A significant piece of Polymarket news broke this week involving a stolen-card scheme worth at least $10 million and a reported response from leadership that's raising real questions about compliance priorities.
Polymarket's own CEO allegedly told employees the company could simply pay a fine if regulators ever caught wind of the problem, rather than pulling back on growth.

Source: WuBloakchain on X
Per the Wall Street Journal's reporting, fraudsters began linking stolen debit cards to Polymarket US accounts back in February, attempting to move at least $10 million through a combination of wagers and withdrawals.
The scale of the problem became clear through the company's own payment processor data.
Here's what stood out:
| Detail | Figure |
| Amount fraudsters attempted to move | $10 million+ |
| Peak fraudulent deposit rate | Over 80% |
| Industry-standard fraud rate | Roughly 1% |
| Payment processor involved | Checkout.com |
| The month the fraud began | February |
That 80% figure is genuinely striking; it means at the peak of this scheme, the overwhelming majority of deposits flowing through Polymarket's payment processor were flagged as fraudulent, a rate roughly 80 times higher than what's typical for the payments industry.
This is really the core of today's Polymarket news. According to multiple people familiar with internal discussions cited by the Journal, compliance staff raised concerns directly with CEO Shayne Coplan after the surge in rejected transactions became apparent.
His reported response was to keep prioritizing growth and treat any eventual regulatory fine as a manageable cost of doing business rather than a reason to slow down or tighten controls immediately.
A few additional details from the reporting worth understanding:
Polymarket had originally required withdrawals to return to the same payment source used for deposits, a safeguard that limited how easily fraudsters could route stolen funds elsewhere
That safeguard was later relaxed as the company worked to smooth out the deposit and withdrawal experience for legitimate users
Fraud rates stayed elevated for months before falling back closer to industry norms by May
To Polymarket's credit, the fraud rate didn't stay at 80% indefinitely.
By May, rates had returned closer to normal levels after the company restricted how many debit cards a single user could connect to their account and brought on Riskified as a dedicated antifraud contractor.
That said, the timeline matters here; months passed between when the fraud was first identified internally and when meaningful fixes were actually implemented.
Adding to the pattern, Polymarket faced an entirely separate security problem in July, this time affecting close to 500 users.
An engineering flaw reportedly let attackers who had stolen personal information access existing accounts and their linked payment methods. Polymarket has said it would cover the lost funds from that particular incident.
Combined with the February fraud scheme, this creates a picture of a platform that experienced two distinct security failures within the same year, both tied to how quickly it was scaling its US operations.
This isn't Polymarket's first encounter with US regulators either. The company previously settled with the CFTC in 2022, paying a $1.4 million penalty for operating unregistered event markets, a settlement that also came with restrictions barring US users at the time.
Given that history, a fresh fraud scandal involving stolen cards and an internal decision to prioritize growth over immediate compliance action carries real weight.
Polymarket's own Market Integrity and Transparency pages describe the company's general framework for detecting, reviewing, and responding to suspicious activity, and a company spokesperson used nearly identical language when responding to the Journal, saying Polymarket has procedures in place to detect and respond to suspicious activity and remains committed to working with regulators and law enforcement.
This round of Polymarket news lands at a particularly sensitive moment, as the company is reportedly seeking $1 billion in new funding at a valuation near $21 billion, with Intercontinental Exchange and Donald Trump Jr.'s 1789 Capital both already invested.
Whether this fraud disclosure and the reported leadership response affect that fundraising or draw fresh regulatory attention given the company's prior CFTC settlement remains to be seen.
What's clear from the reporting so far is that internal concerns about fraud were raised, and growth was reportedly prioritized over an immediate, aggressive response.
This article is for educational and informational purposes only and should not be considered financial or investment advice. Always conduct your own research before making investment decisions.