FULLTEXT DEL 2 AV 5
10-K – 2026-02-18 – hood-20251231.htm
Beginning in May 2026, as a result of the amended round lot and odd-lot definitions, the SIPs will begin making information about smaller-sized orders publicly available, which will result in the contraction of spreads across many securities, and we expect may lead to a decrease in the PFOF earned from such orders. Any new or heightened PFOF regulation, including the September 2024 Final Rules will result in increased compliance costs and otherwise could materially decrease our transaction-based revenue, might make it more difficult for us to expand our platforms in certain jurisdictions, and could require us to make significant changes to our revenue model, which changes might not be successful. Because some of our competitors either do not engage in PFOF or derive a lower percentage of their revenues from PFOF than we do, any legal or regulatory change that impacts PFOF could have an outsized impact on our results of operations. Furthermore, depending on the nature of any new requirements, heightened regulation could also increase our risk of potential regulatory violations and civil litigation, which could result in fines or other penalties, as well as negative publicity. Risks Related to Negative Publicity Associated with PFOF, Transaction Rebates or our Liquidity Providers Additionally, any negative publicity surrounding PFOF or Transaction Rebate practices generally, or our implementation of these practices, could harm our brand and reputation. For example, as a result of the Early 2021 Trading Restrictions (as defined in Note 15 - Commitments & Contingencies to our consolidated financial statements in this Annual Report), we faced allegations that our decision to temporarily prevent our customers from purchasing specified securities was influenced by our relationship with certain market makers. Furthermore, as registered broker-dealers, market makers must comply with rules and regulations that are generally intended to prohibit them from taking advantage of information they obtain while executing orders (e.g., through the prohibition on “front running”). Market makers also have a duty to seek “best execution” of customers’ equity and option orders we send to them. If the market makers we use to execute our customers’ equity and option trades were to violate such rules and regulations and use this data for their own benefit in violation of applicable rules and regulations, it could result in negative publicity for us by association. Developments in any proposals related to the regulation 36 Table of Contents of PFOF or market structure design have generated and might continue to generate negative publicity associated with PFOF. Additionally, if our customers or potential customers believe that they might get better execution quality (including better price improvement) directly from our competitors that have different execution arrangements, or if our customers perceive our PFOF practices to create a conflict of interest between us and them, or if they begin to disfavor the specific market markers with which we do business due to any negative media attention, they might come to have an adverse view of our business model and might decide to limit or cease the use of our platforms. Some customers might prefer to invest through our competitors that do not engage in PFOF or Transaction Rebate practices or engage in them differently than do we. Any such loss of customer engagement as a result of any negative publicity associated with PFOF or Transaction Rebate practices could adversely affect our business, financial condition, and results of operations. RHC has started to allow customers to choose a fee-based model in lieu of a liquidity provider rebate-based model (under which RHC receives Transaction Rebates from Liquidity Providers) for cryptocurrency orders routed to cryptocurrency exchanges for execution. This shift may lead to negative publicity due to potential differences in total costs for customers under the two models. Depending on the nature of these cost differences, concerns might arise about (i) the use of PFOF with respect to other asset classes like equities and options and/or (ii) the replacement of Transaction Rebates with customer fees for cryptocurrency orders routed to cryptocurrency exchanges for execution. Any negative publicity associated with adopting this model may have an adverse impact on our business, financial condition and results of operations. We are directly and indirectly exposed to fluctuations in interest rates, and rapidly changing interest rate environments have in the past and could in the future reduce our net interest revenues and otherwise result in reduced profitability. A portion of our revenue comes from interest income earned from our corporate cash and investment portfolio, our securities lending activities, cash sweep, and from interest-rate sensitive assets, including receivables from users’ margin-borrowing and other assets underlying the customer balances we hold on our balance sheets as customer accounts. Interest rates are the key driver of our net interest income and are subject to many factors beyond our control. Reductions in interest rates have negatively impacted, and a return to a low interest rate environment would negatively impact our total net revenues, net income (loss), and cash flows, prior to any income tax effects, and adversely impact our customers’ returns on their cash deposits. Changes to the level or mix of interest earning balances could also negatively impact our total net revenues, net income (loss), and cash flows, prior to any tax income effects, if customers react to the rising interest rate environment by moving cash that would have otherwise been spent on services or products with higher revenue potential for Robinhood into Robinhood accounts that offer customers high interest rates. For a more detailed discussion of interest rate risk and an estimate of how hypothetical 50, 100 or 150 basis point increases or decreases in interest rates to the period end balances of our interest-earning assets and liabilities could affect our total net revenues, net income (loss), and cash flows, prior to any income tax effects, see “Quantitative and Qualitative Disclosures about Market Risk-Interest Rate Risk” elsewhere in this report. Higher interest rates also lead to higher payment obligations by our customers to us and to their creditors under mortgage, credit card, and other consumer and merchant loans, which might reduce our customers’ ability to satisfy their obligations to us, including failing to pay for securities purchased, meet minimum credit card payments, deliver securities sold, or meet margin calls, and therefore lead to increased delinquencies, charge-offs, and allowances for loan and interest receivables, which could have an adverse effect on our net income. Fluctuations in interest rates could adversely impact our customers’ general spending levels and ability and willingness to invest and spend through our platforms. As registered broker-dealers, we are subject to “best execution” requirements under SEC guidelines and FINRA rules. We could be penalized if we fail to comply with these requirements and these requirements might be modified in the future in a way that could harm our business. 37 Table of Contents As registered broker-dealers, we are subject to “best execution” requirements under SEC guidelines and FINRA rules, which requires us to obtain the best reasonably available terms for customer orders. We have in the past and continue to be subject to investigations related to our best execution practices. We may face additional investigations and/or a risk of penalties in the future related to our best execution practices. We also might be adversely affected in the future by regulatory changes related to our obligations with regard to best execution. In particular, receipt of PFOF and best execution requirements have drawn heightened scrutiny from the U.S. Congress, the SEC, and other regulatory and legislative authorities, who have at times alleged that PFOF arrangements, like those we have with our Liquidity Providers, can result in harm to customer execution quality. There is a risk that these bodies might adopt new laws or regulations relating to PFOF practices and best execution requirements as a result of such heightened scrutiny or otherwise. For instance, the SEC previously proposed rules relating to best execution requirements in December 2022 but formally withdrew them in June 2025. Any such new laws or regulations could have a material adverse impact on our business and one of our primary sources of revenue. We might need additional capital to provide liquidity and support business growth and objectives, and this capital might not be available to us on reasonable terms, if at all, might result in stockholder dilution, or might be delayed or prohibited by applicable regulations. Maintaining adequate liquidity is crucial to our securities brokerage, cryptocurrency and money services business operations, including key functions such as transaction settlement, custody requirements, and margin lending. The SEC and FINRA also have stringent rules with respect to the maintenance of specific levels of net capital by securities broker-dealers. We meet our liquidity needs primarily from working capital and cash generated by customer activity, as well as from external debt and equity financing. Despite these resources, increases in the number of customers, and fluctuations in customer cash or deposit balances, as well as market conditions or changes in regulatory treatment of customer deposits, could affect our ability to meet our liquidity needs. We might be adversely affected by regulatory changes related to our obligations with regard to capital maintenance requirements. For example, in December 2024, the SEC adopted amendments to the broker-dealer customer protection rule (SEC Rule 15c3-3) to require certain broker-dealers to compute their customer and broker-dealer reserve deposit requirements, and to make any required deposits, daily rather than weekly. These amendments, which require broker-dealer compliance by June 2026, will increase the operational complexity and burden related to such calculations and funding. Additionally, there is no definitive guidance on whether or how these rules may apply to most cryptocurrencies, and we might be adversely affected in the future if the SEC determines that they do. In addition, our clearing and carrying broker-dealer is subject to cash deposit and collateral requirements under the rules of the clearinghouses in which it participates (including DTC, NSCC, and OCC), which requirements fluctuate significantly from time to time based upon the nature and volume of customers’ trading activity and volatility in the market or individual securities. If we fail to meet any such deposit requirements, our ability to settle trades through the clearinghouse may be suspended or we might be forced to restrict trading in certain stocks in order to limit clearinghouse deposit requirements. For example, from January 28 to February 5, 2021, due to increased deposit requirements imposed on our clearing and carrying broker-dealer by NSCC in response to unprecedented market volatility, particularly in certain securities, we implemented the Early 2021 Trading Restrictions. This resulted in negative media attention, customer dissatisfaction, reputational harm, litigation, and regulatory and U.S. Congressional inquiries and investigations, as well as capital raising by us in order to lift the trading restrictions while remaining in compliance with our net capital and deposit requirements. We face a risk that similar events could occur in the future and, if we are unable to satisfy our deposit requirements, the clearinghouse may cease to act for us and may liquidate our unsettled clearing portfolio. We also need to hold capital and make deposits with respect to certain event contracts in accordance with applicable CFTC regulations and ForecastEx, LLC, Kalshi Klear LLC, and KalshiEx LLC’s Rulebooks for RHD. Further, RHEU and Bitstamp Europe S.A., are licensed crypto asset service providers under the EU’s MiCA, the provisions of which went into effect as of December 30, 2024. Among other requirements, 38 Table of Contents RHEU and Bitstamp Europe S.A. are subject to mandatory capital requirements that vary based on the services we provide. Failure to meet these capital requirements or any future increases to these requirements could limit our ability to obtain or maintain authorization, constrain operational flexibility, or result in penalties or sanctions. A reduction in our liquidity position could reduce our customers’ confidence in us, which could result in the withdrawal of customer assets and loss of customers, or could cause us to fail to satisfy broker-dealer or other regulatory capital guidelines, which may result in immediate suspension of securities activities, regulatory prohibitions against certain business practices, increased regulatory inquiries and reporting requirements, increased costs, fines, penalties or other sanctions, including suspension or expulsion by the SEC, FINRA or other SROs or state regulators, and could ultimately lead to the liquidation of our broker-dealers or other regulated entities. Factors which might adversely affect our liquidity positions include temporary liquidity demands due to timing differences between brokerage transaction settlements and the availability of segregated cash balances, timing differences between cryptocurrency transaction settlements between us and our cryptocurrency Liquidity Providers and between us and our cryptocurrency customers, fluctuations in cash held in customer accounts, a significant increase in our margin lending activities, increased regulatory capital requirements, changes in regulatory guidance or interpretations, other regulatory changes, or a loss of market or customer confidence resulting in unanticipated and/or excessive withdrawals or redemptions, or a suspension of redemptions or withdrawals of customer assets. For example, in May 2025, the UK’s FCA published three papers which announced new proposals for certain aspects of the prudential requirements for crypto firms. These proposals are largely modelled on the requirements for investment firms and, if adopted, would, among other requirements, require authorized crypto asset firms to hold a required minimum amount of regulatory capital. In particular, any increase in capital or liquidity requirements under the proposed FCA regime could reduce available liquidity and constrain flexibility in Bitstamp’s operations. If adopted, these regulations could also limit our ability to obtain or maintain authorization, constrain operational flexibility, affect our ability to raise capital or result in penalties or sanctions. We might also need additional capital to continue to support our business and any future growth and to respond to competitive challenges, including the need to promote our products and services, develop new products and services, enhance our existing products, services and operating infrastructure, acquire and invest in complementary businesses and technologies, and to fund payments on our obligations at the parent company level, such as the income tax withholding and remittance obligations that arise upon the vesting and/or settlement of our outstanding RSUs, and any debt obligations we might incur. To meet liquidity needs at the parent level, we might need to rely on dividends, distributions and other payments from our subsidiaries. Regulatory and other legal restrictions might limit our ability to transfer funds to or from some subsidiaries. For example, under FINRA rules applicable to RHS, a dividend of over 10% of a member firm’s excess net capital must not be paid without FINRA’s prior written approval. When available cash is not sufficient, we might seek to engage in equity or debt financings to secure additional funds. However, such additional funding might not be available on terms attractive to us, or at all, and our inability to obtain additional funding when needed could have an adverse effect on our business, financial condition, and results of operations. If we issue equity or convertible debt securities, our stockholders could suffer significant dilution, and the new shares could have rights, preferences and privileges superior to those of our current stockholders. Any debt financing could involve restrictive covenants relating to our capital-raising activities and other financial and operational matters, which might make it more difficult for us to obtain additional capital and to pursue future business opportunities. Unfavorable media coverage and other events that harm our brand and reputation have in the past, and may in the future, adversely affect our revenue and the size, engagement, and loyalty of our customer base. Our brand and our reputation are two of our most important assets. Our ability to attract, build trust with, engage, and retain existing and new customers might be adversely affected by events that harm our brand and reputation, such as public complaints and unfavorable media coverage about us, our platforms, and our customers, even if factually incorrect or based on isolated incidents. 