Skip to content
RiskTemplates · The Daily Brief Thursday, October 1, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Compliance Strategy

The DOJ Just Charged Two Engineers for Trading Crypto on a DEX With Listing MNPI. Your MNPI Policy Probably Doesn't Cover This.

DOJ charged two former Robinhood engineers in September 2026 for front-running crypto listing announcements using perpetual futures on Hyperliquid. The case reveals surveillance gaps in every crypto-adjacent MNPI policy.

By Rebecca Leung · September 29, 2026 ·
Table of Contents

TL;DR

  • On September 15, 2026, DOJ charged two former Robinhood engineers — Hefu Chai and Huaisong Xiang — with trading perpetual futures on a decentralized exchange (Hyperliquid) using MNPI about upcoming crypto listings on Robinhood Crypto.
  • The charges are under the Commodity Exchange Act (commodities fraud, not securities fraud), because they traded futures, not tokens.
  • Robinhood’s “Coin Aware Individual” designation gave both engineers access to a private Slack channel with planned listing dates. That was the MNPI.
  • Most MNPI policies in the financial services industry do not cover crypto listing decisions, perpetual futures, or DEX activity. If yours doesn’t, the Robinhood case just described a gap you need to close.

There is a compliance program gap that most financial firms haven’t noticed yet. The Robinhood engineers case just made it impossible to ignore.

On September 15, 2026, the U.S. Attorney’s Office for the Southern District of New York unsealed criminal complaints against Hefu Chai and Huaisong Xiang, two former Robinhood software engineers. The DOJ alleges both men used material non-public information about which crypto assets Robinhood planned to list on its platform, then bought perpetual futures contracts on Hyperliquid — a decentralized exchange — before those listing announcements were made public.

The scheme allegedly generated just over $50,000 each in illicit profits. The charges carry maximum sentences of 10 years (commodities fraud) and 20 years (wire fraud).

The dollar amounts are small. The compliance program implications are not.

The Scheme

Robinhood designated Chai and Xiang as “Coin Aware Individuals” — a category of employees given access to a private Slack channel that contained planned listing dates for crypto assets. This access gave them advance notice of which tokens were coming to Robinhood Crypto before the public announcement.

According to the DOJ, between 2025 and 2026, both men repeatedly bought perpetual futures contracts on Hyperliquid — a decentralized, non-custodial perpetual futures exchange — linked to those tokens in advance of Robinhood’s listing announcements. After the listing was announced publicly, the token typically increased in value. The perpetual futures positions rose in value with it.

They then closed the positions, extracting the profit.

The alleged conduct is straightforward misappropriation: using confidential business information — the listing calendar — in breach of their duties to Robinhood, for personal financial gain. What makes this case operationally significant is not the scheme itself. It’s the infrastructure they used to execute it.

Why a Decentralized Exchange Changes the Surveillance Problem

Every traditional securities MNPI enforcement case shares a common structure: an employee with inside information trades on a regulated, monitored platform. That platform — a broker-dealer, an exchange — has surveillance systems. Clearing and settlement create a paper trail. The compliance team can run a report. The SEC can subpoena records.

Chai and Xiang didn’t use a regulated platform. They used Hyperliquid.

Hyperliquid is a decentralized perpetual futures exchange operating on a Layer 1 blockchain. It is non-custodial — there is no broker-dealer intermediary holding assets. Trades settle on-chain through smart contracts. There is no clearing firm. There is no FINRA member. There is no central counterparty that files a suspicious activity report.

From a compliance surveillance perspective, Hyperliquid trades are essentially invisible to the firm’s internal monitoring systems. A traditional broker-dealer pre-clearance and surveillance program would catch an employee buying listed equity options through their E*Trade account. It would not catch the same employee buying perpetual futures on a DEX using a self-custody wallet.

This is not a theoretical gap. It is the gap that two Robinhood engineers allegedly exploited for more than a year before federal prosecutors caught it — apparently through blockchain analytics rather than internal compliance controls.

The Commodities Dimension

The choice of perpetual futures rather than tokens was not accidental. Crypto perpetual futures are treated as commodities under CFTC jurisdiction. Trading perpetual futures using MNPI triggers Commodity Exchange Act fraud provisions rather than SEC securities fraud.

That matters for two reasons.

First, CFTC jurisdiction extends the legal risk. Most financial services compliance programs are built around securities law. If your MNPI policy says “don’t trade securities or derivatives on non-public information,” you may have forgotten that crypto derivatives fall under CFTC, not SEC jurisdiction. The legal prohibition exists regardless — but the jurisdictional framing affects which regulator could come looking, and whether your compliance program is actually monitoring for the right things.

