TLDR: Polymarket faced at least $10M in stolen-card fraud, testing safeguards behind its rapid U.S. expansion. Checkout.com rejected over 80% of deposits as fraudulent at one point, versus an
TLDR:
- Polymarket faced at least $10M in stolen-card fraud, testing safeguards behind its rapid U.S. expansion.
- Checkout.com rejected over 80% of deposits as fraudulent at one point, versus an industry rate near 1%.
- Fraud levels stayed elevated until May, prompting debit-card limits and the hiring of fraud firm Riskified.
- The CFTC is reportedly investigating the February episode as Polymarket expands its regulated U.S. business.
Polymarket’s fast-growing U.S. prediction-market operation faced a major test in February after fraudsters attempted to move at least $10 million using stolen debit cards. The Wall Street Journal reported attackers linked stolen cards to Polymarket US accounts, placed wagers, then routed proceeds toward clean cards or controlled accounts.
The scale of the activity quickly strained payment controls. Checkout.com reportedly rejected more than 80% of deposits it processed at one point as fraudulent. That rate stood far above the roughly 1% industry level cited by the Journal, turning the episode into a significant operational problem.
$10M Fraud Attempt Tests Polymarket’s U.S. Growth Controls
Current and former employees told the Journal that compliance staff escalated the surge to Chief Executive Shayne Coplan. According to those sources, Coplan urged the company to keep expanding and suggested paying a fine if regulators later intervened.
However, Polymarket has not publicly confirmed that account. The timing matters as the company was building a regulated U.S. presence. CFTC records show QCX LLC began operating under the Polymarket US name after receiving designated contract market status on July 9, 2025.
That status places the platform inside a federal derivatives framework while its business continues expanding. The company also has earlier enforcement history with the regulator. In 2022, the CFTC ordered its operator to pay $1.4 million for offering event-based binary options without required registration.
The February episode therefore emerged against an already documented compliance history. Fraud levels remained elevated for months, according to the Journal, before moving closer to industry norms by May. The company then reduced the number of debit cards users could connect and hired fraud-prevention firm Riskified.
Tighter Safeguards Follow Months of Elevated Fraud
The Information separately reported that Visa pushed Checkout.com to strengthen controls after rising chargebacks and failed transactions. Riskified has also warned that prediction markets face account takeovers, rapid-withdrawal schemes, and card-number attacks.
The Journal later reported another security incident affecting nearly 500 users, adding further pressure on the platform’s risk systems. Meanwhile, the CFTC is investigating the company, according to the newspaper.
Employees were instructed to preserve records tied to the February fraud episode and other matters, the Journal reported. The agency has not publicly detailed that reported investigation. Polymarket says it uses systems to identify suspicious activity and cooperates with regulators and law enforcement.
Its market-integrity page says more than 90 accounts were referred to authorities, alongside over 315 wallet details. The February fraud attempt places those safeguards under closer scrutiny as the company expands its regulated U.S. business and considers a potential public listing.
The post Polymarket’s $10M Fraud Attempt Puts Its Rapid U.S. Growth Under Scrutiny appeared first on Blockonomi.