To Top

Report: Polymarket Signup Flaw Exposed Existing U.S. Accounts in Late-July Fraud Attack

A Wall Street Journal report says nearly 500 Polymarket U.S. users were affected after a signup flaw reportedly let people using stolen personal information access existing accounts and linked payment methods.
Joe Boozell Avatar
3 mins read
Share Share
Copy link Share on X Share on Facebook Share on Reddit Share via Email

Bonus TL;DR

  • A July signup flaw on Polymarket allowed fraudsters to use stolen personal details to access active U.S. user accounts.
  • Despite previous security warnings and a June frontend hack, nearly 500 users were impacted before Polymarket promised full reimbursement.

A Wall Street Journal report says a signup flaw at Polymarket, a prominent prediction market, let people using stolen personal information enter existing U.S. user accounts in a late-July fraud attack that affected nearly 500 users.

The issue matters because the reported bug did not just create duplicate accounts. According to the Journal, someone who signed up with another trader’s personal details, including a stolen Social Security number, could be dropped into that trader’s live profile, with access to linked bank accounts and debit cards.

One user told the Journal that $5,783.51 in gains was sent to a debit card he did not own. The same user said he later filed reports with local police, the FBI, and the Commodity Futures Trading Commission. A Polymarket spokeswoman told the Journal the company would cover money lost in the incident.

How the reported Polymarket flaw worked

The Journal described the episode as an engineering problem and reported that the total amount stolen through the exploit was small, citing a person familiar with the matter. Polymarket has not published a public postmortem on the signup flaw, according to the report.

A user quoted by the Journal criticized the company’s response, saying, “Polymarket US was silent for weeks and weeks” after he discovered his positions had been sold and funds were missing.

The report adds that Polymarket credited that user’s account with $25, though the company also said it would make affected users whole. Based on the facts currently reported, it remains unclear how many users had funds actually taken versus how many had account or payment details exposed.

Fraud and security problems preceded the July incident

The Journal said Polymarket had already been warned about fraud risks earlier this year. In February, payment processor Checkout.com reportedly told the company that thieves were linking stolen debit cards to thousands of new U.S. accounts.

According to the report, attempted theft tied to that earlier problem reached at least $10 million, and Checkout.com at one point rejected more than 80% of the deposits it handled for Polymarket as fraudulent. By May, fraud rates had returned to industry norms after Polymarket limited the number of debit cards per account and brought on antifraud contractor Riskified.

The company also dealt with a separate security incident in June, when Polymarket said a compromised third-party vendor injected a malicious script into its website frontend for some users. Blockchain monitors estimated that drain at about $3.1 million in PUSD across at least 11 wallets. Polymarket said at the time it removed the dependency and would refund affected users in full.

What to watch next is whether Polymarket publishes a technical explanation of the late-July flaw or whether regulators respond to complaints tied to the incident.

Source: As reported by Kyle Torpey.

About the Author
VIEW ALL POSTS

Joe Boozell is the Content Lead at Bonus.com. He specializes in online casino and sportsbook bonus strategy, sweepstakes casinos, and U.S. gambling legislation, with a focus on evaluating real player value. Over the past decade, he has managed and produced iGaming content across national and state-level brands, including PlayUSA and several regional Play markets. He also spent five years as a Lead Writer for NCAA.com covering college basketball. Find more of Joe’s work at Bonus.com and across the Play network of gambling sites.

VIEW ALL POSTS