A new investigation has disclosed two distinct fraud and account-security incidents at Polymarket’s U.S.-facing platform in 2026.
They should be analysed separately:
- a February stolen-debit-card fraud campaign involving at least $10 million in attempted activity;
- a late-July account-registration flaw that reportedly exposed nearly 500 existing users.
Neither incident should be compressed into the headline “Polymarket lost $10 million.”
February: at least $10 million in attempted stolen-card fraud
According to current reporting on the Wall Street Journal investigation, fraudsters began using stolen debit cards to fund Polymarket U.S. accounts in February.
The reported pattern was:
- deposit funds using a stolen card;
- place prediction-market bets;
- withdraw proceeds to a different “clean” card or controlled account.
The goal was not simply betting profit. It was a laundering/fraud flow designed to move stolen-card value into a new payment endpoint.
Attempted amount versus successful loss
The report describes at least:
$10 million in attempted theft/fraud.
It does not establish that $10 million was successfully withdrawn.
One source cited in the investigation said most attempted deposits failed.
The report also said:
- around seven users were responsible for most of the attack;
- one user attempted roughly 4,000 deposits;
- Polymarket’s payment processor at one stage rejected more than 80% of deposits as fraudulent.
CEXVia therefore records the $10 million number as:
Attempted Fraud Value — Not Confirmed Net Loss.
Payment controls and withdrawal safeguards
The fraud campaign reportedly created a backlog for legitimate withdrawals and pressure on Polymarket’s compliance team.
The investigation says Polymarket leadership later dropped a control requiring funds deposited from one payment source to be withdrawn to the same source.
That type of closed-loop withdrawal rule is not necessarily mandatory for every prediction market, but it is a common anti-fraud / anti-money-laundering control because it makes stolen-card laundering harder.
The report says some employees warned that removing the control could increase risk.
July: separate account-registration flaw
A separate incident in late July reportedly targeted nearly:
500 Polymarket users.
The reported vulnerability was an account-registration / identity-matching problem.
Attackers with stolen personal information—such as a victim’s Social Security number—could reportedly create or claim access in a way that exposed the victim’s existing account, linked bank accounts and debit cards.
Critically, attackers reportedly did not need the victim’s existing username or password.
User loss from the July incident
The amount stolen in the account-takeover incident was described as small, but no reconciled figure was published in the reporting reviewed.
Some users reportedly lost thousands of dollars.
Polymarket told the Journal that it would cover affected-user losses.
Therefore the correct status is:
- account compromise: reported;
- affected population: ~500 reported;
- exact confirmed loss: unknown;
- reimbursement commitment: company-stated.
Polymarket’s response
Polymarket says it is committed to fair and transparent markets and cooperation with regulators and law enforcement.
The company says it has improved:
- risk-management staffing;
- product testing;
- payment/fraud controls;
- infrastructure.
The report says fraud rates returned to industry norms by May after controls including limits on the number of debit cards users could link.
Internal investigation and compliance conclusion
Reporting says outside law firm Sullivan & Cromwell conducted an internal investigation and concluded that Polymarket had complied with regulations.
That finding is important but does not erase operational-control failures.
Regulatory compliance and security adequacy are related but not identical questions.
CFTC investigation status
The Journal previously reported that the CFTC was investigating Polymarket and that employees were instructed to preserve records related to fraud and other matters.
The CFTC has said it can neither confirm nor deny an investigation.
CEXVia therefore labels the regulatory-investigation claim:
Media / Developing.
It should not be presented as a publicly confirmed enforcement case.
Why this matters for prediction markets and crypto platforms
Polymarket sits at the intersection of:
- regulated derivatives/event markets;
- card payments;
- KYC identity systems;
- bank-linked accounts;
- crypto settlement infrastructure.
Fraud controls must therefore cover more than on-chain wallets.
A platform can have secure blockchain settlement while still suffering large losses through:
- stolen cards;
- identity theft;
- account recovery;
- payment processors;
- bank-linking logic;
- support operations.
Evidence Status
Major-Media Reporting
- ≥$10M attempted stolen-card fraud in February.
- Payment processor rejection rate exceeded 80% at one point.
- Separate late-July incident targeted nearly 500 accounts.
- Identity data could reportedly be used without existing credentials.
Company Statements Reported
- Polymarket says controls and infrastructure were strengthened.
- Polymarket says affected account losses will be covered.
- Polymarket says it cooperates with regulators/law enforcement.
Developing
- Exact successful loss from February fraud.
- Exact loss from July account takeover.
- Full vulnerability root cause.
- CFTC investigation status/outcome.
- User reimbursement completion.
Risk Assessment
High fraud / identity / compliance risk.
The incidents are historical but newly disclosed, and they expose material control weaknesses relevant to U.S. platform scaling.
What to Watch Next
CFTC statements, payment-partner changes, fraud-loss accounting, affected-user reimbursement, identity-system remediation and any enforcement or consent order.
FAQ
Did Polymarket lose $10 million?
The report says at least $10M was attempted; it does not establish $10M in successful loss.
How many accounts were targeted in July?
Nearly 500, according to the report.
Did attackers need usernames and passwords?
The reported flaw allegedly allowed takeover using stolen identity information without the existing credentials.
Will affected users be reimbursed?
Polymarket reportedly said it would cover account-incident losses.
Is the CFTC investigation confirmed?
The investigation has been reported, but the CFTC says it can neither confirm nor deny it.
Why is this a crypto risk issue if stolen cards were involved?
Crypto/prediction platforms depend on fiat payment rails, identity systems and account recovery as well as blockchain security.