Polymarket US Platform Faces Alleged $10M Fraud Campaign Involving Stolen Cards

Polymarket’s U.S. app reportedly allowed users to receive up to $50,000 per day in “instant buying power,” letting them trade before debit-card deposits had cleared. That feature accelerated legitimate onboarding but also gave fraudsters access to wagers before banks could reverse stolen-card transactions.
The incident was specific to Polymarket’s U.S. payment infrastructure: the U.S. platform accepts dollars through conventional card and banking systems, while Polymarket’s international platform uses blockchain settlement. The fraud therefore began at the payment gateway rather than onchain.
Polymarket faced a separate July security problem in which an engineering issue exposed nearly 500 accounts to potential takeover, adding to operational concerns surrounding its U.S. expansion.
A separate investigation found that Polymarket paid creators to promote simulated trades through replicas of its trading interface, prompting the company to overhaul its marketing practices.
The company expanded its senior risk and compliance leadership after the incidents: Megan McGrath, formerly Robinhood’s chief compliance officer, became chief compliance officer of Polymarket US; former Nasdaq executive Paul Jordan became chief risk officer; and former FBI official and Coinbase investigator Shana Bautista became global head of investigations and intelligence.
Polymarket's U.S. platform faced a major fraud attack in February when criminals linked stolen debit cards to thousands of accounts and attempted to steal at least $10 million through fake wagers WSJ. At the peak, payment processor Checkout.com rejected more than 80% of Polymarket deposits as fraudulent — roughly 80 times the industry average of about 1% WSJ. The incident exposed a critical flaw: Polymarket's "instant buying power" feature let users trade with up to $50,000 per day before their debit-card deposits had even cleared, giving fraudsters a window to place bets before banks could reverse the stolen transactions Cryptopolitan.
The company responded by restricting linked debit cards, hiring outside fraud monitors, and overhauling its compliance team. But internal emails show CEO Shayne Coplan allegedly told staff to keep pushing growth and suggested the company could simply pay regulatory fines if needed WSJ — a remark Polymarket has not confirmed. The fraud incident is now one of several operational crises that have shadowed Polymarket's U.S. expansion, including a security breach and marketing misconduct investigations.
Polymarket U.S. offers new users up to $50,000 per day in "instant buying power" — the ability to trade immediately after linking a debit card, even before the deposit fully clears Finance Yahoo. For honest users, this speeds onboarding. For fraudsters, it created a perfect opportunity: link a stolen card, trade large amounts, and try to withdraw before the bank flags the theft and reverses the transaction WSJ.
The scheme exploited a gap between Polymarket's settlement speed and traditional banking timelines. One fraudster alone attempted over 4,000 deposits WEEX. Checkout.com's fraud rejection rate hit 80%, far above the roughly 1% industry baseline WSJ. Even after the company relaxed a rule that required withdrawals to return to the original payment source, fraudsters continued exploiting the flaw.
Polymarket operates two separate platforms with opposite payment models. Outside the U.S., the platform uses blockchain settlement — deposits and withdrawals happen onchain, which is harder for traditional card fraudsters to exploit WEEX. The U.S. platform, by contrast, accepts dollars through conventional debit cards and bank transfers routed through a traditional payment processor Cryptopolitan.
This friction point — the junction between stolen cards and Polymarket's instant-buying system — is where the February attack occurred. The fraud began at the payment gateway, not onchain. It revealed that U.S. dollar banking, faster and more accessible than crypto, also brings greater exposure to card-fraud schemes.
Current and former Polymarket employees told WSJ that compliance staff raised red flags about fraud risks with CEO Shayne Coplan. According to those accounts, Coplan urged the company to keep expanding and said Polymarket could absorb regulatory fines if they came WSJ. Polymarket has not confirmed this characterization of the CEO's comments.
The alleged tension between compliance and growth reflects a broader pattern at fintech startups: regulators and risk teams flag problems; executives prioritize expansion. In Polymarket's case, the gamble backfired. The February fraud campaign forced the company to act: restrict card linking, hire external fraud-monitoring vendors, and expand its in-house compliance and risk staff PYMNTS.
The $10 million fraud attempt was not Polymarket's only U.S. crisis. In July, an engineering error exposed roughly 500 user accounts to potential takeover, revealing gaps in security infrastructure WSJ. A separate investigation also found that Polymarket had paid creators to promote simulated trades using fake versions of its trading interface — a deceptive marketing practice the company later shut down WSJ.
In response, Polymarket brought in senior compliance talent: Megan McGrath from Robinhood as chief compliance officer, former Nasdaq executive Paul Jordan as chief risk officer, and ex-FBI investigator and Coinbase employee Shana Bautista as global head of investigations Cryptopolitan. These hires signal the company is taking operational risk seriously, but they also underscore how much remediation work remains.
Publishers
29
Articles
12
Reach
41