Bonus TL;DR
- A July signup flaw on Polymarket allowed fraudsters to use stolen personal details to access active U.S. user accounts.
- Despite previous security warnings and a June frontend hack, nearly 500 users were impacted before Polymarket promised full reimbursement.
A Wall Street Journal report says a signup flaw at Polymarket, a prominent prediction market, let people using stolen personal information enter existing U.S. user accounts in a late-July fraud attack that affected nearly 500 users.
The issue matters because the reported bug did not just create duplicate accounts. According to the Journal, someone who signed up with another trader’s personal details, including a stolen Social Security number, could be dropped into that trader’s live profile, with access to linked bank accounts and debit cards.
One user told the Journal that $5,783.51 in gains was sent to a debit card he did not own. The same user said he later filed reports with local police, the FBI, and the Commodity Futures Trading Commission. A Polymarket spokeswoman told the Journal the company would cover money lost in the incident.
How the reported Polymarket flaw worked
The Journal described the episode as an engineering problem and reported that the total amount stolen through the exploit was small, citing a person familiar with the matter. Polymarket has not published a public postmortem on the signup flaw, according to the report.
A user quoted by the Journal criticized the company’s response, saying, “Polymarket US was silent for weeks and weeks” after he discovered his positions had been sold and funds were missing.
The report adds that Polymarket credited that user’s account with $25, though the company also said it would make affected users whole. Based on the facts currently reported, it remains unclear how many users had funds actually taken versus how many had account or payment details exposed.
Fraud and security problems preceded the July incident
The Journal said Polymarket had already been warned about fraud risks earlier this year. In February, payment processor Checkout.com reportedly told the company that thieves were linking stolen debit cards to thousands of new U.S. accounts.
According to the report, attempted theft tied to that earlier problem reached at least $10 million, and Checkout.com at one point rejected more than 80% of the deposits it handled for Polymarket as fraudulent. By May, fraud rates had returned to industry norms after Polymarket limited the number of debit cards per account and brought on antifraud contractor Riskified.
The company also dealt with a separate security incident in June, when Polymarket said a compromised third-party vendor injected a malicious script into its website frontend for some users. Blockchain monitors estimated that drain at about $3.1 million in PUSD across at least 11 wallets. Polymarket said at the time it removed the dependency and would refund affected users in full.
What to watch next is whether Polymarket publishes a technical explanation of the late-July flaw or whether regulators respond to complaints tied to the incident.
Source: As reported by Kyle Torpey.