Markets · 4 min
WSJ: Polymarket US faced stolen-card wave; same-source withdrawal rule dropped
21 Sept 2026 · Studio note 20 Sept 2026
Polymarket US stolen-card fraud wire — quiet-room cashier debit motif on a canopy field. · Bonusjungle illustration
The Wall Street Journal reported on 20 September 2026 that fraudsters tried to push at least $10 million through Polymarket US in February using stolen debit cards. Leadership later dropped a same-source withdrawal safeguard. Contested Coplan remarks stay attributed.
WSJ: Polymarket US faced stolen-card wave; same-source withdrawal rule dropped
On 20 September 2026, *The Wall Street Journal* published an investigation — title circulated as “Polymarket’s Rush to Grow Left a Door Wide Open For Fraudsters” — saying that in February 2026 fraudsters linked stolen debit cards to thousands of new Polymarket US accounts, funded wagers, and tried to cash out to cleaner instruments. Desks attributing that reporting put the attempted flow at at least $10 million. Public write-ups have not established how much actually left the platform; at least one person familiar with the matter told secondary desks that most attempted deposits failed.
This is a US cashier / debit-rail story on the CFTC-designated American venue. It is not the Lithuania block piece, not the South Korea user prosecutions, and not a state sportsbook-licence claim.
Newest casinos
Added:
Welcome offer: 100% up to €500
35× bonus · €20
Added:
Welcome offer: 100% up to €750 + 50 no-wager spins
35× bonus · €20
Added:
Welcome offer: No Welcome Offer
18+ · Affiliate links. We may earn a commission.
What the desks say about the February wave
Secondary desks (PYMNTS, FinanceFeeds, Crypto Times and others, all 20–21 September) attribute these named facts to the Journal:
- Payments firm Checkout.com, which handled debit-card deposits for Polymarket US, at peak classified more than 80% of the deposits it was processing as fraudulent, against an industry benchmark near ~1%. Checkout.com has not publicly confirmed that peak figure in statements those desks reviewed.
- About seven users drove most of the activity; one account alone attempted roughly 4,000 deposits.
- The attempted $10 million figure is flow tried, not a proven successful loss total.
Those numbers belong to investigative journalism and its mirrors — not to hands-on testing by Bonusjungle.
Same-source withdrawal safeguard removed
Trade desks say leadership later removed a “same-source” withdrawal control — deposit instrument must match withdrawal instrument — while withdrawal backlogs and growth pressure mounted. Employees warned that dropping the rule could open a money-laundering path; executives argued other controls were enough. Federal rules do not require prediction markets to keep that safeguard. Desk-attributed contrast only: DraftKings and FanDuel are described as keeping a same-source rule; Kalshi is described as inspecting mismatched withdrawals rather than banning them outright. Do not treat that contrast as a Bonusjungle audit of any operator.
Contested Coplan remarks — attribute, do not treat as admitted
People familiar with events told the Journal that when compliance raised the alarm with CEO Shayne Coplan, the reply was to keep growing and pay a fine if regulators found out. Polymarket has not publicly confirmed that remark. A company spokesman said the firm detects and responds to suspicious activity and cooperates with regulators and law enforcement. Hold the contested employee account as WSJ-attributed, never as a verified company statement.
Aftermath reported on the desks
Desk-attributed aftermath: fraud stayed elevated for months; by May 2026 rates were nearer industry norms after debit-card linking limits and antifraud vendor Riskified. Andrew Clifford, Polymarket US chief compliance officer, resigned in April 2026 after a fraud memo, people familiar said. US CEO Justin Hertzberg was later dismissed; US regulation and AML heads also left. Law firm Sullivan & Cromwell later concluded the company had complied, according to people familiar with that review. The CFTC is investigating; employees were told to retain records. A separate July account-takeover / engineering incident (~500 users in desk accounts) is neighbour context only — do not merge those totals with the February card wave.
Fundraising and IPO talk on secondary desks (valuation figures, 1789 Capital, possible 2027 listing) stays desk-attributed capital-raise context. Invent no CFTC fine amount, no licence revocation, and no IPO filing date.
Why the wire matters
Polymarket US sits on a regulated prediction-market rail that takes retail debit deposits. How deposit and withdrawal controls scale with growth is the live question for vault readers — not a cue to chase losses, bypass KYC, or work around geo or self-exclusion blocks. If payment risk feels personal, that is a banking and wellbeing problem; national helplines such as 1-800-GAMBLER exist for anyone who wants them.
Read it next to [Lithuania LPT blocks Polymarket](/news/lithuania-lpt-blocks-polymarket) and [South Korea Polymarket users / prosecutors](/news/south-korea-polymarket-users-prosecutors). Keep small print and responsible play in view.
More desk notes: news, casinos, [Lithuania LPT blocks Polymarket](/news/lithuania-lpt-blocks-polymarket), [South Korea Polymarket users / prosecutors](/news/south-korea-polymarket-users-prosecutors), small print, responsible play.
Also on this walk
Sources
- The Wall Street Journal — Polymarket’s Rush to Grow Left a Door Wide Open For Fraudsters (~19–20 Sep 2026; cite by title/date; URL paywalled from this box)
- PYMNTS — Polymarket Accused of Ignoring Fraud in Pursuit of Growth (20 Sep 2026)
- FinanceFeeds — Polymarket Faced $10 Million Fraud Attempt Using Stolen Debit Cards, WSJ Says (20 Sep 2026)
- The Crypto Times — Polymarket Hit by $10M Stolen-Card Fraud Attempt as CEO Told Staff to Keep Growing: WSJ (21 Sep 2026)
- Bonusjungle — Lithuania LPT blocks Polymarket
- Bonusjungle — South Korea Polymarket users / prosecutors
