Polymarket's $10 Million Fraud Attempt Tests Its Blockchain Brand
Key Takeaways
- •A Wall Street Journal investigation published on September 20 reported that Checkout.com alerted Polymarket in February about its US platform being flooded with deposits from stolen debit cards, and the processor at one point rejected more than 80% of the deposits it handled as fraudulent, compared with an industry benchmark of roughly 1%.
- •Thieves attempted to move at least $10 million through the US platform, but that figure reflects attempted transactions, and no regulator has issued a public finding confirming a completed loss of that amount.
- •Polymarket's US operation runs through QCX, a CFTC-designated contract market handling dollars, while its international platform settles trades onchain using pUSD, an ERC-20 token on Polygon backed by USDC.
- •A separate late-July attack exploiting an account-creation flaw reportedly gave attackers access to nearly 500 Polymarket US customer profiles using stolen personal information, and the company said it would cover the funds lost in that incident.
- •Blockchain records cannot verify whether a payment card was stolen, who controls a customer account, or whether a withdrawal was authorized, meaning the technology could not have prevented the reported card fraud.

Polymarket's US platform accepts dollars through conventional payment systems, while the company's international platform settles on a blockchain. That separation is central to understanding both what failed in a recently reported fraud attempt and what blockchain technology could never have prevented. The company operates prediction markets, where users trade positions on the outcomes of real-world events.
According to a Wall Street Journal investigation published on September 20, a payment processor warned Polymarket in February that its US platform was being flooded with deposits made from stolen debit cards. Payment processors sit between platforms and the card networks, screening transactions before they settle. The cards were allegedly linked to thousands of newly created accounts. At one point, the processor, Checkout.com, classified more than 80% of the deposits it handled as fraudulent and rejected them — a figure the Journal contrasted with an industry benchmark of approximately 1%. Card-network rules also generally route disputed fraudulent charges back to the merchant that accepted them.
Thieves attempted to move at least $10 million, but that figure describes attempted transactions, not completed losses. The high rejection rate indicates that the processor stopped a substantial share of the transactions before they could go through. The Journal's account remains an investigative report rather than a public enforcement finding, and no regulator has established through a published order that Polymarket suffered a completed $10 million loss.
The Withdrawal Route Created the Opening
Blocking a suspicious deposit is only one part of card-fraud prevention. A platform must also control where the money can leave.
The Journal reported that Polymarket US initially required withdrawals to be returned to the payment source used for the deposit. The company later relaxed that restriction as it tried to reduce delays for customers withdrawing their funds.
Returning money only to the original card can inconvenience legitimate customers when a card expires or an account closes. It also removes the easiest route for transferring stolen funds into a different account. Once another withdrawal destination is permitted, however, the platform must establish that both payment methods belong to the same verified customer — a determination that depends on identity checks, processor controls and account monitoring.
Polymarket Operates Two Different Systems
The reported card activity affected Polymarket US. It did not originate on the company's international blockchain platform.
Polymarket US operates through QCX, which the Commodity Futures Trading Commission lists as a designated contract market — a status reserved for exchanges that meet federal core principles and remain under continuing CFTC oversight. An Associated Press review of Polymarket's US return described the regulated operation as dollar-based and separate from its international crypto product.
Polymarket.com runs on different infrastructure. Its documentation describes pUSD as an ERC-20 token on Polygon backed by USDC, a dollar-pegged stablecoin. Orders are matched through an order book, while completed trades are settled through blockchain contracts.
Both products carry the same Polymarket brand. Problems in the dollar-based entrance can therefore damage confidence in the wider company even when the blockchain contracts themselves perform as intended.
What a Ledger Sees — and What It Cannot
A blockchain can record which addresses transferred assets, when each transaction occurred, which contract processed the trade and where onchain funds moved afterward. It cannot independently verify whether a payment card was stolen, who controlled a customer account, whether identity documents were genuine or whether a withdrawal was authorized.
In other words, the ledger may expose the path of funds after a transaction without proving that their original source was legitimate.
A Separate July Flaw Reportedly Exposed Existing Accounts
The July incident was not a continuation of the February stolen-card operation. In late July, nearly 500 Polymarket US customers were affected by another attack that appeared to exploit an account-creation flaw, according to the Journal.
Using an existing customer's stolen personal information, an attacker could allegedly create an account and gain access to that customer's existing profile — including connected cards and bank accounts — without knowing the original username or password.
The Journal did not provide a complete loss figure for the episode, saying the overall amount was limited, although individual users described losing thousands of dollars. A Polymarket spokeswoman said the company would cover funds lost in the incident.
CFTC Oversight Now Faces a Practical Test
Registration as a designated contract market establishes regulatory supervision and operating responsibilities. It does not make card fraud, identity theft or account takeover technically impossible.
The case arrives as the CFTC works to advance digital-asset rules through powers it already holds. The agency recently sent a crypto market proposal to the White House after broader legislation stalled in Congress.
For Polymarket US, the relevant question is no longer whether the CFTC has a relationship with the platform — it already does. The question is how the exchange's customer checks, withdrawal procedures and response to unauthorized transactions measure up to the obligations attached to that status.
The Journal also attributed an alleged remark to CEO Shayne Coplan suggesting that the company should continue growing and deal with a fine if regulators intervened. That account came from people described as familiar with internal discussions and has not been established in any public regulatory finding.
Polymarket's public response emphasized new leadership appointments, infrastructure improvements and responsible expansion The published statement did not directly address the alleged remark attributed to Coplan.
What Potentially Affected Customers Should Check
Customers with concerns can take several practical steps:
- Freeze an affected card through its bank or issuer.
- Review account sessions and change compromised login credentials.
- Remove unrecognized cards or withdrawal destinations.
- Save supporting records, including statements, emails and transaction identifiers.
- Report unauthorized activity separately to the payment provider and to Polymarket.
Bank records, platform logs and blockchain transactions document different stages of an incident. Keeping all three may be necessary, because no single record provides the complete sequence.
Polymarket's Growth Now Depends on Controls Users Cannot See
Public markets and blockchain transactions allow outsiders to examine prices, trades and asset movements. Customers cannot inspect the private systems that approve deposits, connect identities or authorize withdrawals. That makes Polymarket's next test less visible than its trading volume.
Reimbursement times, fraud disclosures, account-recovery procedures and any regulatory findings will offer better evidence of whether the company's controls have caught up with its expansion. If Polymarket wants blockchain transparency to support institutional trust in its brand, it will need comparable clarity about the systems operating before and after the chain.
This article is provided for informational purposes only. Allegations attributed to external reporting may change as additional information or regulatory findings become available.