Polymarket Faced a $10 Million Fraud Attempt, Blocking More Than 80% of Deposits at One Point
Polymarket’s U.S. platform spent part of this year dealing with a deposit fraud wave that pushed Checkout.com to reject more than 80% of processed deposits as fraudulent, far above the roughly 1% market average. For high-risk PSPs, the useful part is not the drama but the mechanics: stolen cards, short-cycle funding, withdrawals to “clean” cards or controlled accounts, and a compliance backlog that forced policy changes.
- According to reporting cited in the source, the attack began in February, a few months after Polymarket opened registration to users from its waitlist. The scheme was straightforward: criminals funded accounts with stolen debit cards, placed bets, and then tried to withdraw winnings to “clean” cards or accounts they controlled.
- At one point, Checkout.com flagged more than 80% of Polymarket US deposits as fraudulent. The source says the market average is around 1%, which gives you the scale of the problem without much need for decoration.
- The flood of fraudulent top-ups made an already large withdrawal queue worse and overloaded the compliance team, according to the report. Polymarket’s management then scrapped a rule meant to limit money laundering: previously, funds deposited from one source could be withdrawn only back to that same source.
- By May, the platform had limited the number of debit cards that could be linked to one account, and fraud levels returned to industry norms. Journalists could not determine how much of the $10 million actually reached the attackers, because most suspicious deposits did not clear. One source told WSJ that most funding attempts failed. The operation was run by about seven people, and one of them made roughly 4000 attempts to complete a transaction.
- The U.S. Commodity Futures Trading Commission (CFTC) has opened an investigation into Polymarket. Employees were instructed to preserve documents related to the fraud attack and some other matters. Separately, Bloomberg’s journalists estimated that roughly $200 million in bets with signs of insider trading flowed through Polymarket’s blockchain platform in the first six months of the year.
For PSPs, acquirers, and banks, the relevant signal is not just that the fraud was large; it is that the attack mixed carding, account funding, and withdrawal abuse in a way that can quickly turn a payments stack into a compliance bottleneck. Once a platform has to relax source-to-source withdrawal controls to keep operations moving, the risk conversation changes fast.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!