Polymarket faced a payment-card fraud attack involving at least $10 million as it expanded in the US this year, highlighting the tension between rapid user growth, compliance spending and platform controls. Attackers used stolen debit cards to fund accounts, place bets and attempt to move deposits and winnings to other cards or accounts they controlled.
The incident occurred several months after Polymarket opened its US platform to users on its waitlist. Its payment processor, Checkout.com, at one point rejected more than 80% of deposits processed for Polymarket US, classifying the transactions as fraudulent. The industryâs typical chargeback or fraud-identification rate during the same period was about 1%. Visa later required Checkout.com to tighten fraud controls for Polymarket-related payments, while the processor pressed the prediction-market operator to strengthen its own safeguards.
It remains unclear how much of the attempted theft ultimately left the platform. A person familiar with the matter said most of the attempted deposits failed and that the attack involved about seven users. One of them allegedly tried roughly 4,000 separate deposits. Polymarket has not disclosed its actual financial losses.
Growth priorities raised concerns inside compliance
Polymarketâs compliance team was surprised by CEO Shayne Coplanâs response to the incident. People familiar with the discussions said Coplan directed the company to prioritize growth and deal with potential regulatory fines later. A company spokesperson said Polymarket is committed to fair and transparent markets and will work with regulators and law-enforcement agencies.
The spokesperson said the companyâs market-integrity framework includes processes to identify, review and address suspicious activity. The card-fraud attack nevertheless added to a backlog of legitimate customer withdrawal requests, increasing pressure on the compliance team.
Polymarketâs management later removed a withdrawal rule intended to limit money laundering. Under the previous policy, funds deposited from a particular payment source had to be withdrawn to that same source. Prediction markets are not expressly required by law to use such a rule, but banks and other financial institutions commonly apply similar controls. When the rule was in place, funds deposited with a stolen debit card generally could not be transferred to a different, clean bank card, limiting the scope for moving the money.
Some employees warned that removing the restriction could increase the risk of money laundering and other attacks. Executives argued that the companyâs remaining rules were sufficient to reduce those activities. By May, after Polymarket introduced measures including limits on the number of debit cards users could link to their accounts, its reported fraud rate had fallen to levels common in the industry.
Executive departures accompanied US expansion
Andrew Clifford, Polymarket USâs chief compliance officer, left the company in April. Before his departure, he submitted a detailed report to management describing the fraud problems facing the business. Polymarket later dismissed its US CEO, Justin Hertzberg, while the heads of its US regulatory function and anti-money-laundering program also departed.
Law firm Sullivan & Cromwell subsequently completed an investigation. People familiar with its findings said the report concluded that Polymarket complied with applicable regulatory requirements. The company has not released the full report or disclosed all of the matters covered by the investigation.
The management changes came as Polymarket prepared for a potential initial public offering and a new financing round. The company later appointed its first chief financial officer, Warren Jenson, who served as Amazonâs CFO for about two and a half years beginning in September 1999. Since May, Polymarket has added risk-management staff and made changes to its compliance processes and product testing.
Registration flaw affected nearly 500 accounts
A separate attack in late July affected nearly 500 Polymarket users. The attackers appear to have exploited a flaw in the account-registration process. A person attempting to register with an existing customerâs personal information, including a stolen Social Security number, could apparently enter that customerâs account without knowing the original username or password. The attacker could then access linked bank accounts and debit cards.
A person familiar with the incident said the amount stolen was relatively small but did not provide a figure. Polymarketâs spokesperson said the company would cover usersâ losses. However, users interviewed about the incident and messages posted on Discord indicated that some losses reached several thousand dollars. Some requests for help sent to Polymarketâs customer service team went unanswered for weeks.
For prediction-market platforms, the consequences of the two incidents extend beyond direct financial losses. They raise questions about payment verification, account takeovers, withdrawal restrictions and the speed of customer support. As the platform expands its user base, it must show that new transactions can be screened accurately without leaving legitimate customers unable to withdraw funds for extended periods because of compliance backlogs.
CFTC scrutiny advances alongside funding plans
The US Commodity Futures Trading Commission is investigating Polymarket. A commission spokesperson previously said the agency could neither confirm nor deny whether an investigation existed. Polymarket employees have been instructed to preserve records related to the fraud attack and other matters.
The company has also faced scrutiny over its marketing activities. An investigation found that Polymarket had paid content creators to simulate betting and wins on imitation websites. Two US senators from different parties subsequently asked the CFTC to investigate, and Polymarket reorganized its marketing team. Those issues, together with the newly disclosed payment and account-security problems, have expanded the matters the company must address around regulation, market integrity and customer protection.
Against that backdrop, Polymarket is seeking about $1 billion in funding at a target valuation of roughly $21 billion. Donald Trump Jr.âs 1789 Capital is reportedly planning to invest about $300 million after previously investing around $200 million. Trump Jr. serves on Polymarketâs advisory board and is also a strategic adviser to rival platform Kalshi. In June, Coplan discussed the companyâs preparations for a possible 2027 IPO with Omeed Malik, 1789 Capitalâs co-founder.
A Polymarket spokesperson said the company was satisfied with its newly appointed management team and continuing infrastructure upgrades, adding that it would keep improving operations as it expanded rapidly. For users and prospective investors, the specific issues still include the size of the actual losses, whether the account flaw has been fixed, whether the CFTC takes further action, and whether the platform can apply its withdrawal and anti-fraud rules consistently.