Polymarket最新最值得关注的Risk Story,并不是Prediction Market结算出错,也不是Smart Contract Exploit。
而是Debit Card Fraud。
Wall Street Journal在9月20日报道称,今年2月有Fraudster尝试使用被盗Debit Card,通过Polymarket美国Platform转移至少1000万美元。
据报道,攻击者把Stolen Card绑定到账户,Deposit、下单,然后尝试把资金Withdraw到Clean Card或自己控制的Account。
Polymarket Payment Processor Checkout.com在某个阶段据报拒绝了超过80%的Deposit,原因是Fraud。WSJ把Industry Normal Level对比为大约1%。
但这里必须非常精确:
1000万美元是Attempted Fraud Flow,不是确认损失1000万美元。
报道没有确认最终有多少资金真正离开Platform,其中一位Source表示大多数Fraudulent Deposit并没有成功。
Onchain Prediction Market也会有传统Fintech Risk
Prediction Market经常被理解成Crypto Trading Infrastructure。
但只要一个美国Retail Product接受Debit Card,它事实上也进入Payment Business。
Card Rail一接入,Attack Surface马上增加:
Stolen Card、Account Identity、Chargeback、Source of Funds、Withdrawal Routing、Device Risk、Account Recovery、Payment Processor Rule。
Blockchain并不会让这些传统Risk自动消失。
这正是Polymarket事件最重要的Lesson:
Onchain Settlement完全可以和Offchain Fraud同时存在。
Same-source Withdrawal为什么通常存在?
WSJ报道称,Polymarket曾取消一项规则:从某个Payment Source充值的资金,需要Withdraw回同一个Source。
这类Rule在金融平台里非常常见,因为它可以阻断一个经典Fraud / Laundering Path:
Stolen Card → Deposit → Transaction → Withdraw到Clean Account。
取消这个Rule可以改善UX。
但也会改变Fraud Model。
报道说部分Employee曾对这一变化提出AML/Fraud Risk担忧,而Company Executive认为其他Control足以覆盖。
这是典型Fintech Trade-off:
减少Friction可以提高Conversion。
但部分Friction本身就是Control。
Fraud Control本身就是Product Architecture
关键不是“某一个Rule一定不能取消”。
而是Fraud Prevention不能被当作Product做完以后再补的Compliance Layer。
对于真正Move Money的Retail Platform,Withdrawal Rule、Card Limit、Identity Verification、Transaction Monitoring本身都是Product Feature。
WSJ报道称,Polymarket后来限制可连接Debit Card数量,引入Riskified,并扩大Risk Staff。
这说明:
当Product本身在移动资金时,Growth Infrastructure和Compliance Infrastructure其实是同一套Infrastructure。
July Account Incident是另一种Risk
同一份报道还提到7月发生另一类事件,接近500个User受到影响。
据WSJ报道,攻击者利用Stolen Personal Information和Account Registration Weakness,能够进入Existing Customer Account以及Linked Payment Method,而不需要Victim原本的Username / Password。
Polymarket据报表示会Cover Lost Funds。
这和2月事件不同:
2月是Stolen Card Funding Fraud。
7月是Identity / Account Access Risk。
放在一起就很清楚:Prediction Market的Risk远不止Market Manipulation与Smart Contract Security。
Polymarket怎么回应?
Polymarket Spokesperson向WSJ表示,公司致力于准确、公平和透明的Market,并会配合Regulator和Law Enforcement。
公司也表示其Market-integrity Framework包含识别、Review与Respond Suspicious Activity的流程。
WSJ还报道称,Sullivan & Cromwell Review得出的结论是公司遵守Regulation;该信息来自熟悉Review的人士。
到5月,Fraud Rate据报已经回到更接近Industry Normal的水平。
因此今天不能简单把故事写成“Polymarket没有Compliance”。
更准确的研究角度是:
Prediction Market快速Scale时,传统Payment与Identity Risk会一起Scale。
Why it matters
Prediction Market正在成为更主流的Financial Product。
一旦它进入Bank Account、Card、Mobile App和受监管美国Venue,就会继承Fintech完整Risk Stack:
Payment Fraud → Identity Fraud → Chargeback → AML Exposure → Consumer Remediation → Regulatory Scrutiny。
真正能长期Scale的Platform,不一定是Market上架最快的那个。
而可能是能够在Liquidity增长时,同时控制Fraud Loss和Fake Identity的那个。
风险与反方观点
2月事件目前主要来自WSJ Investigation与其引用Source。
CFTC并没有公开确认Investigation;此前CFTC Spokesperson对The Block表示Neither Confirm nor Deny。
1000万美元不能写成Confirmed Loss。
WSJ关于CEO与内部讨论的内容也必须保留Attribution,不能写成CEXVia独立认定。
What to watch next
看是否出现正式CFTC Action、Polymarket是否披露Fraud / Chargeback Data,以及Card、Withdrawal与Account Recovery Control是否进一步调整。
真正值得长期观察的是:Platform能不能同时保留Fast Deposit / Withdrawal与足够强的Fraud Control。
FAQ
Polymarket损失了1000万美元吗?
不能这样写。WSJ报道的是至少1000万美元Attempted Fraud Flow,并没有确认全部成功被盗。
Attack怎么做?
据报道利用Stolen Debit Card充值、交易,并尝试Withdraw到Clean Card或Account。
Checkout.com发现了什么?
据报道某阶段超过80%的Deposit被判定为Fraud并拒绝。
Polymarket后来加了什么Control?
据报道包括限制Linked Debit Card数量、引入Riskified与增加Risk Staff。