TLDR
- Criminals attempted to exploit Polymarket US for at least $10 million using stolen debit cards during February.
- Payment processor Checkout.com flagged over 80% of transactions as fraudulent at the peak of the attack, far exceeding typical industry rates.
- According to Wall Street Journal reporting, CEO Shayne Coplan urged employees to prioritize growth over compliance worries.
- The platform subsequently implemented stronger fraud prevention measures, normalizing fraud rates to industry standards by May.
- Polymarket is currently pursuing approximately $1 billion in funding at a roughly $21 billion valuation while considering a future public offering.
A sophisticated fraud operation targeted Polymarket with an attempted theft of at least $10 million earlier this year, exploiting stolen debit cards on the company’s U.S. prediction market platform, Wall Street Journal reporting has revealed.
The criminal campaign launched in February, coinciding with Polymarket US expanding access to its platform for additional users.
The scheme involved bad actors connecting stolen debit cards to platform accounts, executing wagers, and subsequently attempting to transfer funds to cards or accounts under their control.
Checkout.com, the company’s payment processor, identified more than 80% of incoming deposits as fraudulent during the height of the attack—a dramatic departure from the typical industry fraud rate of approximately 1%, sources told the Journal.
Criminal Network Behind $10M Polymarket Attack
The majority of fraudulent deposit attempts were ultimately unsuccessful, according to reports.
Sources familiar with the situation indicated that roughly seven individual users orchestrated most of the fraudulent activity, with a single account making approximately 4,000 deposit attempts.
The Journal’s investigation could not establish the precise amount successfully stolen from the attempted $10 million target.
Staff members reportedly escalated their concerns about the ongoing attack to CEO Shayne Coplan.
According to individuals with knowledge of internal conversations, Coplan’s response emphasized maintaining growth momentum and addressing potential regulatory issues as they arose. The company has publicly stated its dedication to maintaining fair markets and working collaboratively with regulators and law enforcement agencies.
The security breach also caused significant delays in processing customer withdrawal requests as compliance teams managed the influx of suspicious transactions.
Polymarket’s leadership subsequently eliminated a policy mandating that deposits and withdrawals occur through matching payment sources.
According to the report, certain employees expressed concern that removing this protective measure could elevate money-laundering vulnerabilities.
Enhanced Security Measures Implemented
Polymarket responded by deploying more robust fraud prevention systems.
According to someone familiar with company operations, fraud rates normalized to industry-standard levels by May.
The enhanced security framework included restricting the quantity of debit cards linkable to individual accounts and partnering with fraud-prevention specialist Riskified.
Multiple high-ranking employees departed the company during this turbulent period.
Andrew Clifford, Polymarket US Chief Compliance Officer, resigned in April following his submission of a detailed report documenting fraud-related concerns.
The organization later terminated U.S. CEO Justin Hertzberg’s employment, while executives overseeing regulatory affairs and anti-money-laundering operations also exited.
An independent assessment conducted by Sullivan & Cromwell law firm determined that Polymarket maintained regulatory compliance, according to sources with knowledge of the review.
Polymarket experienced an additional security breach in July when an account-registration vulnerability reportedly impacted nearly 500 users.
The exploit allegedly enabled attackers possessing stolen personal data to compromise existing accounts and associated payment methods without requiring usernames or passwords. Polymarket committed to reimbursing affected users for any losses.
Fundraising Push and IPO Aspirations
These security challenges emerge as Polymarket pursues approximately $1 billion in new capital at an estimated $21 billion valuation.
1789 Capital is contributing roughly $300 million to this funding round, supplementing its previous $200 million investment, according to reports from the Journal and The Block.
Coplan has reportedly engaged in preliminary discussions regarding a potential 2027 initial public offering, and the company has appointed Warren Jenson, Amazon’s former chief financial officer, to serve as its inaugural CFO.
Polymarket maintains that it has substantially enhanced its risk management infrastructure, compliance protocols, product testing procedures, and leadership team in preparation for continued expansion.


