal

8 Minutes

Follow on Google

Polymarket under scrutiny after reported $10 million stolen-card scheme

Polymarket, a high-profile prediction-market operator, has been thrust into renewed scrutiny after a Sept. 19 report claimed fraudsters used stolen debit-card credentials on Polymarket US in February to attempt roughly $10 million in illicit deposits, trades and withdrawals. The figure circulated in coverage describes the amount criminals allegedly tried to move through the platform — not a verified loss borne by customers or the company.

The episode raises fresh questions about payments risk, account verification and market integrity for crypto-linked prediction markets operating in both regulated and blockchain-native environments. Below, we unpack what has been reported about the incident, how Polymarket responded operationally, and the regulatory and compliance context shaping the company’s U.S. product, Polymarket US (operating under QCX).

Key takeaways

  • Media reports say fraudsters attempted at least $10 million using stolen debit cards on Polymarket US during February.
  • Checkout.com — the payments processor handling many of Polymarket’s card deposits at the time — reportedly flagged over 80% of Polymarket US deposits as fraudulent at the attack’s peak, compared with industry norms near 1%.
  • Polymarket says it implemented stronger card controls and brought in third-party anti-fraud tools; reported fraud metrics later returned toward industry norms.
  • Polymarket US trades under QCX LLC, a CFTC-designated contract market subject to U.S. federal derivatives oversight.
  • The company has expanded compliance, investigations and risk-management teams, and recently hired veteran finance executive Warren Jenson as CFO.

What the reporting says about the February fraud wave

According to the Wall Street Journal and sources it cited, fraudsters linked stolen debit cards to thousands of accounts on Polymarket US. They allegedly funded accounts with those cards, used prediction-market trades to move value through the platform, then withdrew funds back to cards or bank accounts they controlled. The amount reported — roughly $10 million — describes attempted moves, and public reporting reviewed for this analysis does not provide a final, independently verified tally of successful withdrawals or losses.

A notable detail in reporting was the claimed peak decline rate by the payments processor Checkout.com. The Journal reported that Checkout.com rejected more than 80% of Polymarket US deposits it handled in that period as fraudulent, a far higher rejection rate than typical merchant experience. Checkout.com’s public materials indicate it supplies merchants with fraud-scoring and transaction-filtering tools, while leaving final acceptance decisions to merchants under its terms. Checkout.com has not released a dedicated public statement confirming the >80% figure in the context of Polymarket.

Internal concerns and an alleged CEO remark

Current and former employees told the Journal they escalated the surge in suspicious payments to CEO Shayne Coplan. The report relayed an alleged response attributed to him — "Just keep growing and pay a fine if regulators ever find out." Polymarket has not publicly confirmed that Coplan made this remark. The company has stated it maintains procedures to detect and respond to suspicious activity and that it cooperates with law enforcement and regulators.

Operational controls implemented to curb card fraud

Following the February spike, Polymarket reportedly tightened debit-card controls and brought in a third-party anti-fraud provider, Riskified. Actions reportedly included limiting the number of debit cards a single account could connect and deploying automated risk-decision systems to screen suspicious activity before approvals. These interventions coincided with a reported fall in fraud rates toward industry norms by May.

Riskified provides machine-learning fraud scoring and merchant transaction controls aimed at reducing chargebacks and disputed transactions. While Riskified’s public materials describe the service broadly, the company has not published Polymarket-specific metrics.

Withdrawal routing and financial-crime risk

Initial steps taken by Polymarket reportedly included forcing some withdrawals to return to the same payment source that funded the account — a common payments-control approach designed to disrupt laundering paths. The Journal said Polymarket later relaxed that restriction. Internal sources cited in reporting flagged concerns that relaxing source-matching increased financial-crime risk. Polymarket’s publicly filed U.S. rulebook, certified in April, grants the exchange authority to restrict accounts, place customers into liquidation-only status and take other actions to protect customers and market integrity.

Regulatory backdrop: QCX, the CFTC and prior enforcement

Polymarket US operates through QCX LLC, a designated contract market registered with the U.S. Commodity Futures Trading Commission (CFTC). QCX received its designation in July 2025; the two-platform structure means U.S. retail customers trade through the federally regulated exchange, while international users access a separate blockchain-based product with different rules and infrastructure.

The distinction is relevant because it places Polymarket US squarely under federal derivatives oversight. The company previously settled CFTC charges in 2022 for offering noncompliant event-based binary options, paying a $1.4 million civil penalty and winding down certain markets. The Wall Street Journal further reported the CFTC is investigating matters connected with the February fraud incident; Polymarket employees were reportedly instructed to preserve documents. As of the latest reporting date, no new public enforcement release from the CFTC addressed the February stolen-card allegations specifically, so any reported investigation should be treated as an open inquiry.

