Polymarket's $10M Fraud Incident: AML and Compliance Lessons for Crypto Firms
A Wall Street Journal investigation published on 20 September 2026 revealed that prediction-market platform Polymarket faced an attempted theft of at least $10 million through stolen debit cards, that its payment processor was flagging more than 80% of US deposits as fraudulent at the peak of the attack, and that the firm's CEO reportedly urged staff to prioritise growth and address potential regulatory fines later. The Commodity Futures Trading Commission is now investigating the company. For accounting firms, auditors, and CFOs advising digital asset businesses, the episode is not simply a fintech news story: it is a detailed case study in how compliance culture, AML control design, and incident-response governance can either contain or dramatically amplify regulatory exposure.
What the WSJ Investigation Found
The reported sequence of events begins in February 2026, when fraudsters began exploiting Polymarket's US-facing platform using stolen debit cards. The scheme was straightforward: deposit funds via compromised cards, place bets, then attempt to withdraw any winnings to separate "clean" cards or accounts under the attackers' control. Checkout.com, Polymarket's payment processor, detected the activity and alerted the platform. At the height of the attack, Checkout.com was reportedly rejecting more than 80% of Polymarket US deposits it processed as fraudulent. The Journal noted that the industry-standard fraud rejection rate sits at roughly 1%. Visa had also instructed Checkout.com to demand tighter controls from the platform.
Scale and concentration of the attack
The $10 million figure represents the attempted theft, not confirmed losses. One source cited by the Journal stated that most attempted deposits failed, and that roughly seven users accounted for the bulk of the activity, with one individual reportedly attempting around 4,000 separate deposits. Polymarket did not confirm to The Block how much money was actually stolen. A company spokesperson told the Journal that Polymarket covers customer losses and that its market integrity framework includes processes to detect and respond to suspicious activity.
CEO response and compliance culture
What transforms this from a fraud incident into a compliance governance issue is the reported leadership response. According to the Journal's sources, CEO Shayne Coplan downplayed the event internally and told staff to focus on growth, with regulatory fines to be handled later. Compliance staff were reportedly surprised by that framing. The incident then compounded an existing backlog of withdrawal requests from legitimate users, overwhelming the compliance team.
The Control That Was Removed and Why It Matters
In the midst of the crisis, Polymarket's leadership dropped a withdrawal-matching rule: the requirement that funds deposited from one payment source must be withdrawn to the same source. This control is not a regulatory mandate specific to prediction markets, but it is a standard safeguard at financial institutions precisely because it neutralises the "clean card" withdrawal vector used in stolen-card fraud.
Warnings from within
Some employees flagged internally that removing the same-source rule could increase money laundering risk and invite further attacks. Executives reportedly maintained that other controls in place were sufficient. By May 2026, after measures that included limiting the number of debit cards a user could link to an account, fraud rates returned to levels consistent with industry norms, according to a person familiar with the matter cited by the Journal.
Why this is an AML control-design issue
From a financial crime compliance standpoint, same-source withdrawal requirements exist at the intersection of two regulatory concepts: knowing your customer's payment methods (a KYC obligation) and detecting layering activity (an AML obligation). Removing such a rule under pressure, without a formal risk-acceptance process and board-level sign-off, creates a documented gap that regulators will find in any subsequent examination. The gap is not merely theoretical: it reportedly contributed to further vulnerability during the July account-takeover attack described below.
The July Account-Takeover Incident
In late July 2026, a separate attack targeted nearly 500 Polymarket user accounts. The attacker reportedly exploited a flaw in the account-registration flow: by attempting to create a new account using an existing customer's personal information, including stolen Social Security numbers, an attacker could gain full access to that customer's account, linked bank accounts, and linked debit cards, without needing to know the customer's established username or password.
Customer impact and support failures
Discord messages reviewed by the Journal and sources interviewed by the publication described some affected users losing thousands of dollars, with weeks of support requests going unanswered. One source characterised the total amount stolen as small without specifying a figure. Polymarket told the Journal it would cover customer losses. The support-response failure is itself a compliance concern: most financial regulatory frameworks, including those applicable to CFTC-registered entities, impose timelines and standards for customer complaint handling.
Regulatory and Personnel Consequences
The CFTC is investigating Polymarket, according to a separate earlier report cited by the Journal, and employees have been instructed to preserve records related to the fraud attack and other matters. A CFTC spokesperson declined to confirm or deny the investigation when contacted by The Block.
Senior compliance departures
The compliance leadership fallout has been significant. US chief compliance officer Andrew Clifford resigned in April 2026 after submitting a detailed report to executives outlining the fraud issues. US CEO Justin Hertzberg was subsequently fired. The heads of US regulation and anti-money-laundering also departed. For auditors and external advisers, the loss of that many compliance-function leaders in rapid succession is a material governance event that warrants disclosure review and counterparty due diligence reassessment.
Internal and external investigations
An internal investigation conducted by law firm Sullivan and Cromwell concluded that Polymarket had complied with applicable regulations, according to people familiar with the findings cited by the Journal. That conclusion sits in tension with the CFTC's ongoing inquiry and with a prior WSJ report, also cited in Saturday's piece, alleging Polymarket paid creators to stage bets and wins on replica websites, which had prompted earlier calls for regulatory action.
