Polymarket International is a prediction-market protocol on Polygon with a 32/100 score (red band), reflecting active regulatory enforcement and an unresolved security incident.
Security: Multiple audits by ChainSecurity, Quantstamp, Cantina, and Certora cover V1/V2 contracts, deposit wallets, and oracle subsystems; the March 2026 CTF Exchange V2 audit found 0 critical/high, 1 medium, and 3 low issues, all reportedly fixed. However, detailed remediation status and bytecode-match verification for many 2026 audits are not verifiable as of September 2026.
Incidents: Two major breaches in 2026: (1) May 21–22 internal-wallet key compromise drained ~$700k in POL from operational wallets (user funds unaffected, resolved); (2) June 25 frontend supply-chain attack via compromised vendor stole ~$3.0–3.1M from <15 users (remediation in progress, full reimbursement pledged but not verified). Both incidents demonstrate operational and third-party risk.
Governance & custody: Non-custodial (users hold keys); no DAO governance verified—control appears centralized with Polymarket/Adventure One QSS Inc. (Panama). Upgrade authority, timelock, and admin structure not verifiable on-chain as of September 2026.
Top risks: (1) Regulatory: 2022 CFTC enforcement ($1.4M penalty, U.S. market wind-down) and ongoing federal scrutiny; international entity structure and compliance posture unclear. (2) Oracle dependence: UMA Optimistic Oracle resolution can be gamed or disputed incorrectly. (3) Collateral: pUSD backing by USDC is claimed but reserve attestation/custodian not disclosed. (4) Operational: Key-compromise and supply-chain incidents show control gaps.
Strengths: Broad market coverage, fast/low-cost Polygon settlement, high liquidity, transparent on-chain execution, and self-custody model. Active bug bounty (Cantina, up to $5M) and extensive 2026 audit program.
Unverified: TVL, live contract balances, proxy-admin ownership, reserve composition/attestation, DAO voting structure, exact legal entity for "Polymarket International," and full remediation/reimbursement status for June 2026 incident all not verifiable as of September 2026 due to unavailable on-chain tooling and incomplete public disclosure.
Recommended exposure: Avoid or limit to <1% of portfolio given red-band score, active enforcement history, and two 2026 incidents. If allocating, use only for short-term event hedging with funds you can afford to lose; verify June incident reimbursement completion, confirm pUSD reserve backing independently, and monitor regulatory developments. Do not rely on DAO governance or decentralized control.
Open questions: (1) Has June 2026 reimbursement been completed and verified on-chain? (2) Who controls upgrade keys and what is the timelock delay? (3) What is the legal entity, jurisdiction, and licensing status of "Polymarket International"? (4) Is pUSD reserve 1:1 USDC backing independently attested, and by whom? (5) What permanent key-management and supply-chain controls were implemented post-incidents?
Score
Component
Weight
Raw
Points
Reason
Security
20%
100
20.0
19 audit(s); fresh audit bonus; active bug bounty bonus
Audits
20%
100
20.0
full audit within 365 days (latest 2026-08-01)
Incidents
20%
100
20.0
1 open incident(s), $3,000,000 at risk = 0.8% of TVL (threshold 10%)
Governance
20%
50
10.0
no DAO governance
TVL
20%
2
0.4
TVL $359,624,825 = 2% of reference ($17,538,184,136)
Active regulatory enforcement (−15): legal fact records active enforcement or sanctions
Identification
protocol identification
two sources
Polymarket International is the Polymarket prediction market protocol running on Polygon, exposed via polymarket.com and its developer/docs stack. Protocol identification
Name: Polymarket (Polymarket International appears to be the institutional / global-facing instance of the same Polygon protocol).
Launch date: Not explicitly stated in the retrieved sources. *Not verifiable as of 2026-09-04.*
Chains: All smart contracts referenced in official docs and third-party technical references are on Polygon mainnet (Chain ID 137); no other chain deployments are documented.
Native token / collateral: Polymarket uses USDC.e and Polymarket USD (pUSD) as collateral rather than a speculative native governance token. pUSD is an ERC‑20 collateral token with proxy/implementation addresses defined in multiple independent sources. Key contract addresses on Polygon (≥2-source cross-check) All of the following are confirmed both by Polymarket’s own docs and independent technical references (so they qualify as explorer/analytics‑verified, not on-chain‑queried):
Proxy wallet factories (user safes/proxies): Gnosis Safe factory 0xaacfeea03eb1561c4e67d661e40682bd20e3541b and Polymarket proxy factory 0xaB45c5A4B0c941a2F231C04C3f49182e1A254052. Explorer verification status of these contracts (e.g., source‑code verified, proxy patterns) depends on direct explorer inspection, which I cannot perform in this turn. *Not verifiable as of 2026-09-04.* Fork lineage and modifications
Polymarket’s core outcome token system is based on the Conditional Token Framework (CTF), originally introduced by Gnosis; this implies a functional fork/derivative lineage from Gnosis’ CTF design, with Polymarket-specific exchanges, negative‑risk adapter, and collateral conventions layered on top.
The retrieved sources describe V2 addressing and additional contracts (neg‑risk exchange, adapter, pUSD) as extensions, but do not explicitly label them as forks of a particular upstream codebase beyond CTF, nor link to formal audit reports for these modifications.
No concrete evidence of malicious modifications in similar forks or exploit history is returned in the available material. *Not verifiable as of 2026-09-04.* Given tool limits this turn, on-chain query IDs, execution IDs, and direct explorer verification cannot be provided and all on-chain claims above rely on docs + independent technical references, not raw-chain Dune evidence.
