Confirm action

Are you sure you want to delete?

Link copied!
Regulation
Sep 22, 2026 · 3 min read

Polymarket’s CEO chose growth over fraud controls, WSJ finds

Affmarketingworld
Patric Mirgeschiss
Editor, Affmarketingworld
Polymarket’s CEO chose growth over fraud controls, WSJ finds

Polymarket’s US platform absorbed two separate 2026 security failures — a $10 million card-fraud scheme in February and a breach of nearly 500 accounts in July — while its CEO reportedly told staff to prioritize growth over compliance concerns.

$10 million in attempted card fraud

Polymarket’s US platform absorbed two separate security failures in 2026, and the details behind both point to a company that knew about the risk and kept moving anyway. In February, fraudsters used stolen debit cards to deposit money, place bets, and then try to withdraw the winnings onto clean cards they controlled, attempting to move at least $10 million through the platform before most of it got blocked. Roughly seven users drove the bulk of the activity, and one of them alone tried close to 4,000 separate deposits. At the peak of the attack, Checkout.com, the payment processor handling Polymarket’s transactions, was rejecting more than 80% of deposits as fraudulent, against an industry norm closer to 1%.

Then in July, a separate flaw let attackers into nearly 500 accounts without needing a username or password at all. Someone who registered a new account using a victim’s stolen personal information — a Social Security number was enough — got dropped straight into that victim’s existing live profile, linked bank accounts and debit cards included. Some users lost thousands of dollars, and support took weeks to respond while people watched their accounts get drained.

“Worry about the fines later”

What makes this more than a routine fraud story is what The Wall Street Journal reported about the company’s response while it was happening. CEO Shayne Coplan reportedly told staff to focus on growth and worry about regulatory fines later, a directive that reportedly caught the compliance team off guard. Around the same time, Polymarket dropped its policy of refunding withdrawals through the same payment method a deposit came in on, despite warnings internally that doing so would make the platform more attractive for laundering money rather than less.

Andrew Clifford, the US chief compliance officer, resigned in April, not long after submitting a detailed report to executives laying out exactly what the fraud exposure looked like. Justin Hertzberg, Polymarket’s US CEO, was fired afterward, and the heads of both US regulation and anti-money-laundering left too. Polymarket has said it will cover the money users lost in the July breach. By May, fraud rates had come back down after the company tightened debit card linking rules, and it brought on former Amazon CFO Warren Jenson along with additional risk-management staff.

The timing lands awkwardly next to how the company has otherwise been selling itself. Polymarket closed a funding round that valued it near $21 billion around the same stretch these reports cover, backed in part by investors including Trump Jr.’s 1789 Capital. A platform can raise money at a growth-stage valuation and still be running fraud controls loose enough to let one person attempt 4,000 fake deposits, and this year it did both at once.

“Telling your team to focus on growth and worry about the fines later isn’t a strategy, it’s a confession that someone already knew what the fines would be for.”

Patric Mirgeschiss
Reviewed by
Patric Mirgeschiss
Editor · AffMarketing World
Published Sep 22, 2026
X Profile →
Related tags