In July, hackers accessed the accounts of nearly 500 users on Polymarket's American platform using only stolen social security numbers. This allowed them to access linked debit cards and bank accounts without needing usernames or passwords. The attack targeted the U.S. version of the platform, which was launched in December 2022 after Polymarket acquired a licensed exchange for $112 million. According to an insider, users had deposited over half a billion dollars on the app. The Wall Street Journal reported two separate attacks: one in February involving stolen debit cards and another in July using identity theft. In February, payment processor Checkout.com alerted Polymarket US to a sharp increase in fraudulent activity. Individuals were linking stolen debit cards to new accounts to place bets and then withdraw money. These fraudsters attempted to steal at least $10 million, and Checkout.com rejected more than 80% of the deposits, far above the typical 1% rejection rate in the industry. A small group of seven users, including one who made nearly 4,000 deposit attempts, were responsible for most of the fraud. Employees informed CEO Shayne Coplan, who reportedly told the compliance team to continue growing the platform and to pay any fines if regulators discovered the issue. The compliance team became overwhelmed, causing delays in customer withdrawals. To speed up the process, management removed the requirement to withdraw funds to the same payment method used for deposits, a move employees warned could help money laundering. Executives argued that other safeguards were enough, as federal rules don't require this for prediction markets. Other companies like DraftKings and FanDuel use this requirement, while Kalshi doesn’t but checks withdrawals to other methods and freezes suspicious transactions. In April, Andrew Clifford, head of compliance at Polymarket US, resigned after submitting a detailed report on fraud issues to executives. In May, a source close to the situation said Polymarket had returned to industry standards by limiting the number of debit cards that could be linked to an account and hiring Riskified, a fraud detection company. Former employees noted that the company often implemented updates without prior testing but recently improved code reviews and added more engineers. Sullivan & Cromwell, a law firm, concluded that Polymarket had complied with regulations, according to insiders. A company spokesperson said Polymarket has systems in place to detect and handle suspicious activities. Joe Konizeski, a former enforcement lawyer at the Commodity Futures Trading Commission (CFTC), explained that in the regulated sector, adults manage customer funds and verify their source. The CFTC is currently investigating Polymarket, and employees were told to keep documents related to the February attack and other issues. Users interviewed by the newspaper reported losing several thousand dollars each and wrote to Polymarket’s support team for weeks without getting a response. In July, an employee wrote on Discord that the engineering team was working on fixes. Polymarket reimbursed part of the affected customers, while others had their debits canceled by their banks. Dane Collins, 26, started using Polymarket US in May to bet on the World Cup. In July, he discovered that someone had sold his positions and withdrawn $5,783.51 in winnings to a debit card he didn’t own. Without explanation, Polymarket credited his account with $25. He filed a complaint with local police and the FBI and reported the incident to the CFTC. “Polymarket US was silent for weeks and weeks,” he said. After sending his verification information twice, the support team put his account on hold without mentioning the missing funds.