Polymarket appears to be a real, live product portal rather than a mere landing page: the main site is active, and its documentation explicitly exposes API reference pages and SDK/API endpoints, which indicates a functional platform with developer access rather than a static marketing shell. The docs also describe trading infrastructure via Gamma, CLOB, and Data API endpoints, supporting the conclusion that an open API exists. For user flows, the public documentation includes deposit/withdrawal guidance, and historical Polymarket materials describe manual and wallet-based deposit/withdrawal processes on Polygon; however, live, current on-chain execution of deposits/withdrawals is not verifiable in this run, so the operational status should be treated as not verifiable as of 2026-09-04.
The presence of app-store listings for Polymarket on both Android and iOS also supports that this is an actual deployed product, not just a template site. I did not find evidence in the gathered material of obvious broken links, fake metrics, or template-site signs. The only caution is that some deposit/withdrawal details are spread across docs and older help posts, so UX consistency is plausible but not fully verifiable from the available web evidence.
Polymarket has an active bug bounty program hosted on Cantina. The program page shows an effective start date of 12 Apr 2026, and Polymarket’s docs link to that Cantina bounty as the reporting channel. The published scope covers Polymarket’s smart contracts, web app, and related infrastructure; the bounty page snippet indicates top payouts up to $5,000,000 for critical smart-contract issues, with web vulnerabilities capped at $250,000.
Reported public coverage describes the program as newly launched and live, with no public disclosure in the gathered sources of payouts or found vulnerabilities; results are therefore Not verifiable as of 2026-09-04.
As of September 6, 2026, Polymarket International’s material dependencies are Polygon PoS, UMA’s Optimistic Oracle, Circle USDC/USDC.e, Polymarket’s bridge/on-ramp contracts, and Polymarket-operated off-chain order matching. It does not appear structurally exposed to lending protocols, LST/restaking, RWA issuers/SPVs, or external yield strategies. Oracle/manipulation risk — high relevance. Market resolution uses UMA on Polygon. Outcomes are initially proposed optimistically, followed by a challenge period and, if disputed, UMA escalation/voting.
Failure modes include ambiguous market rules, insufficiently challenged false proposals, UMA governance/voter concentration, or an attacker economically overwhelming the dispute process. A wrong resolution can make winning claims unredeemable or transfer value to the wrong side. Stablecoin and bridge risk. Deposits from supported chains/assets are converted into pUSD on Polygon; pUSD is described as a USDC-backed ERC-20, while users may deposit native USDC or bridged USDC.e. This creates dependence on USDC solvency/depeg risk, USDC.e/Polygon bridge integrity, the on-ramp/off-ramp contracts, and Polygon availability.
The pUSD backing and pause controls are protocol documentation claims; independent reserve verification was not identified. Custody/operator risk. Polymarket describes the product as non-custodial and trades settle through smart contracts, but orders are created and matched off-chain by an operator. Operator censorship, API failure, market suspension, contract pause, or frontend compromise remain relevant operational risks. CEX/MM, insolvency, and active incidents. Specific CEX, market-maker, treasury, reserve, or counterparty concentrations: Not verifiable as of September 6, 2026. No active dependency failure was independently verified in this review.
RWA/SPV, LST/restaking, and lending-protocol exposure: Not verifiable as of September 6, 2026. Contradiction: the prior description characterized settlement as directly USDC-based; current documentation describes pUSD as the trading collateral wrapper, backed by USDC. The current documentation supersedes the older description, but reserve independence remains unverified.
Polymarket International is organized as non-custodial: users hold their own private keys, Polymarket says it does not custody or control user funds, and collateral backing an open position is held in a smart contract rather than in a Polymarket company account. In practical terms, custody sits with user-controlled wallets plus onchain escrow/settlement contracts on Polygon; Polymarket can facilitate matching and execution, but it does not take possession of the crypto.
Bug bounty: Polymarket says security vulnerabilities can be reported through a Cantina bug bounty program, and independent coverage states the program launched on Cantina with rewards up to $5M. The exact scope and reward tiers for key-compromise scenarios were not fully verifiable from the available material.
On May 21–22, 2026, Polymarket’s Polygon operational/reward infrastructure was drained after compromise of an internal private key. Early reports attributed the activity to the UMA CTF Adapter, but Polymarket engineering said contracts and core infrastructure were not exploited. Affected assets were POL held in internal top-up/reward and administrative wallets; user deposits, open trades, settlements, and USDC collateral were reported unaffected.
The protocol contained the compromise and could continue operating. No user reimbursement was required. Exact recovery and permanent remediation are Not verifiable as of September 5, 2026; public reporting indicates the stolen assets were routed through intermediaries and exchanges.
Current status: resolved for users, with residual security-remediation details undisclosed.
On May 22, 2026, an attacker compromised a private key controlling Polymarket internal operational/top-up and reward wallets on Polygon. Approximately $700,000 in POL was drained; user deposits, open trades, market settlements, USDC collateral, and core contracts were reported unaffected. The attacker routed proceeds through multiple addresses and centralized exchanges.
Polymarket contained the drain and stated the issue was a wallet-key compromise, not a protocol or smart-contract exploit. Approximately $164,000 was reportedly frozen during recovery efforts, but actual recovery or return of those funds is Not verifiable as of September 6, 2026. No user reimbursement was required.
Remediation reportedly included migrating keys to KMS-backed infrastructure; independent confirmation of all permanent controls is limited. Current status: resolved.
Since launch, Polymarket has had at least two publicly reported security incidents: a May 22, 2026 internal-wallet private-key compromise that drained about $520k to $700k from an operational rewards/top-up wallet on Polygon, and a June 25, 2026 frontend supply-chain breach via a compromised third-party vendor that stole about $3.0M to $3.1M from fewer than 15 users. In the May incident, reported losses were tied to an internal wallet used for operations, not core contracts; in the June incident, the platform said user funds were affected through a malicious script injected into the frontend, while smart contracts were not compromised. Public reporting indicates Polymarket said it rotated/revoked the compromised key, moved to KMS-based key management, contained and removed the bad dependency, and pledged full reimbursement to impacted users in the June incident.
