Loose Polymarket controls lead to $10 million fraud scheme

Data breaches are simply a way of life in the digital age, so much so that you probably didn’t even hear about the theft and sale of more than 150 million driver’s licenses earlier this month.

That breach was so widespread that a digital scan of Secretary of Defense Pete Hegseth’s license was included, according to Krebs on Security.

While many Americans have signed up for identity theft protection and some are notified when their information is up for sale on the dark web, the same reality has been proven over and over again: our data is not safe.

So the fact that the prediction market company Polymarket allowed fraudsters to access user accounts through personal information that they’d stolen should raise some red flags.

Yet the company’s response to the breach, according to a Wall Street Journal investigation, is not what you’d expect.

Fraudsters attempt $10 million Polymarket theft using stolen debit cards

In February, payment processor Checkout.com warned Polymarket that online fraudsters were tying stolen debit cards to thousands of new U.S. accounts to fund wagers, the proceeds from which were then pulled onto clean cards and accounts they controlled, according to The Wall Street Journal.

The problem became so widespread that at one point, Checkout.com rejected more than 80% of the deposits it was handling for Polymarket as the scheme racked up at least $10 million in charges.

The fraudsters targeted Polymarket’s U.S. facing platform just months after it began admitting users off its waitlist.

While falling for the scheme was bad enough, Polymarket’s reaction to being told about the security breach was even more egregious.

Online fraudsters tied stolen debit cards to thousands of new U.S. accounts to fund Polymarket wagers.

d3sign / Getty Images

Polymarket CEO told staff not to worry about the fraud

According to the Journal, employees notified Polymarket CEO Shayne Coplan of the breach, but his response seems a bit unsatisfactory.

Sources at the company told the Journal that Coplan told them to keep growing the platform and that Polymarket would just pay a fine if regulators ever found out about the breach. Meanwhile, fraud rates remained elevated for months after the initial breach, before returning to industry norms of 1% (instead of 80%) by May.

A Polymarket spokesperson told the Journal that its “market integrity framework includes processes to detect and respond to suspicious activity.” Still, the company’s response to the fraud shows just how much it was caught off guard.

Polymarket fires U.S. CEO, executive resigns

Shortly after the breach was discovered, Polymarket Chief Compliance Officer Andrew Clifford resigned after sending an executive a report detailing the fraud issues at the company, the Journal reported.

Later, Polymarket U.S. CEO Justin Hertzberg was fired, and the heads of its U.S. regulation and anti-money-laundering units also left the company.

Polymarket hired the law firm Sullivan & Cromwell to investigate the breach, and it determined that Polymarket had acted in compliance with regulations.

Polymarket users had to fight to be made whole

In order to clear the backlog of pending withdrawals due to the increase in fraud, Polymarket executives eliminated the company policy of returning money through the same payment method used for deposits. The company did that despite being warned that doing so would invite money laundering.

One Polymarket user interviewed by the Journal said he joined the market to place bets on the World Cup. In July, he logged into his account to find his positions sold and nearly $5,800 in gains sent to a debit card he did not own.

Related: Kalshi, Polymarket bets are big problem for NFL

Polymarket credited his account $25 while offering no explanation. “Polymarket U.S. was silent for weeks and weeks,” he said, so he filed reports with the local police, FBI, and the Commodity Futures Trading Commission.

The company eventually put his account on hold, but only after he submitted verification information twice — the same information the scammers didn’t need when they stole his money in the first place.

Regulators investigate Polymarket

The Commodity Futures Trading Commission has opened an investigation into Polymarket, the Journal reported. It has also instructed staff to preserve records tied to the fraud attack and other matters.

Former federal prosecutors told the Journal that weak anti-money laundering safeguards could potentially violate federal statutes regarding money laundering and illicit fund transfers.

Related: Polymarket’s public ledger may be leaking military secrets