NewsCryptoPolymarket's $10 Million Fraud Attempt Tests Whether Growth Outran Compliance

Polymarket's $10 Million Fraud Attempt Tests Whether Growth Outran Compliance

Author: Cryptopolitan·

Key Takeaways

  • Attackers tied stolen debit cards to thousands of newly created Polymarket accounts in an attempt to steal at least $10 million, with seven users accounting for most of the fraudulent activity.
  • Polymarket's US compliance chief resigned and the US division's CEO was fired along with other anti-money-laundering executives, although a Sullivan & Cromwell review reportedly concluded the company had complied with regulations.
  • The company has since added risk personnel, hired its first CFO, limited linked debit cards, and partnered with Riskified, and says fraud rates returned to industry norms by May.
  • More than 80 accounts have been flagged for suspicious trading across nearly 30 markets, prompting CFTC-authorized investigations and a Senate letter questioning Polymarket's marketing practices.
  • Prediction markets generated $63.5 billion in volume in 2025, and a Stanford-SMU study associated Polymarket's five-minute Bitcoin contracts with spot-market price disruptions that largely hurt retail traders.
Polymarket's $10 Million Fraud Attempt Tests Whether Growth Outran Compliance

In February, Polymarket — a prediction-market platform where users trade contracts on the outcomes of real-world events — became the target of a fraud attempt that sought to steal at least $10 million from its US app, according to a Wall Street Journal investigation. Despite the episode, CEO Shayne Coplan told employees to press ahead with the company's expansion plans regardless of any sanctions that might follow.

The $10 million figure refers to the amount the thieves attempted to steal — not money Polymarket actually lost, according to the report.

The incident raises an overarching question for a company looking to fundraise at a valuation of about $21 billion and weighing a possible path to going public: has Polymarket outpaced the compliance and market-integrity protections that would generally be required of a regulated trading platform?

Stolen cards and an 80% rejection rate

The scheme surfaced after payment processor Checkout.com flagged a surge in suspicious debit-card activity. Attackers tied stolen cards to thousands of newly created accounts, placed wagers, and attempted to cash out to accounts under their control. At the peak, more than 80% of deposits were rejected as fraudulent, compared with an industry norm of about 1%, the Journal reported.

Seven users accounted for most of the activity, with one alone making close to 4,000 deposits. As genuine withdrawals mounted, Polymarket changed its policy on returning withdrawals to the original funding source. Some employees warned that dropping the rule, a standard safeguard in payment compliance, could raise the likelihood of money laundering, while executives maintained that other internal controls were sufficient.

According to the report, people who currently or formerly worked at Polymarket said Coplan kept pushing for continuous growth regardless of any regulatory issues that might arise. Word of the fraud incident quickly reached senior management.

Andrew Clifford, who oversaw compliance in the US, resigned after publishing an internal report on the fraud issues. Justin Hertzberg, CEO of the US division, was fired along with other executives responsible regulatory compliance and anti-money-laundering policies. A review by law firm Sullivan & Cromwell concluded that Polymarket complied with regulations, according to sources with knowledge of the findings.

Polymarket says it has since strengthened its controls. The company added risk staff, including a former FBI agent; hired former Amazon finance chief Warren Jenson as its first CFO; limited the number of debit cards users could link; and brought in Riskified. Fraud rates returned to industry norms by May, the company says.

An insider-trading problem that predates the fraud

The concerns around fraud come in addition to an older market-integrity issue: trading on nonpublic information. According to a report published by The New York Times, more than 80 Polymarket accounts have been flagged for questionable trading across nearly 30 markets. In one example, 13 users bet $140,000 that Israel would launch military action against Iran and ended up gaining more than $600,000.

Federal scrutiny has intensified. WIRED reported that Commodity Futures Trading Commission (CFTC) Chairman Michael Selig authorized investigations into Polymarket trades tied to Biden pardons, contracts with Iran, and Google's search results. Separately, a US Special Forces soldier has been accused of using classified information to gain more than $400,000 from bets related to Maduro.

According to the CFTC, misuse of material nonpublic information could constitute a violation of commodities law. Chainalysis, however, notes that the transparency of blockchain allows law enforcement to trace suspicious transactions and investigate wallet links.

Polymarket's marketing practices have attracted scrutiny as well. A June 25 letter from Sens. John Curtis and Adam Schiff asked the CFTC to investigate allegations that Polymarket paid creators to stage trades on lookalike websites without clearly disclosing the payments. The Journal's reporting detailed how fake bets were promoted online. As Cryptopolitan reported, JPMorgan closed Polymarket's bank account in August over regulatory concerns, while the New York City Council opened a probe into prediction-market marketing practices.

A sector big enough to matter

The stakes extend well beyond one company. Prediction markets generated $63.5 billion in volume in 2025, while Kalshi and Polymarket together handled $52.7 billion in the first 86 days of 2026, according to Artemis. Intercontinental Exchange's stake in Polymarket was valued at about $1.6 billion, representing roughly 22% of the company.

Several recurring fraudulent or prohibited practices appear across prediction markets. The important distinction is that some are confirmed enforcement cases, while others are suspicious activity or allegations still under investigation.

Market design can spill into crypto itself. A Stanford-SMU study found that Polymarket's five-minute Bitcoin contracts were associated with settlement-time spikes in spot order flow and sharp price reversals, with retail traders absorbing most of the losses during manipulated cycles. The effect was far weaker in 15-minute contracts.

That makes Polymarket's compliance problems more than a company-specific concern. For banks, regulators, and institutional traders, weak controls can raise the cost of entering the sector, fragment liquidity across jurisdictions, and slow the broader integration of prediction markets with crypto finance. With the CFTC-authorized investigations, the senators' requested review, and the New York City Council probe still open, their findings are the next markers of whether prediction markets of this scale can meet the market-integrity standards expected of traditional trading venues.