For the May incident, reporting says user funds and market resolution were unaffected; a full reimbursement commitment was not clearly established in the material found. As of 2026-08-29, a precise, on-chain verified breakdown of affected addresses and reimbursements is not verifiable from the available sources.
Polymarket’s key management is organized in a layered, non-custodial model. A user keeps control of the wallet private key, which is used for L1 EIP-712 signing to create or recover API credentials; those credentials are then used for L2 HMAC-based authentication on trading and account requests. In practice, the trading stack separates three things: the wallet signer, the API credential set, and any optional session/builder signer.
The API credential set consists of an API key, secret, and passphrase; the secret/passphrase are issued for authenticated use and are not the wallet private key. Polymarket also supports scoped signer patterns. Documentation describes session keys as separate signers authorized by a deposit wallet owner for trading, and builder-related tooling mentions separate builder headers and a revocation flow for compromised builder credentials.
For operational handling, the recommended pattern is to keep the wallet key under the user’s control and store it securely on the client side; third-party guidance notes common storage tiers such as local env files for small setups, self-hosted vaults for larger ones, and cloud KMS for higher-value or multi-bot deployments. The main risk-management implication is that Polymarket’s architecture does not centralize custody in the protocol, but it does create multiple secrets to manage: wallet private key, API credentials, and possibly session/builder keys. Credential rotation and revocation are part of the documented lifecycle.
As of September 6, 2026. Dune MCP was unavailable; therefore proxy-admin ownership, decoded role events, timelock delay, balances, and current pause/withdrawal state are Not verifiable as of 2026-09-06. No on-chain claims are made. Addresses reported in public materials (Polygon, chain 137): CTF Exchange V2 0xE111180000d2663C0091e4f400237545B87B996B; Neg Risk Exchange 0xe2222d279d744050d28e00520010520000310F59; Conditional Tokens 0x4D97DCd97eC945f40cF65F87097ACe5EA0476045; pUSD proxy 0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB, implementation 0x6bBCef9f7ef3B6C592c99e0f206a0DE94Ad0925f; UMA Adapter 0x6A9D222616C90FcA5754cd1333cFD9b7fb6a4F74.
These are documentation/repository claims, not independently on-chain verified in this run. Architecture:Users → off-chain CLOB/operator → Exchange → CTF/ERC-1155 + pUSD ↘ UMA Adapter/Oracle → resolutionUSDC → Onramp → pUSD proxy/UUPS → Offramp → USDC The published V2 code describes admin/operator access, global trading pause, per-user pause, configurable fee receiver and maximum fee rate (default 5%), plus permissioned ramp admin/witness roles. The collateral token is documented as UUPS-upgradeable; combo modules and Exchange are separately listed as proxy/implementation pairs. Contradiction / address-control finding: the current contracts page labels 0xE111… “CTF Exchange,” while the security registry labels 0xe333… “Exchange” and the contracts page labels 0xe333… the combo Exchange proxy. This likely reflects distinct trading/combo components, but exact production routing is Not verifiable as of 2026-09-06.
Audits are publicly listed for V2, including Quantstamp and Cantina; audited-deployment equivalence and unresolved findings are Not verifiable as of 2026-09-06. If privileged keys are compromised, plausible impact includes trading freeze, fee escalation within code limits, collateral wrapping/unwrapping disruption, oracle/resolution manipulation if oracle authority is compromised, or proxy implementation replacement where upgradeable modules are involved. Whether admins can directly drain user assets, whether exits remain available during pauses, and whether any timelock/renunciation exists are Not verifiable as of 2026-09-06.
v1-contracts audit report — oz uma ctf adapter; file audit-reports/v1-contracts/oz_uma_ctf_adapter.pdf in Polymarket/contract-security (protocol audit catalog).
CTF Exchange V2 on Polygon has also been audited by Cantina in March 2026. Scope:
Same CTF Exchange V2 core trading and settlement contracts on Polygon, with focus on market creation, order processing, and risk around resolution flows. Severity / findings:
The Polymarket contract listing confirms the existence of the Cantina report but does not summarise specific issue counts or severities.
Detailed critical/high/medium/low findings and their remediation status are Not verifiable as of 2026‑08‑30 without direct access to the Cantina PDF. Fix status:
Polymarket’s resources table implies the report is final (not “preliminary”) but does not explicitly state whether all findings were fixed; this is therefore Not verifiable as of 2026‑08‑30. Bytecode‑match / deployed code coverage:
The audit is advertised as covering CTF Exchange V2, which is the production exchange on Polygon, but an explicit bytecode hash comparison to the currently deployed contracts is Not verifiable as of 2026‑08‑30 under current constraints.
ctf-exchange-v2 codebase, including order matching, settlement, collateral adapters, and exchange accounting.
Findings
Critical: 0; High: 0; Medium: 5; Low: 6; additional informational/gas issues are described in the report. Noted issues include insufficient taker-side aggregate reconciliation and zero-sized orders being marked filled without economic execution.
Fix status
Some findings were fixed and verified; complete remediation status is Not verifiable as of 2026-09-05.
V1 Exchange governance and exchange contracts; functional correctness, access control, signatures, complexity, and gas efficiency. Polygon deployment reference: CTF Exchange V1 0x4bFb41d5B3570DeFd03C39a9A4D8dE6Bd8B8982E.
