Fraudsters linked thousands of stolen debit cards to Polymarket US accounts in February, aiming to move at least $10 million. At its peak the payment processor blocked more than 80% of deposi
- Fraudsters linked thousands of stolen debit cards to Polymarket US accounts in February, aiming to move at least $10 million.
- At its peak the payment processor blocked more than 80% of deposits as fraudulent, against an industry norm near 1%.
- CEO Shayne Coplan reportedly waved off compliance staff, telling them to keep growing and settle any fine later.
- A CFTC investigation is now open while Polymarket raises $1 billion at a $21 billion valuation.
In February 2026, organized fraudsters flooded Polymarket’s US platform with thousands of stolen debit cards, pushing the funds through fast wagers and withdrawals in an effort to siphon out at least $10 million, according to reporting by The Wall Street Journal. The company’s payment processor at the time, Checkout.com, caught the surge and began rejecting most incoming deposits. What turned a fraud episode into a governance problem was the reaction at the top: current and former employees told the Journal that CEO Shayne Coplan brushed off compliance warnings and instructed staff to keep scaling, on the reasoning that the company could absorb a regulatory fine later. Polymarket, for its part, says it maintains procedures to detect and respond to suspicious activity and is committed to working with regulators and law enforcement.
How stolen cards turned into a laundering pipeline
The scheme worked because Polymarket US let users connect debit cards directly and move balances quickly. Fraudsters loaded accounts with stolen cards, opened and closed positions, and steered the proceeds toward cards or accounts they controlled, converting dirty money into clean withdrawals. At the height of the attack Checkout.com rejected more than 80% of the deposits it handled. That figure only makes sense next to the baseline. Card processors typically flag around 1% of transactions, so an 80% block rate points to a coordinated assault rather than scattered abuse.
Fraud snapshot
Detail
Attack window
February 2026, elevated for months after
Funds targeted
At least $10 million
Peak deposit rejection
Over 80% flagged as fraudulent
Industry norm
Roughly 1%
Processor at the time
Checkout.com
The fix
Debit-card linking limits plus Riskified; rates normalized by May 2026
Why Polymarket was an easier target than a traditional exchange
Former CFTC, Justice Department and IRS officials described both the scale of the attempted fraud and the company’s response as atypical for commodities and gambling operators. The structural reason is simple. Established commodities exchanges sit behind brokers and clearing layers that screen incoming money before it ever reaches the market. Polymarket takes funds straight from retail traders, which shortens the path for anyone feeding stolen cards into the system. Fraud rates stayed high for months, though they never again reached 80%. They came back down around May, after the company capped how many debit cards a single account could link and brought in Riskified, an anti-fraud specialist, to harden screening. Executives departed in the interim, and an internal investigation began.
A pattern of compliance gaps, not a single lapse
The February attack lands inside a year of legal and operational trouble that repeatedly tested the same weakness: an appetite for growth running ahead of controls.
Feb 2026
Stolen-card fraud wave
At least $10M targeted; the processor rejected over 80% of deposits as fraudulent.
Jun 2026
Deceptive marketing lawsuit
Suit filed over paid TikTok clips showing fake winnings on dummy sites; names Coplan and the CMO.
Jun 2026
$3M front-end exploit
A compromised vendor script injected a wallet-drainer; pUSD drained from users, later pledged for refund.
Jun 2026
$3.8M settlement reversal
A retrospective clarification
overturned a market resultacross 1,838 accounts.
Aug 2026
NYC Council investigation
Speaker Julie Menin opened a probe into marketing practices and alleged exposure to minors.
Ongoing
CFTC geo-block gaps
A 2022 settlement banned US users; VPN traffic still circumvents it, now under fresh scrutiny.
The money riding on the growth push
Coplan is raising roughly $1 billion in fresh capital at a $21 billion valuation. Donald Trump Jr.’s venture fund, 1789 Capital, is contributing about $300 million to the current round. The Intercontinental Exchange, owner of the New York Stock Exchange, disclosed in July that it holds a 22% stake worth $1.6 billion. To project discipline before a possible listing, Polymarket hired its first chief financial officer, Warren Jenson, who ran finance at Amazon. The stakes rose with each new name. Every backer that joins deepens the exposure that regulators, investors and the public now carry in how the company manages risk.
What the CFTC probe sets in motion
The CFTC’s investigation, opened after the February attack, has already ordered employees to preserve internal records. That step carries weight, because a preservation order usually lays the groundwork for document demands and testimony rather than closing a matter. Polymarket also still operates under a January 2022 CFTC settlement that carried a $1.4 million fine and a promise to bar US users, a ban that VPN traffic routinely defeats. For anyone weighing the current raise, the live question is whether that US activity, much of it technically prohibited, hardens into a liability a fine cannot cleanly settle.
One tension sits unresolved beneath the fundraising. ICE, a federally regulated exchange operator, now owns close to a quarter of a platform under active federal investigation, binding a mainstream market institution to the outcome of the CFTC’s work in a way that did not exist a year ago. How that link plays out, whether it nudges Polymarket toward formal US licensing or draws ICE’s own compliance posture into the conversation, will likely be tested long before any IPO filing reaches a regulator’s desk.
The post Polymarket Fraud Scandal Puts Its $21B IPO Plan Under Scrutiny appeared first on ETHNews.