Insider Trading Controls Weren’t Built for Prediction Markets

 

A trader on Polymarket won 41 out of 42 bets on whether specific companies would beat their quarterly earnings. All 18 companies in that pattern had one thing in common: KPMG audited them.

Nobody guesses their way to a 98% hit rate.

My co-host, David Leary, and I got into this on Episode 505 of The Accounting Podcast, and the more we dug into the story, the less it looked like a curiosity.

 
 

The numbers behind the pattern

Blockchain forensics firm Bubblemaps traced the activity across dozens of yes-or-no contracts tied to KPMG audit clients, including Wells Fargo, Home Depot, and DoorDash.

The pattern started in November 2025 and netted roughly $22,000.

The same trader also bet on companies audited by other firms and won 82% of those. That’s a strong number, but nowhere near the KPMG rate.

Bubblemaps traced the money flow across 19 different Polymarket accounts. That suggests one person or team deliberately spread bets around to stay under the radar.

Federal investigators are now looking into whether a KPMG employee is behind it.

The Wall Street Journal reported that charges against a KPMG employee could come as soon as this fall. KPMG, meanwhile, says it has zero tolerance for trading on nonpublic client information.

This isn’t just another crazy crypto story

It’s tempting to file this under “weird blockchain gambling thing” and move on. I get it. Prediction markets still feel like a novelty to many professionals.

But strip away the fact that Polymarket is a cryptocurrency-based platform. If the pattern is what it looks like, someone with access to material nonpublic information found a low-friction, semi-anonymous way to monetize it.

And an outside analytics firm had to notice the pattern.

That’s a controls problem.

Audit firms built insider trading safeguards around the channels they know. Employees can’t trade in their clients' stock. They sign an acknowledgment every year.

But those controls assume the leak happens through a phone call, stock trade, or Signal message to a friend.

They weren’t designed with a permissionless betting market in mind. You don't even need a brokerage account, just a wallet and an opinion on whether Home Depot beats estimates next quarter.

This should worry every firm

The same transparency that let someone place these bets is also what exposed the pattern. Every wager on Polymarket is on a public blockchain.

Bubblemaps didn’t need a subpoena to spot the pattern. It needed public on-chain data and the patience to trace money across 19 accounts.

It's reassuring that this kind of activity is more traceable than a whispered stock tip. But it’s also a warning: traceability only works if somebody's looking.

An outside firm only spotted this because the pattern got weird enough to attract attention.

So, what needs to change?

Banning employees from Polymarket is a good first step for firms that haven't already.

But they also need to recognize that new channels for monetizing information keep showing up. Prediction markets won't be the last one.

They need to monitor for this stuff, not just prohibit it and hope.

The old model assumed employees might leak information through the channels you know about, and you watched those channels.

The new model has to assume new channels will appear faster than policy manual updates, and build monitoring that doesn't rely on an outside blockchain analytics firm to do your job for you.

 
Next
Next

Nvidia's $500 Billion Deal Has an Enron Problem, and GAAP Lets It Happen