Findings
Critical: 2 (signature valid for arbitrary address; incorrect ORDER_TYPEHASH). High: 1 (fee rate not hashed). Medium: 3 (fee approval, unintended order types, zero-address EOA signer). Low: 10. The report lists all findings as corrected or specification-changed during the engagement.
Fix status
Resolved during engagement according to the report; independent post-deployment remediation verification: Not verifiable as of 2026-09-05.
Conditional Tokens used for binary-outcome positions; functional correctness and elliptic-curve calculations for token-ID computation.
Findings
No critical, high, or medium findings identified in the published executive summary. The report notes complexity around negated elliptic-curve IDs and possible valueless 'all-purpose' position tokens, without treating it as a security risk in the framework.
Fix status
No material severity findings reported; deployed-code remediation status: Not verifiable as of 2026-09-05.
Audit(s) of multiple Polymarket Polygon contracts used by Polymarket International, including Conditional Tokens and proxy/safe factories.
Auditor
ChainSecurity
Report date
2024-04-12
Scope
ChainSecurity audits cover at least: Proxy Factory, Safe Factory, Conditional Tokens, and additional adapters (e.g., NegRisk) used by Polymarket, all deployed on Polygon mainnet and referenced as upstream contracts for Polymarket International.[3][6][9][10]
Findings
ChainSecurity’s **Conditional Tokens** audit finds high security for functional correctness and elliptic‑curve ID computation, noting a complexity/usage risk around potential infinite minting of position tokens with no value but not as a security flaw.[9] Severity counts (critical/high/medium) are not summarised in accessible snippets and are Not verifiable as of 2026-09-04. The **Proxy Wallet Factories** audit similarly concludes high security for functional correctness and signature handling, again without publicly summarised severity counts in snippets; exact issue tally is Not verifiable as of 2026-09-04.[10]
Fix status
Immunefi and Polymarket’s contract-security repo state these audited contracts are the ones deployed on **Polygon mainnet**.[3][8] However, without direct bytecode comparison or explicit "all issues fixed" statements per report, precise fix status and bytecode-match for each contract are Not verifiable as of 2026-09-04.
Earlier audit of Polymarket Exchange smart contracts, covering governance and exchange parts of the protocol on Polygon.
Auditor
ChainSecurity (legacy Polymarket Exchange)
Report date
2022-01-13
Scope
Governance and exchange smart contracts forming the earlier version of Polymarket’s trading system on Polygon.[7][12]
Findings
The ChainSecurity exchange audit states the contracts provide a "high level of security" with focus on functional correctness, access control, signature handling, code complexity, and gas efficiency.[7] Specific severity counts (critical/high/medium) are not exposed in snippets and are Not verifiable as of 2026-09-04.
Fix status
The audit summary indicates the then‑current codebase was considered secure, but whether all identified issues were remediated in the deployed Polygon version and whether this legacy exchange is still in active use for Polymarket International is Not verifiable as of 2026-09-04.
Audit of Polymarket CTF Exchange V2 smart contracts on Polygon mainnet.
Auditor
Quantstamp
Report date
2026-03-11
Scope
CTF Exchange V2 (central limit order book for Polymarket markets on Polygon), including functional correctness, access control, and security properties of the exchange contracts.[1][4][5]
Findings
Quantstamp’s report for **CTF Exchange V2** (March 2026) states **no high‑severity issues**, **one medium‑severity issue**, **three low‑severity issues**, and **one informational issue** were identified.[5] Detailed issue descriptions and recommendations are contained in the PDF report.[5]
Fix status
Quantstamp’s certificate indicates the issues were addressed; however, exact remediation status for each issue (e.g., fully fixed vs. acknowledged) is only described inside the report and is Not verifiable as of 2026-09-04 without direct access to the full text beyond the summary.[5] Whether the deployed Polygon bytecode matches the audited commit is also Not verifiable as of 2026-09-04.
Polymarket CTF Exchange V2 source commit a9d2397; exchange, adapters, collateral layer, order matching, settlement, signatures, fees, and access control.
Findings
Critical: 0; High: 0; Medium: 1; Low: 3; Informational: 1. Main medium finding: inconsistent COMPLEMENTARY-path fill inputs could overcharge or underfill takers. All five findings were marked fixed in the fix-review update dated 2026-03-25.
Fix status
Fixed and reviewed by Quantstamp; exact bytecode match to currently deployed Polygon contracts: Not verifiable as of 2026-09-05.
Polymarket appears to be a real operating company, not just a web front: independent reporting consistently identifies Shayne Coplan as founder and CEO, and notes he started the business in 2020 from a New York apartment/“bathroom office” before it scaled into a major prediction market. Coplan’s prior public project was TokenUnion (a crypto loyalty project), which is the only clearly documented earlier venture in the sources gathered. Public sources also show a small founding-team origin, but I could not independently verify the full roster of early cofounders or current team composition beyond Coplan from the materials gathered.
On credibility, the company has both signals of traction and regulatory risk. Reporting ties Polymarket to major election-volume growth and to large venture backing, while also documenting a 2024 FBI search of Coplan’s home in connection with a criminal/probe related to the platform. That is a material governance and compliance red flag, even though it does not by itself prove misconduct.
On the office / onshore-offshore question, the gathered sources support that Coplan was operating from New York, and later reporting describes Polymarket as headquartered in New York City. However, the company’s exact legal entity structure, offshore components, and whether operations are materially split across jurisdictions are Not verifiable as of 2026-09-04 from the sources gathered. Reality check: Polymarket looks like a functioning business with a named founder, visible staff footprint, and major market adoption, but the information available here is stronger on product and founder visibility than on transparent corporate structure.
The biggest unresolved issue is jurisdictional/compliance clarity, especially given the FBI/CFTC-related reporting.
