polymarket phone
Polymarket loosened anti-money-laundering controls amid $10M fraud attack using stolen debit cards
The prediction market's CEO reportedly told staff to prioritize growth over compliance, saying the company could deal with fines later.
Polymarket, the prediction market platform that became a cultural phenomenon during the 2024 US election cycle, faced a $10 million fraud attack in February 2026 after leadership deliberately weakened anti-money-laundering safeguards in pursuit of growth.
The scheme involved fraudsters creating thousands of new accounts linked to stolen debit cards, attempting to process at least $10 million in wagers before withdrawing the funds to accounts they controlled. Checkout.com, Polymarket’s payment processor, flagged and rejected more than 80% of the deposits as suspicious. For context, the typical industry rejection rate sits around 1%.
Growth over guardrails
According to a Wall Street Journal investigation, Polymarket’s internal compliance team had raised alarms about escalating fraud risks to CEO Shayne Coplan. His reported response: prioritize growth, and deal with potential fines later.
One of the most consequential decisions was removing a “same-source” withdrawal requirement. This is a standard industry safeguard that ensures funds can only be withdrawn back to the same account that deposited them. Polymarket employees reportedly warned that scrapping this rule would increase money laundering risks. Leadership removed it anyway.
The February 2026 attack exploited exactly the kind of vulnerability that the same-source rule was designed to prevent. Fraudsters deposited funds via stolen debit cards, placed wagers on the platform, and then attempted to withdraw winnings to accounts they controlled, effectively laundering the stolen funds through prediction market bets.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The cleanup and the fallout
By May 2026, Polymarket had implemented stricter controls that brought fraud rates back to normal levels. The company placed limits on the number of debit cards that could be linked to a single account and brought on Riskified, a fraud detection firm, to bolster its prevention capabilities.
Several senior compliance executives departed during this period, including US Chief Compliance Officer Andrew Clifford and US CEO Justin Hertzberg. Polymarket commissioned an internal review from Sullivan & Cromwell, the heavyweight law firm. That review concluded the company had remained compliant with applicable regulations.
Why prediction markets are a unique compliance challenge
Polymarket is a regulated US prediction-market platform that uniquely accepts fiat deposits via debit cards, differentiating it from its international crypto-based services. The platform had previously relaunched US access under the oversight of the CFTC following a 2022 settlement that resulted in a $1.4 million penalty due to previous unregistered activities.
The 80% rejection rate flagged by Checkout.com is staggering. When a payment processor is blocking four out of every five transactions as potentially fraudulent, the platform isn’t experiencing a minor glitch. It’s experiencing a systemic failure in its onboarding and verification processes.
What regulators are watching
The company has reportedly been preparing for potential growth initiatives, including a possible IPO. The CFTC has already taken enforcement actions in the space, and platforms that handle fiat deposits through regulated payment processors are subject to anti-money-laundering obligations under the Bank Secrecy Act.