Friday, October 9, 2026 SourcesAbout🌓
🇺🇸 US ▾
BREAKING
Technology

Polymarket Bug Reportedly Let Identity Thieves Into Existing Accounts

Gizmodo ·
Polymarket Bug Reportedly Let Identity Thieves Into Existing Accounts

Nearly 500 Polymarket US users were hit in late July by a fraud attack that did not require a password, a username, or a compromised phone, according to a Wall Street Journal report published Saturday . A person who tried to create a new account with an existing trader’s personal information, such as a stolen Social Security number, was reportedly dropped into that trader’s live profile. Linked bank accounts and debit cards also became accessible, the report says.

With the seemingly constant drumbeat of new data breaches taking place these days, the ability to access someone else’s account by effectively using personal data as a password is an incredible security vulnerability. Just a few weeks ago, 153 million driver’s licenses were put on sale following the breach of an identity verification company.

The Journal, citing a person familiar with the matter, described the episode as an engineering problem and indicated the total amount stolen via the exploit was small. However, users told a different story in interviews with the media outlet. They described losses in the thousands of dollars and weeks of unanswered support messages.

One Polymarket user in the U.S. told the Journal he joined the prediction market platform to bet on the World Cup. In July, he logged in to find his positions sold and $5,783.51 in gains sent to a debit card he did not own. Polymarket credited his account $25 and offered no explanation. The user said he filed reports with local police, the FBI, and the Commodity Futures Trading Commission (CFTC). “Polymarket US was silent for weeks and weeks,” he said. Support later put his account on hold after he submitted verification information twice but still did not address the missing funds.

A Polymarket spokeswoman told the Journal the company would cover lost money from the incident. The company has not published a public postmortem on the signup flaw.

The July attack sits inside a broader picture the Journal painted of a company that treated fraud acceptance as a cost of scaling. In February, payment processor Checkout.com warned Polymarket that thieves were tying stolen debit cards to thousands of new U.S. accounts, funding wagers, and trying to pull the money onto clean cards or accounts they controlled. Attempted theft ran to at least $10 million. At one point Checkout.com rejected more than 80% of the deposits it was handling as fraudulent, against an industry benchmark of roughly 1%.

Employees took the problem to CEO Shayne Coplan, but the compliance team’s recollection of his answer was that Coplan said to keep growing and pay a fine if regulators ever find out.

Fraud rates stayed elevated for months after February. By May, the Journal said, they had returned to industry norms after Polymarket limited debit cards per account and brought on antifraud contractor Riskified. Some customers were reimbursed while others clawed money back through their banks.

The July identity flaw was not Polymarket’s only security problem this year. In June the company said a compromised third-party vendor had injected a malicious script into its website frontend for some users.

Read the full article on Gizmodo ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on gizmodo.com — the content belongs to Gizmodo.

More from Gizmodo

See all ›

More in Technology

See all ›