Business Context: Growth, Financing, and the IPO Track
The compliance failures are unfolding against an ambitious growth backdrop. Polymarket is reportedly seeking approximately $1 billion in financing at a valuation of around $21 billion. Donald Trump Jr.'s investment firm, 1789 Capital, is contributing roughly $300 million on top of approximately $200 million previously invested. CEO Coplan met with 1789 Capital co-founder Omeed Malik in June to discuss a potential IPO in 2027, according to sources cited by the Journal.
Polymarket has since hired Warren Jenson, a former Amazon CFO, as its first chief financial officer, and has added risk-management staff and improved compliance procedures since May. A company spokeswoman told the Journal the firm is "focused on growing responsibly at the frontier of finance, tech, and culture."
Implications for Accounting Firms and CFOs
The Polymarket episode carries several concrete takeaways for practitioners advising digital asset businesses or using crypto compliance reporting frameworks to serve such clients.
Fraud-rate monitoring as a compliance metric
An 80%-plus payment-rejection rate is not a technology problem: it is a compliance signal of the first order. Any digital asset platform handling fiat on-ramps should have defined escalation thresholds in its AML policy, with clear lines of responsibility for notifying the board, external auditors, and, where applicable, regulators. If those thresholds do not exist in writing, that gap should be addressed before the next audit cycle. Robust crypto accounting software and bookkeeping workflows should surface payment anomalies in near real time, not after a processor flags them externally.
Control changes need formal risk-acceptance
Removing or relaxing a financial crime control, even one that is not a strict regulatory requirement, must go through a documented risk-acceptance process. That process should involve the compliance function, legal counsel, and, depending on the materiality of the change, the board's audit or risk committee. An informal executive decision made under operational pressure, with dissenting compliance voices on record, is precisely the fact pattern that regulators and litigators find most useful.
Record preservation and document holds
The report that Polymarket employees have been instructed to preserve records is a signal that external counsel anticipates formal regulatory process. Accounting firms supporting clients under investigation need to understand whether their own work product, including transaction data exports, reconciliation schedules, and internal communications, falls within the scope of a document hold. Digital asset accounting software that maintains an immutable audit trail will reduce the forensic burden significantly.
CCO resignation as a disclosure trigger
For publicly reporting entities or those approaching an IPO, the resignation of a CCO following a documented fraud event and the subsequent departure of other senior compliance staff are material events that require careful disclosure analysis. Auditors should assess whether the departures, taken together with the fraud incidents and the CFTC inquiry, affect the going-concern assessment or require disclosure in the notes to the financial statements.
Counterparty and due diligence considerations
Accounting firms conducting due diligence on digital asset platforms ahead of financing rounds or M&A should now treat payment-processor rejection rates and compliance-team turnover as standard due diligence data points. The Polymarket situation illustrates that a high rejection rate and a series of senior compliance departures, viewed together, can indicate systemic control failure rather than isolated incidents. Understanding how OFAC sanctions shape AML obligations for digital asset firms is one part of that picture; understanding internal control design and escalation culture is another.
Frequently Asked Questions
Is Polymarket a registered entity with the CFTC?
Polymarket relaunched its US platform as a CFTC-regulated designated contract market. The CFTC is currently investigating the firm in connection with the events described in the WSJ report, though the agency has neither confirmed nor denied the investigation publicly.
Does the CFTC require a same-source withdrawal rule for prediction markets?
The same-source withdrawal requirement that Polymarket dropped is not a specific CFTC regulatory mandate for prediction markets. It is, however, a common financial-crime control at regulated financial institutions. Removing it without a documented risk-acceptance process creates an exploitable gap and potential evidence of inadequate AML procedures in any subsequent regulatory examination.
What record-preservation obligations apply when a regulator is investigating?
Once a firm has reason to anticipate regulatory or legal proceedings, a litigation hold obligation typically attaches. This means relevant records, including transaction data, internal communications, and compliance reports, must be preserved and not destroyed or altered. Accounting teams and their software providers should have a clear protocol for responding to such holds, including suspending any automated data-purge routines.
How should an auditor treat a CCO resignation following a fraud incident?
A CCO resignation in the context of a documented fraud event, particularly where the resignation follows submission of a report to executives outlining compliance concerns, is a red flag that auditors should evaluate carefully. It may affect the auditor's assessment of the control environment, the risk of material misstatement, and, for entities approaching a public offering, the adequacy of related-party and contingent-liability disclosures.
What should digital asset CFOs do right now in light of this case?
CFOs at digital asset platforms should verify that their payment fraud thresholds and escalation protocols are documented in AML policy, that any recent control changes have been formally risk-accepted with appropriate sign-off, that their digital asset accounting software surfaces payment anomalies in near real time, and that the compliance function has a clear, documented channel to the board that does not depend on CEO discretion. If a CFTC or FinCEN examination were to begin tomorrow, those four items would be among the first things requested.
Source: The Block
