Polymarket Dropped Key Anti-Money-Laundering Rule Amid $10 Million Stolen-Card Attack
Key Takeaways
- •A stolen-debit-card scheme that began in February saw about seven users account for the bulk of an effort to move roughly $10 million through Polymarket's U.S. platform, with one account alone attempting around 4,000 deposits.
- •Polymarket leadership removed the requirement that withdrawals go to the same payment source used for deposits, a change employees warned invited money laundering, while CEO Shayne Coplan reportedly told staff to prioritize growth and address regulatory fines later.
- •The fallout included the April resignation of chief compliance officer Andrew Clifford and the firing of U.S. CEO Justin Hertzberg, and the CFTC is now investigating the fraud with staff ordered to preserve records.
- •Fraud rates reportedly returned to industry norms by May after Polymarket capped the number of linked debit cards and added screening vendor Riskified, though a separate late-July registration flaw let attackers with a victim's Social Security number take over roughly 500 accounts.
- •QCX LLC, the entity operating Polymarket U.S., holds CFTC Designated Contract Market status granted on July 9, 2025, placing the platform under federal derivatives oversight even as the company raises roughly $1 billion at a $21 billion valuation and discusses a potential 2027 IPO.

The $10 Million Stolen-Card Operation
Fraudsters attempted to move roughly $10 million through Polymarket's U.S. platform — a prediction market where users trade contracts tied to real-world outcomes — in a stolen-debit-card operation that began in February, according an investigation published Saturday. The scheme relied on compromised cards linked to thousands of accounts, which were used to fund bets before the perpetrators attempted to withdraw proceeds to accounts under their control. The attackers exploited standard card-payment rails: Checkout.com, the processor handling Polymarket's deposits, flagged the operation and at its peak rejected more than 80% of Polymarket U.S. deposits as fraudulent — against an industry-standard rate near 1%.
The activity was highly concentrated. About seven users accounted for the bulk of it, and one account alone attempted roughly 4,000 separate deposits. The investigation did not establish how much of the $10 million actually left the platform, and a person cited in the reporting said most attempted deposits failed.
The more consequential disclosure sits in Polymarket's internal response. With fraudulent deposits piling up alongside a backlog of legitimate withdrawals, leadership removed the requirement that funds be withdrawn to the same payment source used for deposits — the standard safeguard that stops stolen-card proceeds from reaching a clean account. Employees warned the change invited money laundering; executives said existing controls were sufficient. CEO Shayne Coplan reportedly told staff to prioritize growth and address any regulatory fines later.
Chief compliance officer Andrew Clifford resigned in April after submitting a detailed report on the fraud. U.S. CEO Justin Hertzberg was fired, and the company's heads of U.S. regulation and anti-money-laundering also departed. An internal review by law firm Sullivan & Cromwell concluded the platform had complied with regulations.
Fraud rates reportedly returned to industry norms by May, after the platform capped how many debit cards a user could link and brought in screening vendor Riskified. A separate registration flaw in late July then let attackers holding a victim's Social Security number take over roughly 500 accounts — with linked bank accounts and cards — without knowing any password. The failure was one of identity verification rather than cryptography: no private key was ever at stake. The CFTC — the Commodity Futures Trading Commission, the federal agency that oversees U.S. derivatives markets — is now investigating the fraud, and staff have been told to preserve records.
A CFTC-Designated Market Under Scrutiny
The compliance record matters more here than it would at an ordinary crypto startup. The regulator's own registration records show QCX LLC, the entity operating Polymarket U.S., received Designated Contract Market (DCM) status on July 9, 2025 and remains listed as designated — placing the platform inside America's formal, federally supervised derivatives regime rather than on its periphery. That status is precisely why card fraud, customer-identification gaps and loosened withdrawal controls at a registered venue carry regulatory weight that a decentralized-protocol breach never would.
Pressure from the payment side reinforced the picture. Visa reportedly raised concerns over the surge in fraudulent activity and pushed Checkout.com to tighten controls on Polymarket flows, with the processor in turn demanding stronger measures from the platform.
Records obtained through a public-records request also show the CFTC examined suspected insider trading on several Polymarket markets — contracts tied to a former U.S. president's pardons, Iran-related events and Google's annual search rankings — with a group of Iran-market accounts netting about $2.4 million and one pardon-market trader roughly $300,000.
Rapid Growth Amid Rising Stakes
The capital markets have treated the growth story kindly regardless. Polymarket is raising roughly $1 billion at a $21 billion valuation, with Donald Trump Jr.'s 1789 Capital adding about $300 million on top of $200 million already invested. Former Amazon finance chief Warren Jenson has been installed as the company's first CFO, and an IPO has reportedly been discussed for 2027.
But scale sharpens the stakes. The first NFL weekend of the 2026 season produced about $3.12 billion in Sunday prediction-market volume and roughly $3.17 billion the prior day on college football. Kalshi turned over about $4.89 billion across the weekend, against Polymarket's roughly $404 million. Industry research this year pegged monthly sector volume near $21 billion. When inflows that size — much of it funded through card networks and stablecoin balances, the dollar-pegged tokens commonly used to move money onto crypto venues — meet a speed-first culture, compliance capacity becomes a core part of the product, and users weighing platform risk across venues now have to price it alongside fees and liquidity.
Compliance Capacity Decides the Winners
Both threads land on one arc: prediction markets have outgrown the control infrastructure that got them here. The CFTC's own registry — QCX LLC's DCM designation — obligates a degree of oversight that the February decisions plainly did not deliver, and the active probe, with staff ordered to preserve records, signals that the bill may still arrive.
With Bitcoin (BTC) holding near $86,570 at press time and mainstream capital rotating into prediction platforms, edge cases now surface on front pages rather than in niche forums. The sequence revives Bitcoin maximalism's oldest argument about platform risk — the long-standing claim that intermediated holdings carry risks self-custody avoids — and it is likely to favor operators, and protections such as DeFi insurance, on-chain coverage against platform failure, built for scrutiny.