Fraudsters attempted to steal at least $10 million from Polymarket's U.S. platform in February by making bets with stolen debit cards, then withdrawing winnings to clean accounts, according to a Wall Street Journal investigation published Saturday. The platform's payment processor, Checkout.com, rejected over 80% of Polymarket US deposits at one point as fraudulent — roughly 80 times the industry standard of 1% — and alerted the firm to the attack. Around seven users were responsible for most of the attempted theft, with one reportedly trying approximately 4,000 separate deposits. The WSJ report did not establish how much money was actually stolen, though one person cited stated most attempted deposits failed.

Polymarket CEO Shayne Coplan reportedly downplayed the incident to compliance staff and told employees to focus on growth now and deal with regulatory fines later. That directive came as the firm faced a backlog of legitimate withdrawal requests from users, overwhelming compliance teams. In response, Polymarket's leadership dropped a safeguard requiring that funds deposited from one payment source be withdrawn to the same source — a rule commonplace at financial institutions to prevent money laundering, though not a regulatory requirement for prediction markets. In a separate July attack, hackers reportedly compromised nearly 500 user accounts using stolen Social Security numbers and other personal information, without needing usernames or passwords. Polymarket told the Journal it has since strengthened infrastructure and leadership, and an internal investigation by law firm Sullivan & Cromwell concluded the firm had complied with regulations.

This matters because it exposes operational risk at prediction markets and raises questions about the viability of compliant platforms under pressure to scale. Polymarket's U.S. platform began admitting users off its waitlist months before the February fraud wave, suggesting Know Your Customer and anti-fraud controls were not built to handle volume. The decision to remove withdrawal safeguards to clear a backlog — while understandable operationally — creates a gap that sophisticated actors will exploit. The June report from The Information that Visa instructed Checkout.com to curb fraudulent Polymarket payments indicates the problem persisted for months and involved card network scrutiny, not just internal compliance flags. For traders, this is sector context: prediction markets face the same fraud and compliance headwinds as any fintech ramp, and growth-at-all-costs strategies invite both operational blowups and regulatory scrutiny.

Watch whether Polymarket faces enforcement action from regulators in the coming quarter. The Journal cited Coplan telling staff to "worry about fines later" — that framing, if accurate, gives regulators a clear narrative of willful non-compliance. Sullivan & Cromwell's internal finding that the firm complied with regulations does not immunize Polymarket from external enforcement, particularly if examiners conclude that dropping the withdrawal safeguard or the CEO's public statements indicate a pattern of prioritizing growth over controls. The next signal is whether Checkout.com or other payment partners publicly distance themselves or impose additional restrictions — payment processor risk is the choke point for every U.S. crypto on-ramp.

Source: The Block