The Best Argument Against This Column's Position on Prediction Markets Was Published Sunday, and It Was Not Written by a State Attorney General
The Wall Street Journal reports that Polymarket's US arm was hit by a $10m stolen-card scheme in February, that its processor was rejecting more than 80% of deposits as fraudulent, that leadership dropped a standard anti-laundering control mid-attack, and that the chief executive told staff to grow now and pay fines later. We have spent six weeks arguing federal licensing is real supervision. This is the case we have to answer.
September 21, 2026 at 4:28 PM EDT
6 min read
This column has taken a position, repeatedly and in labelled commentary: states should not be bringing criminal process against exchanges holding a federal licence. The argument has always rested on a premise rather than a preference. The premise is that registration with the Commodity Futures Trading Commission is supervision — a real examination regime with real controls behind it — and that a state gaming regulator duplicating it, with handcuffs, adds risk to consumers rather than protection.
On Sunday the Wall Street Journal published reporting that goes directly at the premise. We should deal with it rather than route around it.
What is alleged
We have not read the Journal's story. It sits behind a paywall we do not have access to, and what follows comes from outlets that have read it and reported it consistently with one another. Where they agree we are reasonably confident; where they do not, we say so.
Beginning in February, fraudsters attached stolen debit cards to thousands of accounts on Polymarket's US platform, placed trades, and attempted to move the proceeds out to accounts they controlled. The target was at least $10 million. Around seven users appear to have driven most of it; one of them is described as attempting roughly 4,000 separate deposits.
The detail that should stop anyone reading quickly is the processor's. Checkout.com, handling Polymarket US deposits, at one point was rejecting more than 80 per cent of the deposits it saw as fraudulent. The industry norm is somewhere around one per cent. That is not a compliance programme missing a signal. That is a compliance programme being screamed at by its own payments vendor.
Two responses are reported. The first is that leadership removed a requirement that funds be withdrawn to the same source they were deposited from. That control is not exotic and it is not mandated for prediction markets; it is, however, close to the single most effective way of stopping stolen-card proceeds from being laundered into clean accounts, which is why banks use it. Employees are reported to have warned that dropping it "invited money laundering." Executives took the view that the remaining controls were enough.
The second is a quotation, attributed by the Journal to compliance staff recollections, in which chief executive Shayne Coplan told employees to focus on growth now and worry about any regulatory fines later.
Then the personnel record, which is the part that reads least like a misunderstanding. US chief compliance officer Andrew Clifford resigned in April, after sending executives a report setting out the fraud problems. The US division's chief executive, Justin Hertzberg, was later fired. The US heads of regulation and of anti-money-laundering also left. In July a separate flaw in account registration let attackers into nearly 500 accounts using stolen personal data, without needing usernames or passwords.
The CFTC is investigating. Staff have been told to preserve records.
We do not know how much money was actually taken. Reporting indicates most of the attempted deposits failed, and no figure for realised losses has been established. We also have not seen a Polymarket response beyond what the Journal carried, and if the company disputes the account we will print the dispute.
Why this lands on us specifically
Strip out the fraud for a second and look at the shape.
The federal-preemption argument — the CFTC's own, asserted in its April suit against Arizona, Connecticut and Illinois, and Kalshi's in every state courtroom this year — is jurisdictional. It says these are federally regulated derivatives, one national regulator governs them, and fifty state gaming regimes may not. We have supported the legal core of that.
But the political argument the industry actually makes is different, and softer: trust the federal regime, because the federal regime is rigorous. States answer that sports event contracts are gambling products sold to consumers, and that a derivatives regulator built to supervise commodity hedgers is not equipped to run consumer protection for retail punters.
We have called that the states' weakest argument. We were wrong to be so confident. A federally registered venue whose payment processor was rejecting four-fifths of its deposits as fraudulent, whose compliance chief quit after writing it up, and which loosened an anti-laundering control while the attack was live, is a fairly exact illustration of what the states have been describing. New Jersey's certiorari petition, filed September 2, argues that this is a question about who protects consumers. Two and a half weeks later it has a case study.
What it does not prove
Three things, and they matter.
The jurisdictional question is untouched. Whether the Commodity Exchange Act preempts state gaming law is a question of statutory interpretation. It does not turn on whether one registrant behaved badly, any more than a bank fraud makes the National Bank Act mean something different. The Ninth Circuit's August 28 panel decision went against Kalshi on the reasoning that the contracts were not swaps because they were sports bets — a textual holding, unaffected by any of this.
A state licence is not a fraud vaccine. Licensed operators have had control failures, laundering findings and enforcement actions, in this industry and every adjacent one. "State regulators would have caught it" is an assertion, and the people making it should be asked for the evidence.
And the remedy question — the one this column actually cares about — is, if anything, strengthened. What happened here is that a federal regulator opened an investigation, records were preserved, and a company's compliance leadership turned over. That is the supervisory machine working, slowly and after the fact, which is how supervisory machines work. It is still not an argument for a state attorney general filing criminal charges against an exchange. Prosecutions are for the people who attached the stolen cards.
Where we come out, and what would move us
The honest revision is this: we have been treating "federally licensed" as a description of how an exchange behaves. It is a description of who has jurisdiction to punish it. Those are not the same claim, and we ran them together.
That does not change our view on criminal enforcement against exchanges, which we still think is the wrong instrument aimed at the wrong party. It does change how much weight the phrase "CFTC-regulated" should carry when an exchange deploys it as a consumer-safety credential, which is most of the time. On the evidence of the last two days it is not one.
The specific thing that would move us further: if the CFTC's investigation closes without a public finding, or with a penalty that reads as a cost of doing business, then the states' case that this regulator is not equipped for retail consumer protection stops being rhetoric and becomes the record. If it produces a substantive enforcement action with remediation the exchange has to live inside, the federal regime will have earned the deference we have been extending it on credit.
We publish a lot of words about who should regulate these venues. It is worth remembering what the argument is nominally about — someone's grandmother's debit card, run four thousand times through a website that takes bets on football.
Editor's note: TrueEdge builds odds and pricing tools and earns affiliate commissions from licensed sportsbooks, which compete directly with the prediction-market exchanges discussed here. That conflict runs toward this piece's conclusions, not against them, which is precisely why the section above on what the reporting does not prove is the longest one. We have argued against criminalising federally licensed exchanges and we have not changed that position. Weigh all of it accordingly.