Fraudsters Linked Stolen Debit Cards to Thousands of Polymarket Accounts in $10 Million Fraud Attack

Polymarket
Image Credit: jackpress / Shutterstock.

Fraudsters linked stolen debit cards to thousands of Polymarket US accounts in February 2026 and attempted to steal at least $10 million, the Wall Street Journal reported. The newspaper described deposits followed by wagers and attempted withdrawals to other cards or accounts. The amount represents attempted theft, not confirmed losses.

Checkout.com rejected more than 80% of the deposits it handled at one point, the Journal reported. Polymarket told the newspaper it monitors suspicious activity and cooperates with regulators and law enforcement.

The American exchange operates through QCX LLC. The CFTC lists QCX, doing business as Polymarket US, as a designated contract market, with a designation date of July 9, 2025. Polymarket’s U.S. customer documentation lists debit cards and bank transfers as ways to fund accounts.

In an August 31 interview with Reuters, Shana Bautista, Polymarket’s global head of investigations and intelligence, described a broader monitoring program combining machine learning, blockchain analytics, trade surveillance and outside providers. Bautista had joined in June after working at Coinbase and the FBI.

Deposits and Withdrawals

Debit card
Illustrative image. Image credit: Shutterstock.

The Information reported that Polymarket hired Riskified after Visa pressed Checkout.com to curb suspicious payment activity. Polymarket’s own payment documentation identifies Checkout.com as its card-payment provider and Aeropay as its provider for ACH bank transfers.

The current documentation describes separate procedures for deposits and withdrawals. Before processing a withdrawal, developers are instructed to retrieve the requirements attached to the funding source and check the requested amount against the available balance and those requirements.

Examples in Polymarket’s funding guide include a requirement to send money back to the original deposit source. Each example identifies a funding source and an amount subject to that restriction. These are sample records illustrating how the payment system handles withdrawal requirements, rather than records of customer transactions.

Monitoring Payments and Trades

Polymarket’s published U.S. integrity policy prohibits fraud, fictitious transactions and market manipulation. The company says its control desk watches trading activity in real time for unusual or disruptive behavior, alongside outside surveillance providers.

The policy also describes a regulatory-services agreement with the National Futures Association covering trade surveillance, investigations and sanctions. A review of suspicious trading can lead to a formal investigation and disciplinary proceedings.

For violations established through an investigation, the published sanctions include suspension, monetary penalties and termination of trading privileges. Polymarket also says it can refer matters to regulators or law enforcement. The policy provides a confidential reporting channel for people who believe they have witnessed prohibited trading activity.

When a Debit-Card Charge Isn’t Yours

A debit-card holder who finds an unauthorized payment should contact the bank or credit union promptly, according to the CFPB. Someone who discovers that a card, PIN or security code has been lost or stolen should report it within two business days. Timely notification generally limits liability to $50 or the amount of unauthorized transfers before notification, whichever is less. Waiting longer can increase that liability.

When the card, PIN and security code have not been lost or stolen but an unauthorized transfer appears on a statement, the CFPB says to report it immediately and no later than 60 days after the institution sends the statement. Missing that deadline can leave the customer responsible for later unauthorized transfers that the bank can show timely notice would have prevented.

The bank cannot require a customer to settle the matter with the merchant before beginning its investigation. The CFPB’s Regulation E guidance says an oral or written error report triggers the institution’s investigation obligations. A police report is not a prerequisite either. The bank must investigate promptly, report its findings and correct an error within the applicable deadlines.