stolen debit cards
Payment processors can flag suspicious deposits before funds move deeper into the financial system. AI-Generated Image/ChatGPT

Stolen debit cards were allegedly used to fund bets on Polymarket US, as fraudsters attempted to move at least $10 million (£7.6 million) through the platform in February 2026.

The alleged scheme went beyond ordinary unauthorised card purchases. The funds were reportedly used to place bets before the perpetrators tried to withdraw money to other cards and accounts they controlled.

That creates a more complicated financial trail, with banks, payment processors, and the betting platform potentially holding different pieces of the transaction history.

Stolen Cards Became a Route Into Betting Accounts

The activity began in February 2026, when fraudsters allegedly linked stolen debit cards to thousands of Polymarket US accounts, deposited funds, placed bets, and then attempted to withdraw the proceeds to other cards or accounts they controlled. The amount represents an attempted theft, not confirmed losses of $10 million. Reporting on the incident said most of the attempted deposits failed.

At the peak of the activity, Polymarket's payment processor Checkout.com reportedly rejected more than 80% of the deposits it handled for the platform as fraudulent, compared with an industry level of roughly 1%. That gap is significant because it shows the alleged fraud was not simply a handful of isolated unauthorised purchases. The payment system was detecting an unusually high volume of suspicious activity.

The Cash-Out Stage Creates a Different Problem

A stolen debit card can usually be cancelled once its owner discovers unauthorised activity. But the financial trail becomes more complicated when the money has already been deposited somewhere else. In this case, the alleged fraudsters did not simply use stolen cards to buy goods. They reportedly tried to use the cards to fund accounts, place wagers, and then move money towards different payment cards or accounts.

That creates several points at which a transaction can potentially be identified or stopped. For consumers, the distinction matters because debit card fraud does not necessarily end when a bank reverses an unauthorised transaction. The money may already have travelled through other businesses, leaving those companies to trace what happened next.

US Regulation E provides protections for certain unauthorised electronic fund transfers, with potential consumer liability depending on factors including when the loss or unauthorised activity is reported.

Polymarket's Payment Controls Became a Key Checkpoint

Polymarket US operates through QCX LLC, which the Commodity Futures Trading Commission lists as a designated contract market under the Polymarket US name. Its designation took effect on 9 July 2025. The February episode therefore occurred while the US operation was still relatively new and expanding its customer base.

A key control reportedly used by the platform required funds deposited through one payment source to be withdrawn through that same source. Such a restriction can make it harder to turn stolen-card deposits into money that can be withdrawn elsewhere. The rule was later removed, according to reporting on the incident, raising a broader question about how financial platforms balance easier payments and withdrawals against fraud prevention.

Where Financial Liability Can Fall

There is no single party automatically responsible for every loss involving a stolen debit card. For banks, the immediate problem is identifying an unauthorised transaction. For payment processors such as Checkout.com, the challenge is detecting suspicious deposits. For platforms, it is preventing stolen funds from becoming usable balances or being transferred elsewhere.

For consumers, the crucial protection is speed. Regulation E sets different liability rules depending on the circumstances and how quickly a customer reports an unauthorised transfer or lost access device. That makes the alleged Polymarket fraud relevant beyond prediction markets.

The same basic chain can apply whenever stolen payment details are used to fund another financial service: a card is compromised, money enters a legitimate platform, transactions take place, and someone then attempts to move the funds somewhere else. The harder question is not simply whether a stolen card can be blocked. It is how quickly every link in the payment chain can recognise that the money should never have entered it in the first place.