35 Comments
User's avatar
Les Barclays's avatar

This article should be mandatory reading for everyone! Very well written. 2FA is more useless than I thought.

Peakview's avatar

Thanks for this. That is a great top about using your password manager to fill in entries. I try to never click on links in emails or texts as a first line of defense and call or go to the web page directly to see if the request is valid. At work, they send monthly fake phishing emails to keep awareness high and they let you know if you were fooled. It is good reinforcement.

Demeisen's avatar

IIRC you used to have to explicitly enable options trading on many brokerage accounts. Maybe that horse has left the barn but it seems like a reasonable thing to do or vendor default.

Golden Mead's avatar

Asking for 2FA on seeing odd trading behavior is an excellent idea. One might even allow users a degree of customization on what should trigger 2FA.

IBKR has a huge incentive to not have its customers fleeced. The commission earned would be irrelevant to such a well run firm. Their only concern would be to not inconvenience legitimate customer trading.

Hopefully, you e shared this idea with them.

Grant Edwards's avatar

On August 13 someone placed a massive, margin-funded market buy order of a crypto alt coin in my Robinhood account. The purchase represented 25% of my account value.

Robinhood’s internal fraud review process did not detect foreign logins, hence they did not classify the transaction as a fraud event (which covers transactions Robinhood considers “fraudulent or erroneous”). Their formal conclusion employs standardized language: the review “confirmed there was no unauthorized activity.”

My whereabouts at the time the trade was placed are well documented, and my prompt report of the incident an hour later (before any material price change had occurred) likewise indicate that I didn’t authorize the trade.

Robinhood says there was no additional step-up verification required because the device was trusted and the IP location aligns with my location. They did flag a VPN connection that could have been used to disguise a hacker’s identity and location. I flagged a suspicious login 4 hours after the trade was executed, with an IP address location more than 300 miles from me.

In my view, and consistent with regulatory guidance, Robinhood’s front-end security failure is responsible for the mess we are now in, including post-event forensic evidentiary uncertainty. It’s in the nature of sophisticated fraud that it’s not easy to detect.

FINRA and other guidance does not require that an extraordinary transaction — one that is radically inconsistent with the account holder’s trading activity, portfolio composition (100% non-crypto in my case), typical order sizes/types, selective use of leverage, etc — trigger a step-up verification before the order can be executed. This appears to be a policy gap in need of addressing.

I can’t say why someone would purchase a boatload of crypto in another’s account. Was there a planned follow-up attack or thwarted withdrawal attempt? Was this a form of market manipulation? Hacker showing off or flexing their skills?

I do not know. But perhaps this case study is useful for your reference.

Thanks for the excellent discussion.

Inverteum Capital's avatar

Thank you for sharing your experience.

It's a good thing you caught the hack early and prevented any potential draining of your account. In terms of illiquidity, an altcoin is just like the 0DTE BYND options that drained Ms. Yeung's brokerage account, and this could've ended much worse if you hadn't taken action early.

It's clear that regulations have not kept up with the sophistication and advancement of hacking and that regulators need to catch up. It's hard to say exactly what the hacker was planning but whatever it was, it definitely wasn't good.

Albert Cory's avatar

It CAN happen to you, no matter how careful you are.

Yesterday I got an "invitation" from "Paperless Post." It was someone I knew, and It WAS plausible that he'd invite me to something.

Nonetheless, it was a scam. He said it got him, too. I should have alerted when it asked me to log in to gmail, and I was already logged in.

When you hover over a link, the browser will show where it's going, at the bottom. This would have saved John Podesta from exposing all of Hillary's emails.

Servaes's avatar

I'm not sure about the mobile app suggestion. It solves the phishing issue, but it introduces the risk of your phone getting stolen, maybe at gunpoint, maybe unlocked, and thieves just opening the app & trading or transferring right there.

yossarian's avatar

What's even more dangerous, a lot of places, even banks and brokers, allow you to recover your password using 2fa. And guess what, it's absolutely easy to get someone to give "some numbers from a message" to a stranger, rather than their password.

toolate's avatar

Many of the largest US brokers still not using passkeys...why?

David Andersen's avatar

Never, ever click on a login link sent to you via text or email. Go to the website yourself. That also would have stopped this.

Inverteum Capital's avatar

Exactly. 2FA has also become meaningless for protecting against phishing.

Daniel's avatar

really getting ridiculous - with AI everything will be unsafe and no one seems to care

Anne Keller's avatar

Looks like a perfect place to deploy AI - why don't they?

Inverteum Capital's avatar

You're exactly right. Quote from article:

"Follow the money: This is not a technical limitation. Brokers make way more money from trading in options than stocks and ETFs, whether they charge payment for order flow (PFOF) or commissions."

VR's avatar

Thank you !!! This is eye opening !!

Tim's avatar

Yes important reading

RBAR's avatar

Your account doesn't need to be authorized to trade options. Default on IKBR is no options trading. That's a glaring miss in this informative article.

Inverteum Capital's avatar

The article mentions just how easy it is for hackers to turn on options trading on a stolen brokerage account where that permission is off.

