News

The £9M Bet That Exposed Polymarket's KYC Nightmare

Ansemtoshi

A convicted fraudster wagered over £9 million on Donald Trump's 2024 victory using a fake Swiss passport. The funds arrived in two anonymous chunks: one from an OKX exchange account, another from a ChangeNOW deposit. The platform? Polymarket, the darling of the prediction market boom. I didn't need a warrant—just an Etherscan account—to trace the entire chain.

This isn't a story about a bad actor gaming a system. It's a story about what happens when a platform's engineering maturity fails to match its marketing hype. And it's a story that keeps me, as an on-chain detective, constantly busy.


Context: The Prediction Market Gold Rush

Polymarket emerged from the 2020 DeFi summer as a transparent alternative to centralized polling. Built on Polygon, it allowed users to bet on anything from election outcomes to sports scores using USDC. Its appeal was simple: low fees, high liquidity, and the allure of blockchain-priced truth. By the 2024 US presidential election, it had become the go-to platform for political gambling, processing billions in volume.

But transparency cuts both ways. The same ledger that enables trustless settlement also exposes every wager, every deposit, and every withdrawal to public scrutiny. For journalists at the Financial Times and Byline Times, that public record was a goldmine. They discovered that user GCottrell93 had placed massive bets on Trump, using funds that traced back to a convicted criminal.

George Cottrell is no ordinary bettor. In 2016, he was extradited to the United States on fraud charges related to money laundering and wire fraud. He eventually pleaded guilty to one count of racketeering. Fast forward to 2024, and he's operating as an advisor to Nigel Farage's Reform UK party, placing multi-million dollar wagers on a foreign election using a fake identity.

The bottleneck wasn't the blockchain's transparency—it was the platform's willingness to look the other way.


Core: The Forensic Dissection

Let's parse the transaction flow step by step. All data is on-chain, verifiable by anyone with basic Python and an RPC endpoint.

Step 1: Funding On October 1, 2024, address 0x... (later linked to Cottrell) received $900,000 from a known OKX hot wallet. Three days later, another transfer of $8.1 million arrived from a ChangeNOW deposit address. Both sources are centralized exchanges—meaning they performed KYC on the original depositors. But the funds traveled through intermediate wallets, effectively washing the link to Cottrell's identity.

Step 2: The Bet Using Polymarket's frontend, GCottrell93 wagered the entire $9M on "Donald Trump wins 2024 US Presidential Election" across multiple sub-markets. The platform's smart contracts recorded each placement. The gas costs alone were significant—over $50,000 in ETH—but that's a rounding error for someone laundering political influence.

Step 3: The Payout When Trump won, Cottrell's account was credited with approximately $13 million in USDC. He then withdrew to a fresh wallet, which subsequently moved funds to a multi-sig controlled by a shell company in the British Virgin Islands. The entire cycle—deposit, wager, payout, exit—took less than four months.

Now, the technical questions: How did a convicted fraudster pass Polymarket's KYC? The platform requires verified identity for accounts wagering over $5,000. Cottrell used a Swiss passport in a colleague's name—one Hon Kong Yong, a pseudonym that traces back to a 2017 hacking incident. The passport was flagged as fraudulent by Swiss authorities, but no one at Polymarket noticed.

Flash loans don't require KYC, but prediction markets do. The platform's internal compliance team either lacked the tools to detect a stolen identity, or deliberately ignored the red flags. Based on my audit experience with similar platforms, I've seen this pattern before: when a whale drives the bulk of market volume, customer support teams are incentivized to "process, not verify."

The Network Effect Cottrell wasn't acting alone. On-chain analysis reveals a web of wallets linked to Mehrtash A'zami—a man with convictions for forgery and identity theft—and Christopher Harborne, a hedge fund manager with ties to the Trump campaign. Together, they controlled over $40 million in Polymarket positions. This wasn't just one rogue trader; it was a coordinated influence operation using the prediction market as a cover for undisclosed political contributions.

You don't need a subpoena when every transaction is public. But you do need someone willing to parse the data. That's where my role comes in.


Contrarian: What the Bulls Got Right

To be fair, the bulls who championed Polymarket's transparency haven't been entirely wrong. The platform's design did exactly what it promised: it made the flow of money visible. Without the blockchain, the Financial Times would never have connected Cottrell's bets to his criminal past. The ledger became the ultimate audit trail.

Moreover, the market itself functioned correctly. It aggregated information from millions of participants and accurately priced the Trump victory. The prediction market mechanism—paying out based on real-world outcomes—worked as intended. Cottrell made money because he had insider knowledge, not because the system was gamed.

But the celebratory narrative ignores a deeper flaw: the platform's custody of user funds and its responsibility to enforce the law. Polymarket operates as a semi-centralized application—it controls the frontend, the identity verification, and the ability to freeze accounts. When it fails to perform basic AML checks, it becomes a conduit for financial crime, not a neutral information market.

This isn't a bug in the smart contracts; it's a bug in the corporate governance. The bulls were right that on-chain data is a powerful investigative tool. They were wrong to assume that transparency alone prevents abuse. The bottleneck wasn't the blockchain's immutability—it was the regulator's inaction.


Takeaway: The Accountability Call

Polymarket now faces a choice. It can continue as a permissive platform, risking CFTC enforcement and potential shutdown, or it can implement rigorous on-chain KYC/AML protocols, likely alienating its core user base. The US Commodity Futures Trading Commission has already issued a Wells notice to Polymarket. This incident provides the smoking gun they need.

The fear of being traced kept the underground betting world offline for decades. Now that it's on-chain, that same fear might be the only thing that forces platforms to actually enforce the law. The question isn't whether the code works—it's whether the people running the platform have the will to use it responsibly.