A Wall Street Journal investigation published September 20 found that fraudsters linked stolen debit cards to thousands of Polymarket US accounts in February and then attempted to use those funds for wagers or withdraw the money into other cards and accounts they controlled. The $10 million figure represents attempted fraudulent activity, not a confirmed $10 million loss.
The most striking figure concerns the volume of transactions caught by Polymarket’s payment processor, Checkout.com. At one point during the attack, the processor was rejecting more than 80% of deposits it handled for Polymarket as fraudulent, according to the Journal. The report compared that with an industry fraud rate of roughly 1%.
That gap suggests the February episode was not simply a handful of compromised cards slipping through an otherwise normal payments system. It represented a sustained attempt to exploit Polymarket’s customer-acquisition and funding infrastructure during a period when prediction markets were attracting rapidly increasing volumes, institutional attention and investment.
Current and former employees told the Journal that compliance staff escalated the problem internally. According to those sources, CEO Shayne Coplan responded that the company should continue growing and could pay a fine if regulators eventually identified problems. The account is based on people familiar with the events rather than a regulatory finding or court judgment.
Polymarket told the Journal that it maintains systems designed to detect and respond to suspicious activity and remains committed to fair and transparent markets. The company has also taken concrete steps to reduce fraud since February.
Fraud rates reportedly remained elevated for several months but had returned to approximately industry norms by May. Polymarket restricted how many debit cards customers could connect to accounts and hired fraud-prevention specialist Riskified to strengthen transaction screening.
The Journal also reported that Polymarket initially required users to withdraw money through the same payment source used to make a deposit but later loosened that restriction. Employees reportedly worried that allowing money to enter through one card and leave through another account could create additional money-laundering and fraud risks. The reporting does not establish that money laundering actually occurred.
The issue arrives alongside other questions about Polymarket’s control environment. Dave Finances recently documented withdrawal delays and account holds affecting some Polymarket US customers, while researchers and regulators have also focused increasingly on insider trading risks across the prediction-market sector.
Another security incident reportedly affected nearly 500 Polymarket users in July. According to the Journal, an engineering flaw allowed attackers armed with stolen personal information to gain access to existing accounts and linked payment methods. Polymarket said it would reimburse affected customers.
Separately, unusual activity remains under scrutiny on the trading side. Independent surveillance services have identified unusual Polymarket wallets with exceptionally strong trading records, while federal authorities have investigated several cases involving possible use of confidential information. Those cases are distinct from the stolen-card attack but add to the broader market-integrity challenge facing the company.
The Commodity Futures Trading Commission is already investigating Polymarket, according to reporting by the Financial Times and others, although the complete scope of that investigation has not been publicly disclosed. The Journal reported that employees have been told to preserve records connected with the February attack and other matters.
Regulatory history makes the latest findings more consequential. In 2022, Polymarket paid a $1.4 million CFTC penalty for operating an unregistered event-contract marketplace. It later acquired CFTC-licensed exchange and clearing infrastructure QCEX for $112 million, paving the way for its regulated U.S. return. The CFTC is now simultaneously rewriting parts of the framework governing event contracts, a process Dave Finances has covered as CFTC rules for prediction markets continue evolving.
The company is also becoming financially significant. Intercontinental Exchange, the parent of the New York Stock Exchange, reported that its Polymarket preferred-share holdings represented roughly 22% of outstanding shares as of June 30. Polymarket is also raising about $1 billion at a reported $21 billion valuation and recently hired former Amazon, Delta Air Lines and Electronic Arts finance chief Warren Jenson as its first company-wide CFO.
That combination — a multibillion-dollar valuation, major institutional shareholders and growing regulatory exposure — makes the February fraud episode substantially more important than a conventional fintech fraud incident.
The uncomfortable number here is not really $10 million.
It is 80%.
A company can be attacked by fraudsters without having weak controls. Banks, exchanges and payment platforms deal with stolen cards every day. In fact, the fact that Checkout.com rejected so many transactions means an important part of the defensive system was working.
But when more than four out of every five deposits flowing through a payment processor are being identified as fraudulent, that tells you something had gone badly wrong upstream. The platform had become attractive enough — and apparently easy enough to probe — that organized fraud activity was flooding the funding channel.
For investors, that matters because growth quality becomes just as important as growth speed.
Polymarket has spent the past two years moving from crypto-native curiosity toward mainstream financial infrastructure. ICE invested heavily. Institutional data products followed. A regulated U.S. exchange was acquired. The company’s valuation surged. Management is now building a team that looks increasingly like one preparing for public-market scrutiny.
Fraud and compliance problems complicate that story.
Payment businesses depend heavily on relationships with banks, card networks and processors. If those partners decide a platform produces excessive fraud or chargebacks, they can impose tighter controls, higher reserves, lower transaction limits or more friction at checkout. Those responses can directly reduce conversion and slow customer acquisition.
Then there is the AML question. A platform where funds can potentially enter through a compromised card and exit through a different payment destination is much more attractive to criminals than one where money must return through the original funding channel. Again, the Journal’s findings do not prove that Polymarket became a money-laundering venue. They do show why internal compliance staff were concerned about the architecture.
Polymarket also has a second problem: individual incidents are starting to accumulate.
The company has dealt with scrutiny over promotional fake bets, suspicious trading, customer-account restrictions, fraud and security incidents. Dave Finances has also tracked recent failures involving Polymarket’s trading infrastructure. Each event has a different cause, and they should not be treated as one scandal, but together they raise a broader question about whether operational controls are scaling as quickly as the business.
That question matters enormously at a $21 billion valuation.
The positive side of the story is that Polymarket appears to have responded. Fraud rates reportedly returned to normal levels by May. Debit-card connections were restricted. Riskified was brought in. Risk-management and compliance functions have been expanded, and the hiring of Warren Jenson introduces an executive with decades of large-company financial experience.
Those are meaningful changes.
What investors need next is evidence that the improvements are structural rather than reactive.
The numbers worth watching are no longer just trading volume, active users and valuation. They are fraud losses versus attempted fraud, chargeback rates, payment-partner stability, account-takeover incidents, enforcement outcomes, compliance spending and whether regulators ultimately identify deficiencies in the company’s control framework.
Polymarket’s growth story is still powerful. Prediction markets have moved rapidly toward mainstream finance, and institutional backing gives the company resources that most startups in the category do not have.
But the WSJ investigation changes the question investors should be asking.
It is no longer simply whether Polymarket can keep growing.
It is whether its controls can grow just as fast.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