Polymarket International has a mixed but high‑profile reputation, combining strong investor backing and growing mainstream usage with significant ongoing legal, regulatory and ethical controversies. Founders / entity / investors
The core entity behind Polymarket is Blockratize Inc., which operates the polymarket.com platform.
The platform is widely covered as one of the leading crypto prediction markets, attracting institutional and retail interest and substantial media attention.
It has attracted notable venture investment and operates as a growth‑stage fintech/crypto startup, though specific investor lists are not detailed in the retrieved regulatory sources. Regulatory and legal history
In January 2022, the U.S. Commodity Futures Trading Commission (CFTC) issued an order against Blockratize/Polymarket for operating an unregistered event‑based binary options trading facility and failing to register as a Designated Contract Market (DCM) or Swap Execution Facility (SEF).
Polymarket paid a $1.4M civil penalty and was ordered to wind down non‑compliant markets and cease and desist from violating the Commodity Exchange Act.
Following this, Polymarket geoblocked U.S. users from its international exchange.
Later reporting indicates that DOJ and CFTC investigations into a breach of that agreement were dropped in 2025, but new federal scrutiny of prediction markets, including Polymarket, has continued.
As of 2026, Polymarket is described as operating in a legal and ethical grey area, with ongoing debate over whether it is a regulated derivatives venue or an unlicensed gambling operation.
Multiple governments (including France, Brazil, Italy, Gibraltar) have banned Polymarket’s services, citing gambling or financial regulation concerns. Current investigations and criticisms
Recent reports describe ongoing or renewed federal investigations into Polymarket by U.S. regulators, including scrutiny over fabricated social‑media “wins” promotions, targeted marketing to college students, and broader questions about manipulation and consumer protection.
A consumer advocacy lawsuit alleges “many layers of manipulation” in Polymarket’s marketing by the CEO and CMO.
Federal prosecutors have been exploring whether lucrative bets on prediction markets involve insider trading, AML, market manipulation, or fraud; Polymarket is among the platforms referenced.
NYC Council and several U.S. states have probed Polymarket over alleged predatory marketing and whether its products should be regulated as gambling rather than financial derivatives. Risk‑relevant integrity signals
Polymarket has cooperated with authorities in at least one insider‑trading case involving military information, referring suspicious accounts to the Justice Department; regulators publicly acknowledged this cooperation.
Nevertheless, independent analysis and major media continue to highlight unresolved legal risk, regulatory uncertainty, bans in multiple jurisdictions, and ethical concerns around markets on wars and military strikes. On‑chain verification
Economic model — Polymarket International (Polygon)
Strategy/assets: Prediction-market trading, not a deposit-based yield strategy. Users deposit supported assets, converted to pUSD, a Polygon ERC-20 collateral token backed 1:1 by USDC; they buy/sell Yes/No outcome shares. Winning shares redeem for $1; losing shares expire worthless after resolution.
Yield source: No protocol APY, lending yield, restaking, or compounding strategy. User returns are directional event-trading P&L and market-making spreads. organic_yield_pct: null.
Organic vs subsidized: Trading returns are not protocol yield. Taker fees on enabled markets fund daily maker rebates, so maker economics are partly incentive-supported/subsidized. Fee-free geopolitics markets generate no Polymarket trading fees.
Market-neutral/exposure: The protocol itself is not market-neutral. Users can take directional outcome exposure; market makers may run hedged strategies, but this is user-specific. No leverage, looping, external yield, or restaking mechanism was identified. leverage_ratio: null.
Lock-ups/withdrawals: Capital can remain encumbered while positions are open or until market resolution. pUSD can be withdrawn through the collateral offramp, unwrapped/swapped to native USDC, and routed to supported chains; Polymarket states withdrawals are instant and fee-free, excluding possible intermediary/network costs.
Fees/limits/gates: Makers pay 0%; taker fees vary by category and price, with crypto markets listed at 7% of the fee formula and most categories 3–5%. Market-specific parameters apply. Deposit/withdrawal limits and account-access restrictions: Not verifiable as of September 6, 2026.
Protocol revenue: DeFiLlama reports approximately $15.3m 30-day revenue and $31.6m fees in one recent snapshot, but the attribution is analytics-platform data, not raw on-chain verification.
TVL: DeFiLlama reports roughly $345–349m, 100% Polygon, with 4.1% 30-day growth in one snapshot; the differing figures indicate dashboard/snapshot inconsistency. Dune TVL, product split, chain trend, APY history/volatility, and sustainability: Not verifiable as of September 6, 2026. Risk conclusion: This is trading/settlement infrastructure, not a conventional yield protocol. Returns are directional and resolution-dependent; reported “revenue” and TVL should not be interpreted as depositor yield.
As of September 6, 2026, no verifiable protocol-level treasury or reserve disclosure was found for Polymarket International. Liquid reserves, reserve addresses, composition, custodian, control/signing structure, reserve policy, and independent attestations are Not verifiable as of September 6, 2026. Dune MCP was unavailable in this run; therefore on-chain balances and reserve concentration are also Not verifiable as of September 6, 2026.
No Dune query ID or execution ID exists for this check. Polymarket’s current documentation identifies Polygon collateral infrastructure: pUSD proxy 0xC011a7E12a19f7B1f670d46F03B03f3342E82DFB, implementation 0x6bBCef9f7ef3B6C592c99e0f206a0DE94Ad0925f, CollateralOnramp 0x93070a847efEf7F70739046A929D47a521F5B8ee, CollateralOfframp 0x2957922Eb93258b93368531d39fAcCA3B4dC5854, PermissionedRamp 0xebC2459Ec962869ca4c0bd1E06368272732BCb08, and Deposit Wallet Factory 0x00000000000Fb5C9ADea0298D729A0CB3823Cc07. These are infrastructure addresses, not evidence of treasury ownership or reserve balances.
