Polymarket Faced $10M Stolen-Card Fraud Attempt, WSJ Says
United States

Marco Bello/Reuters
Source Analysis
What Happened
What Happened
Where Sources Agree
- arrows_inputFebruary Fraud Attempt Scale: Most coverage notes that an attempted $10 million stolen-card fraud scheme targeted Polymarket in February; at the peak of the attack, processor Checkout.com rejected over 80% of deposits as fraudulent, according to a Wall Street Journal investigation.
- arrows_inputJuly User Account Compromise: Reporting largely establishes that an engineering weakness in July allowed attackers to access approximately 500 Polymarket accounts by using stolen personal information to bypass password requirements, according to a Wall Street Journal report.
- arrows_inputDeceptive Marketing Practices: Most outlets confirm that Polymarket paid content creators to feature fake winning trades on dummy websites as part of a marketing campaign that falsely displayed $1.9 million in winnings, according to a Wall Street Journal investigation.
Where Sources Disagree
- arrows_outputJuly Identity Theft Losses: The Wall Street Journal reports that the total amount stolen during the July identity theft exploit was small, whereas no public disclosures from Polymarket have provided an independently confirmed total for the losses.
- arrows_outputMarketing Practices vs. Corporate Strategy: Recent reporting highlights allegations of deceptive marketing campaigns involving dummy sites and fake trades, while the company emphasizes its ongoing corporate growth, capital-raising efforts, and the appointment of new executive leadership.
Timeline
September 20, 2026
July–September fallout and investigations: A separate July account‑security episode affected nearly 500 users, and blockchain investigators later estimated roughly $3.1 million in losses across 11 wallets; Polymarket hired a former FBI investigator as global head of investigations in August and named a CFO on Sept. 10, while the Journal's Sept. 19–20 reporting spurred a reported CFTC inquiry (employees were told to preserve documents) and said Polymarket has since built out internal investigations and strengthened fraud controls.
September 19, 2026
February stolen-card scheme revealed: The Wall Street Journal reported that in February fraudsters used stolen debit cards on Polymarket's U.S. platform to fund thousands of accounts and attempted at least $10 million in illicit withdrawals and wagers; at the peak, Checkout.com rejected more than 80% of deposits as fraudulent, the Journal said. This disclosure tied the February spike to a broader fraud wave described in later reporting.
June 20, 2026
June WSJ TikTok probe and breach: On June 20 the WSJ published findings based on interviews and an analysis of over 1,100 TikTok videos alleging paid creators falsely showed customers winning about $1.9 million, and Polymarket said it would audit promotional content; separately in June the company confirmed a compromised third‑party vendor injected malicious code into its frontend for some users and said it removed the dependency and would reimburse affected customers.
Summary by Ground AI
Sources
See All 27A varied selection of sources chosen by Ground to reflect the diversity of this story’s coverage.
Most Written About
The stories getting the most coverage from the last 24 hours
Source Analysis
Timeline
September 20, 2026
July–September fallout and investigations: A separate July account‑security episode affected nearly 500 users, and blockchain investigators later estimated roughly $3.1 million in losses across 11 wallets; Polymarket hired a former FBI investigator as global head of investigations in August and named a CFO on Sept. 10, while the Journal's Sept. 19–20 reporting spurred a reported CFTC inquiry (employees were told to preserve documents) and said Polymarket has since built out internal investigations and strengthened fraud controls.
September 19, 2026
February stolen-card scheme revealed: The Wall Street Journal reported that in February fraudsters used stolen debit cards on Polymarket's U.S. platform to fund thousands of accounts and attempted at least $10 million in illicit withdrawals and wagers; at the peak, Checkout.com rejected more than 80% of deposits as fraudulent, the Journal said. This disclosure tied the February spike to a broader fraud wave described in later reporting.
June 20, 2026
June WSJ TikTok probe and breach: On June 20 the WSJ published findings based on interviews and an analysis of over 1,100 TikTok videos alleging paid creators falsely showed customers winning about $1.9 million, and Polymarket said it would audit promotional content; separately in June the company confirmed a compromised third‑party vendor injected malicious code into its frontend for some users and said it removed the dependency and would reimburse affected customers.













