Sign up
Subscribe
Home / news / Polymarket Faces CFTC Review After $10 Million Card Fraud Incidents in 2026
news

Polymarket Faces CFTC Review After $10 Million Card Fraud Incidents in 2026

Polymarket, the U.S. prediction-market platform, is now under review by the CFTC after a February fraud episode involving at least $10 million in attempted transactions. For PSPs and risk teams, the useful bit is not the headline number alone: the company had to loosen a withdrawal rule, then later plug the gap with tighter card controls and an anti-fraud vendor.

  1. According to The Wall Street Journal, the February attack hit Polymarket US through stolen debit cards: fraudsters registered accounts at scale, funded them with stolen cards, placed bets, and then tried to withdraw the money to their own accounts. The attempted volume reached at least $10 million, with most of the activity concentrated in just seven users, including one account that made about 4,000 deposit attempts.
  2. Checkout.com warned Polymarket about the problem. At peak moments, it flagged more than 80% of deposits on the platform as fraudulent, compared with a normal industry fraud rate of 1%. That is the kind of mismatch that stops being a “fraud spike” and starts becoming a payments architecture problem.
  3. Polymarket also faced a backlog of withdrawals. To clear it, management отменed a rule requiring users to withdraw funds via the same method used for deposit, despite internal warnings that the change would make it easier to cash out stolen cards and raise money-laundering risk. WSJ sources said CEO Shayne Coplan pushed the team to focus on growth and was prepared to pay a fine later if regulators found violations.
  4. By May, fraud levels were brought back to roughly the industry norm after Polymarket limited the number of cards per account and added Riskified for fraud prevention. But at the end of July, a new attack followed: a vulnerability in the registration system let fraudsters enter the personal data of real Polymarket customers and access their accounts, affecting almost 500 users.
  5. The February episode also had personnel consequences. Polymarket US compliance director Andrew Clifford prepared an internal report on the issues and left the company, and later Justin Herzberg, head of the U.S. division, was dismissed. A prior review by Sullivan & Cromwell concluded that Polymarket had met regulatory requirements; now the CFTC is doing its own assessment.

For high-risk PSPs, the signal is straightforward: withdrawal rules, card-link limits, and registration checks are not back-office details. They are the controls regulators and acquirers end up asking about when fraud turns into a platform-level incident.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!