Polymarket rules eased before $10m fraud attack
Checkout.com rejected over 80% of deposits during the attack, against a 1% industry norm, reports say.
The hit
Polymarket reportedly scrapped a standard anti-money-laundering safeguard before fraudsters hit the platform with a $10m attack using stolen debit cards, according to a Wall Street Journal investigation. CEO Shayne Coplan allegedly told staff to prioritise growth over compliance & deal with fines later.
Why it matters
The episode raises the stakes for prediction markets that take fiat deposits through regulated payment processors, which fall under Bank Secrecy Act anti-money-laundering duties. The company has reportedly been preparing for potential growth initiatives, including a possible IPO.
The record
| Fraud attempted | February 2026, via thousands of accounts linked to stolen debit cards (Wall Street Journal) |
|---|---|
| Deposit rejection rate | 80%+ flagged by Checkout.com, vs 1% industry norm |
| Prior CFTC penalty | $1.4m fine, 2022 settlement over unregistered activity |
| Departures | US Chief Compliance Officer Andrew Clifford & US CEO Justin Hertzberg exited |
| Internal review | Sullivan & Cromwell review found Polymarket remained compliant, according to the review |
| May 2026 clean-up | Stricter controls, debit-card limits per account & Riskified hired to bolster fraud detection |
What happens next
Watch for any CFTC response or enforcement move given Polymarket’s fiat deposit model, & for further disclosure as the company reportedly weighs an IPO.
Sources: Polymarket is being used for massive money laundering
Named in this story? Reply to newsdesk@pollbet.com & we publish it.
18+. Betting involves risk. If gambling is a problem for you or someone close to you, help is available.
Discussion
Ask a question, add useful context or share a source. Keep it relevant & respectful.