‘Keep Growing and Pay a Fine’: Polymarket CEO Allegedly Ignored Warnings as Fraud Attempts Hit $10M

0
1
Polymarket’s reported $10 million fraud attempt paired the “future of betting” with one of crime’s oldest tricks, stolen cards.

Key Takeaways

  • Fraudsters allegedly used stolen debit cards to attempt at least $10 million in transactions through Polymarket US.

  • Payment processor Checkout.com reportedly rejected more than 80% of the deposits it handled at the attack’s peak, compared with an industry norm of roughly 1%.

  • CEO Shayne Coplan’s response to anonymous employee accounts has come under fire.

Polymarket CEO Shayne Coplan allegedly told employees to “just keep growing and pay a fine if regulators ever find out” after compliance staff raised concerns about a $10 million stolen-card fraud attempt.

Current and former employees made the allegation in a Wall Street Journal investigation.

The warning reportedly came as criminals linked stolen debit cards to Polymarket US accounts and attempted to withdraw funds using other cards or accounts they controlled.

At the height of the February attack, payment processor Checkout.com rejected more than 80% of the deposits it handled for Polymarket as fraudulent. The comparable industry rate is just 1%.

How the Polymarket Card Scheme Worked

Fraudsters reportedly linked stolen debit cards to Polymarket US accounts before attempting to place wagers and withdraw the resulting balances to different cards or bank accounts under their control.

Approximately seven users were responsible for the majority of the attack, while one attempted around 4,000 separate deposits, according to a person cited by the Journal.

One source said most of the fraudulent deposits were unsuccessful, and no verified figure has been published showing how much money was ultimately withdrawn.

The attack nonetheless created a significant operational problem.

Compliance employees were reportedly overwhelmed, while legitimate customers faced a growing backlog of withdrawal requests.

Polymarket’s leadership removed a rule requiring customers to withdraw funds using the same payment method they used to make their deposit.

These restrictions make stolen-card schemes harder, as criminals cannot easily deposit funds from one card and withdraw them to a separate, “clean” account.

Employees reportedly warned that removing the safeguard could increase the risk of money laundering. Executives maintained that the company’s other controls were sufficient, according to the report.

Coplan Accused of Prioritizing Growth

Current and former employees told the Journal that compliance staff escalated the surge in fraud to Polymarket CEO Shayne Coplan.

According to their account, Coplan responded:

“Just keep growing and pay a fine if regulators ever find out.”

The alleged comment has not been confirmed by Polymarket.

A company spokesperson instead said the platform was committed to operating transparent markets and cooperating with regulators and law enforcement.

“Our market integrity framework includes processes to detect, review and respond to suspicious activity,” the spokesperson told the Journal.

Polymarket US Chief Compliance Officer Andrew Clifford resigned in April after reportedly submitting to executives a detailed account of the company’s fraud issues.

However, an internal investigation by law firm Sullivan & Cromwell concluded that Polymarket had complied with applicable regulations, according to people familiar with its findings.

Fraud Levels Returned to Normal by May

Polymarket eventually restricted the number of debit cards customers could link to an account and partnered with the fraud-prevention company Riskified.

By May, the proportion of transactions identified as fraudulent had reportedly returned to normal industry levels.

The company has also expanded its compliance and risk operations as it prepares for further growth.

Polymarket said its recent leadership appointments and infrastructure improvements reflected a commitment to expanding responsibly.

Those changes arrived amid reports that the company is seeking approximately $1 billion at a valuation of around $21 billion.

Not Polymarket’s First Security Problem

The stolen-card scheme differs fundamentally from the attack that affected Polymarket users in June.

In that incident, a compromised third-party dependency injected malicious code into parts of the platform’s frontend.

Investigators estimated that around $3.1 million was drained from 11 wallets.

The February fraud instead targeted Polymarket US, a federally regulated exchange operating through QCX.

Polymarket is also facing separate regulatory scrutiny.

As CCN previously reported, the Commodity Futures Trading Commission authorized at least three investigations into potential insider trading involving Polymarket contracts between May and July.

Those investigations cover markets connected to presidential pardons, Iran-related events and Google’s annual search rankings.

Top Trending Crypto Articles

The post ‘Keep Growing and Pay a Fine’: Polymarket CEO Allegedly Ignored Warnings as Fraud Attempts Hit $10M appeared first on ccn.com.

Disclaimer : This story is auto aggregated by a computer programme and has not been created or edited by DOWNTHENEWS. Publisher: finance.yahoo.com