洞察

analysis / market analysis

Polymarket $10M Fraud Attempt:Prediction Market为什么会继承Fintech全部Compliance Risk?

Wall Street Journal报道称,2026年2月Fraudster曾尝试利用被盗Debit Card经由Polymarket US转移至少1000万美元。事件说明Prediction Market一旦接入Card与Fiat Rail,就会继承传统Fintech的Payment Fraud、Identity与AML风险。

发布于 2026-09-21更新于 2026-09-21约 7 分钟

Polymarket最新最值得关注的Risk Story,并不是Prediction Market结算出错,也不是Smart Contract Exploit。

而是Debit Card Fraud。

Wall Street Journal在9月20日报道称,今年2月有Fraudster尝试使用被盗Debit Card,通过Polymarket美国Platform转移至少1000万美元。

据报道,攻击者把Stolen Card绑定到账户,Deposit、下单,然后尝试把资金Withdraw到Clean Card或自己控制的Account。

Polymarket Payment Processor Checkout.com在某个阶段据报拒绝了超过80%的Deposit,原因是Fraud。WSJ把Industry Normal Level对比为大约1%。

但这里必须非常精确:

1000万美元是Attempted Fraud Flow,不是确认损失1000万美元。

报道没有确认最终有多少资金真正离开Platform,其中一位Source表示大多数Fraudulent Deposit并没有成功。

Onchain Prediction Market也会有传统Fintech Risk

Prediction Market经常被理解成Crypto Trading Infrastructure。

但只要一个美国Retail Product接受Debit Card,它事实上也进入Payment Business。

Card Rail一接入,Attack Surface马上增加:

Stolen Card、Account Identity、Chargeback、Source of Funds、Withdrawal Routing、Device Risk、Account Recovery、Payment Processor Rule。

Blockchain并不会让这些传统Risk自动消失。

这正是Polymarket事件最重要的Lesson:

Onchain Settlement完全可以和Offchain Fraud同时存在。

Same-source Withdrawal为什么通常存在?

WSJ报道称,Polymarket曾取消一项规则:从某个Payment Source充值的资金,需要Withdraw回同一个Source。

这类Rule在金融平台里非常常见,因为它可以阻断一个经典Fraud / Laundering Path:

Stolen Card → Deposit → Transaction → Withdraw到Clean Account。

取消这个Rule可以改善UX。

但也会改变Fraud Model。

报道说部分Employee曾对这一变化提出AML/Fraud Risk担忧,而Company Executive认为其他Control足以覆盖。

这是典型Fintech Trade-off:

减少Friction可以提高Conversion。

但部分Friction本身就是Control。

Fraud Control本身就是Product Architecture

关键不是“某一个Rule一定不能取消”。

而是Fraud Prevention不能被当作Product做完以后再补的Compliance Layer。

对于真正Move Money的Retail Platform,Withdrawal Rule、Card Limit、Identity Verification、Transaction Monitoring本身都是Product Feature。

WSJ报道称,Polymarket后来限制可连接Debit Card数量,引入Riskified,并扩大Risk Staff。

这说明:

当Product本身在移动资金时,Growth Infrastructure和Compliance Infrastructure其实是同一套Infrastructure。

July Account Incident是另一种Risk

同一份报道还提到7月发生另一类事件,接近500个User受到影响。

据WSJ报道,攻击者利用Stolen Personal Information和Account Registration Weakness,能够进入Existing Customer Account以及Linked Payment Method,而不需要Victim原本的Username / Password。

Polymarket据报表示会Cover Lost Funds。

这和2月事件不同:

2月是Stolen Card Funding Fraud。

7月是Identity / Account Access Risk。

放在一起就很清楚:Prediction Market的Risk远不止Market Manipulation与Smart Contract Security。

Polymarket怎么回应?

Polymarket Spokesperson向WSJ表示,公司致力于准确、公平和透明的Market,并会配合Regulator和Law Enforcement。

公司也表示其Market-integrity Framework包含识别、Review与Respond Suspicious Activity的流程。

WSJ还报道称,Sullivan & Cromwell Review得出的结论是公司遵守Regulation;该信息来自熟悉Review的人士。

到5月,Fraud Rate据报已经回到更接近Industry Normal的水平。

因此今天不能简单把故事写成“Polymarket没有Compliance”。

更准确的研究角度是:

Prediction Market快速Scale时,传统Payment与Identity Risk会一起Scale。

Why it matters

Prediction Market正在成为更主流的Financial Product。

一旦它进入Bank Account、Card、Mobile App和受监管美国Venue,就会继承Fintech完整Risk Stack:

Payment Fraud → Identity Fraud → Chargeback → AML Exposure → Consumer Remediation → Regulatory Scrutiny。

真正能长期Scale的Platform,不一定是Market上架最快的那个。

而可能是能够在Liquidity增长时,同时控制Fraud Loss和Fake Identity的那个。

风险与反方观点

2月事件目前主要来自WSJ Investigation与其引用Source。

CFTC并没有公开确认Investigation;此前CFTC Spokesperson对The Block表示Neither Confirm nor Deny。

1000万美元不能写成Confirmed Loss。

WSJ关于CEO与内部讨论的内容也必须保留Attribution,不能写成CEXVia独立认定。

What to watch next

看是否出现正式CFTC Action、Polymarket是否披露Fraud / Chargeback Data,以及Card、Withdrawal与Account Recovery Control是否进一步调整。

真正值得长期观察的是:Platform能不能同时保留Fast Deposit / Withdrawal与足够强的Fraud Control。

FAQ

Polymarket损失了1000万美元吗?

不能这样写。WSJ报道的是至少1000万美元Attempted Fraud Flow,并没有确认全部成功被盗。

Attack怎么做?

据报道利用Stolen Debit Card充值、交易,并尝试Withdraw到Clean Card或Account。

Checkout.com发现了什么?

据报道某阶段超过80%的Deposit被判定为Fraud并拒绝。

Polymarket后来加了什么Control?

据报道包括限制Linked Debit Card数量、引入Riskified与增加Risk Staff。