Polymarket states that pUSD is backed by USDC and that backing is enforced by the smart contract. This supports a product-level collateral claim, but does not disclose the backing account(s), custodian, real-time balance, reconciliation process, or audit/attestation. Contradiction / gap: the existence of pUSD backing language should not be treated as proof of a disclosed corporate reserve. The previously recorded third-party claim regarding segregated accounts and monthly attestations could not be independently confirmed in this check and remains secondary/unverified.
No published protocol liabilities figure was located. Structured fields: liquid_reserves_usd: null; liabilities_usd: null.
Polymarket International does not have a publicly verified native token as of the information gathered here; therefore token name/ticker, contract address, total supply, circulating supply, market cap, FDV, emissions, unlocks, allocations, and holder concentration are Not verifiable as of 2026-09-04. The available sources instead describe Polymarket as operating on Polygon mainnet and using USDC / pUSD collateral plus CTF-related contracts, not a native protocol token.
Native token: No official native Polymarket token is confirmed in the gathered sources; claims of a future POLY token remain speculative and are not a verified launch.
Token utility / governance: Not verifiable as of 2026-09-04. No source here confirms token-based governance, revenue share, buybacks, burns, or staking rewards.
Mint / blacklist / fee-switch controls: Not verifiable as of 2026-09-04. The sources do confirm Polymarket’s deployed contracts are on Polygon and reference CTF, exchange, and collateral contracts, but not a token admin model for a native token.
Unlock schedule / announced unlocks: Not verifiable as of 2026-09-04. No verified native-token allocation or vesting schedule was found, so there is nothing on-chain to confirm as having unlocked.
DEX liquidity / main listings: Not verifiable as of 2026-09-04 for a native Polymarket token, because no verified token exists in the gathered sources. The platform’s core activity is prediction-market trading with USDC/pUSD collateral on Polygon. The strongest verified point is that Polymarket’s contracts are deployed on Polygon mainnet and its trading uses USDC/pUSD collateral; any article or post claiming an official POLY token should be treated as unverified unless Polymarket publishes a contract and tokenomics or a reputable market listing confirms it.
For the stress scenario of Bitcoin falling below $10,000, the only directly relevant Polymarket-linked evidence in the provided results is a secondary report saying Polymarket-priced odds for a $10,000 crash were about 5% in an extreme geopolitical/liquidity downside case. That implies the scenario is treated as a low-probability tail event, not a base case. I could not verify a Polymarket market specifically for below $10,000 from the provided results alone, so the exact contract-level probability is Not verifiable as of 2026-09-04.
The closest direct Polymarket evidence shows much higher probabilities for milder downside levels, such as below $75,000 at 71% on Polymarket’s Bitcoin page, which is consistent with a market that prices gradual downside more heavily than an outright collapse. For institutional risk framing, the main takeaway is that a sub-$10k outcome appears to be an extreme stress case rather than a market-implied central scenario in the available evidence.
Polymarket’s collateral on Polygon is pUSD in the current documentation, while older materials still describe the platform as having used USDC.e on Polygon, so the exact collateral stack has changed over time. For a 20% depeg of the largest collateral asset, the direct stress impact on users is a 20% haircut in collateral value for any position or account that is marked against that asset; however, Polymarket’s public docs do not provide enough information to quantify protocol-wide losses, insolvency exposure, or a reserve backstop from the available sources, so those figures are Not verifiable as of 2026-09-04. For the market mechanics, Polymarket states that its markets are fully collateralized and that liquidation / margin checks are based on account equity versus maintenance requirements, so a collateral depeg would mainly create under-collateralization risk for any balances still held in the depegged asset rather than open-ended protocol leverage.
stress scenario - top counterparty insolvent — each with expected loss path, who absorbs it, compensation, and the impact path through the smart contracts;
two sources
Polymarket is a non-custodial prediction market where users trade against each other via AMMs; there is no central “counterparty” providing guarantees in the core protocol design. Because Dune MCP is unavailable, all on-chain confirmation is: Not verifiable as of 2026‑09‑04. Below, “top counterparty” is interpreted as a large liquidity provider/trader becoming insolvent off-chain. ### 1. Large LP insolvent
Path: LP has funded their Polygon wallet from an off-chain entity that goes bankrupt. On-chain liquidity in Polymarket pools remains unless withdrawn.
Expected loss:
Other traders are exposed only to price risk, not the LP’s solvency. Settlement uses Chainlink oracles and smart contract logic, not LP credit.
If the LP stops managing positions, pools may become imbalanced, causing worse prices and higher slippage but not direct loss from default.
Who absorbs it:
The LP’s beneficial owners/creditors off-chain bear the loss.
Remaining traders bear market impact (adverse prices, thin liquidity) but not counterparty default.
Compensation:
No automatic protocol-level compensation; smart contracts pay out based solely on oracle outcome and token balances.
Smart-contract impact path:
The LP’s liquidity remains in AMM contracts until they or a legal representative withdraw.
No special “insolvency” branch; contracts are oblivious to off-chain status. ### 2. Centralized intermediary (if any) insolvent Polymarket previously settled with the CFTC and changed its structure, including geo-restrictions and compliance measures. Any remaining centralized entities (front-end operator, fiat on-ramp, KYC provider) could fail.
Path: Operator or on-ramp becomes insolvent.
Expected loss:
Users may lose access to web UI, account services, or fiat balances held off-chain.
On-chain positions on Polygon should remain controlled by users’ wallets, but this is Not verifiable as of 2026‑09‑04.
Who absorbs it:
Losses from custodial fiat or off-chain accounts are borne by affected users and the intermediary’s creditors.
Compensation:
Depends on local insolvency law and any investor protection schemes; no protocol-native coverage stated in public docs.