39 Table of Contents We receive a high volume of media coverage, which has included, and might continue to include, negative coverage regarding our products and services and the risk of our customers’ misuse or misunderstanding of our products and services, inappropriate or otherwise unauthorized behavior by our customers and litigation or regulatory activity. In addition, given our public profile, any unanticipated system disruptions, outages, technical or security-related incidents, or other performance problems relating to our platforms have in the past and are likely in the future to receive extensive media attention. Furthermore, any negative experiences our customers have in connection with their use of our products and services, including as a result of any such performance problems, have in the past, and may in the future diminish customer confidence in us and our products and services, which have in the past, and may in the future result in unfavorable media coverage or publicity. Damage to our brand and reputation could also be caused by: • cybersecurity attacks, privacy or data security breaches, or other security incidents, payment disruptions or other incidents that impact the reliability of our platforms; • actual or alleged illegal, negligent, reckless, fraudulent or otherwise inappropriate behavior by our management team, our other employees or contractors, our customers or third-party service providers or partners as well as complaints or negative publicity about such individuals or companies; • future restructurings or any similar such reductions or activities in the future; • any repeat imposition of temporary trading restrictions (similar to our Early 2021 Trading Restrictions), or any outright failure to meet our deposit requirements; • litigation, regulatory actions, settlements, or investigations involving our platforms or our business; • regulators requesting or requiring us to cease offering specific products or services; • any failures to comply with legal, tax and regulatory requirements; • any perceived or actual weakness in our financial strength or liquidity; • any regulatory action or settlement that results in changes to, or prohibits us from offering, certain features, products or services; • any new policies, features, products, or services, or changes to our policies, features, products, or services, that customers or others perceive as overly restrictive, unclear, inconsistent with our values or mission, or not clearly articulated; • a failure to operate our business in a way that is consistent with our values and mission; • inadequate or unsatisfactory customer support experiences; • negative responses by customers, regulators, or other third parties to our business model or to particular features, products or services; • a failure to adapt to new or changing customer preferences; • our decision to offer products viewed by some as controversial; • our inability to successfully expand into new markets or make successful acquisitions of, or investments in, other companies, products or technologies; 40 Table of Contents • a prolonged weakness in popular equities or cryptocurrencies specifically or in U.S. or international equity and cryptocurrency markets generally, or a sustained downturn in the U.S. or international economies; • negative claims or publicity involving our culture or businesses, regardless of whether such claims are accurate; and • any of the foregoing with respect to our competitors, to the extent the resulting negative perception affects the public’s perception of us or our industry as a whole. These and other events could negatively impact the willingness of our existing customers, and potential new customers, to do business with us, which could adversely affect our trading volumes and number of Funded Customers, as well as our ability to recruit and retain personnel, any of which could have an adverse effect on our business, financial condition, and results of operations, as well as the trading price of our Class A common stock. We could incur substantial losses from our cash and investment accounts if one or more of the financial institutions that we use fails or is taken over by the FDIC. We maintain cash and investment accounts, as well as restricted cash as certificates of deposits for facility leases and other contractual obligations, at multiple financial institutions in amounts that are significantly in excess of the limits insured by the FDIC. In spring 2023, certain U.S. banks failed and were taken over by the FDIC (the “2023 Banking Events”). If any of the financial institutions where we hold significant deposits were to fail or be taken over by the FDIC, our ability to access such accounts has in the past and could be in the future temporarily or permanently limited, which could adversely affect our business. In particular, while we have taken steps to help ensure that the loss of all or a significant portion of any uninsured amount would not have an adverse effect on our ability to pay our operational expenses or make other payments, the failure of a financial institution where we hold significant deposits has in the past and may in the future require us to move funds to another bank, which could cause a temporary delay in making payments to our vendors and employees, or under other contractual arrangements, and cause other operational inconveniences. Additionally, any losses or delay in access to funds as a result of such events could have a material adverse effect on our ability to meet contractual obligations, earnings, financial condition, cash flows, and stock price. Our business has been and might continue to be harmed by changes in business, economic, or political conditions that impact global financial markets, or by a systemic market event. As we are a financial services company, our business, results of operations, and reputation are directly and indirectly affected by elements beyond our control, such as financial market volatility (such as we previously experienced during the COVID-19 pandemic or have experienced and may experience in the future due to trade policy shifts and the imposition or escalation of tariffs implemented by the U.S. and other countries or blocs, including China, Canada, and the EU, and those countries’ or blocs’ responses to such shifts and tariffs), economic and political conditions including unemployment rates, inflation, tax and interest rates, geopolitical conflicts, such as the Russian invasion of Ukraine and ongoing events in the Middle East, significant increases in the volatility or trading volume of particular securities, cryptocurrencies, or Futures (such as we experienced during the meme stock events of early 2021 and the Dogecoin surge of mid-2021), broad trends in business and finance, actual events or concerns involving liquidity, defaults, or non-performance by third-party financial institutions or transactional counterparties (such as the 2023 Banking Events), changes in volume of securities, cryptocurrencies, or Futures trading generally and changes in the markets in which such transactions occur, and changes in how such transactions are processed. These elements can arise suddenly, and the full impact of such conditions could have an adverse effect on our business results or remain uncertain indefinitely. Because a large percentage of our customers are first time investors, we might be disproportionately affected by declines in investor confidence caused by adverse economic conditions. A prolonged market weakness, such as a slowdown causing reduced trading volume in securities, derivatives, or cryptocurrency markets, has resulted, and could result in the future in reduced revenues and adversely affect our business, financial condition, and results of operations. Conversely, significant upturns in such markets or 41 Table of Contents conditions might cause individuals to be less proactive in seeking ways to improve the returns on their trading or investment decisions and, thus, decrease the demand for our products and services. Additionally, concerns regarding the U.S. and/or international financial systems, such as in connection with the 2023 Banking Events, could result in less favorable commercial financing terms available to us, including higher interest rates or costs and tighter financial and operating covenants, or systemic limitations on our access to credit and liquidity sources. Any of these changes could cause our future performance to be uncertain or unpredictable, and could have an adverse effect on our business and results of operations. Our future success depends on the continuing efforts of our key employees and our ability to attract and retain senior management and other highly skilled personnel. Our future success depends, in part, on our ability to continue to identify, attract, develop, integrate and retain qualified and highly skilled personnel. In particular, our CEO, Vladimir Tenev, has been critical to the development and execution of our business, vision, and strategic direction. In addition, we have heavily relied, and expect we will continue to heavily rely, on the services and performance of our senior management team, which provides leadership, contributes to the core areas of our business and helps us to efficiently execute our business. Although we have entered into employment offer letters with some of our key personnel, most of these agreements have no specific duration and are terminable by either party at-will and our senior management team has experienced recent changes. We do not maintain key person life insurance policies on any of our employees. We also might not be successful in attracting, integrating or retaining qualified personnel to fulfill our current or future needs. In particular, there continues to be particularly high competition in the San Francisco Bay Area for software engineers, computer scientists and other technical personnel. This competition is likely to increase further due to ongoing changes in U.S. immigration policies and enforcement practices, particularly given the foreign national employee population from which we and other companies hire for these positions, and is likely to present increased challenges to attracting, integrating or retaining qualified personnel. Given our heavy emphasis on SBC, the performance of our stock price has in the past had, and could continue to have, a significant impact on our ability to recruit, retain, and motivate highly skilled personnel. Additionally, our working model may negatively impact our ability to retain and recruit highly skilled personnel, especially to the extent other companies continue to allow more flexible remote working models. Attrition and workforce reorganizations and reductions have also and might continue to adversely affect our reputation among job seekers, demoralize our remaining employees, and result in a loss of institutional know-how, reduced productivity, slower customer service response, reduced effectiveness of internal compliance and risk-mitigation programs, and cancellations of or delays in completing new product developments and other strategic projects. For example, in the periods immediately following our past restructurings, we experienced higher rates of voluntary employee attrition and declines in reported employee job satisfaction. We might continue to experience difficulty in hiring and retaining highly skilled employees with appropriate qualifications. We believe that a critical component of our efforts to attract and retain employees has been our corporate culture of innovation. We have invested substantial time and resources in building our team. As we continue to expand internationally, we will face new challenges to maintain our corporate culture of innovation among a larger number of geographically dispersed and remote employees, as well as other service providers. Failure to preserve our company culture could harm our ability to retain and recruit personnel. If we are unable to attract, integrate, retain, or effectively replace our key employees and qualified and highly skilled personnel, our ability to effectively focus on and pursue our corporate objectives will decline, and our business and future growth prospects could be harmed. Acquisitions of, or investments in, other companies, products or technologies have in the past and could in the future require significant management attention, disrupt our business, dilute stockholder value, and adversely affect our results of operations. 42 Table of Contents As part of our business strategy, we have made and might continue to make acquisitions of, or investments in, other compatible companies, products, technologies, or specialized employees. We also have entered into and might continue to enter into relationships with other businesses in order to expand our products and services. Negotiating these transactions can be time-consuming, difficult, and expensive. Our ability to close these transactions has been and might in the future be subject to third-party approvals and customary closing conditions, such as governmental and other regulatory approvals, some of which are beyond our control, and may take longer than expected to be obtained, if at all. If pending transactions are not completed, we have in the past and could in the future be subject to losses from legal fees and other expenses as well as impairment charges. In general, our efforts to grow through acquisitions are subject to the risks that we might be unable to find suitable acquisition or investment candidates or to complete acquisitions on favorable terms or in a timely manner, if at all. Moreover, these kinds of acquisitions or investments can result in unforeseen risks, operating difficulties and expenditures prior to and following closing, including disrupting our ongoing operations, diverting management from their primary responsibilities, subjecting us to additional liabilities, compliance obligations and/or regulatory costs and penalties, exposing us to increased regulatory risk in connection with acquired companies, increasing our expenses, and adversely impacting our business, financial condition and results of operations. In connection with such acquisitions, we have encountered and may encounter in the future challenges in successfully integrating the acquired personnel, operations, products, and technologies, including in connection with our recent acquisitions of TradePMR and Bitstamp, and have and may have in the future difficulty effectively managing the combined business following such acquisitions. Moreover, the anticipated benefits of any acquisition or investment might not be realized, the acquisition or investment might not perform in accordance with expectations, and we might be exposed to unknown liabilities or risks. In connection with these types of transactions, we might issue additional equity securities that would dilute our stockholders, use cash that we might need in the future to operate our business, incur debt on terms unfavorable to us or that we are unable to repay, incur large charges or substantial liabilities, encounter difficulties integrating diverse business cultures, and become subject to adverse tax consequences, substantial depreciation, or deferred compensation charges. Rothera, owned and operated as a joint venture with SIG, operates a futures and derivatives exchange and clearinghouse through its subsidiary, Rothera E&C. We do not wholly own or operationally control Rothera and its subsidiaries, and actions taken by Rothera and its subsidiaries could adversely affect our business, financial condition, results of operations, and reputation. On November 19, 2025, Robinhood invested in Rothera, a joint venture established to operate an independent and institutional-grade futures and derivatives exchange and clearinghouse. On January 20, 2026, Rothera acquired 90% of the issued and outstanding equity of Rothera E&C, a CFTC-licensed DCM, DCO, and SEF to accelerate delivery of futures and derivative product offerings, including prediction markets. Rothera is an independent entity with its own management team and employees responsible for the day-to-day operations of the joint venture. While Robinhood is entitled to designate a majority of the members of the board of directors of Rothera and one representative to serve on the board of directors of Rothera E&C, and expects to exercise governance control at Rothera’s board level and as otherwise set forth in Rothera’s governance documents, we will not have decision-making authority over all operational, strategic, or commercial decisions made by Rothera or any of its subsidiaries, and certain decisions may be subject to applicable regulatory requirements or require the consent of SIG and other holders of the equity of Rothera and its subsidiaries, any of whom may have economic or other business interests that are inconsistent with ours. Although we do not own a majority of Rothera’s equity interests and Rothera’s day-to-day operations are conducted by its management team, we designate the majority of the members of its board of directors which exercises governance control over Rothera, and thus consolidate the financial results of 43 Table of Contents Rothera and its subsidiaries into our consolidated financial statements. As a result, any failure by Rothera or its subsidiaries to operate effectively, comply with applicable laws or regulations, maintain adequate internal controls, manage liquidity or capital requirements, or successfully execute their business strategy, could adversely affect our business, financial condition, results of operations, and reputation. We currently operate in certain international markets and plan to further expand our international operations, which exposes us to significant new risks, and our international expansion efforts might not succeed. We currently only offer select services to the public outside the U.S. in certain jurisdictions, including brokerage and futures services in the U.K. through RHUK, crypto and brokerage services in the EU, through RHEU, and our Robinhood Wallet, which is available in over 150 countries and offered through our Cayman Islands subsidiary, Robinhood Non-Custodial Ltd. In addition, Bitstamp, which we acquired in June 2025 and expect to help accelerate our international growth, currently has entities operating internationally in the U.K., EU, Singapore, and the British Virgin Islands, and also offers services in other countries globally. We intend to continue expanding our operations outside of the U.S. International expansion requires significant resources and management attention and subjects us to additional regulatory, economic, operational, and political risks on top of those we already face in the U.S. There are significant risks and costs inherent in establishing and doing business in international markets, including: • difficulty establishing and managing international entities, offices, and/or operations and the increased operations, travel, infrastructure, and legal and compliance costs associated with operations, entities, and/or people in different countries or regions; • the need to understand, interpret and comply with local laws, regulations and customs in multiple jurisdictions, including laws and regulations