WSJ: Polymarket Dropped a Laundering Control as Fraudsters Ran $10m Through It
By Antonina Tupikova · Founder, iGaming Times3 min read
A processor was rejecting more than 80% of Polymarket's US deposits as fraudulent in February, the compliance chief resigned after writing it up, and the chief executive told staff to keep growing and pay any fine later, the Journal reports. The CFTC is investigating, and the company is raising $1 billion.
- Fraudsters attached stolen debit cards to thousands of Polymarket US accounts from February, placed trades and tried to withdraw the proceeds to accounts they controlled, in an attack the Wall Street Journal puts at about $10 million attempted, according to an investigation published on Saturday
- Payment processor Checkout.com at one point rejected more than 80% of the deposits it handled for Polymarket US as fraudulent, against an industry norm near 1%, the Journal reported, with roughly seven users behind most of it and one attempting about 4,000 deposits
- Chief executive Shayne Coplan told employees to prioritise growth and address regulatory penalties later, and leadership dropped a rule requiring withdrawals to go back to the source of the deposit, the Journal said, citing current and former employees
- US chief compliance officer Andrew Clifford resigned in April after sending executives a report on the fraud; US chief executive Justin Hertzberg was later fired and the heads of US regulation and anti-money-laundering also left
- The Commodity Futures Trading Commission is investigating and has told employees to preserve records, the Journal reported, as Polymarket raises about $1 billion at a $21 billion valuation
The Growth Story Had a Fraud Problem Nobody Outside Was Told About
Polymarket's US exchange faced a sustained stolen-card attack in the months after its relaunch, and its leadership responded by loosening a control rather than tightening one, according to a Wall Street Journal investigation published on Saturday and drawing on current and former employees and internal records. Beginning in February, fraudsters linked stolen debit cards to thousands of Polymarket US accounts, deposited, traded and tried to withdraw the proceeds to accounts they controlled, in an attack the Journal sizes at about $10 million attempted. It did not establish how much succeeded; one person cited said most attempted deposits failed.
The company's payment processor, Checkout.com, raised the alarm. At one point it rejected more than 80% of the deposits it handled for Polymarket US as fraudulent, the Journal reported, against a rate near 1% that is typical across the industry. Roughly seven users accounted for the bulk of the activity, and one attempted about 4,000 separate deposits.

Chief executive Shayne Coplan's response, the Journal said, was to tell employees to keep growing and to deal with any regulatory fine later. As fraudulent deposits piled up alongside a backlog of legitimate withdrawal requests, leadership dropped a requirement that funds deposited from one payment source be withdrawn to that same source. That rule is not mandated for prediction markets, but it is standard at financial institutions and is the specific safeguard that prevents stolen-card proceeds being moved to a clean account. Employees warned the change invited money laundering; executives said existing rules were sufficient, according to the report.
The personnel consequences followed within months. Polymarket US chief compliance officer Andrew Clifford resigned in April after submitting a detailed report on the fraud to executives. The company then fired US chief executive Justin Hertzberg, and its heads of US regulation and anti-money-laundering also departed. An internal investigation by law firm Sullivan & Cromwell concluded Polymarket had complied with applicable regulations, the Journal reported, citing people familiar with the matter. Fraud rates returned to industry norms by May after the platform capped the number of debit cards a user could link.
A second, separate incident came in late July: a registration flaw allowed attackers who held a victim's Social Security number to take over roughly 500 existing accounts, with their linked bank accounts and cards, without any password, the Journal said. Polymarket said it would cover customer losses. The CFTC is investigating the company and has instructed employees to preserve records relating to the fraud attack and other matters, according to the report. A Polymarket spokesperson told the Journal its "market integrity framework includes processes to detect, review and respond to suspicious activity".
The disclosures land in the middle of Polymarket's largest fundraising. The company is raising about $1 billion at a $21 billion valuation, with 1789 Capital, the firm associated with Donald Trump Jr., reported to be adding about $300 million to $200 million already invested, and Coplan has discussed a 2027 listing. It has hired former Amazon finance chief Warren Jenson as its first chief financial officer. Polymarket US relaunched in beta in late 2025 after returning to the American market under CFTC registration, and in August referred dozens of its own traders to the Justice Department.
The Rule That Was Dropped Is the One a Gambling Regulator Would Have Required
Closed-loop withdrawals, money going back to the instrument it came from, are a standard condition of licensed gambling operators' payment arrangements in most regulated markets, because they are the control that makes a stolen card useless as a laundering tool. They are not a CFTC requirement for a designated contract market, which is precisely the gap prediction markets have argued makes them a different kind of business. The Journal's account is of a company facing a live attack, an 80% rejection rate at its processor and a withdrawal backlog, and choosing to remove that control to keep money moving. Whatever Sullivan & Cromwell concluded about compliance with the rules that applied, the episode is the clearest illustration yet of what the rules that apply do not cover, and every state attorney general with a cease-and-desist letter in the post will read it that way.

A CFTC Investigation and a $21 Billion Round Are Now the Same Story
The regulator that has spent a year suing states on prediction markets' behalf is, on this report, investigating one of the two largest of them for how it handled fraud, and has issued a preservation instruction, which signals something more than a routine enquiry. Investors putting $1 billion into the company at $21 billion, and a founder discussing a 2027 flotation, now have a disclosure question that did not exist on Friday. The company's answer so far is a spokesperson's sentence about a framework. The compliance chief who wrote the report is gone, and so is the US chief executive, which tells the market that the internal account of events was serious enough to act on even if the external one is not.
The Timing Could Not Be Worse for the Industry's Argument
Polymarket and Kalshi have told courts, legislators and now state election officials that federal oversight makes them safer than the state-licensed sportsbooks they compete with. That argument survives a fraud attack; every operator has them. It does not survive easily the reported instruction to keep growing and pay the fine later, because that is the exact behaviour state regulators exist to prevent and the exact behaviour the exchanges say federal registration precludes. Missouri's attorney general sent six exchanges cease-and-desist letters on Friday citing age controls; the next letter from any state will cite this.
The Journal's reporting is attributed, and the company's response addresses its framework rather than the events. The people who would know best have left the building.


