Polymarket Stolen Debit Card Fraud Attempt Hits $10 Million; CEO Shayne Coplan Pushed Growth Over Security

Polymarket Fraudulent Accounts

A Wall Street Journal investigation published Saturday says fraudsters linked stolen debit cards to new Polymarket US accounts in February, funded trades, and tried to withdraw the money to cards they controlled. The attempted haul reached at least $10 million. Checkout.com, which processed those deposits, rejected more than 80% of them as fraudulent, compared with an industry rate of about 1%.

Compliance staff took the warning to Chief Executive Shayne Coplan. They recalled a reply that stunned the team: keep growing, and pay a fine if regulators ever find out. Polymarket has not confirmed that wording. The company said it flags suspicious activity and will cooperate with regulators and law enforcement.

The surge hit just as the U.S. venue admitted traders off a waitlist and users complained on Discord about slow withdrawals. Leadership wanted faster payouts. That push met a coordinated attack driven by about seven accounts, including one person who tried roughly 4,000 deposits.

How the Stolen Debit Card Scheme Worked

The plan was simple. Criminals linked stolen credit card numbers to thousands of new accounts, deposited funds, placed rapid wagers, and then tried to cash out to “clean” cards. Dirty money to clean money. The Journal did not establish how much of the $10 million actually left the platform. One person familiar with the matter said most attempted deposits failed.

Visa had already pressed Checkout.com to curb suspicious Polymarket payments earlier in the year. The processor declined to comment on the incident but said it is continuing to work with the company. Its merchant terms still leave the venue with final acceptance decisions, even when fraud-scoring tools flag a spike. This is true for all companies, not just Polymarket. The onus was on the approver.

2026 Polymarket US Controls Timeline

Instead of tightening matching rules at once, leadership removed a same-source withdrawal requirement that would have sent cash-outs back to the original card. Employees warned that the change could aid money laundering. Traders wanting quicker access to funds were the stated reason. The payout path widened at the same moment stolen-card traffic was rising.

By May, rejection rates had fallen toward industry norms after Polymarket limited debit cards per account and hired Riskified. The February peak did not return. The Journal ran an opinion piece arguing that Polymarket willingly accepted the fraud risk to avoid hampering platform growth at a key moment for the business. A rather damning comment.

July Account Takeover Hit Nearly 500 Traders

February was not the only scare. In late July, nearly 500 Polymarket US traders faced an attack that needed no password. Someone who tried to open an account with an existing trader’s personal data, such as a stolen Social Security number, landed inside that live profile. Linked banks and debit cards became entirely accessible.

One trader said he logged in after following World Cup contracts and found his positions sold, with $5,783.51 sent to a card he did not own. Polymarket credited him $25 and offered no explanation, he said. Others described losses in the thousands and weeks of unanswered support messages. A person familiar with the matter called the July episode an engineering problem and said the total taken through that flaw was small. Small in terms of the Polymarket volume; not small to the customers personally affected.

Chief Compliance Officer Andrew Clifford resigned in April after sending a fraud report to executives as he left. U.S. CEO Justin Hertzberg was later fired. Regulation and anti-money-laundering leads also left. The company later named Warren Jenson, formerly of Amazon, as its first chief financial officer and added investigations staff.

CFTC Review and What Comes Next

People cited by the Journal said the Commodity Futures Trading Commission is investigating and that employees were told to preserve documents. Polymarket US onshore operates through QCX, a designated contract market. A stolen-card pipeline and a registration flaw are not side issues under that license. It will be delved into thoroughly.

An 80% rejection rate can exist alongside continued onboarding because the processor can decline cards while the venue still sets withdrawal speed and card limits. After February, Polymarket capped attached cards, hired Riskified, and later added a former FBI agent to anti-fraud work. Fraud rates slowed down. The CEO allegedly saying growth mattered more than security turned this from a fraud case into a larger media story about corporate governance.

Furthermore, the open questions are now pretty specific. How much of the $10 million was funded? Which affected traders Polymarket made whole. Whether the July identity path is closed. The newspaper published no final February loss figure. Most attempted deposits failed, one source said. That is clearly not the same as zero loss.

Staffing changes and tighter card rules will not erase this past record now in full public view. More to come on this story, most certainly.

References

  1. Wall Street Journal: Polymarket’s Rush to Grow Left a Door Wide Open For Fraudsters
  2. The Block: Polymarket faced $10 million fraud attempt as its CEO pushed growth over compliance concerns
  3. Checkout.com
  4. Wall Street Journal post on X
  5. Gizmodo: Polymarket Bug Reportedly Let Identity Thieves Into Existing Accounts
  6. Legal Sports Report: WSJ Report Details Coplan’s Plans To Grow Polymarket Despite Rampant Fraud
  7. Commodity Futures Trading Commission
  8. crypto.news: Polymarket hit by alleged $10M stolen-card fraud

Author

  • PolyPunter Staff

    The PolyPunter staff works tirelessly to bring you the latest and most insightful news, information, and tips on the fast-growing economic, financial, and social phenomenon that is prediction markets.

Leave a Reply

Your email address will not be published. Required fields are marked *