TLDR
- Fraudsters attempted to steal over $10 million using stolen debit cards linked to Polymarket accounts in February 2026.
- Payment processor Checkout.com flagged nearly 80% of transactions as fraudulent at one point, far above the industry norm of about 1%.
- CEO Shayne Coplan reportedly told compliance staff to keep growing and pay fines later if regulators found out.
- The CFTC, New York City Council, and multiple state lawsuits are now examining Polymarket’s practices.
- A second fraud incident in July exposed nearly 500 accounts to unauthorized access through an engineering flaw.
Polymarket is facing new scrutiny after reports revealed that fraudsters attempted to steal more than $10 million from the platform. The scheme took place in February 2026 and involved stolen debit cards.
Fraudsters linked hacked payment cards to Polymarket accounts. They placed bets and then tried to withdraw the funds into cards or accounts they controlled.
Payment processor Checkout.com flagged close to 80% of transactions as fraudulent at one point. That rate is far higher than the industry standard of roughly 1%.
Fraud Concerns Reached the CEO
Compliance staff raised concerns about the fraud with CEO Shayne Coplan. Sources familiar with the matter say he told the team to keep growing and pay any fines later if regulators found out.
Polymarket has not confirmed this account of events. The company says it has systems in place to detect and respond to suspicious activity in line with regulatory requirements.
The $10 million figure represents the amount fraudsters attempted to move. It does not reflect confirmed losses by Polymarket or its users.
Fraud rates stayed elevated for months after the February incident. Polymarket says the numbers returned to industry norms by May.
To address the problem, Polymarket limited how many debit cards can be linked to a single account. The company also hired a fraud prevention firm called Riskified.
Visa reportedly urged payment processors to step up screening after the rise in disputed transactions. The incident drew added attention to payment systems used across prediction market platforms.
Investigations and Lawsuits Pile Up
The Commodity Futures Trading Commission is investigating Polymarket, and the February fraud is part of that inquiry. In 2022, the company paid $1.4 million to settle separate CFTC charges over unregistered contracts.
Polymarket also faces a congressional inquiry into its customer identification and suspicious activity procedures. The New York City Council is separately examining the platform’s advertising practices.
Nearly two dozen traders have filed lawsuits accusing Polymarket of deceptive business practices. More than a dozen state lawsuits are questioning whether Polymarket and rivals like Kalshi and Coinbase operate as unlicensed gambling platforms.
During the February attack, Polymarket dropped a rule requiring deposits and withdrawals to use the same payment source. Some employees warned this could open the door to money laundering.
The company’s chief compliance officer, Andrew Clifford, resigned in April. Around the same time, Polymarket fired Justin Hertzberg, the head of its U.S. division.
A review by law firm Sullivan & Cromwell concluded that Polymarket had complied with regulations. Since then, the company has added risk management staff, including a former FBI agent.
In July, Polymarket faced a second incident. Nearly 500 users had their accounts accessed after an engineering flaw let attackers take over accounts using stolen personal information.
Polymarket said it would cover any funds lost in the July attack. Some users reported waiting weeks for customer support to respond.
Polymarket’s prediction markets continue to track political events closely. As of September 20, 2026, a market on a possible U.S.-Denmark agreement over Greenland showed an 83% chance of a positive outcome by September 23.