Second, the DEX structure creates novel evidence issues. Unlike a broker-dealer account, a self-custody wallet on a DEX doesn’t require KYC. Chai and Xiang’s trades could in principle be attributed to a pseudonymous wallet address. The DOJ attributed them using blockchain analytics, correlating wallet activity, on-chain transaction history, and timing patterns against internal communications. That’s a law enforcement capability — it is not a compliance surveillance capability that most firms have.

If an employee is front-running your crypto product decisions on a DEX, you probably won’t catch it through your existing compliance program. You’ll catch it when DOJ calls.

What the “Coin Aware Individual” Designation Tells You

Robinhood’s designation of certain employees as “Coin Aware Individuals” is exactly the kind of information barrier structure that a well-designed MNPI policy should create. Identify who has access to listing decisions. Track that access. Restrict trading by those employees in the assets under consideration.

The problem, apparently, is that the restrictions didn’t cover perpetual futures on decentralized exchanges. Or if they did, there was no surveillance mechanism to detect violations.

The Robinhood case is a reminder that information barriers are only as strong as the trading restrictions that enforce them, and trading restrictions are only as strong as the surveillance that monitors compliance. A designation that puts employees on an access list without corresponding trading restrictions and monitoring is a compliance artifact, not a compliance control.

This pattern appears across recent MNPI enforcement actions. The SEC’s September 2026 charges in the Doximity/Jorgensen insider trading case involved similar information barrier breakdowns — employees with access to material information who didn’t treat it as MNPI because the written policies hadn’t mapped the access to the information. The Billimek/Williams front-running case showed what happens when surveillance programs can’t monitor certain trading channels.

Robinhood adds a third dimension: the trading channel the MNPI was exploited through was a DEX, which existing surveillance architecture essentially can’t see.

The Three Gaps in Most Crypto MNPI Policies

Most MNPI policies in regulated financial services were written for traditional securities. Even policies at crypto-native firms are typically built around centralized exchange trading. The Robinhood case exposes three specific gaps:

Gap 1: Crypto listing decisions are not covered as MNPI

Traditional MNPI policies cover information about corporate events — earnings announcements, M&A, material contracts, regulatory filings. They were not written to cover asset listing decisions, which are operational and product decisions rather than corporate events.

But at Robinhood, a listing decision has the same market-moving characteristics as a material corporate announcement: the public doesn’t know, the decision will move the price when announced, and employees who know it in advance can profit. A listing decision is MNPI. Most policies don’t say so explicitly.

If your firm makes crypto listing decisions — or if you work with a firm that does, such as a crypto exchange, a prime broker launching digital asset products, or a fintech building out a crypto offering — your MNPI policy needs to explicitly identify listing decisions as a category of covered information.

Gap 2: Derivatives and DEX activity are excluded from pre-clearance

Pre-clearance requirements in most MNPI policies cover purchases of the covered security or closely related securities on regulated platforms. They were not written to cover perpetual futures contracts on decentralized exchanges linked to those assets.

This is a coverage gap that mirrors the gap the Gotbit crypto wash trading case highlighted in SEC enforcement actions against crypto market manipulation: the policy covered what the firm assumed employees would do, not the full range of what they could do in a crypto-native trading environment.

An MNPI policy governing crypto-adjacent firms should specify that pre-clearance requirements apply to:

  • The underlying crypto asset
  • Any derivative, perpetual futures, or options contract on the asset
  • Any tokenized wrapper, synthetic, or structured product whose value tracks the asset
  • Trading on both centralized and decentralized platforms

Gap 3: Surveillance can’t see DEX activity

Even a well-written MNPI policy is a compliance artifact if there’s no monitoring. Most broker-dealer and investment adviser surveillance programs work by consuming trade data from accounts the firm can see — accounts at registered broker-dealers, prime brokers, and custodians that submit data to compliance platforms.

Self-custody wallets on DEXs submit nothing. A firm’s surveillance program has zero visibility into an employee’s Metamask wallet transacting on Hyperliquid. This is not a deficiency in surveillance technology — it’s a structural limitation of decentralized infrastructure that doesn’t interface with traditional compliance data flows.

The practical implication: for any employee with access to crypto listing decisions, product roadmaps, partnership discussions, or other crypto-market-moving information, attestation may be the only available monitoring control for DEX activity. The policy should require employees to attest annually (or more frequently) that they have not conducted trades on non-custodial platforms using covered information. And violations should be treated as serious compliance failures with clear escalation paths — including to the issues management tracker that documents how internal compliance violations are investigated and resolved.