Smart-contract impact path:
If the front-end disappears, contracts continue to exist on Polygon; users must interact via alternative interfaces or direct calls. ### 3. Oracle / infrastructure failure as “counterparty” If the oracle provider or infrastructure becomes effectively insolvent (ceases operation):
Markets may fail to resolve or be delayed, locking funds in outcome tokens.
Governance / operators may need manual intervention; no fully trustless fallback is clearly documented. All detailed on-chain behaviours and exact contract logic are Not verifiable as of 2026‑09‑04.
stress scenario - committed fraud by the DAO or owners
two sources
For a stress scenario on committed fraud by the DAO or owners, I find no verified evidence that Polymarket International’s DAO or owners have committed fraud. The available reporting instead shows allegations and investigations around user misconduct, manipulation, and phishing/exploit events, not a proven owner/DAO fraud finding. What is verifiable is that Polymarket has faced several integrity incidents and accusations: Reuters reported a NYC Council probe into alleged predatory marketing practices, including undisclosed influencer payments and fake-trade videos; the New York Times reported suspicious betting patterns consistent with insider trading; and Reuters also reported Polymarket referred dozens of potentially suspicious military-related accounts to the Justice Department.
There were also security incidents affecting users: a third-party frontend compromise reportedly led to about $3 million in stolen funds, and another exploit on a Polygon smart contract reportedly drained over $600,000. These incidents are serious operational and control failures, but the sources do not establish committed fraud by the DAO or owners themselves. Accordingly, the appropriate risk framing is: fraud by DAO/owners is not verifiable as of 2026-09-04, while platform-level manipulation, insider-trading allegations, and exploit risk are clearly documented.
Polymarket International does not appear to have a public yield product that can be stress-tested as a “primary yield source” on the basis of the web results available here. Bathymark notes that there is no DeFiLlama yield-pools map for this slug and frames it as a protocol “without public yield products,” which makes a 30-day primary-yield analysis not verifiable as of 2026-09-04. The public Polymarket materials and third-party coverage instead describe the protocol as a prediction market and, in one case, a separate incentive program paying up to 4% annualized yield on select long-term positions funded by the Polymarket Treasury; that is a market incentive, not a clearly documented protocol-level yield source for the slug.
For a stress scenario, the correct risk statement is therefore: if the assumed “primary yield source” is the Treasury-funded holding reward, a negative 30-day yield would mean the program is under pressure or unavailable, but the magnitude cannot be verified from the provided sources because no on-chain or audited revenue/yield series is available here. If you need a chain-specific exposure or yield decomposition for Polygon, that is Not verifiable as of 2026-09-04 with the current source set.
As of September 13, 2026, Polymarket International appears company-controlled, not DAO-governed.
Operator / legal control: The site identifies Adventure One QSS Inc. as the international platform operator and states that Polymarket operates through separate legal entities. A CFTC complaint identifies Adventure One QSS Inc. as a Panamanian corporation and Blockratize, Inc. as a Delaware corporation doing business as Polymarket. Publicly verified registration number and current directors: Not verifiable as of September 13, 2026. An Ontario filing identified Harry Jones as Adventure One’s officer in March 2025; this is not sufficient to establish the current board or control structure.
Frontend, rules and enforcement: Operational control rests with Polymarket. The transparency page says the international platform is governed by its Terms of Use and that violations are enforced by Polymarket, including wallet-level restrictions and law-enforcement referrals.
Proposal process / DAO: No public token-governance contract, voting token, proposal forum, delegated-voting process, DAO constitution, or binding community approval process was identified. DAO governance is therefore not evidenced and appears symbolic/nonexistent. Voting concentration and top holders via Dune: Not verifiable as of September 13, 2026; Dune MCP was unavailable.
Funds: Polymarket states that the international platform is non-custodial, users hold private keys, and collateral is held in smart contracts rather than by Polymarket. This is an official platform claim; contract-level authority to move or freeze user collateral was not independently verified in this run.
Timelock / multisig: Timelock delay, multisig threshold, signer identities, signer independence, upgrade authorities, and emergency powers: Not verifiable as of September 13, 2026. Contradiction / risk note: Polymarket describes the system as non-custodial and smart-contract-based, but its own transparency materials simultaneously document centralized rulemaking, surveillance, wallet restrictions, and enforcement. Non-custody does not establish decentralized governance. Assessment: Company control is evidenced for the frontend, rules, compliance and enforcement layers. Contract-admin powers and treasury controls remain unresolved without address-level on-chain verification.
Polymarket International appears to be the current international-facing front end of Polymarket, a prediction market protocol originally operated by Blockratize Inc. in the U.S.; after CFTC enforcement, the consumer-facing activity was reorganized and geo-restricted, while liquidity remains on Polygon. Entity & jurisdiction • The original operator, Blockratize Inc. (Polymarket), is a New York–based company that was investigated and sanctioned by the U.S. Commodity Futures Trading Commission (CFTC) in January 2022 for offering off‑exchange event‑based binary options to U.S. persons without registration. • Polymarket’s current “International” branding suggests a non‑U.S. targeting strategy, but a precise legal entity name, jurisdiction of incorporation, and group structure for “Polymarket International” are Not verifiable as of 2026‑09‑04; the public-facing site does not clearly disclose the operating entity, and third‑party sources mostly still refer to Blockratize/Polymarket generically. Regulatory actions & enforcement • The CFTC issued and settled an enforcement action against Blockratize Inc.