Congressional interest

Congressional scrutiny has also touched Polymarket. On May 22, the House Committee on Oversight and Government Reform requested records from the firm regarding identity verification, suspicious-activity referrals, geographic restrictions and interactions with U.S. authorities. That inquiry primarily focused on insider trading and information security issues and requested data on the number and disposition of suspicious-activity reports since January 1, 2024; it was not limited to the payment-card situation reported in September.

Company response: strengthening teams and tools

Polymarket has publicly described bolstering its internal investigations, compliance and risk-management capabilities since early 2026. In that build-out, the company named Shana Bautista, a former FBI investigator, as global head of investigations and intelligence. The company says it combines blockchain analytics, machine learning and trading surveillance to detect anomalous behavior.

Polymarket’s market-integrity page reports that the company has referred more than 90 accounts to law enforcement and provided details for more than 315 wallets — figures the company has released publicly but that do not exclusively relate to payment-card fraud. Federal authorities have acknowledged cooperation in at least one unrelated case involving alleged insider trading tied to classified information; the U.S. Attorney’s Office for the Southern District of New York announced Polymarket’s cooperation in that matter.

Executive hires, capital raising and business context

Polymarket added Warren Jenson as its first chief financial officer on Sept. 10. Jenson previously held senior finance roles at major companies including Amazon, Electronic Arts, Delta Air Lines and Nielsen. The company said Jenson will oversee finance, capital strategy and long-range planning. Reports indicate Polymarket is preparing for potential future corporate milestones, including a possible public listing, though the firm has not filed any public IPO paperwork.

Funding activity has been significant: ICE, the parent company of the New York Stock Exchange, disclosed a $600 million cash investment in March following an earlier $1 billion investment in 2025. Media coverage of Polymarket’s fundraising suggested the company was seeking roughly $1 billion at a valuation near $21 billion, though such discussions had not been presented as a formal IPO filing at the time of reporting.

Other security incidents in 2026 and their fallout

Payment-card fraud was not Polymarket’s only security challenge this year. In June, the company confirmed a third-party vendor had been compromised and malicious code was injected into the frontend for certain users. Polymarket said it removed the affected dependency, contained the incident and planned to reimburse impacted customers. Blockchain investigators later estimated losses of about $3.1 million across 11 wallets tied to that incident, with AMLBot reporting that stolen funds moved from Polygon to Ethereum.

Separately, reporting also documented a July security episode affecting nearly 500 users where attackers exploited stolen personal information to access accounts and link payment methods via an engineering weakness. Polymarket reportedly agreed to cover losses for affected customers, though public statements have not produced an independently verified aggregate loss total for that event.

Implications for prediction markets and crypto payments

These incidents underline the persistent risks when traditional payment rails intersect with crypto-oriented or blockchain-native markets. Stolen-card schemes exploit weak onboarding controls, synthetic identities and gaps in transaction monitoring. Prediction markets that allow real-money trading must therefore maintain layered defenses — chargeback mitigation, strong KYC/AML, device intelligence, behavioral analytics and source-of-funds controls — to reduce both direct financial exposure and systemic market manipulation risk.

Polymarket’s experience also illustrates the trade-offs firms face when balancing rapid user growth against stringent fraud prevention. Aggressive growth strategies can increase attack surface and create incentives for bad actors to exploit scale, while overly restrictive controls can hinder legitimate user access and liquidity.

What this means for users and the broader crypto ecosystem

For users, the episode is a reminder to practice strong account hygiene: use unique, strong passwords, enable multi-factor authentication, and monitor card and bank statements closely for unauthorized activity. Platforms must also communicate clearly about payment policies, restrictions on withdrawal routing and remediation procedures if customers are impacted by fraud.

For regulators and enforcement authorities, the incident highlights the importance of cross-sector cooperation — between payments processors, crypto platforms, blockchain analytics firms and law enforcement — to trace funds, recover assets where possible and deter future schemes. It also signals that regulated U.S. platforms like Polymarket US operating under QCX will face heightened scrutiny when operational lapses or security incidents arise.

Looking ahead

Polymarket says it has tightened controls, deployed third-party fraud tools, expanded investigations staffing and is cooperating with authorities. Whether those steps materially reduce persistent payment-fraud threats will depend on continued investment in fraud detection, improvements to payments-routing controls, stronger identity verification and ongoing collaboration with payment processors and regulators.

As reporting continues and any regulatory or enforcement actions become public, the details will matter for market participants, compliance teams and investors watching fraud, AML, and operational resilience across the crypto and prediction-market landscape.

Zoya Akhtar
"I’m Zoya, and crypto is my playground. I dive deep into blockchain trends, DeFi, and how digital assets shape our future economy."

Leave a Comment

Comments (1)

coinflux

Wow this is wild, if true. Huge gap in controls, 10M attempted? Platforms gotta step up fraud defenses, like now