governing cryptocurrency-related, credit, payments services, derivatives, broker-dealer, money transmitter, or regulated entity practices, some of which do or might require permissions, registrations, authorizations, licenses or consents, or are or might be different from, or conflict with, those of other jurisdictions or foreign cybersecurity, data privacy or labor and employment laws; • the additional complexities of any merger or acquisition activity internationally, which could subject us to additional regulatory scrutiny, approvals, obligations, costs and penalties or risk; • the need to adapt, localize, and position our products for specific countries (also known as “product-market fit”); • increased exposure to foreign fraud vectors; • increased competition from local providers of similar products and services; • challenges of obtaining, maintaining, protecting, defending and enforcing intellectual property rights abroad, including the challenge of extending or obtaining third-party intellectual property rights to use various technologies in new countries; • the need to offer customer support and other aspects of our offering (including websites, articles, blog posts, and customer support documentation) in various languages or locations; • compliance with anti-bribery and anti-corruption laws, such as the FCPA and equivalent AML and sanctions rules and requirements in local markets, by us, our employees, and our business partners; • the need to recruit and manage staff in new countries and regions to support international operations, and comply with employment law, tax, payroll, and benefits requirements in multiple countries; 44 Table of Contents • the need to enter into new business partnerships with third-party service providers in order to provide products and services in the local market, or to meet regulatory obligations; • varying levels of internet technology adoption and infrastructure, and increased or varying network and hosting service provider costs and differences in technology service delivery in different countries; • fluctuations in currency exchange rates, inflation, and tariffs and trade policy shifts could limit our ability to operate efficiently across or within borders, and the requirements of currency control regulations, which might restrict or prohibit conversion of other currencies into U.S. dollars; • double taxation of our international earnings and potentially adverse tax consequences due to requirements of or changes in the income and other tax laws of the U.S. or the international jurisdictions in which we operate; and • political or social change or unrest or economic instability in a specific country or region in which we operate. We have limited experience with international legal and regulatory environments and market practices, and we might not be able to enter, penetrate or successfully operate in the markets we choose. In addition, we might incur significant expenses as a result of our international expansion, and we might not be successful, which could lead to substantial losses. We are exposed to funding transaction losses due to reversals or insufficient funds. Some of our products and services are paid for by electronic transfer from customers’ bank accounts which exposes us to risks associated with reversals and insufficient funds. Unwinding of funds transfers due to reversals, and insufficient funds could arise from fraud, misuse, unintentional use, settlement delay, or other activities. Also, criminals are using increasingly sophisticated methods to engage in illegal activities, such as counterfeiting and fraud. If we are unable to collect and retain such amounts from the customer, or if the customer refuses or is unable, due to bankruptcy or other reasons, to reimburse us, we bear the loss for the amount of the chargeback, refund, or return. While we have policies and procedures designed to manage and mitigate these risks, we cannot be certain that such processes will be effective. Our failure to limit returns, including as a result of fraudulent transactions, could lead payment networks or our banking partners to require us to increase reserves, impose penalties on us, charge additional or higher fees, or terminate their relationships with us. These risks may be amplified as we continue to expand our operations internationally and increase our exposure to foreign fraud vectors. Our working model, which allows a subset of our employees to work remotely, subjects us to heightened operational risks. We currently have a large segment of employees who work remotely and are not required to come into the office on a daily basis. Allowing employees to work remotely subjects us to heightened operational risks. For example, technologies in our employees’ homes might not be as robust or effective as in our offices and could lead to lower productivity and/or increased vulnerability to cybersecurity attacks or other privacy or data security incidents. There is no guarantee that the data security and privacy safeguards we have put in place will be completely effective or that we will not encounter risks associated with employees accessing company data and systems remotely. Additionally, in June 2024 FINRA’s new Residential Supervisory Location Designation Rule became effective, under which the homes of certain of our employees who work remotely could be treated as “residential supervisory locations” subject to inspections on a regular periodic schedule, which in turn has required certain operational changes and compliance adjustments. Non-compliance with the Residential Supervisory Location Designation Rule could subject us to fines, penalties or enforcement actions. We also face 45 Table of Contents challenges due to the need to operate with a dispersed and remote workforce, as well as increased costs related to business continuity initiatives. Allowing for remote work has in the past made and may continue to make it more difficult for us to preserve our corporate culture of innovation and our employees might have decreased opportunities to collaborate in meaningful ways. Further, we cannot guarantee that requiring a subset of employees to work in-office, or allowing certain employees to continue to work remotely, will not have a negative impact on employee morale or productivity. Any failure to overcome the challenges presented by our working model could harm our future success, including our ability to retain and recruit personnel, innovate and operate effectively, maintain product development velocity, and execute on our business strategy. Risks Related to Regulation and Litigation Our business is subject to extensive, complex and changing laws and regulations, and related regulatory proceedings and investigations. Changes in these laws and regulations, or our failure to comply with these laws and regulations, could harm our business. We are subject to a wide variety of local, state, federal, and international laws, regulations, licensing schemes, and industry standards in the U.S., the U.K., the EU, the United Arab Emirates, Singapore, the British Virgin Islands, and in other countries and regions in which we operate. These laws, regulations, and standards govern numerous areas that are important to our business, and include, or might in the future include, those relating to all aspects of financial services, the securities and futures markets, investment advisory, investment companies, money transmission, the origination, marketing, servicing, and collection of consumer debt, foreign exchange, payments services and products (such as payment processing, settlement services, and credit cards), cryptocurrency (including crypto-asset perpetuals), derivatives, trading in shares and fractional shares, fraud detection, consumer protection, AML, escheatment, sanctions regimes and export controls, data privacy, data protection, data security, as well as climate risk and environmental impact, including with respect to disclosure of GHG emissions and other metrics related to climate change. The substantial costs and uncertainties related to complying with these laws and regulations continue to increase, and our introduction of new products or services, expansion of our business into new jurisdictions or subindustries, acquisitions of other businesses that operate in similar regulated spaces, or other actions that we may take might subject us to additional laws, regulations, or other government or regulatory scrutiny. For example, after announcing in March 2024 the launch of the Robinhood Gold Card, which is offered through Robinhood Credit exclusively to Robinhood Gold Subscribers and provides rewards via the Robinhood Gold Credit Card Rewards Program, we received requests for information from the MSD related to the Robinhood Gold subscription service and the Robinhood Gold Card. Regulations are intended to ensure the integrity of financial markets, to maintain appropriate capitalization of broker-dealers and other financial services companies, and to protect customers and their assets. These regulations could limit our business activities through capital, customer protection, and market conduct requirements, as well as restrictions on the activities that we are authorized to conduct. We operate in highly regulated industries and, despite our efforts to comply with applicable legal requirements, like all companies in our industries, we must adapt to frequent changes in laws and regulations, and face complexity in interpreting and applying evolving laws and regulations to our business, heightened scrutiny of the conduct of financial services firms and increasing penalties for violations of applicable laws and regulations. We might fail to establish and enforce procedures that comply with applicable legal requirements and regulations. We might be adversely affected by new laws or regulations, changes in the interpretation of existing laws or regulations, or more rigorous enforcement. Furthermore, the U.S. Congress continues to consider potential legislation relating to digital assets and cryptocurrencies. For example, on July 17, 2025, the House of Representatives passed the CLARITY Act, which seeks to provide for a system of regulation of the offer and sale of digital assets by the SEC and CFTC and establish a provisional registration regime. The CLARITY Act is currently under consideration by the U.S. Senate, where the Senate Committee on Banking, Housing, and Urban Affairs released preliminary discussion drafts on July 22, 2025, September 5, 2025, and January 12, 2026, of its proposed “Digital Asset Market Clarity Act” that builds upon the CLARITY Act. On January 29, 2026, the Senate 46 Table of Contents Committee on Agriculture, Nutrition, and Forestry voted in favor of advancing its proposed “Digital Commodity Intermediaries Act,” which likewise builds upon the CLARITY Act. Additionally, on July 18, 2025, the President signed into law the GENIUS Act, which establishes a federal regulatory framework for “payment stablecoins” and their issuers, as well as contemplates scope for state-only regulation. If the CLARITY Act or any of the related bills discussed above are enacted, or as the GENIUS Act is implemented, we could be required to make significant operational changes and incur increased compliance costs. Our ability to offer certain products may also be impacted by actions taken by government regulators. Regulators have requested and, in the future, could request or require us to cease offering specific products or services. Such regulatory actions have led, and in the future could lead, to the suspension or termination of product offerings, which have resulted, and may in the future result in increased compliance costs, financial losses and negative publicity. For example, after the U.S. District Court for the District of Nevada denied our motion for a preliminary injunction on November 25, 2025, we agreed to cease offering new sports-related event contracts in Nevada as of December 1, 2025, and to take action to explore unwinding longer-duration open sports-related event contracts in Nevada. For additional information, refer to Note 15 - Commitments & Contingencies to our consolidated financial statements in this Annual Report. Broker-Dealer, FCM, Investment Adviser, and Insurance Regulations As broker-dealers, our U.S. based subsidiaries RHF, RHS, and TradePMR are subject to extensive regulation by federal and state regulators and SROs and are subject to laws and regulations covering all aspects of the securities industry. Similarly, our broker-dealer subsidiary in the U.K., RHUK, is subject to comprehensive regulation by the FCA, including the Consumer Duty which establishes standards requiring regulated firms to, among other things, deliver good outcomes for retail customers. This includes outcomes relating to products and services, price and value, consumer understanding, and consumer support. Our TradePMR insurance agency subsidiary is subject to regulation by state insurance regulators. Federal and state regulators (and, in the case of RHUK, the FCA), and SROs, including the SEC and FINRA, can, among other things, investigate, censure or fine us, issue cease-and-desist orders or otherwise restrict our operations, require changes to our business practices, products or services, limit our acquisition activities or suspend or expel a broker-dealer or any of its officers or employees. We also might be adversely affected by other regulatory changes related to our obligations with regard to suitability of financial products, supervision, sales practices, application of fiduciary or best interest standards (including the interpretation of what constitutes an “investment recommendation” for the purposes of the SEC’s “Regulation Best Interest” and state securities laws) and best execution in the context of our business and market structure, any of which could limit our business, increase our costs and damage our reputation. Our subsidiary RHD, which is registered with the CFTC as a FCM, is also subject to extensive regulation by federal and state regulators and SROs related to offering our customers Futures products. Rothera E&C, a subsidiary of the Rothera joint venture, is also registered with the CFTC and operates as a regulated DCM, DCO and SEF and is similarly subject to extensive regulation. Similarly, state attorneys general and other state regulators, including state securities and financial services regulators, can bring legal actions on behalf of the citizens of their states to assure compliance with state laws. In addition, criminal authorities such as state attorneys general or the DOJ may institute civil or criminal proceedings against us for violating applicable laws, rules, or regulations. Our subsidiaries, RAM and RHV are registered as investment advisers with the SEC under the Advisers Act. The Advisers Act mandates a variety of requirements for RIAs, including fiduciary duties, record-keeping, operational protocols, and disclosure obligations. The Advisers Act grants regulatory bodies such as the SEC significant administrative authority to govern investment advisory firms. If the SEC or other government agencies determine that RAM or RHV have not complied with relevant laws or regulations, they can impose fines, suspend registrants and individual employees, or enact other sanctions, which may include revoking RAM’s and RHV’s registrations under the Advisers Act. Money-Transmitter Regulation As money transmitters, certain of our subsidiaries are subject to regulation, primarily at the state level. We are also subject to regulation by the Consumer Financial Protection Bureau (“CFPB”). We have obtained or are in the process of obtaining licenses to operate as a money transmitter (or as another type of regulated financial services institution, as applicable) at the federal level and in the states where this is 47 Table of Contents required. As a licensed money transmitter, we are subject to obligations and restrictions with respect to the movement of customer funds, reporting requirements, bonding requirements, and inspection by state regulatory agencies concerning those aspects of our business considered money transmission. Evaluation of our compliance efforts, as well as the questions of whether and to what extent our products and services are considered money transmission, are matters of regulatory interpretation and could change over time. There are substantial costs and potential product and operational changes involved in maintaining and renewing these licenses, certifications, and approvals, and we could be subject to fines, other enforcement actions, and litigation if we are found to violate any of these requirements. There can be no assurance that we will be able to (or decide to) continue to apply for or obtain any such licenses, renewals, certifications, and approvals in any jurisdictions. In certain markets, we might rely on local banks or other partners to process payments and conduct foreign currency exchange transactions in local currency, and local regulators might use their authority over such local partners to prohibit, restrict, or limit us from doing business. The need to obtain or maintain these licenses, certifications, or other regulatory approvals could impose substantial additional costs, delay or preclude planned transactions, product launches or improvements, require significant and costly operational changes, impose restrictions, limitations, or additional requirements on our business, products, and services, or prevent us from providing our products or services in a given market. Certain Non-U.S. Regulations As investment firms and crypto-asset service providers, our subsidiaries RHEU, Bitstamp Europe S.A., Bitstamp Financial Services Ltd., Bitstamp Asia Pte. Ltd., and Bitstamp UK Limited are subject to extensive regulation by regulators in Lithuania, Luxembourg, Slovenia, Singapore, and the U.K., respectively. Specifically, our subsidiaries, RHEU and Bitstamp Europe S.A., are licensed crypto asset service providers under MiCA, the provisions of which went into effect as of December 30, 2024. Among other provisions, MiCA introduces a comprehensive authorization and compliance regime for crypto-asset service providers, including requirements related to governance, reserves, capital, asset safeguarding, segregation and security. In addition, our subsidiaries, RHEU and Bitstamp Financial Services Ltd., are licensed under MiFID to provide brokerage, multilateral trading facilities and/or investment advisory services. Compliance with MiFID imposes extensive regulatory requirements on our operations in the EU, including obligations related to client classification, product governance, transaction reporting, and best execution standards. As a result of holding both MiCA and MiFID licenses, we are subject to comprehensive regulation covering virtually all financial and crypto activities within the EU. This dual licensing framework subjects us to broad and evolving supervisory regimes governing traditional financial instruments, crypto-assets, client protections, disclosure obligations, and operational standards. As we continue to evaluate and align our licensing and supervisory frameworks in the EU, including assessing the optimal structure for our MiCA and MiFID entities, we will face periods of overlapping or evolving regulatory oversight, which could result in increased compliance costs, operational burdens, and extended approval timelines in connection with any changes. Certain of our subsidiaries, including Bitstamp Asia Pte. Ltd. and Bitstamp UK Limited, are registered or regulated in a number of other foreign jurisdictions and subject to oversight by the applicable regulators, including the MAS and the FCA. These regulatory frameworks generally impose ongoing compliance requirements related to customer due diligence, AML, transaction monitoring, reporting and governance. Maintaining and renewing any of these licenses, qualifications and approvals could impose substantial costs, delay or preclude planned expansions of business activities, require significant and costly operational changes, impose restrictions, limitation or additional requirements on our business, products and services, or prevent us from providing our products or services in any given market. In addition, we could be subject to fines, enforcement actions and litigation if we are found to violate any of the requirements of such licenses, qualifications and approvals. There can be no assurance that we will be able to (or decide to) continue to apply for or obtain any such licenses, renewals, qualifications and approvals in any jurisdictions. We have been subject to regulatory investigations, actions, and settlements and we expect to continue to be subject to such proceedings in the future, which could cause us to incur substantial costs or require us to change our business practices in a materially adverse manner. 