(Polymarket) on 3 January 2022, requiring cessation of “all markets” offering event‑based binary options, payment of a $1.4m civil monetary penalty, and an orderly wind‑down of markets in the U.S. • This is direct enforcement against the protocol’s operator, not mere guidance, and demonstrates that U.S. regulators treat many Polymarket markets as unregistered swaps/event‑based binary options under the Commodity Exchange Act. Sanctions status • There is no indication in major public sanctions lists or regulatory releases that Polymarket or “Polymarket International” is itself designated or sanctioned as an entity. Not sanctioned as of 2026‑09‑04 based on available information. ToS, restrictions, KYC/AML • Polymarket’s public materials and coverage emphasize geo‑blocking of U.S. users and the use of a non‑U.S. front end to avoid U.S. regulatory exposure after the CFTC action. • Specific details on KYC/AML implementation (e.g., level of identity verification, screening vendors, PEP/sanctions processes) are Not verifiable as of 2026‑09‑04; media and analytics sources do not provide operational compliance details, and the site’s policies are not fully indexed. • Likewise, detailed data protection practices (GDPR alignment, DPA location, breach history) are Not verifiable as of 2026‑09‑04. Classification & legal risk • U.S. regulators have already classified Polymarket’s event contracts as off‑exchange swaps / binary options subject to CEA/CFTC jurisdiction. • For non‑U.S. users, local classification may fall under betting/gaming, CFD/binary‑options, or derivatives law, but systematic coverage by EU/UK or other regulators is Not verifiable as of 2026‑09‑04. • Key residual risks: renewed CFTC action if U.S. access/solicitation is detected; potential enforcement by non‑U.S. gambling/derivatives regulators; opaque legal-entity structure for "Polymarket International" complicates counterparty and operational risk assessment.
Active enforcement
Yes
Sanctioned
No
Entity
Blockratize Inc. (Polymarket); specific legal entity for “Polymarket International” Not verifiable as of 2026-09-04
Jurisdiction
United States (CFTC enforcement against Blockratize Inc.); non-U.S. jurisdiction for Polymarket International Not verifiable as of 2026-09-04
No exact GLEIF LEI record for 'Blockratize Inc', 'Polymarket International'. OFAC SDN screening of 'Blockratize Inc', 'Polymarket International': no match. SEC litigation and administrative release feeds: no mention.
Polymarket historically used bridged USDC.e on Polygon as collateral, and its current docs also describe a migration to Polymarket USD (pUSD), a Polymarket-issued token backed 1:1 by USDC. A depeg of the collateral stablecoin was not verifiable from the gathered sources, so depeg_count, last_depeg_date, and max_depeg_pct remain Not verifiable as of 2026-09-06. Because pUSD is now documented as a Polymarket-issued collateral token, own_stablecoin is true if current-state docs are accepted; however, the historical setup alone would not support that, so this field is only partially verifiable from the available evidence.
Polymarket International’s principal risks are regulatory perimeter uncertainty, oracle-dependent settlement, smart-contract and upgrade risk, Polygon/pUSD infrastructure exposure, and user-controlled wallet or operational failure. The platform’s international entity is explicitly not CFTC-regulated, while its market-resolution and collateral mechanisms remain dependent on external systems and protocol-controlled implementation choices. TVL, exposure concentration, contract balances, and live on-chain health are Not verifiable as of September 5, 2026 because Dune MCP was unavailable.
Risk
Impact
Severity
Probability
Mitigation in place
Residual risk
Regulatory perimeter uncertainty
The international platform may face enforcement, forced market wind-downs, access restrictions, licensing demands, or liability across jurisdictions. The 2022 CFTC action demonstrates this is an evidenced, not hypothetical, risk.
High
High
Geographic blocking, sanctions screening, terms prohibiting circumvention, and separate Polymarket US structure are in place [S1][S2].
High residual risk because cross-border prediction-market, gambling, derivatives, AML, and sanctions treatment remains jurisdiction-specific and changeable.
Oracle and resolution failure
Incorrect, delayed, ambiguous, or manipulated resolution can transfer the full market payoff to the wrong outcome and create litigation or confidence loss.
High
Medium
Predefined resolution rules, proposer bonds, challenge periods, and escalation to UMA token-holder voting [S3].
Medium-High residual risk: economic security and voter incentives may be insufficient for exceptionally large or politically contentious markets.
Smart-contract upgrade risk
Bugs in exchange, conditional-token, rewards, or pUSD contracts could freeze, misroute, or permanently lose user funds.
High
Medium
External audits and a 2026 contract migration are reported; contracts are deployed on Polygon and are open source [S4][S5].
Medium-High residual risk because audits are time-boxed and do not cover every future deployment, integration, or operational change.
Polygon and pUSD dependency
Polygon outages, reorgs, congestion, token-contract failure, or a breakdown in pUSD-to-USDC convertibility could impair trading, settlement, or withdrawals.
High
Medium
pUSD is stated to be backed 1:1 by USDC through an on-chain contract, with Polygon as the deployment network [S5].
Medium residual risk; backing, balances, and concentration are Not verifiable as of September 5, 2026 without on-chain queries.
Wallet and irreversible-transfer loss
Compromised credentials, leaked private keys, incorrect network/token transfers, or phishing can cause irreversible loss despite non-custodial design.
High
Medium
User custody, key-export capability, recovery tooling, and warnings about private-key responsibility are provided [S6].
Medium-High residual risk because the user, not the platform, bears much of the key-management and transaction-error risk.
Polymarket International’s top strengths are its broad market coverage, fast and low-cost trading on Polygon, high liquidity and tight spreads, transparent on-chain settlement, and self-custody / non-custodial fund control. These strengths are consistently reflected across independent reviews and technical explainers: Polymarket offers a wide range of topics including politics, sports, crypto, and culture; it runs on Polygon for quick, inexpensive transactions; it is described as having very tight spreads and strong liquidity; its trades are recorded onchain; and users keep control of funds rather than depositing into a central house.