"What’s more, brokerages put almost no speed bumps on turning that options permission on. There is no second 2FA. The signature is typing a name in a Sign Here box. The review period can be as short as overnight, and the only reason it exists is because regulators require an approval delay, not because the broker wants friction."

Cameron Levitt Real Estate's avatar

The story behind this article is so obviously false that it reveals an astonishing lack of basic understanding of how options markets actually work.

These are stock options on a U.S.-listed company, traded through regulated exchanges and cleared by the OCC. There is an enormous regulatory, clearing and transaction infrastructure in place that you can't hijack to make this work at a fundamental level.

Firstly, you can't control who buys your options. It's not Facebook Marketplace.

As soon as the hacked buyer started providing liquidity at an attractive price for a particular strike, market makers, traders and hedge funds would rush in to compete for that order flow. These are sophisticated, multi-billion dollar firms whose entire business is built around doing exactly this. The hacker would just end up sending the victim's money to Citadel or Susquehanna.

Secondly, the short side of these trades would require substantial collateral. $1.1 million lost across 30 trades is roughly $36,000 per trade.

The options would be extremely cheap because the stock is trading at a low price, the options are out of the money and they're close to expiry, leaving very little time value. To collect roughly $36,000 in premium per trade, the seller would need to bundle thousands, potentially tens of thousands, of contracts at a time.

Each contract represents 100 shares, so the notional exposure is hundreds of thousands or even millions of shares. If the options expired in the money and were assigned, the seller could ultimately be responsible for delivering those shares at the $1.50 strike.

Brokerages and trading platforms force you to have the capital to manage that risk. It could literally be millions of dollars worth here.

Which also means the math on the whole scame doesn't add up either. It's potentially committing millions of dollars amd taking enormous 0DTE assignment risk to make about $36,000 per trade.

A brokerage account being compromised is entirely plausible. Using the listed options market as a private pipeline to transfer $1.1 million from that account to another account controlled by the hacker makes no sense.

Inverteum Capital's avatar

1) The idea that the "market makers would just compete the flow away" is true for liquid securities and derivatives but not uniformly across the entire market. There are ~5,000 exchange-listed US stocks, over 12,000 when you include OTC, and ~5,100 US-listed ETFs, and layering call and put options across many strikes and expiries pushes the number of option series into the millions. The edge that market makers have follows a power law, concentrated in the most highly traded securities and options contracts.

The way the heist was executed used low-volume options contracts derived from individual stocks, where market makers don't necessarily have the edge that comes from vast amounts of trading data to reliably make a profit. For a highly liquid options contract, one of several competing offers would fill buy orders far below the hacker's inflated price, but for a thinly traded contract, there is no stack of competing offers, so the victim's buy order is filled by the hacker's sell order. This is precisely why the hacker chose an illiquid option.

The notion that a market maker can profitably trade against everything everywhere has been tested by Alameda Research on FTX, and we all know how that turned out for both companies. Undoubtedly, Citadel and Susquehanna have far better risk controls and know not to trade against every possible counterparty in every possible derivative.

2) When it comes to collateral, the hacker is selling options contracts they already hold and letting them expire out-of-the-money. There is no short obligation and no shares that need to be delivered. The $1.50 strike price was 19% above the highest traded price for BYND stock on Dec 19, 2025 ($1.26). Thus, the options stayed out of the money and expired worthless at the end of the day, and the premium was kept free and clear by the seller.

Cameron Levitt Real Estate's avatar

How did the hacker already own the calls and not lose money? OTM 0DTE value disappears faster than a fart in a hurricane. That's not even mentioning execution costs and slippage. It's nonsense.

If you're suggesting the buyer notably overpaid for the options, that's exactly the kind of situation market makers notice and take advantage of. They literally scan markets and compete with each other for order flow like that.

And the idea that market makers aren't paying attention because the options are illiquid has it completely backwards. If market makers only paid attention to options that were already liquid, they wouldn't be making markets. Providing liquidity where there isn't any is literally what market making is.

Mercenary Pen's avatar

If the hacker lost the race to buy and Citadel beats them to it, why would the hacker care? Just move on to the next account.

Inverteum Capital's avatar

The important thing to keep in mind is that the hacker and victim's purchases of the BYND 0DTE options happened under totally different conditions and circumstances.

The hacker probably purchased the options earlier in the day. Due to the illiquidity and the requisite lack of a resting market maker offer for that specific option contract, their buy order could have taken minutes to be noticed and filled by a market maker.

The hacker then specifically engineered buy and sell trade pairs using their account and the victim's account respectively by submitting orders within milliseconds of each other, each trade being small enough to avoid attracting an opportunistic market maker.

This is why instead of one big trade of $1m, there were 30+ small trades ranging from $5k to $70k each: https://youtu.be/gkXd-nIs9uo?t=221

After a script places the sell order on the hacker's own account, the hijacked session on the victim's side is driven programmatically to place the matching buy order within milliseconds using browser automation.

With no better-priced offer present at that specific millisecond, there is nothing for the buy order to route to except the resting sell, and the buy and sell orders cross. By controlling both order-entry moments, the hacker can ensure that the buy can execute right after the sell. There doesn't even need to be a human in the loop.

Whether you believe it or not, it happened to Ms. Yeung, and she lost $1m of her life savings. The scariest thing is it could happen to anyone.