Fraudsters tried to steal about $10 million through Polymarket U.S. beginning in February, using stolen debit cards to deposit funds, place bets, and then attempt withdrawals to accounts they controlled, according to a Wall Street Journal investigation published Saturday.
The Journal said Polymarket CEO Shayne Coplan responded to the attack by telling employees to prioritize growth and deal with any regulatory fines later. Payment processor Checkout.com had alerted Polymarket to the attack, the report said.
At one stage, Checkout.com rejected more than 80% of the Polymarket U.S. deposits it handled as fraudulent, versus an industry-standard rate near 1%, according to the Journal. The activity was concentrated among roughly seven users, the report said, adding that one user attempted around 4,000 separate deposits.
The Journal did not establish how much of the attempted $10 million was successfully taken. One person cited in the report said most of the attempted deposits failed.
As fraudulent deposits mounted and legitimate withdrawal requests built up in a backlog, Polymarket leadership allegedly removed a requirement that funds deposited from one payment source had to be withdrawn back to that same source.
The Journal said that rule is not specifically required for prediction markets, but it is standard at financial institutions and is the safeguard that prevents proceeds from stolen cards from being moved to a clean account. Employees warned that removing it opened the door to money laundering, but executives said existing rules were enough, according to the report.
Polymarket U.S. chief compliance officer Andrew Clifford resigned in April after submitting a detailed report on the fraud to executives. The company then fired U.S. CEO Justin Hertzberg, and its heads of U.S. regulation and anti-money-laundering also departed.
An internal investigation by law firm Sullivan & Cromwell concluded that Polymarket had complied with regulations, the Journal reported, citing people familiar with the matter.
Fraud rates reportedly returned to industry norms by May after the platform capped how many debit cards a user could link.
In late July, a separate registration flaw allowed attackers who had a victim’s Social Security number to take over roughly 500 accounts, along with linked bank accounts and cards, without knowing any password, the Journal reported, citing a person familiar with the matter.
The Commodity Futures Trading Commission is investigating Polymarket in relation to the fraud attack, and staff have been told to preserve records, according to the Journal.
Polymarket relaunched in the U.S. in beta in late 2025. The company is now raising roughly $1 billion at a $21 billion valuation, with Donald Trump Jr.’s 1789 Capital adding about $300 million on top of $200 million already invested. Coplan has also reportedly discussed a 2027 IPO.
Polymarket has hired former Amazon finance chief Warren Jenson as its first CFO.
A Polymarket spokesperson told the Journal that the company’s market integrity framework includes processes to detect, review, and respond to suspicious activity.

