Polymarket Faced $10M Stolen-Card Fraud Attempt, Journal Reported
The Wall Street Journal reported that fraudsters used stolen debit cards on Polymarket US in February to attempt at least $10 million in illicit moves, with Checkout.com rejecting over 80 percent of deposits at the peak.

15 Broad Street in the Financial District of Manhattan, New York, across from the New York Stock Exchange. Photo: Arild Vagen via Wikimedia Commons (CC BY-SA 4.0). Source
Polymarket faced an attempted theft of at least $10 million through stolen debit cards on its U.S. platform in February, the Wall Street Journal reported on Sept. 19. Criminals linked stolen cards to thousands of Polymarket US accounts, funded them and tried to move the money through trading before withdrawing it, according to the detailed account crypto.news published Sept. 20.
"Just keep growing and pay a fine if regulators ever find out." That is what chief executive Shayne Coplan answered when compliance workers escalated their concerns about the surge, current and former employees told the newspaper. Polymarket has not publicly confirmed that Coplan made the remark. The company told the newspaper it maintains procedures to identify and respond to suspicious activity and remains committed to cooperating with regulators and law enforcement.
At the peak of the February attack, payment processor Checkout.com rejected more than 80 percent of the deposits it handled for Polymarket as fraudulent. The newspaper compared that rate with an industry level of roughly 1 percent. The 80 percent figure has not been independently confirmed by Checkout.com in a public statement, and the $10 million figure represents the amount the fraudsters tried to move, not a confirmed loss suffered by customers or the company. Public reporting does not give a final amount successfully withdrawn through the scheme.
The high fraud levels did not clear up in days. Rejection rates stayed high for months after the first wave, though they did not return to the February peak. By May the rates had moved back toward normal industry levels, after Polymarket limited how many debit cards users could connect to their accounts and brought in Riskified as an outside antifraud provider. The Information had separately described prediction-market operators strengthening card-fraud controls, and Visa pushed processors to tighten screening as disputes rose.
A loosened withdrawal rule
Polymarket had initially required some withdrawals to return to the same payment source that funded an account. The platform later loosened that restriction, according to the newspaper account, which cited employees who raised concerns about financial-crime risks. The current U.S. rulebook gives the exchange authority to restrict accounts, place customers into liquidation-only status and take other steps to protect customers and market integrity.
The company has since built out its internal investigation team under Shana Bautista, a former FBI investigator who joined as global head of investigations and intelligence. Reuters reported in August that the company uses blockchain analytics, machine learning and trading surveillance to spot anomalous behavior. Its market-integrity page lists more than 90 accounts referred to law enforcement and details on more than 315 wallets, though those company-reported figures cover more than payment-card fraud.
Federal authorities have publicly acknowledged cooperation in at least one separate case. In April, the U.S. Attorney's Office for the Southern District of New York said Polymarket cooperated with investigators in the case of an Army service member accused of using classified information to trade event contracts. The CFTC filed a parallel insider-trading complaint alleging the defendant earned more than $404,000 trading a market tied to the capture of Nicolas Maduro. That case stands apart from the February payment-card allegations.
A regulated U.S. venue
Polymarket US is legally separate from the company international blockchain-based prediction market. The Commodity Futures Trading Commission register lists QCX LLC, doing business as Polymarket US, as a designated contract market, with the designation dated July 9, 2025 and a remark that the company now operates under the assumed name, the filing shows. U.S. customers trade through the federally regulated exchange, while the international product uses separate infrastructure and access rules.
The regulatory status differs from where the company stood in 2022. The CFTC then ordered Blockratize Inc., doing business as Polymarket, to pay a $1.4 million civil penalty for offering event-based binary options without operating through a registered market. The settlement required the company to wind down noncompliant markets and cease the violations cited in the order.
The newspaper reported that the CFTC is now investigating issues connected with Polymarket and that employees were instructed to preserve documents involving the February fraud incident and other matters. No new public CFTC enforcement release addressing the February episode had appeared as of Sept. 20, so the reported investigation should be read as an ongoing inquiry rather than a finding that the company broke federal law.
Separate congressional scrutiny was already underway. On May 22, the House Committee on Oversight and Government Reform requested records from Polymarket concerning identity verification, suspicious activity, geographic restrictions and referrals to U.S. authorities. The committee asked for documents showing the number and handling of suspicious-activity referrals since Jan. 1, 2024. That inquiry centered on insider trading and sensitive information, not the stolen-card scheme reported this weekend.
Payment fraud was not the company's only security problem this year. In June, Polymarket confirmed that a compromised third-party vendor injected malicious code into its frontend for some users. The company said it removed the affected dependency, contained the incident and would reimburse affected customers. Blockchain investigators later estimated losses at roughly $3.1 million across 11 wallets, with stolen assets moved from Polygon to Ethereum after the malicious activity.
The newspaper also described an account-security episode in July involving nearly 500 users. Attackers used stolen personal information to access existing accounts and linked payment methods through an engineering weakness, according to the u.today summary of the report. Polymarket agreed to cover affected losses.
The company has added senior executives while dealing with the fallout. On Sept. 10 it named Warren Jenson its first chief financial officer. Jenson previously held senior finance roles at Amazon, Electronic Arts, Delta Air Lines and Nielsen, and the company said he will oversee finance, capital strategy and long-range planning. No IPO timetable was announced, though the newspaper reported the company is preparing itself for a potential public listing. ICE, the parent of the New York Stock Exchange, disclosed a further $600 million cash investment in March after investing $1 billion in 2025, and the company has separately been seeking roughly $1 billion in new capital at a valuation near $21 billion. That financing has not been presented as a formal IPO filing, and the company position remains that its fraud controls have been strengthened and that it works with law enforcement on suspicious activity.