48 Table of Contents From time to time, we have been and currently are subject, and, given the highly regulated nature of the industries in which we operate, we expect that we will be subject in the future, to a number of legal and regulatory examinations and investigations arising out of our business practices and operations, conducted by the DOJ, SEC, FINRA, the CFTC and the NFA or other SROs or federal agencies such as OFAC, FinCEN, the FDIC or CFPB, state regulatory agencies, such as the MSD, the CAGO, the NYDFS, and international regulatory agencies, such as the U.K.’s FCA, Luxembourg’s Commission de Surveillance du Secteur Financier, Slovenia’s Agencija za trg vrednostnih papirjev, the MAS, and the Bank of Lithuania, among other authorities. These examinations and investigations have in some instances in the past and might in the future lead to lawsuits, arbitration claims, and enforcement proceedings, as well as other actions and claims, that result in injunctions, fines, penalties, and monetary settlements. For example: • In connection with the Early 2021 Trading Restrictions, we and our employees, including our CEO, Vladimir Tenev, have received requests for information, and in some cases, subpoenas and requests for testimony from the USAO, the DOJ, Antitrust Division, the SEC Staff, FINRA, the New York Attorney General’s Office, other state attorneys general offices, and a number of state securities regulators. Also, a related search warrant was executed by the USAO to obtain Mr. Tenev’s cell phone. We received inquiries from the SEC’s Division of Examinations and Division of Enforcement and FINRA related to employee trading during the week of January 25, 2021 in some of the securities that were subject to the Early 2021 Trading Restrictions, including GameStop Corp. and AMC Entertainment Holdings, Inc., and specifically as to whether any employee trading in these securities may have occurred after the decision to impose the Early 2021 Trading Restrictions and before the public announcement of the Early 2021 Trading Restrictions on January 28, 2021. On January 10, 2025, SEC Enforcement advised us in writing that it had closed its investigation into the Early 2021 Trading Restrictions and any contemporaneous employee trading issues. On March 6, 2025, we resolved FINRA’s investigations into the Early 2021 Trading Restrictions and employee trading issues. • In January 2024, we settled a matter with the MSD related to supervision of certain product features and marketing strategies, the service outages on our U.S. stock trading platform on March 2-3, 2020 and March 9, 2020 (the “March 2020 Outages”), and our options trading approval process, as well as the November 2021 Data Security Incident, under which we paid a $7.5 million fine and engaged an independent consultant to review, among other things, implementation of the FINRA independent consultant’s recommendations, policies and procedures regarding certain application features, and cybersecurity measures. • In August 2024, we settled a matter with the CAGO related to, among other things, certain disclosures by RHC and delivery of customers’ cryptocurrency assets under California Corporations Code Sections 29520 and 29505 during the period January 2018 through April 2022. We paid a monetary penalty of $3.9 million. • In January 2025, we settled multiple matters with the SEC (including investigations into Regulation SHO, the timeliness of our broker-dealers’ SAR filings, EBS submissions, various brokerage recordkeeping issues, the November 2021 Data Security Incident, and Regulation S-ID violations) in which RHF and RHS paid penalties totaling $45 million, and agreed to certain undertakings (together, the “January 2025 SEC Settlement”). • In March 2025, we settled multiple matters with FINRA (including investigations into RHF’s historical practice of collaring market orders, CIP, use of certain social media influencers, delivery of certain regulatory required documents to customers, and origin code designations for professional customers; RHS’s supervision of its clearing system technology, improper rejection of certain ACATS requests, improper effectuation of trades in securities during trading halts, execution of trades during extraordinary market volatility at prices that were above or below specified price bands, and the maintenance and reporting of inaccurate or incomplete trade, order, and position data to FINRA, FINRA TRF, CAT, Central Repository, and the OCC; and both broker-dealers’ AML programs, registration of required personnel, and supervision of trading in associated persons’ brokerage accounts) (together, the “March 2025 FINRA Settlement”). RHF 49 Table of Contents and RHS paid a penalty totaling $26 million, and agreed to pay restitution of approximately $3.76 million to customers plus interest and certain undertakings. These and other proceedings, some of which are described in Note 15 - Commitments & Contingencies to our consolidated financial statements in this Annual Report, have in the past and might in the future relate to broker-dealer, derivatives, investment adviser, credit card, cryptocurrency, and financial services rules and regulations, including our trading and supervisory policies and procedures, our clearing and routing practices, our trade reporting, our public communications, our compliance with FINRA registration requirements, AML and other financial crimes regulations, cybersecurity matters, a particular cryptocurrency’s status as a “security,” and our licensing status, among other topics. These sorts of proceedings, inquiries, examinations, investigations, and other regulatory matters have in the past and might in the future subject us to fines, penalties, and monetary settlements, harm our reputation and brand, require substantial management attention, result in additional compliance requirements, result in certain of our subsidiaries losing or being unable to obtain their regulatory licenses or losing their ability to conduct business in some jurisdictions (which could, among other things, result in statutory disqualification by FINRA and the SEC), increase regulatory scrutiny of our business, restrict our operations or require us to change our business practices, require changes to our products and services, require changes in personnel or management, delay planned product or service launches or development, limit our ability to acquire other complementary businesses and technologies, or lead to the suspension or expulsion of our other regulated subsidiaries or their officers or employees. In connection with litigation settlements, we have in the past and might in the future be required to make expenditures to enhance our compliance activities. For example, in connection with the August 2022 NYDFS settlement, we engaged an independent consultant to perform a comprehensive evaluation of our compliance program and remediation efforts with respect to identified deficiencies and violations. The independent consultant completed its evaluation and made recommendations to implement enhancements in certain areas identified in the settlement, which required significant effort to implement. Additionally, while we offer select services and products in certain countries outside the U.S., we are not currently licensed, authorized, or registered in every jurisdiction (and in some cases are not licensed in every state). Under the terms of our customer agreements, we currently offer services only to citizens and permanent residents with a legal address within those jurisdictions where we are authorized and registered, and our application includes features designed to block access to our services from unauthorized jurisdictions. However, to the extent a customer accesses our application or services outside of jurisdictions where we have obtained required governmental licenses and authorization, we face a risk of becoming subject to regulations in that local jurisdiction. A regulator’s investigation as to whether, or conclusion that we are servicing customers in its jurisdiction without being appropriately licensed, registered, or authorized has in the past and could in the future result in fines or other enforcement actions or settlements. For example, in December 2024, we were required to pay fines and entered into consent orders with the Nebraska Department of Banking and Finance and the Massachusetts Division of Banks in connection with prior unlicensed activity. Previous statements by lawmakers, regulators and other public officials have signaled an increased focus on new or additional regulations that could impact our business and require us to make significant changes to our business model and practices. Various lawmakers, regulators and other public officials have previously made statements about our business and that of other broker-dealers signaling an increased focus on new or additional laws or regulations that, if acted upon, could impact our business. For instance, the former SEC Chair previously indicated that he had instructed the SEC Staff to study, and in some cases make rulemaking recommendations to the SEC, relating to, or had otherwise discussed the following, among other topics: PFOF, digital engagement practices, and whether broker-dealers are adequately disclosing their policies and procedures around potential trading restrictions; whether margin requirements and other payment requirements are sufficient; whether broker-dealers have appropriate tools to manage their liquidity and risk; conflicts that can arise from the use of predictive analytics, in particular conflicts that may arise to the extent advisors or brokers are optimizing their own interests as well as others; the use of mobile app features such as rewards, bonuses, push notifications and other prompts and that such prompts could 50 Table of Contents promote behavior that is not in the interest of the customer, such as excessive trading, and whether expanded enforcement mechanisms are necessary; and digital engagement practices. Although the SEC, under the current administration, withdrew certain notices of proposed rulemaking that were issued under the former SEC Chair, if the SEC enacts similar rules in the future, whether in this current or future administration, such rules could impose additional regulatory requirements on our business and operations and could require us to make significant changes to our business model and practices. Additionally, from time to time, we have received requests from regulators, including from the SEC, regarding our collection and uses of customer data and related disclosures. In addition, in 2022, FINRA issued a regulatory notice requesting comment on complex products and options including “whether the current regulatory framework…is appropriately tailored to address current concerns raised by complex products and options.” If FINRA amends its rules to impose additional requirements on firms with respect to determining customer eligibility and/or suitability to trade options, such rule changes could result in fewer Robinhood customers being approved to trade options which could negatively impact our options trading volumes and associated revenues. Also, in September 2021, FINRA announced that it is reviewing firms’ use of social media marketing, including social media influencers, which is a marketing channel that we actively utilize. In February 2022, FINRA opened an investigation into our use of social media marketing, which we resolved as part of the March 2025 FINRA Settlement. In February 2023, FINRA provided updated guidance about firms’ practices related to their acquisition of customers through social media channels, as well as firms’ sharing of customers’ usage information with affiliates and non-affiliated third parties. In light of this updated guidance, we narrowed the scope of our social media influencer and affiliate publisher programs. Any additional limits that FINRA might impose on our use of this marketing channel could make it more difficult for us to attract new customers, resulting in slower growth. To the extent that the SEC, FINRA, or other regulatory authorities or legislative bodies adopt additional regulations or legislation in respect of any of these areas or relating to any other aspect of our business, we could face a heightened risk of potential regulatory violations and could be required to make significant changes to our business model and practices, which changes might not be successful. Any of these outcomes could have an adverse effect on our business, financial condition and results of operations. We are involved in numerous litigation matters that are expensive and time consuming, and, if resolved adversely, could expose us to significant liability and reputational harm. In addition to regulatory proceedings, we are also involved in numerous other litigation matters, including putative class action lawsuits, and we anticipate that we will continue to be a target for litigation in the future. Potential litigation matters include commercial litigation matters, derivative matters, insurance matters, securities litigation matters, privacy and cybersecurity disputes, intellectual property disputes, contract disputes, consumer protection matters (including gambling loss recovery matters), and employment matters. This risk might be more pronounced during market downturns, during which the volume of legal claims and amount of damages sought in litigation and regulatory proceedings against financial services companies have historically increased. Litigation matters brought against us have in the past and might in the future require substantial management attention and might result in settlements, awards, injunctions, fines, penalties, and other adverse results. A substantial judgment, settlement, fine, penalty, or injunctive relief could be material to our results of operations or cash flows for a particular period, or could cause us significant reputational harm. For more information about the legal proceedings in which we are currently involved, see Note 15 - Commitments & Contingencies to our consolidated financial statements in this Annual Report. We are subject to governmental laws and requirements regarding anti-corruption, anti-bribery, economic and trade sanctions, AML, and counter-terror financing that could impair our ability to compete in international markets or subject us to criminal or civil liability if we violate them. 51 Table of Contents We are required to comply with U.S. economic and trade sanctions administered by OFAC and we have processes in place to facilitate compliance with OFAC regulations. As part of our customer onboarding process, in accordance with the CIP rules under Section 326 of the USA Patriot Act, we screen all potential customers against OFAC watchlists and continue to screen all customers, vendors and employees daily against OFAC watchlists. Although our application includes features designed to block access to our services from sanctioned countries, if our services are accessed from a sanctioned country in violation of trade and economic sanctions, we could be subject to enforcement actions. We are subject to the FCPA, U.S. and foreign bribery laws, and other U.S. and foreign anti-corruption laws. Anti-corruption and anti-bribery laws have been enforced aggressively in recent years and while there may currently be a reduced focus on enforcement in the U.S. in light of a February 2025 Presidential executive order, these laws are interpreted broadly to generally prohibit companies, their employees and their third-party intermediaries from authorizing, offering, or providing, directly or indirectly, improper payments or benefits to recipients in the public sector. These