Polymarket Under Scrutiny After Alleged $10 Million Stolen-Card Fraud Attempt
Key Takeaways
- •Criminals allegedly used stolen debit cards in attempts to move at least $10 million through Polymarket's U.S. prediction-market platform, a figure representing attempted transactions rather than confirmed losses.
- •Payment processor Checkout.com rejected more than 80% of deposits as fraudulent at the peak of the activity in February, compared with a roughly 1% industry norm.
- •The alleged scheme involved attaching stolen debit cards to thousands of Polymarket U.S. accounts, depositing funds, placing wagers, and attempting withdrawals to accounts the fraudsters controlled.
- •Polymarket responded by limiting the number of debit cards a user could connect, bringing in additional antifraud resources, and expanding its compliance, investigations, and risk-management operations.
- •The episode arrives amid broader regulatory scrutiny of prediction markets, with Polymarket previously having settled with U.S. regulators over its operation of event-based contracts.

Polymarket is confronting renewed scrutiny after criminals allegedly used stolen debit cards in an attempt to move at least $10 million through the company's U.S. prediction-market platform earlier this year. The episode surfaced as the firm accelerated its American expansion.
Prediction markets let users trade contracts on the outcomes of real-world events, and Polymarket's U.S. platform accepts deposits through linked debit cards — the same payment channel the alleged scheme exploited.
According to reports, payment processor Checkout.com rejected more than 80% of the deposits it handled as fraudulent at the peak of the activity in February, a rate far above the roughly 1% industry norm. Deposit-rejection rates are a standard gauge payment processors use to measure fraudulent transaction attempts.
How the Alleged Scheme Worked
The reported fraud involved criminals attaching stolen debit cards to thousands of Polymarket U.S. accounts. Once linked, they deposited funds, placed wagers, and attempted to withdraw money to accounts or cards under their own control — a pattern long documented in online payment fraud, where cards obtained elsewhere fund accounts and withdrawals are redirected to destinations the fraudsters control.
The $10 million figure reflects attempted transactions rather than confirmed losses. Public reporting has not established that Polymarket or its customers ultimately lost the full amount.
The episode also raised questions about the platform's fraud defenses during a period of rapid growth. People familiar with the matter said compliance employees raised concerns internally as rejection rates surged.
Tightened Risk Controls
Fraud activity reportedly remained elevated for several months before falling back toward industry norms. In response, Polymarket limited the number of debit cards a user could connect and brought in additional antifraud resources. The company has also expanded its compliance, investigations, and risk-management operations.
Polymarket's U.S. platform operates through a federally regulated exchange and maintains rules prohibiting fraud, market manipulation, and other prohibited activity.
The reported episode arrives amid broader regulatory attention on prediction markets. Polymarket previously settled with U.S. regulators over its operation of event-based contracts and now faces continued scrutiny as the sector expands.
For the company, the incident underscores a familiar challenge for financial platforms: rapid user growth can lift transaction volume while also creating new avenues for payment fraud. Polymarket is now operating with expanded controls as it works to build out its U.S. business. One measure to watch is whether deposit-rejection rates hold near industry norms as the U.S. user base grows, and whether further public detail about the February episode emerges.