# Google Security Engineer Charged with $1.2 Million Insider Trading Scheme on Crypto Prediction Market


A Google security engineer exploited his authorized access to confidential corporate data to orchestrate an elaborate insider trading scheme on a cryptocurrency prediction market, netting $1.2 million in illegal proceeds before federal investigators unraveled the operation. Michele Spagnuolo, 36, appeared in U.S. District Court in the Southern District of New York on Wednesday following criminal charges brought by federal prosecutors and the Commodity Futures Trading Commission (CFTC).


## The Threat


Spagnuolo, an Italian citizen residing in Switzerland and a Google employee since 2014, allegedly weaponized his position as a security engineer to gain unauthorized insight into one of Google's most closely guarded annual announcements: the "Year in Search" rankings. Beginning in October 2025, he accessed an internal software tool containing the confidential "Year in Search" data—marked with a prominent red "Google Confidential" banner—and used that information to place bets on Polymarket, a decentralized prediction market built on blockchain technology.


Operating under the alias "AlphaRaccoon," Spagnuolo placed wagers on whether specific individuals would appear on Google's top trending search lists. The strategy proved remarkably successful: he achieved near-perfect accuracy across approximately 25 unlikely outcomes while risking roughly $2.75 million in total capital.


When Google publicly announced its Year in Search results on December 4, 2025, markets on Polymarket resolved in Spagnuolo's favor. Between December 4 and 10, 2025, the AlphaRaccoon account collected approximately 3.9 million USDC.e (a wrapped form of USD Coin), from which it transferred 5.045 million USDC.e to an external wallet. The net result: $1.2 million in illegal profits from a single transaction.


## Background and Context


The case represents one of the most significant insider trading prosecutions tied to decentralized financial markets—a growing concern for regulators as traditional financial crimes migrate onto blockchain-based platforms. Polymarket, which operates globally and allows users to bet on real-world outcomes, has become a venue for high-stakes speculation on everything from political elections to tech company developments.


Spagnuolo's position as a security engineer at Google provided legitimate access to internal systems and confidential business information. However, federal prosecutors contend he fundamentally breached his fiduciary duty to his employer by misappropriating that data for personal financial gain. The timing of his trades—before public disclosure and with remarkable predictive accuracy—painted a clear pattern of insider knowledge exploitation.


Key Timeline:


| Date | Event |

|------|-------|

| October 2025 | Spagnuolo begins placing bets using AlphaRaccoon account |

| December 4, 2025 | Google publicly announces Year in Search results |

| December 4-10, 2025 | AlphaRaccoon account receives ~$3.9M in USDC.e |

| Post-December 10 | Online communities on Discord and X speculate AlphaRaccoon is a Google insider |

| Following exposure | Spagnuolo removes username from account, reverting to alphanumeric wallet address |

| Post-detection | Spagnuolo moves proceeds through multiple cryptocurrency-swapping services |


## Technical Details: How the Scheme Unraveled


Federal investigators leveraged traditional financial forensics adapted for cryptocurrency transactions. The FBI traced the AlphaRaccoon account through its payment processor connection to a processor account registered in Spagnuolo's name and linked to an Italian government identification card—a critical error that anchored digital identity to real-world identity.


When online communities on cryptocurrency trading platforms began speculating about AlphaRaccoon's insider status, Spagnuolo attempted damage control by removing the username from the account, leaving only an alphanumeric wallet address. However, this action came too late. Prosecutors allege that he subsequently moved the $1.2 million in illegal proceeds through multiple cryptocurrency-swapping services, including at least one designed to remove wallet addresses from public blockchain visibility.


Despite these obfuscation efforts, blockchain's immutable ledger and standard cryptocurrency compliance practices—including anti-money laundering (AML) protocols at exchange interfaces—created an investigative trail. Unlike traditional wire transfers, which can be deleted or archived, every transaction on the blockchain remains permanently recorded and traceable through forensic analysis.


## Regulatory and Legal Implications


The charging decision sends a forceful message from federal prosecutors: confidential business information holds the same legal protection regardless of whether it is misappropriated for traditional stock trading or cryptocurrency speculation.


