Polymarket’s chief executive told compliance staff to “just keep growing and pay a fine if regulators ever find out” while fraudsters tried to steal at least $10 million from its U.S. platform. That is not a startup quirk. It is the old rule in a new suit: the fine belongs to the company, the loss belongs to somebody else.
The mechanism was plain. Executives removed a rule requiring withdrawals to return to the same payment source used for deposits, despite warnings that the change could invite money laundering. Fraudsters then linked stolen debit cards to thousands of new accounts. One user attempted roughly 4,000 deposits. Checkout.com rejected more than 80 percent of Polymarket’s deposits as fraudulent, against an industry rate of roughly 1 percent.
That is not friction. It is a business decision with a customer standing underneath it.
The class is the venture-backed financial platform that treats compliance as a speed bump: Polymarket and Shayne Coplan at the operating end, with a $1 billion fundraising round valuing the company at roughly $21 billion, and capital behind it including Donald Trump Jr.’s 1789 Capital and Intercontinental Exchange. The investors are not alleged here to have ordered the protocol change. They are the money surrounding a model in which growth is urgent, oversight is negotiable, and fines are entered as an operating cost.
The exceptions are the people who had to pay in real time. Dane Collins logged in to find $5,783.51 in gains withdrawn to a debit card he did not possess. Polymarket credited his account $25. A New York user reported $950 missing. A California user said $1,500 could not be withdrawn. A Massachusetts user said his account was locked and Polymarket employees could not be reached after dozens of attempts.
The company says it will cover lost funds. That is not the same as protecting customers before the money leaves. A promise made after the theft is not a safeguard. It is a receipt.
The U.S. compliance chief, Andrew Clifford, resigned in April after sending executives a lengthy report on fraud problems. The U.S. division’s chief executive, Justin Hertzberg, was fired. The heads of U.S. regulation and anti-money-laundering left. Sullivan & Cromwell later concluded that Polymarket had complied with regulations, according to people familiar with the findings. The customer still had $5,783.51 missing.
In late July, nearly 500 users were hit by another exploit. A malicious actor using an existing trader’s personal information could gain access to the trader’s account and linked financial instruments without a password or username. The stolen amount was described as small. Five hundred accounts is not a small number. It is a warning with a head count.
Earlier reporting on Polymarket’s trading activity found that 19 accounts won 98 percent of bets on KPMG-audited firms. That is not an exhibit for “efficient markets.” It is another reason to ask who knew what, when they knew it, and whether the ordinary trader was ever playing on the same field.
We have seen this arrangement before. Wells Fargo opened millions of unauthorized accounts under sales-quota pressure, then reached a $3 billion settlement with the bank rather than the individuals responsible for the fraud. GM admitted it failed to disclose a deadly safety defect to its regulator; the company paid $900 million and no individuals were charged. HSBC admitted laundering money for drug cartels and sanctioned regimes, paid billions, and no individual was prosecuted.
The fine-as-fuel crowd calls this risk. The customer calls it an empty account.
The Commodity Futures Trading Commission is investigating. New York City is probing Polymarket’s advertising. Traders have filed almost two dozen lawsuits alleging deceptive practices. More than a dozen state cases challenge whether prediction markets are unlicensed gambling. Those proceedings do not prove every allegation. They do establish that the company’s legal and compliance posture is not the tidy success story its valuation would like to tell.
Polymarket may become large. That is precisely why the standard must rise before the valuation does. A company cannot ask the public to treat it as financial infrastructure while treating fraud controls as something to fix after the next attack.
The law binds the customer first, then sends the bill to the company. That is not equal justice. It is a business model.