Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Prediction Markets

WSJ: Polymarket Dropped a Laundering Control as Fraudsters Ran $10m Through It

Antonina TupikovaBy Antonina Tupikova · Founder, iGaming Times3 min read
Polymarket Launches Full US iOS Exchange in Long-Awaited Return

A processor was rejecting more than 80% of Polymarket's US deposits as fraudulent in February, the compliance chief resigned after writing it up, and the chief executive told staff to keep growing and pay any fine later, the Journal reports. The CFTC is investigating, and the company is raising $1 billion.

  • Fraudsters attached stolen debit cards to thousands of Polymarket US accounts from February, placed trades and tried to withdraw the proceeds to accounts they controlled, in an attack the Wall Street Journal puts at about $10 million attempted, according to an investigation published on Saturday
  • Payment processor Checkout.com at one point rejected more than 80% of the deposits it handled for Polymarket US as fraudulent, against an industry norm near 1%, the Journal reported, with roughly seven users behind most of it and one attempting about 4,000 deposits
  • Chief executive Shayne Coplan told employees to prioritise growth and address regulatory penalties later, and leadership dropped a rule requiring withdrawals to go back to the source of the deposit, the Journal said, citing current and former employees
  • US chief compliance officer Andrew Clifford resigned in April after sending executives a report on the fraud; US chief executive Justin Hertzberg was later fired and the heads of US regulation and anti-money-laundering also left
  • The Commodity Futures Trading Commission is investigating and has told employees to preserve records, the Journal reported, as Polymarket raises about $1 billion at a $21 billion valuation

The Growth Story Had a Fraud Problem Nobody Outside Was Told About

Polymarket's US exchange faced a sustained stolen-card attack in the months after its relaunch, and its leadership responded by loosening a control rather than tightening one, according to a Wall Street Journal investigation published on Saturday and drawing on current and former employees and internal records. Beginning in February, fraudsters linked stolen debit cards to thousands of Polymarket US accounts, deposited, traded and tried to withdraw the proceeds to accounts they controlled, in an attack the Journal sizes at about $10 million attempted. It did not establish how much succeeded; one person cited said most attempted deposits failed.

The company's payment processor, Checkout.com, raised the alarm. At one point it rejected more than 80% of the deposits it handled for Polymarket US as fraudulent, the Journal reported, against a rate near 1% that is typical across the industry. Roughly seven users accounted for the bulk of the activity, and one attempted about 4,000 separate deposits.

iGaming glossary: 430+ terms explained.

Chief executive Shayne Coplan's response, the Journal said, was to tell employees to keep growing and to deal with any regulatory fine later. As fraudulent deposits piled up alongside a backlog of legitimate withdrawal requests, leadership dropped a requirement that funds deposited from one payment source be withdrawn to that same source. That rule is not mandated for prediction markets, but it is standard at financial institutions and is the specific safeguard that prevents stolen-card proceeds being moved to a clean account. Employees warned the change invited money laundering; executives said existing rules were sufficient, according to the report.

The personnel consequences followed within months. Polymarket US chief compliance officer Andrew Clifford resigned in April after submitting a detailed report on the fraud to executives. The company then fired US chief executive Justin Hertzberg, and its heads of US regulation and anti-money-laundering also departed. An internal investigation by law firm Sullivan & Cromwell concluded Polymarket had complied with applicable regulations, the Journal reported, citing people familiar with the matter. Fraud rates returned to industry norms by May after the platform capped the number of debit cards a user could link.

A second, separate incident came in late July: a registration flaw allowed attackers who held a victim's Social Security number to take over roughly 500 existing accounts, with their linked bank accounts and cards, without any password, the Journal said. Polymarket said it would cover customer losses. The CFTC is investigating the company and has instructed employees to preserve records relating to the fraud attack and other matters, according to the report. A Polymarket spokesperson told the Journal its "market integrity framework includes processes to detect, review and respond to suspicious activity".

The disclosures land in the middle of Polymarket's largest fundraising. The company is raising about $1 billion at a $21 billion valuation, with 1789 Capital, the firm associated with Donald Trump Jr., reported to be adding about $300 million to $200 million already invested, and Coplan has discussed a 2027 listing. It has hired former Amazon finance chief Warren Jenson as its first chief financial officer. Polymarket US relaunched in beta in late 2025 after returning to the American market under CFTC registration, and in August referred dozens of its own traders to the Justice Department.

The Rule That Was Dropped Is the One a Gambling Regulator Would Have Required

Closed-loop withdrawals, money going back to the instrument it came from, are a standard condition of licensed gambling operators' payment arrangements in most regulated markets, because they are the control that makes a stolen card useless as a laundering tool. They are not a CFTC requirement for a designated contract market, which is precisely the gap prediction markets have argued makes them a different kind of business. The Journal's account is of a company facing a live attack, an 80% rejection rate at its processor and a withdrawal backlog, and choosing to remove that control to keep money moving. Whatever Sullivan & Cromwell concluded about compliance with the rules that applied, the episode is the clearest illustration yet of what the rules that apply do not cover, and every state attorney general with a cease-and-desist letter in the post will read it that way.

iGaming glossary: 430+ terms explained.

A CFTC Investigation and a $21 Billion Round Are Now the Same Story

The regulator that has spent a year suing states on prediction markets' behalf is, on this report, investigating one of the two largest of them for how it handled fraud, and has issued a preservation instruction, which signals something more than a routine enquiry. Investors putting $1 billion into the company at $21 billion, and a founder discussing a 2027 flotation, now have a disclosure question that did not exist on Friday. The company's answer so far is a spokesperson's sentence about a framework. The compliance chief who wrote the report is gone, and so is the US chief executive, which tells the market that the internal account of events was serious enough to act on even if the external one is not.

The Timing Could Not Be Worse for the Industry's Argument

Polymarket and Kalshi have told courts, legislators and now state election officials that federal oversight makes them safer than the state-licensed sportsbooks they compete with. That argument survives a fraud attack; every operator has them. It does not survive easily the reported instruction to keep growing and pay the fine later, because that is the exact behaviour state regulators exist to prevent and the exact behaviour the exchanges say federal registration precludes. Missouri's attorney general sent six exchanges cease-and-desist letters on Friday citing age controls; the next letter from any state will cite this.

The Journal's reporting is attributed, and the company's response addresses its framework rather than the events. The people who would know best have left the building.

Comments

Be the first to comment.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.