laws also require that we keep accurate books and records and maintain internal controls and compliance procedures designed to prevent any such actions. The failure to comply with any such laws could subject us to criminal or civil liability, cause us significant reputational harm, and have an adverse effect on our business, financial condition, and results of operations. We are also subject to various AML and counter-terrorist financing laws and regulations that prohibit, among other things, our involvement in transferring the proceeds of criminal activities. In the U.S., most of our services are subject to AML laws and regulations, including the Bank Secrecy Act, as amended, and similar laws and regulations. Regulators in the U.S. continue to increase their scrutiny of compliance with these obligations. For example, in August 2022, we settled an NYDFS investigation of our cryptocurrency business related primarily to AML and cybersecurity-related issues, under which we paid a monetary penalty of $30 million and engaged an independent compliance consultant and in January 2025, as part of the January 2025 SEC Settlement, RHF and RHS paid penalties totaling $13 million for violations of the timeliness of our broker-dealers’ compliance with SAR filing requirements from January 2020 through March 2022. Although our operations are currently concentrated in the U.S., we have expanded our operations outside of the U.S. As we have started to expand internationally, we have become subject to additional non-U.S. laws, rules, regulations, and other requirements regarding economic and trade sanctions, AML, and counter-terror financing. In order to comply with applicable laws, we have revised and expanded, and will continue to, revise and expand our compliance program, including the procedures we use to verify the identity of our customers and to conduct ongoing monitoring of our customers and their transactions on our systems, including payments to persons outside of the U.S. The need to comply with multiple sets of laws, rules, regulations, and other requirements could substantially increase our compliance costs, impair our ability to compete in international markets, and subject us to risk of criminal or civil liability for violations. Our ability to offer event contracts is subject to the outcome of currently ongoing and potential future regulatory enforcement actions and litigation, as well as potential changes in federal or state law, that could immediately or subsequently prevent us from offering, or continuing to offer, event contracts. Event contracts, whether offered by us or others, have drawn scrutiny from federal and state regulators and resulted in litigation that we are party to as well as litigation against other companies that offer event contracts. In particular: • After we began to offer certain event contracts in October 2024 related to the U.S. presidential election and in March 2025 related to the annual NCAA college basketball tournaments, we received requests for information and a subpoena from the MSD, respectively. • In February 2025 after we began offering sports-related event contracts tied to the pro football championship, the CFTC formally requested that RHD “not permit customers to access” sports- 52 Table of Contents related event contracts “until staff can complete a review,” leading us to suspend the rollout of that product. After we began offering sports event contracts tied to the annual NCAA college basketball tournaments in March 2025 and provided the CFTC with certain information and documents, the CFTC indicated it lacked a “legal justification” to prevent us from offering access to those event contracts. • In March 2025, the NJDGE issued a letter to RHM demanding that we, among other things, cease and desist from offering sports-related event contracts, which the NJDGE views as unlicensed sports wagering under state law. Other state regulators with authority over sports wagering, including in Ohio and Connecticut, have since sent RHM and/or RHD similar demand letters. • On April 8, 2025, the U.S. District Court for the District of Nevada issued a preliminary injunction in KalshiEx, LLC v. Hendrick, et al. preventing the Nevada Gaming Commission and Nevada Gaming Control Board from enforcing Nevada state laws and pursuing civil or criminal liability against KalshiEx, LLC for offering sports-related event contracts because the Commodity Exchange Act (“CEA”) grants the CFTC exclusive jurisdiction over event contracts that are traded or executed on a designated contract market and the CFTC has impliedly approved the contracts. On November 25, 2025, the court dissolved KalshiEx’s preliminary injunction. KalshiEx has appealed the decision. On February 17, 2026, the Nevada Gaming Control Board filed a civil enforcement suit against KalshiEx seeking injunctive relief to enjoin KalshiEx from offering outcome-based event contracts. KalshiEx has removed the action to federal court. KalshiEx filed for similar injunctive relief in New Jersey, Maryland, Ohio, New York, Connecticut, and Tennessee. On April 28, 2025, the federal district court in the New Jersey lawsuit, KalshiEx LLC v. Flaherty, et al., issued a preliminary injunction against the New Jersey gaming regulators concluding that KalshiEx has demonstrated a likelihood of prevailing on its preemption arguments. The New Jersey gaming regulators have appealed this decision to the Third Circuit Court of Appeals, which heard oral argument in September 2025. The U.S. District Court for the District of Maryland denied KalshiEx’s motion for injunctive relief and KalshiEx has appealed this decision to the Fourth Circuit Court of Appeals. KalshiEx has also been sued by the Massachusetts Attorney General seeking to enforce Massachusetts state gaming laws. On January 20, 2026, the Massachusetts Superior Court granted Massachusetts’ motion for a preliminary injunction. The injunction was issued on February 6, 2026, and an appeal has been noticed. On February 17, 2026, the Massachusetts Appeals Court stayed the injunction pending appeal. In Tennessee, KalshiEx’s motion for a temporary restraining order was granted on January 12, 2026. • On October 14, 2025, the U.S. District Court for the District of Nevada denied motions by North American Derivatives Exchange, Inc. (“Crypto.com”) for a judgment on the pleadings and a preliminary injunction because the Court found Crypto.com’s sports-related event contracts are not “swaps” falling within the CFTC’s exclusive jurisdiction. The district court found that Crypto.com was unlikely to prevail on its argument that the CFTC has exclusive jurisdiction over sports-related event contracts. Crypto.com has appealed the decision to the United States Court of Appeals for the Ninth Circuit. • On January 16, 2026, the Nevada Gaming Control Board filed a civil enforcement action in Nevada state court against Blockratize, Inc. d/b/a Polymarket; QCX LLC d/b/a Polymarket US; and Adventure One QSS, Inc. d/b/a Polymarket (together "Polymarket") seeking injunctive relief to enjoin Polymarket from offering outcome-based event contracts. On January 29, 2026, the Nevada State Court issued a temporary restraining order against Polymarket. On February 5, 2026, Polymarket removed the case to the U.S. District Court for Nevada. • On February 2, 2026, the Nevada Gaming Control Board filed a civil enforcement action in Nevada state court against Coinbase seeking injunctive relief to enjoin Coinbase from offering outcome-based event contracts. On February 4, 2026, Coinbase filed a complaint against Nevada in the U.S. District Court for the District of Nevada seeking to enjoin Nevada's civil enforcement action. On February 5, 2026, the Nevada state court issued a temporary restraining 53 Table of Contents order against Coinbase. On February 7, 2026, the U.S. District Court for Nevada dismissed Coinbase's suit. • On August 19, 2025, RHD filed suits in the U.S. District Court for the District of Nevada and the U.S. District Court for the District of New Jersey seeking injunctive relief similar to the relief sought by KalshiEx. On September 15, 2025, RHD filed suit in the U.S. District Court for the District of Massachusetts seeking similar injunctive relief. New Jersey has agreed to a preliminary injunction pending the outcome of its appeal to the Third Circuit in its litigation with KalshiEx. In Nevada, the court denied RHD’s motion for a preliminary injunction and RHD has appealed the decision to the United States Court of Appeals for the Ninth Circuit. Nevada has agreed to refrain from enforcing its state gaming laws during the pendency of the appeal, subject to certain conditions which included ceasing to offer new sports-related event contracts (absent an injunction pending appeal staying an enforcement action, which RHD has sought from the Ninth Circuit). In Massachusetts, the court initially dismissed RHD’s suit as unripe. RHD moved for reconsideration, and the court granted that motion. Pursuant to the court’s order, RHD filed an amended complaint on January 20, 2026 and renewed its motion for a preliminary injunction. • We are also subject to and have been named as a defendant in lawsuits by private plaintiffs and certain Indian tribes alleging statutory and regulatory violations, including that our sports event contracts constitute illegal sports betting, and seeking, among other things, damages (including under “statute of Anne” laws providing for triple damages) and injunctive relief. In one of those cases, Blue Lake Rancheria v. Kalshi Inc., the U.S. District Court for the Northern District of California denied the plaintiff’s motion for a preliminary injunction prohibiting the trading and execution of sports-related event contracts on tribal lands, finding that the CEA confers exclusive jurisdiction over the regulation of such contracts to the CFTC. The plaintiff has appealed that ruling to the Ninth Circuit Court of Appeals, and briefing is ongoing. The outcome of these cases or new laws or regulations, changes in the interpretation of existing laws or regulations, or more rigorous enforcement in this space could immediately or subsequently prevent us from offering, or continuing to offer, some or all types of event contracts in the future, including in specific states. In particular, additional federal or state courts, including appellate courts, may conclude that state laws attempting to prevent the trading of CFTC-regulated sports-related event contracts are not preempted by the CEA, or that outcome based event contracts are not “swaps” or contracts in excluded commodities falling within the jurisdiction of the CFTC, which would likely require us to cease offering certain event contracts in one or more states (or across all jurisdictions in which we operate) and could lead to adverse litigation and regulatory actions against us for doing so. Any such decision(s) could also result in us becoming subject to various new state-specific regulations relating to or implicating other event contracts, which would further limit our ability to offer access to event contracts within such state(s). Changes in CFTC or other regulatory policy that seek to ban or more heavily regulate event contracts, particularly event contracts that we offer such as those related to sporting events, could also require us to cease offering event contracts or materially impact our ability to offer event contracts and we may be required to cease offering such contracts in one or more jurisdictions in which we operate either immediately or with minimal advanced notice to customers. The CFTC has previously proposed a rule amendment that, if adopted by the CFTC as proposed, would likely have prohibited us from offering sports and election event contracts (similar to the ones we offered in November 2024). While the CFTC withdrew this proposed rule amendment on February 4, 2026, it also announced that it intends to engage in further event contract rulemaking. In the future, the CFTC could also take broader and more expansive actions with respect to these or other event contracts without notice at any time. Further, the tax treatment of event contracts is unclear, and unfavorable interpretations of tax laws or regulations by foreign or U.S. federal or state tax authorities could result in income and other taxes being imposed on Robinhood, our counterparties and our customers. If our ability to offer event contracts (either entirely or in certain categories) in one or more jurisdictions in which we operate is threatened, the perception of our brand may suffer and we may be unable to retain customers, and we may incur significant costs to attempt to continue listing some or all such event contracts. Any of these outcomes could have an adverse effect on our business, financial condition and results of operations. Risks Related to Attracting, Retaining, and Engaging Customers 54 Table of Contents We operate in highly competitive markets, and many of our competitors have greater resources than we do and may have products and services that are more appealing than ours to our current or potential customers. The markets in which we compete are evolving and highly competitive, with multiple participants competing for the same customers. Our current and potential future competition principally comes from incumbent brokerages, established financial technology companies, venture-backed financial technology firms, banks, cryptocurrency exchanges, asset management firms, financial institutions, consumer financial service providers and technology platforms. The majority of our competitors have longer operating histories and greater capital resources than we have and offer a wider range of products and services. Some of our competitors, particularly new and emerging technology companies, are not subject to the same regulatory requirements or scrutiny to which we are subject, which could allow them to innovate more quickly or take more risks, placing us at a competitive disadvantage. The impact of competitors with superior name recognition, greater market acceptance, larger customer bases, or stronger capital positions could adversely affect our results of operations and customer acquisition and retention. Our competitors might also be able to respond more quickly to new or changing opportunities and demands and withstand changing market conditions better than we can, especially larger competitors that might benefit from more diversified product and customer bases. For example, some of our competitors have quickly adopted, or are seeking to adopt, some of our key offerings and services, including commission-free trading, fractional share trading, no account minimums, and IRA match since their introduction on our platforms in order to compete with us. In addition, competitors might conduct extensive promotional activities, offer better terms or offer differentiating products and services that could attract our current and prospective customers and potentially result in intensified competition within our markets. We continue to experience aggressive price competition in our markets, and we might not be able to match the marketing efforts or prices of our competitors. In addition, our competitors might choose to forgo PFOF, which could create downward pressure on PFOF and make it more difficult for us to maintain our PFOF arrangements, which are a significant source of our revenue. We might also be subject to increased competition as our competitors enter into business combinations or partnerships, or established companies in other market segments expand to become competitive with our business. Our ability to compete successfully in the financial services and cryptocurrency markets depends on a number of factors, including, among other things: • maintaining competitive pricing; • providing easy-to-use, innovative, and attractive products and services that are adopted by customers; • retaining customers (such as by providing effective customer support and avoiding outages, security breaches, and trading restrictions); • recruiting and retaining highly skilled personnel and senior management; • maintaining and improving our reputation and the market perception of our brand and overall value; • maintaining our relationships with our counterparties; and • adjusting to a dynamic regulatory environment. Our competitive position within our markets could be adversely affected if we are unable to adequately address these factors. If we fail to retain existing customers or attract new customers, or if our customers decrease their use of our products and services, our revenue will decline. 55 Table of Contents We have experienced customer growth in recent years, including a significant fraction of new customers, often more than 50%, who have told us that Robinhood is their first brokerage account. Our business and revenue growth depends on our efforts to attract new customers, retain existing customers, and increase the amount that our customers use our products and services (including premium services, such as Robinhood Gold). It is particularly important that we retain and engage our most active brokerage customers, who account for a disproportionately large percentage of our brokerage trading volumes. Any erosion of this active customer base would have a disproportionately large negative impact on our revenues, which could cause the trading price of our Class A common stock to decline significantly. Our efforts to attract and retain customers might fail due to a number of factors, including our customers losing confidence in us or preferring a competitor’s offerings. Additional factors that could lead to a decline in our number of customers or their usage of our products and services or that could prevent us from increasing our number of customers include: • a decline in our brand and reputation; • increased pricing for our products and services; • a shift in pricing models, including allowing customers to choose a fee-based model for cryptocurrency orders; • ineffective marketing efforts or a reduction in marketing activity; • certain of our customers, due to being new and inexperienced, might be less loyal to our product or less likely to maintain historical trading patterns and interest in investing; • a broad decline in the equity or other financial markets, which could result in many of these investors feeling discouraged and exiting the markets altogether (as has occurred in connection with prior bear market cycles); • rising inflation resulting in less disposable income for our customers to invest; • our customers experiencing difficulties using the Robinhood app as intended, due to any number of reasons such as design errors, service outages, or trading restrictions imposed by us; • our customers experiencing security or data breaches, account intrusions, or other unauthorized access; • our failure to provide adequate customer service; • customer resistance to and non-acceptance of cryptocurrencies; and • customer dissatisfaction with the limited number of cryptocurrencies available on our platforms or with our ceasing support for cryptocurrencies on our RHC, RHEU, or Bitstamp platforms because they failed our regular listing committee review; and • customer dissatisfaction with the RHC and Bitstamp USA, Inc. platforms removing certain cryptocurrencies because the SEC or a court has asserted or determined that the cryptocurrencies or similar cryptocurrencies are securities. Our customers may choose to cease using our platforms, products, and services at any time, and may choose to transfer their accounts to another broker-dealer. For example, during the first quarter of 2021 many customers became upset by our imposition of the Early 2021 Trading Restrictions and we saw an increase in customers choosing to transfer their accounts to other broker-dealers. If we fail to provide and monetize new and innovative products and services that are adopted by customers, our business may become less competitive and our revenue might decline. 