Polymarket faces $10M fraud attempt, regulatory scrutiny

Polymarket's US platform faced a $10M fraud attempt in February. Over 80% of deposits were flagged as fraudulent. The incident led to regulatory scrutiny and internal reforms.

Polymarket's US platform faced a major fraud attempt in February. Fraudsters linked thousands of stolen debit cards to user accounts, attempting to move at least $10 million through bets and withdrawals. At the peak of the attack, payment processor Checkout.com flagged and rejected over 80% of deposits as fraudulent—far above the industry average of about 1%. This high rejection rate indicates that most fraudulent transactions were stopped before completion. Initially, Polymarket required withdrawals to be sent back to the original deposit source, limiting the movement of stolen funds. However, this safeguard was later relaxed. Compliance staff raised concerns, but leadership reportedly prioritized growth over regulatory compliance. The incident drew regulatory attention, including a CFTC investigation, and prompted Polymarket to strengthen its compliance and risk management teams. Security issues persisted, with a later engineering problem exposing hundreds of accounts to potential takeover.