Growth-First Culture Exposed Polymarket to Major Fraud Wave

A recent investigation by The Wall Street Journal and also covered by the Times has detailed how Polymarket’s aggressive expansion strategy left its U.S. platform vulnerable to fraud, including a coordinated scheme in which criminals linked stolen debit cards to thousands of accounts and attempted to move at least $10 million. The reporting arrives at a critical moment for the prediction-market operator, which is pursuing a $1 billion funding round at a reported $21 billion valuation and preparing for a potential initial public offering.
A Coordinated Attack Exploited Weak Controls
According to the Journal, the fraud campaign unfolded in February, when fraudsters tied stolen debit cards to thousands of new accounts on Polymarket’s U.S. platform. The scheme involved deposits, followed by wagers and attempted withdrawals to different cards or accounts. At the peak of the attack, payment processor Checkout.com rejected more than 80% of the deposits it processed on the platform – a figure that stands in sharp contrast to industry fraud rates of roughly 1%.
The Journal reported that Chief Executive Shayne Coplan downplayed the severity of the attack. Citing current and former employees, the investigation stated that Coplan told compliance staff to “just keep growing and pay a fine,” a response that reportedly surprised members of the risk and compliance teams. Employees told the Journal that the reaction reflected a broader culture in which growth was prioritized over internal controls.
Compliance Concerns Extended Beyond Payment Fraud
The investigation outlined additional issues that have drawn attention from compliance professionals. Among the most significant findings: Polymarket removed one of its anti-money-laundering programs during the fraud attack, a change that alarmed some staff members who warned that it invited laundering activity. Executives, according to the report, proceeded with the adjustment.
Separately, the Journal documented persistent engineering glitches that have cost some customers thousands of dollars, with users describing limited responsiveness from support staff. Reports in other outlets, citing the same investigation, indicate that a technical flaw also allowed identity thieves to access existing accounts and the card and banking information attached to them.
The reporting comes amid heightened regulatory attention to prediction markets more broadly. The Commodity Futures Trading Commission has been examining issues connected to Polymarket, and employees have reportedly been instructed to preserve documents. The platform has also faced congressional scrutiny over insider-trading concerns and, earlier this year, over promotional practices following related Journal reporting.
Remediation Efforts and Company Response
The company has taken corrective steps in the months since the February attack. Polymarket restricted debit-card linking, and fraud rates reportedly returned toward industry norms by May. The company also engaged fraud-prevention firm Riskified after Visa pressed Checkout.com to curb suspicious payments on the platform.
In response to the Journal’s findings, Polymarket said it monitors suspicious activity and cooperates with regulators and law enforcement, noting that its monitoring program combines machine learning, blockchain analytics, trade surveillance, and external providers. The company has also moved to strengthen its executive ranks, appointing former Amazon finance chief Warren Jenson as its first chief financial officer – a governance milestone widely read as preparation for a public listing.
Weighing Growth Against Market Integrity
The episode highlights a familiar tension for rapidly scaling financial platforms: the cost of compliance infrastructure in the short term versus the reputational and regulatory exposure that follows when controls lag behind growth. Polymarket’s U.S. operations, which received designated contract market status from the CFTC in 2025 through its QCX entity, operate under federal oversight that imposes surveillance and anti-fraud obligations similar to those governing traditional exchanges.
For industry observers, the case underscores that venture capital enthusiasm and institutional partnerships – including a substantial investment commitment from Intercontinental Exchange – do not substitute for operational maturity. As Polymarket competes with regulated rivals such as Kalshi and contemplates an IPO, the durability of its recent control improvements will likely be a central question for investors, regulators, and counterparties alike.













