Polymarket’s biggest recent risk story is not about an incorrect prediction-market resolution or a smart-contract exploit.
It is about debit cards.
The Wall Street Journal reported on September 20 that fraudsters attempted to move at least $10 million through Polymarket’s U.S. platform in February using stolen debit cards.
According to the Journal, users linked stolen cards to accounts, funded wagers and then tried to withdraw funds to clean cards or accounts they controlled.
Polymarket’s payment processor, Checkout.com, reportedly rejected more than 80% of deposits at one point as fraudulent. The Journal compared that with an industry norm of roughly 1%.
The report did not establish how much of the attempted $10 million actually left the platform. One person cited by the Journal said most attempted deposits failed.
That distinction is essential.
The $10 million figure represents attempted fraudulent flow, not a confirmed $10 million platform loss.
Prediction Markets Can Be Onchain and Still Have Traditional Fintech Risk
Crypto-native prediction markets are often discussed as trading infrastructure.
But a U.S. retail platform that accepts debit cards also becomes a payments business in practice.
The moment card rails enter the system, the attack surface changes.
The platform must manage:
- stolen cards;
- account identity;
- chargebacks;
- source-of-funds controls;
- withdrawal routing;
- device risk;
- account recovery;
- payment-processor rules.
None of those problems disappear because the underlying market is built with crypto technology.
This is the broader lesson from the reported Polymarket incident.
Onchain settlement can coexist with very offchain fraud.
Same-Source Withdrawals Are Friction for a Reason
The Journal reported that Polymarket later removed a safeguard requiring funds deposited from one payment source to be withdrawn to that same source.
That control is common in financial platforms because it makes a classic laundering pattern harder:
stolen card → deposit → transaction → withdrawal to a clean account.
Removing the rule improves user experience.
It also changes the fraud model.
The report says some employees warned that the change could create additional money-laundering and fraud risk, while company executives believed other controls were sufficient.
This is a common fintech tradeoff.
Every step removed from onboarding or withdrawal can improve conversion.
Some steps exist because they stop abuse.
Fraud Controls Become Product Architecture
The most important point is not whether one specific control should always be mandatory.
It is that fraud prevention cannot be treated as a compliance layer added after the product is built.
For a retail financial platform, withdrawal rules, account-linking limits, transaction monitoring and payment authentication are product features.
The Journal reported that Polymarket later limited the number of debit cards users could connect, added anti-fraud vendor Riskified and expanded risk staffing.
Those changes illustrate a broader principle:
growth infrastructure and compliance infrastructure are the same infrastructure when the product moves money.
The July Account Incident Adds a Second Risk Layer
The same Journal investigation also described a separate July event affecting nearly 500 users.
According to the report, attackers using stolen personal information could exploit an account-registration weakness and gain access to existing customer accounts and linked payment methods without knowing the victim’s existing username or password.
Polymarket said it would cover lost funds, according to the Journal.
The two incidents are different.
The February event centered on fraudulent funding with stolen cards.
The July event involved account access using stolen identity information.
Together they show why prediction-market risk cannot be reduced to market manipulation or smart-contract safety.
Identity and payments can be equally important.
What Polymarket Says
A Polymarket spokesperson told the Journal that the company is committed to accurate, fair and transparent markets and to cooperation with regulators and law enforcement.
The company said its market-integrity framework includes processes to detect, review and respond to suspicious activity.
The Journal also reported that a Sullivan & Cromwell review concluded the company had complied with regulations, according to people familiar with that review.
By May, fraud rates had reportedly returned closer to industry norms after additional controls were introduced.
Those points matter because the investigation describes alleged internal decisions and recollections from sources, while the company disputes the implication that it lacked appropriate compliance.
Why It Matters
Prediction markets are becoming mainstream financial products.
As they integrate bank accounts, cards, mobile apps and regulated U.S. venues, they inherit the full risk stack of fintech.
That includes risks crypto users often overlook:
payments fraud → identity fraud → chargebacks → AML exposure → consumer remediation → regulator scrutiny.
The most successful prediction-market platform will not necessarily be the one with the fastest market creation or lowest trading friction.
It may be the one that can scale liquidity without allowing fraud losses and false identities to scale with it.
The Broader CEX Comparison
The same framework applies to crypto exchanges.
An exchange can have secure custody and still fail at account security.
It can have strong KYC and still fail at payment fraud.
It can have excellent blockchain monitoring and still accept compromised cards or bank credentials.
That is why exchange verification should separate:
- custody security;
- account security;
- payment security;
- AML controls;
- market integrity;
- operational resilience.
Polymarket’s case is useful because it shows all of those layers converging in a product that is not traditionally described as an exchange.
Risks and Counterarguments
The February facts are based primarily on the Wall Street Journal investigation and people it cited.
The CFTC has not publicly confirmed an investigation; a spokesperson previously told The Block that the agency could neither confirm nor deny one.
The attempted $10 million should not be reported as a confirmed loss.
The CEO comments described by the Journal are attributed to people familiar with the events and should remain attributed rather than stated as independently established fact.
What to Watch Next
Watch for any formal CFTC action, additional disclosures from Polymarket, changes to card and withdrawal controls, and whether the company publishes fraud-loss or chargeback data.
Also watch the product design of Polymarket US as it scales.
The key question is whether the platform can preserve fast deposits and withdrawals without recreating the weak controls that traditional financial firms spent decades learning to build.
FAQ
Did Polymarket lose $10 million?
The Journal reported an attempted fraud flow of at least $10 million. It did not establish that $10 million was successfully stolen, and one source said most attempted deposits failed.
How did the fraud attempt work?
According to the Journal, attackers used stolen debit cards to fund accounts, make wagers and attempt withdrawals to clean cards or accounts.
What did the payment processor detect?
Checkout.com reportedly rejected more than 80% of deposits at one point as fraudulent.
Did Polymarket add new controls?
The Journal reported that Polymarket later limited linked debit cards, hired anti-fraud provider Riskified and expanded risk staffing.
Why does this matter for crypto?
It shows that crypto and prediction-market platforms can inherit traditional payment and identity fraud risks even when trading or settlement uses blockchain infrastructure.