The alleged insider trading scheme involving two former Robinhood engineers has put a spotlight on a growing weakness in employee compliance programmes. Personal trading is increasingly happening in places traditional brokerage feeds simply cannot reach.
According to StarCompliance, on 15 September 2026, US federal prosecutors charged Hefu Chai and Huaisong “Jerry” Xiang with commodities fraud and wire fraud, according to an announcement from the US Attorney’s Office for the Southern District of New York.
The pair are accused of using confidential knowledge of forthcoming Robinhood Crypto token listings to trade before those listings were made public, with each allegedly making more than $50,000.
For compliance leaders, the most important detail is not the alleged conduct itself but the venue where it took place.
Prosecutors say both engineers were aware of upcoming listings and were barred from trading the relevant tokens around announcement windows. Rather than buying the tokens outright, however, they allegedly took positions in perpetual futures on Hyperliquid, a decentralised derivatives exchange.
Perpetual futures let traders bet on an asset’s price movements without holding the asset itself, a subtle but significant difference for anyone tasked with monitoring employee activity.
Most personal account dealing frameworks are built on disclosures, brokerage feeds, pre-clearance and restricted lists. Those tools struggle when employees can operate across decentralised exchanges, crypto derivatives, prediction markets and numerous wallets. A policy may forbid the behaviour, but the real test is whether the firm can detect it.
Regulators are already widening their gaze. In August 2026, the CFTC brought and settled charges over the misuse of material nonpublic information to trade prediction market event contracts. The Robinhood case now extends that concern to crypto derivatives on a decentralised platform. The instruments and venues shift, yet the underlying conduct risk is unchanged.
Conventional controls remain necessary, but they can leave gaps once activity moves on-chain. Employees may spread activity across several wallets, bridge assets between blockchains, or trade derivatives tied to a token they never own. The pool of at-risk staff is also broadening, as engineers and product teams often see listings and launches early despite not being classed as access persons.
Firms reviewing their programmes should consider three key questions. First, whether perpetual futures, prediction market contracts and other derivatives are treated within the same risk framework as the underlying asset or event, and whether pre-clearance and restricted lists capture them.
Second, whether oversight extends beyond disclosed wallets, since on-chain monitoring can reveal activity across linked wallets and transactions. Third, whether the right people are in scope, including anyone with early sight of digital asset listings, product roadmaps or event contract launches.
Read the full StarCompliance post here.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