56 Table of Contents Our ability to attract, engage, and retain our customers and to increase our revenue depends heavily on our ability to evolve our existing products and services and to create and monetize new products and services that are adopted by customers. Rapid and significant technological changes continue to confront the financial services industry, including developments in the methods in which securities are traded and developments in cryptocurrencies. To keep pace or to innovate we have introduced and might continue to introduce significant changes to our existing products and services or acquire or introduce new and unproven products and services, including using technologies with which we have little or no prior development or operating experience (for instance, event contracts). Our efforts have been and might continue to be inhibited by industry-wide standards, legal restrictions, incompatible customer expectations, demands, and preferences, or third-party intellectual property rights. Our efforts to innovate have been and might continue to also be delayed or blocked by new or enhanced regulatory scrutiny or technical complications. Incorporating new technologies into our products and services, or realizing the intended benefits of acquisitions of, or investments in, other companies, products or technologies, has required and might continue to require substantial expenditures and take considerable time, and we might not be successful in realizing a return on these efforts in a timely manner or at all. It might be difficult to monetize products in a manner consistent with our brand’s focus on low prices. If we fail to innovate and deliver products and services with market fit and differentiation, or fail to do so quickly enough as compared to our competitors, we might fail to attract and retain customers and maintain customer engagement, causing our revenue to decline. Our international expansion efforts may increase these risks as we expect to adapt our product and service offerings to reflect local regulatory requirements, customer preferences, and other location-specific factors, as discussed in “-Risks Related to Our Business-We currently operate in certain international markets and plan to further expand our international operations, which exposes us to significant new risks, and our international expansion efforts might not succeed.” Risks Related to Our Platforms, Systems, and Technology Our products and services rely on software and systems that are highly technical and have been, and may in the future be, subject to interruption, instability, and other potential flaws due to software errors, design defects, and other processing, operational, and technological failures, whether internal or external. We rely on technology, including the internet and mobile services, to conduct much of our business activity and allow our customers to conduct financial transactions on our platforms. Our systems and operations, including our cloud-based operations and disaster recovery operations, those of the third parties on which we rely to conduct certain key functions, and those of companies we have acquired or may seek to acquire in the future, are vulnerable to disruptions from natural disasters, power and service outages, interruptions or losses, computer and telecommunications failures, software bugs, cybersecurity attacks, computer viruses, malware, distributed denial of service attacks, spam attacks, phishing or other social engineering, ransomware, security breaches, credential stuffing, technological failure, vulnerabilities, human error, terrorism, improper operation, unauthorized entry, data loss, intentional bad actions, and other similar events and we have experienced such disruptions in the past. For example, on October 20, 2025, Amazon Web Services (AWS) experienced a major disruption in its US-EAST-1 region due to a failure in an internal system. This affected certain of our operations, resulting in service instability and interruption. Further, we have in the past and might in the future be particularly vulnerable to any such internal technology failures because we rely heavily on our own self-clearing platform, proprietary order routing system, data platforms, and other back-end infrastructure for our operations, and any such failures could have an adverse effect on our reputation, business, financial condition, and results of operations. Our products and internal systems also rely on software that is highly technical and complex (including software developed or maintained internally and/or by third parties and also including machine learning models) in order to collect, store, retrieve, transmit, manage and otherwise process immense amounts of data. The software on which we rely has in the past contained and might in the future contain errors, bugs, vulnerabilities, design defects, or technical limitations that might compromise our ability to meet our objectives. Some such problems are inherently difficult to detect, and some such problems 57 Table of Contents might only be discovered after code has been released for external or internal use. Media outlets have in the past and might in the future learn of our plans for features by examining hidden but unprotected images and code in publicly available beta versions of our app, resulting in unwanted publicity prior to our intended announcement dates. Such problems might also lead to negative customer experiences (including the communication of inaccurate information to customers), compromised ability of our products to perform in a manner consistent with customer expectations, delayed product introductions, compromised ability to protect data and intellectual property, or an inability to provide some or all of our services. While we have made, and continue to make, significant investments designed to correct software errors and design defects and to enhance the reliability and scalability of our platforms and operations, the risk of software and system failures and design defects is always present, we do not have fully redundant systems, and we might fail to maintain, expand, and upgrade our systems and infrastructure to meet future requirements and mitigate future risks on a timely basis. It might become increasingly difficult to maintain and improve the availability of our platforms, especially as our platforms and product offerings become more complex and our customer base grows. For instance, we have needed and will continue to need to have adequate capacity and infrastructure on our platform with respect to the rollout, offering, and settlement of event contracts. We might also encounter technical issues in connection with changes and upgrades to the underlying networks of supported cryptocurrencies. Any number of technical changes, software upgrades, soft or hard forks, cybersecurity incidents, or other changes to the underlying blockchain networks might occur from time to time, causing incompatibility, technical issues, disruptions or security weaknesses to our platforms. If we are unable to identify, troubleshoot, and resolve any such issues successfully, we might no longer be able to support such cryptocurrency, our customers’ assets might be frozen or lost, the security of our hot or cold wallets might be compromised, and our platforms and technical infrastructure might be affected. In addition, surges in trading volume on our platforms have in the past and might in the future cause our systems to operate at diminished speed or even fail, temporarily or for a more prolonged period of time, which would affect our ability to process transactions and potentially result in some customers’ orders being executed at prices they did not anticipate, executed incorrectly, or not executed at all. For example, we experienced (i) the March 2020 Outages, which resulted in some of our customers being unable to buy and sell securities and other financial products on our U.S. trading platform for a period of time, and (ii) the partial service outages and degraded service on our RHC cryptocurrency platform from time to time in mid-April and early May 2021 caused by a surging demand for cryptocurrency trading (the “April-May 2021 Disruptions”), which resulted in some of our customers being unable to buy and sell cryptocurrencies for a period of time. Our platforms have otherwise in the past and might in the future experience outages. The March 2020 Outages resulted in putative class action lawsuits, arbitrations, and regulatory examinations and investigations, as well as cash remediation payments. Disruptions to, destruction of, improper access to, breach of, instability of, or failure to effectively maintain our information technology systems (including our data processing systems, self-clearing platform, and order routing system) that allow our customers to use our products and services, and any associated degradations or interruptions of service could result in damage to our reputation, loss of customers, loss of revenue, regulatory or governmental investigations, civil litigation, and liability for damages. In addition, our customer service team from time to time experiences backlogs responding to customer support requests. These backlogs have compounded when we have experienced any market outages, provider network disruptions, or platform outages or errors, including, for example, in connection with the March 2020 Outages and the April-May 2021 Disruptions, and may compound in the future as a result of such events. Frequent or persistent interruptions, or perceptions of such interruptions whether true or not, in our products and services could cause customers to believe that our products and services are unreliable, leading them to switch to our competitors or to otherwise avoid our products and services. Additionally, our insurance policies might be insufficient to cover a claim made against us by any such customers affected by any disruptions, outages, or other performance or infrastructure problems. Our success depends in part upon continued distribution through app stores and effective operation with mobile operating systems, networks, technologies, products, hardware and standards that we do not control. 58 Table of Contents A substantial majority of our customers’ activity on our platforms occurs on mobile devices. We are dependent on the interoperability of our app with popular mobile operating systems, networks, technologies, products, hardware, and standards that we do not control, such as the Android and iOS operating systems. Any changes, bugs or technical issues in such systems, new generations of mobile devices or new versions of operating systems, or changes in our relationships with mobile operating system providers, device manufacturers or mobile carriers, or in their terms of service or policies that degrade the functionality of our app, reduce or eliminate our ability to distribute applications, give preferential treatment to competitive products, limit our ability to target or measure the effectiveness of applications, or impose fees or other charges related to our delivery of our application could adversely affect customer usage of the Robinhood app. For example, from time to time we have experienced delays in our ability to launch products or update features on our platforms as a result of prolonged app store review processes. Further, we are subject to the standard policies and terms of service of these operating systems, as well as policies and terms of service of the various application stores that make our application and experiences available to our developers, creators and customers. These policies and terms of service govern the availability, promotion, distribution, content and operation generally of applications and experiences on such operating systems and stores. Each provider of these operating systems and stores has broad discretion to change and interpret its terms of service and policies with respect to our platforms and those changes might be unfavorable to us and our customers’ use of our platforms. If we were to violate, or an operating system provider or application store believes that we have violated, its terms of service or policies, that operating system provider or application store could limit or discontinue our access to its operating system or store. Any limitation or discontinuation of our access to any third-party platform or application store could adversely affect our business, financial condition or results of operations. Additionally, in order to deliver a high-quality mobile experience for our customers, it is important that our products and services work well with a range of mobile technologies, products, systems, networks, hardware and standards that we do not control. We need to continuously modify, enhance, and improve our products and services to keep pace with changes in internet-related hardware, mobile operating systems and other software, communication, browser, and database technologies. We might not be successful in developing products that operate effectively with these technologies, products, systems, networks or standards or in bringing them to market quickly or cost-effectively in response to market demands. If our customers choose to not update our app to the latest version, or if it is otherwise difficult for them to access or use our app on their mobile devices, or if they use mobile products that do not offer access to our app, our customer growth and engagement could be adversely affected and our revenues might decline. In addition, if our customers use older versions of our app it may result in customer complaints and regulatory inquiries that could lead to arbitration claims or regulatory sanctions. We rely on third parties to perform some key functions, and their failure to perform those functions could adversely affect our business, financial condition and results of operations. We rely on certain third-party computer systems or third-party service providers, including several cloud technology providers such as AWS (on which we primarily rely to deliver our services to customers on our platforms), internet service providers, payment services providers, market and third-party data providers, regulatory services providers, clearing systems, Liquidity Providers, securities and cryptocurrency exchanges, facilitators of cryptocurrency staking services, alternative trading systems (such as BOATS with respect to Robinhood 24 Hour Market), exchange systems (such as ForecastEx, LLC and KalshiEx LLC, with respect to certain event contracts), banking systems, payment gateways that link us to the payment card and bank clearing networks to process transactions, co-location facilities, communications facilities, and other third-party facilities to run our platforms, facilitate trades by our customers (such as Wells Fargo Clearing Services, LLC for TradePMR customers), provide the technology we use to manage some of our cryptocurrency custody, transfer, and settlement operations and support or carry out some regulatory obligations. In addition, external content providers provide us with financial information, market news, charts, option and stock quotes, cryptocurrency quotes, research reports, and other fundamental data that we provide to our customers. These providers have been and are susceptible to processing, operational, technological and security vulnerabilities, including security breaches, which might impact our business, and our ability to monitor our third-party service providers’ 59 Table of Contents data security is limited. In addition, these third-party service providers might rely on subcontractors to provide services to us that face similar risks. We face a risk that our third-party service providers might be unable or unwilling to continue to provide these services to meet our current needs in an efficient, cost-effective manner or to expand their services to meet our needs in the future. Any failures by our third-party service providers that result in an interruption in service, unauthorized access, misuse, loss or destruction of data or other similar occurrences could interrupt our business, cause us to incur losses, result in decreased customer satisfaction and increase customer attrition, subject us to customer complaints, significant fines, litigation, disputes, claims, regulatory investigations or other inquiries and harm our reputation. Regulators might also hold us responsible for the failures of our providers. For example, after BOATS, the trading venue that primarily supports overnight trading on Robinhood 24 Hour Market (8:00 pm - 4:00 am ET), experienced