Polymarket Fraud Attempt: Stolen Cards Used in  Million U.S. Attack

Polymarket Fraud Attempt: Stolen Cards Used in $10 Million U.S. Attack


For several weeks in February, more than 80% of deposits being processed for Polymarket’s U.S. platform were flagged as fraudulent.

A Wall Street Journal investigation published this week found that fraudsters linked stolen debit cards to thousands of Polymarket accounts, funded them and placed wagers before attempting to withdraw the money. The attempted transactions totaled at least $10 million, according to people familiar with the activity cited by the Journal. That is attempted fraudulent volume, not $10 million that Polymarket or its users necessarily lost.

“Fraudsters linked stolen debit cards to thousands of accounts in February and attempted to steal at least $10 million. At one point, payment processor Checkout.com rejected more than 80% of deposits it handled as fraudulent, compared with industry rates of roughly 1%,” according to The Wall Street Journal‘s investigation.

The Wall Street Journal reports that Polymarket responded to the February fraud wave by restricting the number of debit cards that could be linked to an account and bringing in Riskified, after which fraud rates moved back toward normal levels.

What Employees Reportedly Raised

The more consequential allegation in the Journal’s reporting concerns what happened inside Polymarket as the problem developed.

The Wall Street Journal reported that current and former employees told the paper compliance staff raised concerns with CEO Shayne Coplan, who responded that the company should continue growing and could pay a regulatory fine if one resulted. The claim comes from people familiar with the discussions and is not an independently established statement from Polymarket.

That distinction matters because the fraud itself was an attack on the platform. The governance question is whether Polymarket’s controls were allowed to lag behind its expansion.

Three Different Security Problems

The February card-fraud operation should not be confused with two other incidents disclosed this year.

“This morning we discovered a 3rd party vendor had been compromised, injecting a malicious script into our frontend for some users. We’ve contained it & removed the affected dependency. We’re contacting impacted users & refunding them in full,” Polymarket said. TechCrunch reported that the company confirmed hackers had stolen funds from users following the third-party breach.

Then in July, an engineering flaw reportedly exposed nearly 500 users to potential account takeovers. The Journal reported that attackers could use stolen personal information to access existing accounts and linked payment methods, with Polymarket agreeing to cover affected users’ losses.

Those incidents had different causes. The February episode involved fraudulent deposits and stolen cards; the June incident involved a compromised third-party vendor; the July problem involved an engineering flaw affecting account security.

Incident Cause / Vector Scale & Impact Mitigation / Outcome
February 2026 (Payment Fraud) Stolen debit cards linked to thousands of accounts; wagers placed to launder funds before withdrawal. $10M+ in attempted transactions. Processor rejected >80% of deposits as fraudulent at peak. Restricted debit card links per account and onboarded risk vendor Riskified; fraud rates normalized by May.
June 2026 (Supply Chain Compromise) Third-party vendor compromised, injecting malicious code into Polymarket’s website for select users. ~$3.1M stolen directly from affected user wallets. Isolated dependencies, contained the breach, and promised full refunds to impacted users.
July 2026 (Account Takeover Vulnerability) Engineering flaw allowed attackers to leverage stolen PII to access existing accounts and linked payment methods. ~500 users exposed to potential account takeovers. Patched the flaw and committed to covering affected users’ losses.

Why The Timing Matters

The problems arrived as Polymarket was trying to scale its U.S. business and raise as much as $1 billion at a valuation of about $21 billion, according to the Journal. That puts its compliance and security systems under a different level of scrutiny than they faced when the company was smaller.

“Chairman James Comer today opened an investigation into how users of prediction market platforms Polymarket and Kalshi potentially are using nonpublic information to engage in insider trading,” the House Oversight Committee said. Its letters sought information about identity verification, geographic restrictions and how the platforms detect anomalous trading activity.

The committee’s inquiry is separate from the February payment-fraud episode, but it adds to the scrutiny around how quickly these platforms are building safeguards as their U.S. operations expand.

Polymarket’s fraud problem therefore has two distinct stories inside it. One is straightforward: fraudsters found weaknesses in the platform’s payment controls and tried to exploit them at scale. The other, based on the Journal’s reporting, is about whether management was willing to accept compliance risk while pursuing faster growth.



Source link

Posted in

Liam Redmond

As an editor at Forbes Europe, I specialize in exploring business innovations and entrepreneurial success stories. My passion lies in delivering impactful content that resonates with readers and sparks meaningful conversations.

Leave a Comment