BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Polymarket’s $10M Fraud Attempt Tests Its Blockchain Brand

Polymarket US accepts dollars through conventional payment systems, while the company’s international platform uses blockchain settlement. That separation is central to understanding what fai

AnonymousCryptoCompass newsroom
September 20, 2026
6 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for markets coverage.

Polymarket US accepts dollars through conventional payment systems, while the company’s international platform uses blockchain settlement. That separation is central to understanding what failed and what blockchain could never have prevented.

Key Takeaways

  • $10 million covers attempted, not completed losses.
  • The alleged scheme began with stolen cards.
  • Polymarket US uses dollars, not crypto collateral.
  • Withdrawal rules can block fraudulent cash-outs.
  • Blockchain records movement, not card ownership.

The $10 million figure describes attempted transactions

A payment processor warned Polymarket in February that its US platform was being flooded with deposits from stolen debit cards, according to a Wall Street Journal investigation published on September 20.

The cards were allegedly connected to thousands of newly created accounts. At one point, processor Checkout.com classified more than 80% of the deposits it handled as fraudulent and rejected them. The Journal compared that figure with an industry benchmark of approximately 1%.

Thieves attempted to move at least $10 million, but that is not the same as successfully withdrawing $10 million. The high rejection rate indicates that the processor stopped a substantial share of the transactions before they were completed.

The Journal’s account remains an investigative report, not a public enforcement finding. No regulator has established through a published order that Polymarket suffered a completed $10 million loss.

The withdrawal route created the opening

Stopping a suspicious deposit is only one part of card-fraud prevention. A platform must also control where the money can leave.

The Journal reported that Polymarket US initially required withdrawals to return to the payment source used for the deposit. The company later relaxed that restriction while trying to reduce delays for customers withdrawing their money.

How the alleged route worked 1. A stolen card funded an accountThe money entered through an ordinary debit-card transaction. 2. Funds became available for tradingDeposited money could be used to purchase event contracts. 3. A withdrawal was requestedThe user attempted to remove money from the platform. 4. The destination could be differentThe objective was to send the money to a card or account controlled by the fraudster.

Returning funds only to the original card can inconvenience legitimate customers when a card expires or an account closes. It also removes the easiest route for transferring stolen money into a different account.

Once another withdrawal destination is permitted, the platform must establish that both payment methods belong to the same verified customer. That decision depends on identity checks, processor controls and account monitoring.

Polymarket operates two different systems

The reported card activity affected Polymarket US. It did not originate on the company’s international blockchain platform.

Polymarket US operates through QCX, which the Commodity Futures Trading Commission lists as a designated contract market. An Associated Press review of Polymarket’s US return described the regulated operation as dollar-based and separate from its international crypto product.

Polymarket.com uses different infrastructure. Its documentation describes pUSD as an ERC-20 token on Polygon backed by USDC. Orders are matched through an order book, while completed trades are settled through blockchain contracts.

The practical limit: A ledger records what moved. Card and identity controls determine whether the person moving it had permission.

Both products operate under the same Polymarket brand. Problems in the dollar-based entrance can therefore affect confidence in the wider company even when the blockchain contracts themselves work as intended.

A ledger sees movement, not permission

A blockchain can record

  • Which addresses transferred assets
  • When each transaction occurred
  • Which contract processed the trade
  • Where onchain funds moved afterward

It cannot independently verify

  • Whether a payment card was stolen
  • Who controlled the customer account
  • Whether identity documents were genuine
  • Whether a withdrawal was authorized

The ledger may expose the path of funds after a transaction without proving that their original source was legitimate.

A separate July flaw reportedly exposed existing accounts

This was not a continuation of the February stolen-card operation. In late July, nearly 500 Polymarket US customers were affected by another attack that appeared to exploit an account-creation flaw, according to the Journal.

A person using an existing customer’s stolen personal information could allegedly create an account and gain access to the customer’s existing profile, including connected cards and bank accounts, without knowing the original username or password.

The Journal did not provide a complete loss figure. It said the overall amount was limited, although individual users described losing thousands of dollars. A Polymarket spokeswoman said the company would cover funds lost in the incident.

READ MORE: Ethereum Jumps Above $2,600, Reaches Highest Price Since January

CFTC oversight now faces a practical test

Registration as a designated contract market establishes regulatory supervision and operating responsibilities. It does not make card fraud, identity theft or account takeover technically impossible.

The case arrives as the CFTC is trying to advance digital-asset rules through powers it already holds. The agency recently sent a crypto market proposal to the White House after broader legislation stalled in Congress.

For Polymarket US, the relevant issue is no longer whether the CFTC has a relationship with the platform. It already does. The question is how the exchange’s customer checks, withdrawal procedures and response to unauthorized transactions meet the obligations attached to that status.

The Journal also attributed an alleged remark to CEO Shayne Coplan suggesting that the company should continue growing and deal with a fine if regulators intervened. The account came from people described as familiar with internal discussions and has not been established in a public regulatory finding.

Polymarket’s response emphasized new leadership appointments, infrastructure improvements and responsible expansion. The published statement did not directly address the alleged remark attributed to Coplan.

What potentially affected customers should check

  • Freeze an affected card through its bank or issuer.
  • Review account sessions and change compromised login credentials.
  • Remove unrecognized cards or withdrawal destinations.
  • Save supporting records, including statements, emails and transaction identifiers.
  • Report unauthorized activity separately to the payment provider and Polymarket.

Bank records, platform logs and blockchain transactions document different stages of an incident. Keeping all three may be necessary because no single record provides the complete sequence.

Polymarket’s growth now depends on controls users cannot see

Public markets and blockchain transactions allow outsiders to examine prices, trades and asset movements. Customers cannot inspect the private systems that approve deposits, connect identities or authorize withdrawals.

That makes Polymarket’s next test less visible than its trading volume. Reimbursement times, fraud disclosures, account-recovery procedures and any regulatory findings will provide better evidence of whether its controls have caught up with its expansion.

If Polymarket wants blockchain transparency to support institutional trust in its brand, it will need comparable clarity about the systems operating before and after the chain.

This article is provided for informational purposes only. Allegations attributed to external reporting may change as additional information or regulatory findings become available.

The post Polymarket’s $10M Fraud Attempt Tests Its Blockchain Brand appeared first on Coindoo.