"Today's charges reinforce a decades-old message: corporate insiders cannot use confidential business information to turn a profit in our markets," said U.S. Attorney Jay Clayton in a statement accompanying the charges. "As alleged, Spagnuolo violated the duties he owed to his employer and used Google's confidential business information to make more than $1.2 million in trading profits on Polymarket."


The CFTC filed a parallel civil complaint on the same day, seeking restitution, disgorgement of illegal profits, civil monetary penalties, and bans on trading and registration in regulated commodity markets.


Spagnuolo faces severe criminal exposure:


  • Commodities fraud: up to 10 years in prison
  • Wire fraud: up to 20 years in prison
  • Money laundering: up to 20 years in prison

  • ## Implications for Organizations


    This prosecution highlights a critical vulnerability in corporate information security: trusted insiders with legitimate system access. Spagnuolo held a security engineering position, meaning he likely had elevated privileges to internal systems—privileges granted based on his role and security clearance. Yet those same privileges became the mechanism for fraud.


    Key organizational risks exposed:


    1. Access Control Failures: Security engineers and privileged employees can access sensitive information but may not face adequate monitoring or audit controls when they do.


    2. Data Classification Without Enforcement: Google marked the Year in Search data with a red "Google Confidential" banner, but data classification alone does not prevent misuse.


    3. External Account Linking: Employees with access to confidential data can establish external financial accounts on cryptocurrency exchanges without corporate visibility or notification.


    4. Cryptocurrency as Laundry: Decentralized exchanges and cryptocurrency-swapping services complicate the investigation of insider trading compared to traditional financial markets, though not impossibly.


    ## Recommendations for Defenders


    Organizations should consider implementing stronger controls in response to this case:


  • Implement user and entity behavior analytics (UEBA) for employees with access to material non-public information, flagging unusual external account creation or financial activity.

  • Require disclosure of external financial accounts for employees in sensitive roles, with periodic verification.

  • Monitor data access patterns for individuals accessing material non-public information, especially those accessing it outside normal business hours or work patterns.

  • Establish clear insider trading policies that explicitly cover cryptocurrency markets and blockchain-based prediction platforms.

  • Educate security and trusted employees on the legal consequences of misappropriating confidential information, regardless of the trading venue.

  • Establish relationships with cryptocurrency compliance partners to detect unusual account activity tied to corporate insiders.

  • ## HackWire Analysis


    This case exposes a profound gap in corporate insider threat detection: while organizations invest heavily in protecting data *in transit* and *at rest*, they often fail to monitor how trusted employees—particularly those in security roles—*use* that data once they access it. Spagnuolo held a security engineering position, which means he likely passed corporate security clearance, background checks, and privilege access reviews. Yet those credentials enabled one of the most brazen insider trading schemes in recent memory.


    The timing is significant. Polymarket and similar decentralized prediction markets have exploded in popularity over the past 18 months, creating a novel arena for insider trading that sits in a regulatory gray zone. Prosecutors are now signaling that they will treat cryptocurrency prediction markets with the same rigor as traditional financial markets—but the case also reveals how cryptocurrency's perceived anonymity creates a *perception* of safety among bad actors that no longer holds.


    What's particularly notable is the pattern: Spagnuolo didn't attempt a sophisticated multi-hop money laundering scheme involving dark pools or jurisdictional arbitrage. He simply registered a Polymarket account under a pseudonym and assumed blockchain's opacity would protect him. This underestimation of investigative capability is becoming common. Blockchain analysis has matured dramatically; every major exchange now implements KYC (know-your-customer) and AML checks. The real vulnerability was the payment processor link—a single node connecting AlphaRaccoon to his real identity.


    For defenders, the lesson is clear: insider threat programs must expand beyond data loss prevention (DLP) to behavioral monitoring for employees with access to material non-public information. The next version of this crime will likely involve more sophisticated obfuscation, but the investigation playbook—linking blockchain wallets to real-world identity through payment processors and KYC records—is now well-established. Organizations should assume that federal regulators and law enforcement will collaborate with cryptocurrency platforms to pursue insider trading on decentralized markets with the same intensity they bring to traditional securities fraud.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)