The U.S. Attorney's Office for the Southern District of New York has charged two former Robinhood engineers with commodities fraud and wire fraud, alleging they misappropriated confidential information about upcoming cryptocurrency listings and used it to trade ahead of public announcements.

The defendants are Hefu Chai, 36, and Huaisong Xiang, 30, according to complaints unsealed Tuesday. Prosecutors allege that between 2025 and 2026 the two repeatedly took positions in tokens before Robinhood's public listing announcements, executing the trades in perpetual futures contracts on Hyperliquid, the decentralized trading venue. Each is alleged to have profited by more than $50,000. The charges were reported by The Block, Decrypt and Crypto Briefing.

The allegations are just that — allegations. Both defendants are presumed innocent unless and until proven guilty, and no findings have been entered against them.

Why this belongs in a security column

Front-running a listing is usually filed under market abuse. But the anatomy of this case, as alleged, is an access-control failure: employees with legitimate access to one of an exchange's most sensitive data assets — the listing calendar — allegedly converted that access into trading profits on an outside venue. Confidential business information is a security surface like any other. The controls that defend it — need-to-know scoping, entitlement reviews, data-loss monitoring, and credible insider-threat detection — are the same controls that defend customer funds and keys.

The venue adds a wrinkle of its own. Hyperliquid appears in the complaints as where the alleged trades happened, not as a subject of them; no wrongdoing by the venue is alleged. But the case underscores that prosecutors now routinely trace market abuse executed through decentralized venues, where account activity is public by default — a persistent ledger of evidence that enforcement has grown increasingly comfortable reading.

A busy week for SDNY

The complaints come one day after the same office filed a civil forfeiture action against approximately $61 million in crypto tied to sanctioned Iranian oil sales — a case we covered here. Taken together, they sketch the current enforcement posture: asset tracing and insider-abuse cases moving in parallel, with no meaningful distinction drawn between centralized and decentralized plumbing.

Exchanges running listing programs should treat the episode as a stress test of their own information handling. The question worth asking internally is blunt: if two engineers decided to monetize the listing calendar today, how many days would pass before anything noticed?

TrustGrade tracks the security posture of exchanges, protocols and infrastructure providers. Verified registry scores and security scans arrive with TrustGrade Code Scoring in December 2026.