Practical Steps for Compliance Teams

If you work at a firm that operates crypto products, is building digital asset capabilities, or has employees with any access to non-public information about crypto assets, here are three things to do this week:

1. Audit your MNPI policy language. Read your MNPI policy and ask whether it explicitly covers: (a) crypto listing decisions, product roadmap decisions, or partnership discussions involving crypto assets; (b) derivatives including perpetual futures and options; (c) trading on decentralized exchanges and non-custodial platforms. If the answer to any of those is “probably not,” schedule a policy update.

2. Map who has access to what. The Robinhood “Coin Aware Individual” designation is actually good practice — the firm knew who had listing access. The gap was in what that designation required of those employees and how it was monitored. Walk your information barrier structure forward: who has crypto listing or product information access? What trading restrictions apply to them? How would you detect a violation?

3. Add DEX attestation to your personal trading policy. If your surveillance program can’t see DEX activity, attestation is your fallback control. Add a requirement for employees designated as having access to crypto-related MNPI to attest that they have not used covered information to trade on any platform, including decentralized exchanges and non-custodial wallets. Keep records. Spot-check against publicly available blockchain data for key employees when you can.

The Enforcement Trajectory

The Robinhood case is the second major crypto listing MNPI enforcement action in four years, following the 2022 Coinbase case. The pattern should be expected to continue: as crypto markets mature and more financial institutions participate in crypto product decisions, the population of employees with access to crypto-related MNPI grows, and the enforcement risk grows with it.

The CFTC and DOJ are both active. Blockchain analytics tools make on-chain activity traceable in ways that weren’t available five years ago. DEX anonymity is not the same as undetectability.

The compliance program that doesn’t address this gap today is the one that will be explaining it to investigators later. The Robinhood engineers case is a pre-enforcement warning.


The DOJ’s charges against Hefu Chai and Huaisong Xiang are described in the September 15, 2026 SDNY press release. For firms managing MNPI-related compliance investigations and corrective actions, the Issues Management Tracker provides a structured framework for logging, investigating, and closing compliance violations including insider trading incidents.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the DOJ charge the Robinhood engineers with in September 2026?
On September 15, 2026, the DOJ's SDNY charged Hefu Chai and Huaisong Xiang, two former Robinhood engineers, with one count of commodities fraud under the Commodity Exchange Act (maximum 10 years) and one count of wire fraud (maximum 20 years). The charges allege they used material non-public information about upcoming crypto listings on Robinhood Crypto to buy perpetual futures contracts on Hyperliquid, a decentralized exchange, before the listings were publicly announced.
Why were the charges brought under the Commodity Exchange Act rather than securities laws?
The defendants traded perpetual futures — derivative contracts — rather than the underlying crypto tokens. Crypto perpetual futures are treated as commodities under CFTC jurisdiction, which triggers Commodity Exchange Act fraud provisions rather than SEC securities fraud. This is a key distinction: employees who trade the token itself could face SEC securities fraud charges; employees who trade derivatives on a DEX may face CFTC-jurisdictional commodities charges instead.
What is the 'Coin Aware Individual' designation at Robinhood?
Robinhood designated certain employees as 'Coin Aware Individuals' — personnel with access to a private Slack channel containing planned listing dates for crypto assets. This access gave them material non-public information about upcoming listings. The case shows that MNPI can flow through informal channels like Slack, not just official briefings or documented information barriers.
How does this case differ from the 2022 Coinbase insider trading case?
In the 2022 Coinbase case, an employee traded the underlying tokens before listing announcements. In the Robinhood case, the defendants traded perpetual futures on Hyperliquid — a DEX — rather than the tokens on Robinhood's platform or any regulated exchange. This distinction matters because most MNPI policies and trading surveillance programs are designed around equity-style trading on monitored platforms, not derivatives activity on decentralized protocols.
What should compliance programs do after this case?
Three immediate actions: (1) Review your MNPI policy to confirm it explicitly covers crypto listing decisions and extends to derivatives and DEX activity, not just token purchases on centralized platforms. (2) Assess whether employees with access to crypto listing calendars, partnership discussions, or product roadmap decisions are designated MNPI-exposed and subject to pre-clearance requirements. (3) Consider whether your surveillance program has any visibility into employee DEX activity — it almost certainly does not, which is the policy gap this case exposes.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.