WSJ: Polymarket hit by $10M fraud attempt as CEO prioritized growth over compliance
Fraudsters attempted to steal $10 million from Polymarket in February
Polymarket, a platform that allows users to bet on the outcome of real-world events, faced an attempt to steal at least $10 million earlier this year, according to a Wall Street Journal investigation published on September 20, 2026. The fraudsters targeted the company's U.S. platform in February by using stolen debit cards to deposit funds, place bets, and then attempt to withdraw the winnings to clean accounts. Checkout.com, the payment processor, identified more than 80% of Polymarket U.S. deposits as fraudulent at one point, a rate far higher than the industry average of roughly 1%. While the report did not confirm how much money was actually stolen, one source stated that most of the attempted deposits failed, and about seven users were responsible for the bulk of the attack, with one person attempting around 4,000 separate deposits.
CEO told staff to focus on growth, not compliance
During the incident, Polymarket CEO Shayne Coplan reportedly told employees to prioritize company growth and deal with potential regulatory fines later, downplaying the severity of the compliance risks. This approach coincided with leadership changes as Polymarket prepares for a possible public offering. Andrew Clifford, the U.S. chief compliance officer, resigned in April after submitting a report on fraud issues, and the company also fired its U.S. CEO, Justin Hertzberg. Sullivan & Cromwell, a law firm that conducted an internal investigation, concluded that Polymarket had complied with regulations, despite the internal warnings.
Company relaxed withdrawal rules and suffered a separate data breach
To manage a backlog of withdrawal requests from legitimate users, Polymarket removed a safeguard that required funds to be withdrawn to the same payment source they were deposited from. This rule is common at financial institutions and helps prevent money laundering. Although some employees warned that removing the rule could increase the risk of fraud, executives believed other systems were sufficient. In late July, a separate attack exposed nearly 500 user accounts due to a registration flaw. Attackers used stolen personal information, such as Social Security numbers, to access accounts and linked bank details without needing passwords. A Polymarket spokesperson said the company would cover lost funds from this breach, while The CFTC is currently investigating the firm's practices.
Key facts and figures
- At least $10 million theft was attempted in February 2026.
- Checkout.com rejected more than 80% of Polymarket deposits as fraudulent.
- One user attempted around 4,000 separate deposits.
- Nearly 500 accounts were compromised in a separate late-July attack.
- Polymarket is raising roughly $1 billion in funding at a $21 billion valuation.
What is confirmed vs. unconfirmed
It is confirmed that a large-scale fraud attempt occurred and that Polymarket's CEO, Shayne Coplan, is leading the company amid these compliance challenges. It is confirmed that the U.S. chief compliance officer resigned and the U.S. CEO was fired. It is confirmed that the Commodity Futures Trading Commission (CFTC) is investigating Polymarket. However, the exact amount of money successfully stolen from the $10 million attempt remains unconfirmed, as Polymarket did not respond to requests for that specific figure. While the WSJ reported that the CEO downplayed compliance concerns, Polymarket has not publicly commented on the specific internal recollections of that meeting.
Why this matters for prediction markets
This story highlights the growing tension between rapid growth and regulatory safety in the prediction market sector. As platforms like Polymarket seek large rounds of funding and consider going public, regulators are watching closely. The company’s relaxation of anti-money-laundering safeguards, specifically the rule requiring withdrawals to match deposit sources, suggests that high-volume growth can sometimes lead to reduced security measures, which puts user funds at risk. The successful compromise of nearly 500 accounts shows that even platforms with sophisticated systems can be vulnerable to data breaches involving personal information.