Skip to main content

On 15 September the US Attorney for the Southern District of New York, Jamie McDonald, charged two former Robinhood engineers, Hefu Chai, 36, and Huaisong Xiang, 30, with commodities fraud and wire fraud. The allegation is that between 2025 and 2026 they repeatedly opened perpetual futures positions on Hyperliquid in tokens they knew Robinhood Crypto was about to list, and that each cleared more than $50,000 doing it. Thirty years of statutory exposure apiece across the two counts, for a combined profit that would not cover a deposit on a two-bed in Dublin.

Every write-up so far has asked the same question: did they break the law? A courtroom will answer it, and the answer will apply to two people and nobody else. The half nobody is asking is this: a true fact about the future price of a token existed inside one company for some length of time before it existed in the market. How long? Nobody knows. No venue on earth publishes that number.

TL;DR

  • The DOJ charged two ex-Robinhood engineers on 15 September 2026 over Hyperliquid perpetual futures positions allegedly taken ahead of Robinhood Crypto listing announcements, for $50,000 each.
  • Robinhood detected it, investigated it and reported it. The indictment exists because the controls worked, and it deserves saying plainly.
  • A listing is not an observed event, it is an authored one. It becomes true the moment a company decides it, and stays private until the company says so. That gap is the whole trade.
  • Hyperliquid recorded the positions in public the entire time, and independent researchers flagged the wallets before the charges were unsealed. Visibility caught it late. Visibility prevented nothing.
  • Commit-and-reveal “provably fair” casinos share the structure: the operator holds the seed first. With Chainlink VRF the outcome is not knowable to anyone, us included, at the moment you stake.

Robinhood deserves the credit first

Robinhood says it has “robust insider trading policies and procedures in place, including for new crypto listings”, that it investigated immediately, and that it reported the matter to law enforcement and regulators. There is no reason to be snide about that. Most firms that catch an employee trading on internal information handle it with a quiet separation agreement. A federal complaint exists here because a company built listing-specific surveillance, ran it against its own staff, found something it did not want to find, and handed it over.

The controls did their job, in the sense that they eventually produced a consequence. Hold that thought, because it is the most interesting fact in the story. Everything went right, and the trades still allegedly ran for a year or more.

Three kinds of outcome, and only one of them is safe

In August we wrote about a former White House teleprompter operator fined for buying prediction-market contracts on words he had already read in a speech. That post drew a line between observed outcomes, where reality produces a fact and somebody sees it early, and generated outcomes, where a machine produces a number on request and there is nothing to see early because the number does not exist yet.

The Robinhood case introduces a third category that sits between them, and it is the most common one in finance: the authored outcome. A token listing is not a fact about the world that leaks. It is a decision. Somebody in a room chooses it, and from that instant the fact is completely true and completely private. No leak is required for asymmetry to exist, because the information was never out there to leak. It was manufactured internally and held.

That difference matters because the defences are different. Against an observed outcome you can shorten the chain of custody: fewer eyes on the speech, later distribution of the draft. Against an authored outcome there is no chain to shorten below one, because somebody has to decide, and deciding takes time, and during that time the answer is already correct. You can shrink the room. You cannot empty it.

Nobody publishes the length of the window

Here is the question that should have been in every headline and was in none. Between the moment Robinhood’s listing decision became final and the moment it was announced, how many minutes, hours or days elapsed, and how many people were inside that window?

Not just Robinhood. Pick any exchange, anywhere. None publish decision-to-announcement latency, none publish how many staff hold listing access, none publish an access log, even a redacted or delayed one. The industry treats the interval as an operational detail when it is the entire surface area of the offence. Insider trading is impossible without a window, and the window is not an accident. It is a design choice every venue makes privately and is never asked to justify.

Ask a platform how it prevents insider trading and you will get policies, blackout periods and monitoring. Every one of those answers is about behaviour during the window. None is about the length of it. That is the unasked half.

The arithmetic does not work, and it is not close

Roughly $100,000 in total alleged profit. Against that: an internal investigation, an SDNY investigation, agents, prosecutors, two criminal complaints and eventually a trial or a plea. The enforcement cost dwarfs the offence so completely that the case is obviously not about recovering money. It is about deterrence, and deterrence is priced per case.

