A WSJ investigation reveals that Polymarket, a prediction-market giant, was targeted by a fraud syndicate attempting to steal at least $10 million from the platform in February this year. CEO Shayne Coplan, however, instructed employees to “prioritize scaling up first; deal with regulatory fines later.” In another attack in July, nearly 500 user accounts were compromised, and a CFTC investigation has been launched. (Background: the U.S. election) Will the CFTC go after the election prediction platform Polymarket, learn from Taiwan’s approach to punishing gambling, and move to block domains and shut it down? (Additional context: Polymarket’s latest valuation is $15 billion and it raised funding twice within a month, though it still trails Kalshi’s $22 billion valuation.) The Wall Street Journal (WSJ) published an investigative report on Saturday revealing that Polymarket faced a large-scale fraud attack in February. The fraud syndicate used stolen bank debit cards to try to steal at least $10 million from the platform, while CEO Shayne Coplan’s response was to tell employees to “first push for scale; handle regulatory fines later.” According to the WSJ investigation, the scam began targeting Polymarket’s U.S. platform in February, just a few months after the regulated platform officially opened to U.S. users. The fraudsters used the stolen cards to deposit funds, place bets, and then attempted to withdraw the winnings to “clean” accounts controlled by them, thereby laundering money. Payment processor rejects 80% of deposits; Visa issued warnings Polymarket’s payment processor Checkout.com sent attack alerts to the platform and, at one point, classified more than 80% of Polymarket deposits as fraudulent transactions and refused them—far above the industry norm of around 1%. Earlier, The Information reported in June that Visa had instructed Checkout.com to curb fraud payments for Polymarket, prompting the processor to demand stricter controls from the platform. But Coplan’s response surprised the company’s internal compliance team: push growth first; deal with regulatory fines later. The WSJ cited internal sources saying that most of the fraudulent funds the attackers tried to deposit ultimately failed. About seven users were reportedly responsible for the attack’s core effort, and one of them allegedly attempted around 4,000 separate deposit transactions. As for how much of the $10 million attempt was actually successful, the report did not specify, and Polymarket did not respond to further questions from The Block. Remove anti–money laundering firewall; top executives leave in succession The scam surge worsened the backlog of legitimate users’ withdrawal requests, overwhelming the compliance team. Polymarket’s management later removed a rule designed to reduce money-laundering risk, which required funds deposited from a particular payment source to be returned to the same source. Although the rule is not a legal regulatory requirement for prediction markets, it is widely used by other financial institutions and effectively blocks fraudsters from depositing stolen debit-card funds and then withdrawing to different “clean” accounts. Even though some employees warned that the change could increase money laundering and attacks, leadership believed other existing rules were sufficient to stop such activity. The incident occurred amid frequent changes in Polymarket’s senior leadership. Polymarket’s U.S. chief compliance officer Andrew Clifford resigned in April after submitting a detailed report to executives outlining the fraud problems. The company then fired the U.S. CEO Justin Hertzberg, and its U.S. regulatory compliance and anti–money laundering officers also left in succession. Second-wave attack in July: 500 user accounts stolen In addition to the February fraud incident, Polymarket faced another wave of attacks at the end of July. Nearly 500 users were targeted. The attackers exploited a glaring account-registration loophole: by using existing customer information (such as stolen Social Security numbers) to try to register a new account, they could obtain full access permissions to that customer’s account, including linked bank accounts and debit cards—without needing to know the original account number or password. An insider described the stolen amounts as not large, but did not provide specific numbers. A Polymarket spokesperson told the WSJ that the company would compensate for the losses. However, WSJ and Discord messages showed that some users lost thousands of dollars, and after sending messages to customer support for weeks they received no response. By May, after Polymarket implemented measures—including limiting the number of linked debit cards users could have—the fraud rate fell back to normal industry levels. CFTC investigation started; IPO and $21 billion valuation face pressure The U.S. Commodity Futures Trading Commission (CFTC) is investigating Polymarket—facts already revealed by the WSJ’s earlier investigation. That earlier probe found that Polymarket paid creators to manipulate fake bets and fake wins on copycat websites, prompting calls from bipartisan senators for a CFTC investigation. According to the latest report, company employees have received instructions to preserve records related to the fraud attacks and other issues. A report by the internal investigations law firm Sullivan & Cromwell concluded that Polymarket had complied with applicable regulations. The company also hired former Amazon CFO Warren Jenson as its first-ever finance chief. Since May, it has added risk-management personnel and improved compliance programs. But whether these remedial steps will satisfy regulators remains unknown. Polymarket is currently seeking about $1 billion in funding, valuing the company at around $21 billion. A firm belonging to Donald Trump Jr., Donald Trump Jr.’s investment company 1789 Capital, plans to invest about $300 million, plus an additional $200 million from prior investments. In June, Coplan also met with 1789 Capital co-founder Omeed Malik to discuss preparations for a potential IPO in 2027. Taiwan observation: legalizing prediction markets—compliance is what determines life or death Polymarket’s situation has direct reference value for Taiwan’s crypto market. Taiwan officially brought crypto assets into a regulatory framework in 2024. The legal status of prediction markets in Taiwan remains in a gray zone, but the CFTC’s regulatory pressure on Polymarket shows that no matter how innovative the product is or how fast user growth is, if the compliance infrastructure is not in place, regulators will target it. After obtaining U.S. compliance licensing, Polymarket instead saw fraud on a larger scale and internal controls failing—indicating that “having a license” does not equal “being fully compliant.” Regulators are never focused only on the license itself; they focus on the anti-fraud and anti–money laundering measures the platform actually implements. If Polymarket wants to conduct an IPO in 2027, the outcome of the CFTC investigation will be the biggest variable. Historically, many fintech companies that faced regulatory investigations before an IPO saw their stock prices take significant discounts during the investigation period. Whether Polymarket’s $21 billion valuation can hold until the IPO moment depends on whether it can prove to regulators that its compliance-control loopholes have truly been fixed, and...