SiaPredict
Back to blog
polymarketcomplianceconsumer-protection

Polymarket's Fraud Response Shows the Cost of Growth-First Compliance

September 22, 2026 · How we source this

A Wall Street Journal investigation reports that Polymarket's CEO told staff to prioritize growth over a February 2026 stolen-card fraud wave, a decision that preceded a compliance officer's resignation and a rebuild of the company's compliance leadership through the rest of the year.

What the investigation found

The Wall Street Journal reported, per coverage of the investigation, that fraudsters attached stolen debit cards to thousands of Polymarket US accounts in February 2026, driving payment processor Checkout.com to flag more than 80 percent of incoming deposits as fraudulent, against a roughly 1 percent rate the Journal described as typical across the industry. Reporting indicates about seven users drove most of the attempted fraud, with one alone attempting close to 4,000 deposits.

According to the Journal's reporting, CEO Shayne Coplan told staff to keep growing and address any resulting regulatory fines later, despite internal warnings tied to the company's decision to drop a safeguard requiring deposits and withdrawals to use the same payment source. The report does not state the amount fraudsters ultimately extracted, and most attempted deposits reportedly failed.

The compliance departures that followed

Andrew Clifford, Polymarket's US chief compliance officer, resigned in April 2026 after submitting a detailed report on the fraud episode to company leadership, according to the Journal. Justin Hertzberg, chief executive of the US business, was fired, and the heads of US regulatory affairs and anti-money-laundering also left the company.

Polymarket brought in Sullivan & Cromwell to review the episode. The law firm's review concluded the company had acted in compliance with applicable regulations, a finding that addresses legal exposure without resolving the operational question of why the safeguard was removed in the first place.

A second incident, months later

The Journal's reporting also disclosed a separate July 2026 flaw in Polymarket's account-registration process that let attackers access roughly 500 accounts using only stolen personal information, such as Social Security numbers, bypassing normal username-and-password verification. By that point Polymarket had already limited the number of debit cards a single account could link, a change reported to have normalized fraud rates by May.

Two incidents in five months, on two different parts of the platform's user-onboarding and payment stack, suggest the February episode was not an isolated lapse but a symptom of infrastructure that had not kept pace with the platform's growth.

The rebuild that came after

Polymarket's compliance-leadership turnover reversed direction over the summer. In August 2026 the company hired Megan McGrath, formerly of Robinhood, as chief compliance officer for its US exchange, and Paul Jordan, from Nasdaq, as chief risk officer, alongside a former FBI official to lead investigations and a Coinbase alumna to head regulatory affairs.

On September 10, 2026, Polymarket named Warren Jenson, a former Amazon and Delta finance executive, as its first chief financial officer, tasked in part with closing a roughly $1 billion funding round reported to value the company near $21 billion, in the range of rival Kalshi's own valuation.

Why the timeline matters more than any single fact in it

None of these events individually would be unusual for a fast-growing financial platform. What the sequence shows is that Polymarket's institutional-credibility push, the executive hires, the CFO appointment, the fundraising round, followed the compliance failures rather than preceded them, arriving only after a chief compliance officer had already resigned over the company's handling of a fraud wave.

For an operator whose core legal exposure already runs through state gambling-law suits and a still-unresolved swap-definition fight in federal court, an internal compliance failure adds a distinct and separate risk. It is one regulators can act on directly, without waiting for any court to decide whether Polymarket's contracts are swaps at all.

Sources

Tracked on SiaPredict

Scoring is illustrative and based on public information. SiaPredict does not provide legal advice.