disruptions during the overnight trading session on August 4-5, 2024, we received requests for information from certain regulators. We continue to incorporate AI technologies into some of our products and processes. These technologies may present business, compliance, and reputational risks. We currently use machine learning and AI to improve our products and processes in certain circumstances, such as to increase the efficiency of our in-app chat support, customer support workflows, fraud detection systems, and software coding optimization, as well as to improve the customer experience in our newsfeed, and we have plans to continue to expand our use of AI in the future. Our research and development of such technology also remains ongoing. As with many new and emerging technologies, AI presents numerous risks and challenges that could adversely affect our business. If we fail to keep pace with rapidly evolving AI technological developments, especially in the financial technology sector, our competitive position and business results may suffer. At the same time, use of AI has recently become the source of significant media attention and political debate. The introduction and use of AI technologies, particularly generative AI, into new or existing offerings may result in new or expanded risks and liabilities, including due to enhanced governmental or regulatory scrutiny, litigation, compliance issues, ethical concerns, confidentiality or security risks, as well as other factors that could adversely affect our business, reputation, and financial results. For example, AI technologies can lead to unintended consequences, including generating content that appears correct but is factually inaccurate, misleading or otherwise flawed, or that results in unintended biases and discriminatory outcomes, which could negatively impact our customers, harm our reputation and business, and expose us to liability. Laws, regulations or industry standards that develop in response to the use of AI may be burdensome or may restrict our ability to use, develop, or deploy AI, particularly generative AI technologies, in our products or processes, or our efforts to expand our business. For example, the EU's AI Act, which became effective on August 1, 2024, governs the development, marketing and use of AI in the EU and could impose significant additional costs on us to comply or significant fines for failing to comply. In the U.S., a patchwork of emerging AI-related laws and regulations could also require us to modify our practices or increase compliance costs. For example, on December 11, 2025, the President issued an executive order to establish a national policy framework for AI intended to preempt state AI laws and regulations. Among other things, the executive order directs the Federal Communications Commission to initiate a proceeding to determine whether to adopt a federal reporting and disclosure standard for AI models, which could impose significant additional costs on us to comply or significant fines for failing to comply. We also use AI technologies from third parties, which may include open source software. If we are unable to maintain rights to use these AI technologies on commercially reasonable terms, we may be forced to acquire or develop alternate AI technologies, which may limit or delay our ability to provide competitive offerings and may increase our costs. These AI technologies also may incorporate data from third-party sources, which may expose us to risks associated with data rights and protection. The legal and regulatory landscape surrounding AI technologies is rapidly evolving and uncertain, including with respect to intellectual property ownership and license rights, cybersecurity, and data protection laws, among others, and has not yet been fully addressed by courts or regulators. The use, development, or adoption of AI technologies into our products may result in exposure to claims by third parties of copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or 60 Table of Contents license fees to third parties. The evolving legal, regulatory and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringing use. Risks Related to Cybersecurity and Data Privacy Our business could be materially and adversely affected by a cybersecurity breach or other attack involving our computer systems or data or those of our customers or third-party or fourth-party service providers. Our systems, including those of companies we have acquired or may seek to acquire in the future, and those of our customers and third-party service providers have been and might in the future be vulnerable to cybersecurity issues. We, like other financial technology organizations, routinely are subject to cybersecurity threats and our technologies, systems, and networks have been and might in the future be subject to attempted cybersecurity attacks. Such issues are increasing in frequency and evolving in nature, including employee and contractor theft or misuse, denial-of-service attacks, and sophisticated nation-state and nation-state-supported actors engaging in attacks. The operation of our platforms involves the use, collection, storage, sharing, disclosure, transfer, and other processing of customer information, including personal data. Security breaches and other security incidents could expose us to a risk of loss or exposure of this information, which could result in potential liability, investigations, regulatory fines, penalties for violation of applicable laws or regulations, litigation, and remediation costs, as well as reputational harm. As the breadth and complexity of the technologies we use and the software and platforms we develop continue to grow, the potential risk of security breaches and cybersecurity attacks increases. Cybersecurity attacks and other malicious internet-based activity continue to increase, and financial technology platform providers have been and expect to continue to be targeted. In light of media attention, we might be a particularly attractive target of attacks seeking to access customer data or assets and have experienced negative publicity in connection with previous security incidents and might in the future experience similar adverse effects relating to real or perceived security incidents, whether or not related to the security of our platforms or systems. We have also received customer complaints and been subject to litigation and regulatory inquiries, examinations, enforcement actions, and investigations by various state and federal regulatory bodies, including the SEC, FINRA, and certain state regulators, including the NYDFS and the New York Attorney General, related to these events. The increasing sophistication and resources of cyber criminals and other non-state threat actors and increased actions by nation-state actors make it difficult to keep up with new threats and could result in a breach of security. Additionally, there is an increased risk that we might experience cybersecurity-related incidents as a result of any of our employees, service providers, or other third parties working remotely on less secure systems and environments. While we take significant efforts to protect our systems and data, including establishing internal processes and implementing technological measures designed to provide multiple layers of security, our safety and security measures might be insufficient to prevent damage to, or interruption or breach of, our information systems, data (including personal data), and operations, such as the November 2021 Data Security Incident. Furthermore, to the extent the operation of our systems relies on our third-party service providers, through either a connection to, or an integration with, third parties’ systems, the risk of cybersecurity attacks and loss, corruption, or unauthorized access to or publication of our information or the confidential information and personal data of customers and employees is increased. Third-party risks include insufficient security measures, data location uncertainty, vulnerabilities and the possibility of data storage in inappropriate jurisdictions where laws or security measures might be inadequate. Our ability to monitor, and our resources to optimize integration with, third-party service providers’ data security practices are also limited. These third-party risks might be exacerbated as our resources are spread across multiple public cloud service providers. Although we generally have agreements relating to cybersecurity and data privacy in place with our third-party service providers, such agreements might not prevent the accidental or unauthorized access to or disclosure, loss, destruction, disablement or encryption of, use or misuse of, or modification of data (including personal data) and/or might not enable us to obtain adequate (or any) reimbursement from our third-party service providers in the event we should suffer any such incidents. 61 Table of Contents For example, in late October 2024, a cyberattack occurred on our Newsroom in which a cyber attacker gained access to our Newsroom website, control of which is subcontracted to a third party vendor, for a limited number of hours. The cyberattack did not result in any unauthorized access of customer information. In addition, in December 2024, a cyberattack occurred at Cyberhaven, a data protection company we utilize as a third-party vendor, creating the potential for attackers to steal sensitive data through a malicious version of a Google Chrome extension. Although we do not believe that this third-party vulnerability impacted us, the attack highlights the growing risk from cybersecurity threats against third-party service providers. Due to applicable laws and regulations or contractual obligations, we could be held responsible for any information security failure or cybersecurity attack attributed to our vendors as they relate to the information we share with them. A vulnerability in a third-party service provider’s software or systems, a failure of our third-party service providers’ safeguards, policies or procedures, or a breach of a third-party service provider’s software or systems has in the past and may in the future result in the compromise of the confidentiality, integrity, or availability of our systems or the data housed in our third-party solutions. Additionally, we could also be exposed to information security vulnerabilities or failures at third parties’ common suppliers or vendors (known as “fourth parties”) that could also impact the security of our data, and we may not be able to effectively directly monitor or mitigate such fourth-party risks, in particular as such risks relate to the use of common suppliers or vendors by the third parties that perform functions and services for us and our limited ability to assess the fourth party’s operational controls. A core aspect of our business is the reliability and security of our platforms. Any unauthorized access to or disclosure, loss, destruction, disablement or encryption of, use or misuse of or modification of data, including personal data, cybersecurity breach or other security incident that we, our customers or our third-party or fourth-party service providers experience or the perception that one has occurred or might occur, could harm our reputation, reduce the demand for our products and services and disrupt normal business operations. In addition, it might require us to expend significant financial and operational resources in response to a security breach, including repairing system damage, increasing security protection costs by deploying additional personnel and modifying or enhancing our protection technologies, investigating, remediating, or correcting the breach and any security vulnerabilities, defending against and resolving legal and regulatory claims, and preventing future security breaches and incidents, all of which could expose us to uninsured liability, increase our risk of regulatory scrutiny, expose us to legal liabilities, including litigation, regulatory enforcement, indemnity obligations, or damages for contract breach, divert resources and the attention of our management and key personnel away from our business operations, and cause us to incur significant costs, any of which could materially adversely affect our business, financial condition, and results of operations. Moreover, our and our third party partners’ efforts to improve security and protect data from compromise has in the past identified and might in the future identify previously undiscovered security breaches or vulnerabilities. There could be public announcements regarding any security incidents or vulnerabilities and any steps we take to respond to or remediate such incidents, and if securities analysts or investors perceive these announcements to be negative, it could have an adverse effect on the trading price of our Class A common stock. While we maintain cybersecurity insurance, our coverage may be insufficient to cover all liabilities resulting from a cybersecurity incident. We cannot be certain that our insurance coverage will be adequate to address the results of regulatory or civil investigations or any liabilities resulting from a cybersecurity incident, that adequate insurance will be available to us on economically reasonable terms, or that our insurer will cover all cybersecurity incident-related claims. The successful assertion of one or more significant claims against us or changes in our cybersecurity insurance coverage, premiums, or deductibles may adversely affect our reputation, business, financial condition or results of operations. We are subject to stringent laws, rules, regulations, policies, industry standards and contractual obligations regarding data privacy and security and might become subject to additional related laws and regulations in jurisdictions into which we expand. Many of these laws and regulations are subject to change and reinterpretation and could result in claims, changes to our business practices, monetary penalties, increased cost of operations, or other harm to our business. 62 Table of Contents We are subject to a variety of federal, state, local, and non-U.S. laws, directives, rules, policies, industry standards and regulations, as well as contractual obligations, relating to privacy and the collection, protection, use, retention, security, disclosure, transfer and other processing of personal data and other data, including the Gramm-Leach-Bliley Act of 1999, Section 5 of the Federal Trade Commission Act and state laws such as the California Consumer Privacy Act, which provides consumers with the right to know what personal data is being collected, know whether their personal data is sold or disclosed and to whom and opt out of the sale of their personal data, among other rights. We also face particular privacy, data security and data protection risks in connection with our expansion into the U.K. and the EU and other jurisdictions in connection with the General Data Protection Regulation, the Digital Operational Resilience Act, the ePrivacy Directive (including its national implementations), and other data protection regulations including but not limited to facing complexity in interpreting, applying, implementing and complying with such regulations. The regulatory framework for data privacy and security worldwide is also evolving and, as a result, interpretation, implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future. New laws, amendments to or reinterpretations of existing laws, regulations, standards and other obligations might require us to incur additional costs and restrict our business operations, and might require us to change how we use, collect, store, transfer or otherwise process certain types of personal data, to implement new processes to comply with those laws and our customers’ exercise of their rights thereunder, and could greatly increase the cost of providing our offerings, require significant changes to our operations, or even prevent us from providing some offerings in jurisdictions in which we currently operate and in which we might operate in the future or incur potential liability in an effort to comply with certain legislation. There is a risk of enforcement actions in response to rules and regulations promulgated under the authority of federal and international agencies and state attorneys general and legislatures and consumer protection agencies. For instance, we have in the past (as discussed in Note 15 - Commitments & Contingencies to our consolidated financial statements in this Annual Report) and may in the future be subject to investigations and examinations regarding, among other things, our cybersecurity practices. In addition, if we fail to follow these security standards, even if no customer information is compromised, we might incur significant fines or experience a significant increase in costs. Following the November 2021 Data Security Incident, we received requests for information from regulatory authorities regarding, among other things, the adequacy of our information security measures, and as part of the January 2025 SEC Settlement, RHF and RHS paid penalties for violating Regulation S-P. Any failure or perceived failure by us or our third-party service providers to comply with our posted privacy policies or with any applicable federal, state or similar foreign laws, rules, regulations, industry standards, policies, certifications or orders relating to data privacy and security, or any compromise of security that results in the theft, unauthorized access, acquisition, use, disclosure, or misappropriation of personal data or other customer data, could result in significant awards, fines, civil and/or criminal penalties or judgments, proceedings or litigation by governmental agencies or customers, including class action privacy litigation in certain jurisdictions and negative publicity and reputational harm, one or all of which could have an adverse effect on our reputation, business, financial condition and results of operations. Risks Related to Our Brokerage Products and Services If we do not maintain the net capital levels required by regulators, our broker-dealer business may be restricted and we may be fined or subject to other disciplinary or corrective actions. The SEC, FINRA, and various state regulators have