Polymarket U.S. 今年其实出现过两条完全不同的 risk path,只是现在才被 WSJ 系统性披露出来:
- 2 月 stolen debit card fraud;
- 7 月 account-registration / identity takeover flaw。
这两条不能混成一句:
“Polymarket 被盗 1,000 万美元。”
因为 1,000 万美元描述的是 attempted fraud,不是 confirmed successful loss。
2 月:至少 $10M Stolen-Card Attempted Fraud
报道显示 fraudsters 利用 stolen debit card:
- 向 Polymarket U.S. deposit;
- 做 prediction-market bets;
- 再尝试 withdraw 到另一张“clean card”或自己控制的 account。
真正目的不是普通 betting,而是把 stolen-card value 洗到新的 payment endpoint。
Attempted $10M ≠ Lost $10M
WSJ investigation 报道的是:
At least $10M attempted
但并没有证明 1,000 万美元全部成功离开平台。
报道还称:
- 大部分 attempted deposits failed;
- 主要 attack volume 集中在约 7 个 users;
- 其中一个 account reportedly attempted ~4,000 deposits;
- Checkout.com 一度 reject >80% Polymarket U.S. deposits 为 fraud。
所以 CEXVia 的字段应该写:
Attempted Fraud Value — Not Confirmed Net Loss
Withdrawal Safeguard 为什么重要?
报道说 fraud campaign 造成 legitimate withdrawal backlog,让 compliance team 压力大增。
随后 Polymarket leadership 据报取消了一条 safeguard:
deposit 从哪个 payment source 来,withdrawal 就回哪个 source。
这类 closed-loop rule 未必是所有 prediction market 的 statutory requirement,但它是典型 AML / fraud control,因为 stolen card 很难把 value 转到另一张 clean card。
部分员工据报曾警告取消该 rule 会提高 laundering / fraud risk。
7 月:接近 500 个 Account 被 Target
late July 又是另一种完全不同的 incident。
报道描述一个 account-registration / identity matching flaw。
Attacker 如果拿到 victim 的 stolen personal data,例如:
- SSN;
- identity details;
可能在不知道 victim 原本 username / password 的情况下,取得:
- Polymarket account access;
- linked bank account access;
- linked debit-card access。
这属于非常严重的 account-recovery / identity-binding failure。
这次到底损失多少?
报道把 account incident 的 stolen amount 描述为“small”,但没有完整数字。
部分 users reportedly lost thousands of dollars。
Polymarket 对 WSJ 表示会:
Cover lost funds for affected users
所以正确状态是:
- compromise:reported;
- ~500 users targeted:reported;
- exact loss:unknown;
- reimbursement commitment:company-stated。
Polymarket 做了什么 Remediation?
Polymarket 表示此后已经加强:
- risk-management staff;
- infrastructure;
- product testing;
- fraud control。
报道说到 5 月,平台通过限制一个 account 可以绑定的 debit cards 等方式,让 fraud rate 回到 industry norms。
Sullivan & Cromwell Internal Investigation
WSJ 还报道称 outside law firm Sullivan & Cromwell 做过 internal investigation,并认为 Polymarket complied with regulations。
这条结论很重要,但不能等同于:
“系统没有 security/control problem。”
Regulatory compliance 与 operational-security quality 是两个不同问题。
CFTC Investigation 怎么写?
WSJ 之前报道称 CFTC 在调查 Polymarket,并要求员工 preserve records。
但 CFTC 的公开回应是:
Neither confirm nor deny
所以 CEXVia 必须写:
Media / Developing
不能写成 CFTC 已正式起诉 Polymarket。
为什么这是 Crypto Risk?
Polymarket 同时连接:
- regulated event-market contracts;
- debit-card rails;
- KYC identity;
- bank accounts;
- crypto settlement。
所以 platform security 不能只看 smart contract。
真实 attack surface 还包括:
- card fraud;
- identity theft;
- account recovery;
- payment processor;
- support workflow;
- bank linking。
Evidence Status
Major-Media Reporting
- ≥$10M attempted stolen-card fraud;
- payment processor >80% reject rate at one point;
- ~500 accounts targeted in separate July incident;
- stolen identity reportedly sufficient without existing username/password。
Company Statements Reported
- controls/infrastructure strengthened;
- affected losses to be covered;
- cooperation with regulators / law enforcement。
Developing
- February successful net loss;
- July exact loss;
- root cause;
- CFTC investigation status;
- reimbursement completion。
Risk Assessment
High Fraud / Identity / Compliance Risk。
事件发生在过去,但今天的新披露让 control failure 变得可量化,因此有独立搜索价值。
What to Watch Next
CFTC statement、payment-partner changes、fraud-loss accounting、reimbursement、identity remediation、enforcement / consent order。
FAQ
Polymarket 真的损失 $10M 吗?
不能这样写。$10M 是 attempted amount。
7 月多少用户被影响?
据报接近 500 accounts。
Attacker 需要 username/password 吗?
报道说不需要,stolen identity data 可能足够。
用户会赔吗?
Polymarket reportedly 表示会 cover affected loss。
CFTC investigation 已 confirmed?
没有,agency 不能 confirm/deny。
为什么 debit-card fraud 属于 crypto risk?
Crypto platform 同样依赖 fiat rails、identity 和 account recovery,这些都是 attack surface。