Polymarket hit by alleged $10M stolen-card fraud

0
7

Polymarket is facing renewed scrutiny after a September 19 report said criminals used stolen debit cards on its U.S. platform in February to attempt at least $10 million in withdrawals and wagers.

According to the report, criminals connected stolen cards to thousands of Polymarket US accounts, added funds and then tried to move the money through trading before withdrawing it to cards or accounts they controlled.

During the peak of the February activity, Checkout.com reportedly rejected more than 80% of deposits it processed for Polymarket as fraudulent. That was far above the industry level of around 1%. However, Checkout.com has not publicly confirmed the 80% figure.

The reported $10 million represents the amount criminals allegedly attempted to move. It does not mean Polymarket or its customers suffered a confirmed $10 million loss. Public information reviewed in the report does not show how much money was actually withdrawn.

Polymarket later introduced stronger card controls and brought in Riskified, an outside fraud-prevention company. By May, the reported fraud rate had returned closer to normal industry levels. Polymarket also limited the number of debit cards users could connect to their accounts.

Polymarket US operates separately from Polymarket’s international blockchain-based prediction market. The U.S. platform operates through QCX LLC, which is registered as a designated contract market under the Commodity Futures Trading Commission.

The company also has a history with the CFTC. In 2022, the regulator ordered Polymarket to pay a $1.4 million civil penalty over unregistered event-based binary options. The current reported investigation into the February fraud is still described as an ongoing inquiry, and no new public CFTC enforcement action specifically related to the stolen-card incident had been announced as of September 20.

Polymarket has also expanded its compliance and investigation teams. Shana Bautista, a former FBI investigator, joined as global head of investigations and intelligence. The company says it uses blockchain analytics, machine learning and trading surveillance to identify unusual activity.

Polymarket’s own market-integrity information says it has referred more than 90 accounts to law enforcement and provided authorities with information about more than 315 wallets. These figures are company-reported and cover suspicious activity more broadly, not only payment-card fraud.

The company appointed Warren Jenson as its first chief financial officer on September 10. Jenson previously held senior finance positions at Amazon, Electronic Arts, Delta Air Lines and Nielsen. Polymarket said he would oversee finance, capital strategy and long-term planning.

Polymarket has also faced other security problems in 2026. In June, a compromised third-party vendor caused malicious code to appear on its website for some users. The company said it removed the affected software, contained the incident and planned to reimburse affected customers. Investigators later estimated losses at around $3.1 million across 11 wallets.

A separate incident in July reportedly affected nearly 500 users after attackers used stolen personal information to access existing accounts and linked payment methods. Polymarket reportedly agreed to cover losses connected to that incident, although no independently confirmed total loss was publicly available.

Polymarket says it has strengthened its fraud controls and continues to work with law enforcement on suspicious activity. The February payment-card problem remains an important part of the company’s broader compliance and security challenges, even as the reported fraud rate later moved back toward industry norms.