Windows are not priced per case. They are priced per decision. Every listing, delisting, fee change and earnings print at every venue in the world opens one, continuously and in parallel. Enforcement capacity scales with the number of prosecutors. Windows scale with the number of decisions. Those two curves are not in the same universe, and one case against two engineers bends neither. If your fairness model depends on the SDNY noticing, it is a lottery with better branding.

The chain saw everything and stopped nothing

This is the part crypto should sit with rather than celebrate. The alleged trades were placed on Hyperliquid. That is an on-chain venue: every position, every size, every timestamp, public and permanent from the moment it was opened. According to The Crypto Times, independent researchers had flagged the pattern before the charges were unsealed: wallets opening perpetual positions shortly ahead of Robinhood listing announcements, and one cluster flagged for a short placed hours before Robinhood’s Q1 2026 earnings. The DOJ has not publicly named tokens or matched wallets to either defendant, so the on-chain trail and the complaint remain separate threads in public.

The shape is clear enough, though. The ledger recorded an alleged informational advantage perfectly, in the open, in real time, for roughly a year, and the advantage kept paying throughout. Transparency was a witness, not a referee: excellent evidence after the fact, zero friction during it. So the next time anyone in this industry, us included, tells you something is fair because it is on-chain, notice how little work that claim is doing. Public data proves what happened. It does not constrain who knew first.

Now point this at gaming, where it is worse

A server-side random number generator has exactly the authored structure. Your spin’s outcome is decided on a machine, is completely true and completely private for some interval, and then appears on your screen. The house does not need to alter anything to be advantaged. Knowing first is the edge, in the same way that knowing about a listing first was the edge.

The interesting case is not the obvious cheat. It is the crypto casino that already calls itself provably fair. The standard design commits to a hashed server seed, mixes in your client seed and a nonce, and reveals the seed later so you can check the maths. That genuinely stops an operator changing an outcome after the fact, and we have argued before that the hash-based version is not the same standard as on-chain verification. The temporal objection is separate and sharper: the operator holds the seed the whole time, so it can compute the entire sequence of results before you play them. Nothing needs altering. Which promotion lands in front of which account, which table gets which limit, and how the house hedges its own exposure all sit downstream of knowing outcomes early. The commitment closes the door on changing the answer. It leaves the window on seeing it first wide open.

What Satoshie claims, stated narrowly

Our claim is not that we are more disciplined than Robinhood. It is that there is no interval to be disciplined about.

When you enter a Satoshie raffle or a coinflip, the number that decides it does not exist. Not on our server, not in our repository, not in anybody’s messages. The contract requests randomness from the Chainlink VRF coordinator named in deployed code you can read before staking. The coordinator returns a value with a cryptographic proof, the proof is verified on-chain before the callback may deliver, and the outcome is computed inside that callback. There is no moment at which the answer is true and privately held, because by the time it is true it is already public. An insider at Satoshie has nothing to be an insider about, not because we vet people well, but because the information does not exist yet. That is a claim about when information is created, not a claim about our character, and you should prefer the first kind.

Three honest limits

One: we have intervals too, just not that one. We decide which games to launch, what a prize pool will be and when a draw opens, and those are authored decisions made in a room like anybody else’s. We can say the outcome of a draw is not knowable in advance. We cannot say every commercial decision we make is public the instant it is taken.

Two: a VRF proof settles randomness and nothing else. It does not stop a front end misrepresenting what you are entering, and it does not govern how your entry transaction is ordered in the mempool around you, which we have written about separately. Proof of the number is not proof of the whole experience.

Three: our controls are not better than Robinhood’s. They are a multibillion-dollar brokerage with a compliance department. If we had an insider problem of a different shape, we would most likely find out the way they did: later, from somebody else. The argument is not that we police the window better. It is that we deleted one specific window, and left the rest honestly on the table.

Three questions to ask any platform

  • Between the moment my outcome is determined and the moment I can see it, how long is the interval, and who is in the room?
  • Is that interval defined in deployed code I can read, or described on a policy page you can edit?
  • If somebody inside your company traded on it, would you learn that from your own logs, or from a prosecutor’s press release?

Nobody at Robinhood had to rig a listing. The listings were real, the announcements were honest, the price moves were genuine. All the alleged trade required was knowing a true thing slightly early. No integrity policy removes the slightly early. The only thing that removes it is an outcome that does not exist until everyone can see it at once.

📷 Photo by Benjamin Child on Unsplash

Valentina Ní Críonna

Author Valentina Ní Críonna

More posts by Valentina Ní Críonna