Polymarket bug hijacked nearly 500 accounts, WSJ reports
Thieves reportedly used stolen Social Security numbers, not passwords, to slip into live trader profiles & linked bank accounts.
The hit
A Wall Street Journal report published Saturday says a Polymarket signup bug in July let identity thieves take over live user profiles by entering stolen personal details, including Social Security numbers, with no password needed. Affected accounts gave fraudsters access to linked bank accounts & debit cards, the report says.
Why it matters
For bettors, the flaw shows a platform holding stolen personal data can be turned against a legitimate user’s login. A Polymarket spokeswoman told the Journal the company would cover losses from the incident, but reported weeks of unanswered support messages suggest reimbursement could be slow. It adds to a pattern of fraud tolerance the Journal says the company treated as a cost of scaling.
The record
| User’s stolen gains | $5,783.51 sent to a debit card he didn’t own (WSJ) |
|---|---|
| Polymarket’s response | $25 credited to that user, no explanation given (WSJ) |
| Checkout.com warning | February alert over at least $10m in attempted card fraud (WSJ) |
| Fraud rejection rate | Checkout.com rejected over 80% of the deposits it was handling as fraudulent, vs ~1% industry norm (WSJ) |
| Separate June hack | About $3.1m in PUSD drained via phishing script (AMLBot) |
What happens next
Polymarket has not published a public postmortem on the July flaw. The affected user says he filed reports with local police, the FBI & the CFTC. Watch for any regulatory follow-up & how the company details its refund process.
Sources: Polymarket Bug Reportedly Let Identity Thieves Into Existing Accounts
Named in this story? Reply to [email protected] & we publish it.
18+. Betting involves risk. If gambling is a problem for you or someone close to you, help is available.


Discussion
Ask a question, add useful context or share a source. Keep it relevant & respectful.
Comments are reviewed before publication.