stringent rules or proposed rules with respect to the maintenance of specific levels of net capital by securities broker-dealers. For example, our broker-dealer subsidiaries are each subject to the SEC Uniform Net Capital Rule, which specifies minimum capital requirements intended to ensure the general financial soundness and liquidity of broker-dealers, and our clearing and carrying broker-dealer subsidiary is subject to Rule 15c3-3 under the Act, which requires broker-dealers to maintain a reserve account to ensure customer securities are protected and accessible, even in cases of firm insolvency. Our failure to maintain the required net capital levels and protect customer assets could potentially result in immediate suspension of securities activities, suspension or expulsion by the SEC or FINRA, restrictions on our ability to expand our existing business or to commence new businesses, and could ultimately lead to the liquidation of our broker-dealer entities 63 Table of Contents and winding down of our broker-dealer business. If such net capital rules are changed or expanded, if there is an unusually large charge against net capital, or if we make changes in our business operations that increase our capital requirements, operations that require an intensive use of capital could be limited. For example, in December 2024, the SEC adopted proposed amendments to Rule 15c3-3, which require certain broker-dealers, including RHS, by June 2026 to increase the frequency with which they perform computations of the net cash they owe to customers and other broker-dealers from weekly to daily. A large operating loss or charge against net capital could have adverse effects on our ability to maintain or expand our business. Our compliance and risk management policies and procedures as a regulated financial services company might not be fully effective in identifying or mitigating compliance and risk exposure in all market environments or against all types of risk. As a financial services company, our business exposes us to a number of heightened risks. We have devoted significant resources to develop our compliance and risk management policies and procedures and will continue to do so, but our efforts might be insufficient. Our previous and continued expanded operations, evolving business, and unpredictable periods of rapid growth make it difficult to predict all of the risks and challenges we might encounter and therefore increase the risk that our policies and procedures for identifying, monitoring, and managing compliance risks might not be fully effective in mitigating our exposure in all market environments or against all types of risk. Further, some controls are manual and are subject to inherent limitations and errors in oversight, which could cause our compliance and other risk management strategies to be ineffective. Other compliance and risk management methods depend upon the evaluation of information regarding markets, customers, catastrophe occurrences, or other matters that are publicly available or otherwise accessible to us, which might not always be accurate, complete, up-to-date, or properly evaluated. Insurance and other traditional risk-shifting tools might be held by or available to us in order to manage some exposures, but they are subject to terms such as deductibles, coinsurance, limits, and policy exclusions, as well as risk of counterparty denial of coverage, default, or insolvency. Any failure to maintain effective compliance and other risk management strategies could have an adverse effect on our business, financial condition, and results of operations. We are also exposed to heightened regulatory risk because our business is subject to extensive regulation and oversight in a variety of areas and geographies, and such regulations are subject to revision, supplementation, or evolving interpretations and application, and it can be difficult to predict how they might be applied to our business, particularly as we introduce new products and services and expand into new jurisdictions. For example, in December 2022, RHF and RHS received investigative requests from the SEC Division of Enforcement regarding their record keeping and preservation practices, including use of personal devices for brokerage communications. RHF and RHS settled the SEC’s investigation into these practices as part of the January 2025 SEC Settlement, paying penalties totaling $8 million and agreeing to complete an internal audit review of electronic communications retention. We are subject to potential losses as a result of our clearing and execution activities. We provide clearing and execution services for our securities brokerage business. Clearing and execution services include the confirmation, receipt, settlement and delivery functions involved in securities transactions. Clearing brokers also assume direct responsibility for the possession or control of customer securities and other assets, the clearing of customer securities transactions and lending money to customers on margin. Self-clearing securities firms are subject to substantially more regulatory control and examination than introducing brokers that rely on others to perform clearing functions. Errors in performing clearing functions, including clerical and other errors related to the handling of funds and securities on behalf of customers, (i) could lead to civil penalties, as well as losses and liability as a result of related lawsuits brought by customers and others and any out-of-pocket costs associated with remediating customers for losses, and (ii) have led to, and could in the future lead to the risk of, fines or other actions by regulators. For example, as part of the January 2025 SEC Settlement, RHS settled investigations with the SEC related to suspicious activity reporting, identity theft protection, unauthorized access to Robinhood systems, off-channel communications, retention of brokerage data, failure to maintain certain templated customer communications, EBS submissions and Regulation SHO in 64 Table of Contents connection with fractional share trading and stock lending, which resulted in RHS paying combined monetary penalties of $33.5 million and agreeing to certain undertakings. Furthermore, as part of the March 2025 FINRA Settlement, RHS resolved multiple matters with FINRA, including RHS’s supervision of its clearing system technology, improper rejection of certain ACATS requests, improper effectuation of trades in securities during trading halts, execution of trades during extraordinary market volatility at prices that were above or below specified price bands, and the maintenance and reporting of inaccurate or incomplete trade, order, and position data to FINRA, FINRA TRF, CAT, and OCC, and RHS’s AML program, registration of required personnel, and supervision of trading in associated persons’ brokerage accounts. RHS, along with RHF, paid a penalty totaling $26 million and agreed to pay restitution and to certain undertakings to resolve these investigations, among others. All customers can place limit orders to buy whole shares of the most traded exchange-traded funds and individual stocks - 24 hours a day, five days a week, through Robinhood 24 Hour Market. Offering U.S. stock trading overnight has heightened risks related to our clearing and execution activities as we do not have previous experience operating or staffing our systems for around-the-clock coverage and may not be able to accurately anticipate the volume of trading activity that will occur outside of regular market hours. Overnight trading on Robinhood 24 Hour Market is primarily supported by BOATS, a trading venue that replicates the role that stock exchanges play during regular market hours. If BOATS becomes unwilling or unable to do business with us or one of our Liquidity Providers in the future, we may be unable to find another trading platform to support Robinhood 24 Hour Market, which could negatively impact our transaction-based revenue and generate negative publicity. Additionally, any disruptions in the services provided by BOATS, whether due to technical malfunctions, operational mishaps, or external factors such as regulatory changes or market volatility, have in the past, and may in the future impair our ability to execute our client's orders. Should BOATS experience downtime or diminished performance (as it has in the past and could again in the future), particularly during overnight trading hours, our ability to execute customer orders through Robinhood 24 Hour Market could be compromised and could have an adverse impact on our business, financial condition, results of operations, and/or brand and reputation. For example, on August 5, 2024, BOATS did not open for overnight trading and as a result, Robinhood customers were unable to execute any trades during that overnight session. Our clearing operations (including for TradePMR customers through TradePMR’s contract with its clearing firm, Wells Fargo Clearing Services, LLC) also require a commitment of our capital and, despite safeguards implemented through both manual and automated controls, involve risks of losses due to the potential failure of our customers or counterparties to perform their obligations under these transactions and margin loans. If our customers default on their obligations, including failing to pay for securities purchased, deliver securities sold, or meet margin calls, we remain financially liable for such obligations, and although these obligations are collateralized, we are subject to market risk in the liquidation of customer collateral to satisfy those obligations. While we have established systems and processes designed to manage risks related to our clearing and execution services, we face a risk that such systems and processes might be inadequate. Any liability arising from clearing and margin operations could have an adverse effect on our business, financial condition and results of operations. In addition, as a clearing member firm of securities and derivatives clearinghouses in the U.S., we are also exposed to clearing member credit risk. Securities and derivatives clearinghouses require member firms to deposit cash, stock and/or government securities for margin requirements and for clearing funds. If a clearing member defaults in its obligations to the clearinghouse in an amount larger than its own margin and clearing fund deposits, the shortfall is absorbed pro rata from the deposits of the other clearing members. Many clearinghouses of which we are members also have the authority to assess their members for additional funds if the clearing fund is depleted. A large clearing member default could result in a substantial cost to us if we are required to pay such assessments. Furthermore, in the event that a significant amount of our customers’ open trades fail to settle, we might be exposed to potential loss of the capital we committed to meet our deposit requirements. Our exposure to credit risk with customers, Liquidity Providers, and other counterparties could result in losses. 65 Table of Contents We extend margin credit and leverage to customers, which are collateralized by customer assets. By permitting customers to engage in margin transactions, we are subject to risks inherent in extending credit. Rapid changes in market conditions or in the trading price of individual securities may cause the value of collateral to fluctuate, potentially resulting in the value of the collateral held by us falling below the amount of a customer’s indebtedness. We also lend and borrow securities in connection with our broker-dealer business. In accordance with regulatory guidelines, we hold cash as collateral when we lend securities, and likewise, we collateralize our borrowings of securities by depositing cash with lenders. Sharp changes in market values of substantial amounts of securities in a short period of time and the failure by parties to the lending or borrowing transactions to honor their commitments could result in substantial losses. Such changes could also adversely impact our capital because our clearing operations require a commitment of our capital and, despite safeguards implemented by our software, involve risks of losses due to the potential failure of our customers to perform their obligations under these transactions and margin loans. We are also exposed to credit risk in our dealings with the Liquidity Providers to which we route cryptocurrency orders. Unlike equities and option trades, cryptocurrency trades do not settle through any central clearinghouses but rather are conducted under bilateral agreements between us and each crypto Liquidity Provider (the risk of the Liquidity Provider’s default therefore falls upon us rather than being distributed among a clearinghouse’s members). The terms of these bilateral agreements vary, but spot transactions are generally aggregated and settled on a net basis once per business day (with the crypto deliveries occurring first and the net cash moving within 24 hours thereafter) and payment obligations are generally unsecured during the interval between delivery and payment. It is not uncommon for us to have an intra-day outstanding net receivable of $100 million that we are owed by any one cryptocurrency Liquidity Provider. Similarly, we routinely have unsecured PFOF receivables from equities and options Liquidity Providers, as well as credit risk from our on-exchange lending and post-trade settlement services. Any payment default by a Liquidity Provider could have adverse effects on our financial condition and results of operations. Our acquisition of Bitstamp has resulted in increased credit risk associated with certain Liquidity Providers, given that some of these firms are also customers of Bitstamp. Additionally, RHD is obligated to establish and maintain an appropriate RITA, which is the amount of RHD’s own capital held in segregation in excess of the amount required to be segregated based on customer positions. RHD also maintains additional firm capital in segregation greater than the established RITA amount, (i.e., excess segregated funds). If the aggregate customer margin deficiency amount on any day exceeds the excess segregated funds amount to the point where RHD breaches its RITA, RHD would be in violation of CFTC rules and would potentially be subject to monetary penalties, sanctions, or other disciplinary actions for failing to maintain an appropriate RITA. As a result of our acquisition of Bitstamp, we now provide additional cryptocurrency products and services to institutional customers both in parts of the U.S. and internationally, including products and services such as retail lending, on-exchange lending, off-exchange settlement, post-trade settlement, and perpetual futures exchange. These offerings to certain institutional clients expose us to risks we have not historically faced at scale, including credit risk. We have policies and procedures designed to manage credit risk, but we face a risk that such policies and procedures might not be fully effective. We regularly update our risk management framework and practices, but eliminating credit risk entirely is difficult. Providing investment advice and recommendations could subject us to investigations, penalties, and liability for customer losses if we fail to comply with applicable regulatory standards, and providing investment education tools could subject us to additional risks if such tools are construed to be investment advice or recommendations. Risks associated with providing investment advice and recommendations include those arising from how we disclose and address possible conflicts of interest, inadequate due diligence, inadequate disclosure, and human error. The Advisers Act and its related rules and interpretations impose a fiduciary duty on our provision of investment advisory services to advisory clients. Other regulations, such as the SEC’s Regulation Best Interest and certain state broker-dealer regulations, impose heightened conduct 66 Table of Contents standards and requirements on recommendations to retail investors. For example, the NASAA (an association of state securities administrators) has adopted amendments to the NASAA model rule regarding Dishonest or Unethical Business Practices of Broker-Dealers and Agents, which are intended to address Regulation Best Interest and other developments in the securities industry. In addition, the SEC and various states have considered or are considering potential regulations or have already adopted certain regulations that could impose additional standards of conduct or other obligations on us to the extent we provide investment advice or recommendations to our customers or use certain covered technologies while communicating with existing or prospective customers. We also provide customers with a variety of educational materials in various jurisdictions, investment tools, and financial news and information, such as our “Snacks” newsletter (which is offered by Sherwood Media), the suite of other editorial offerings that Sherwood Media has launched and will continue to launch, and the Robinhood Investor Index. Additionally, Robinhood Gold Subscribers have access to Robinhood Cortex, which is an AI-powered investing assistant that enhances Robinhood product offerings with tailored insights and information through features such as Digests and customizable market scanners, and stock research reports prepared by our third-party collaborator, Morningstar, Inc. Based on current law and regulations, we believe these services do not constitute investment advice or investment recommendations. If the law were to change or if a court or regulator were to interpret current law and regulations in a novel manner, we face a risk that these services could come to be considered as investment advice. If services that we do not consider to be recommendations (such as educational materials, and our editorial offerings, including Robinhood Snacks) are construed as constituting investment advice or recommendations, we have been and could be in the future subject to investigations by regulatory agencies. For example, in December 2020, the Enforcement Section of MSD filed a complaint against us alleging that a fiduciary conduct standard applies to us under Massachusetts securities law by claiming that certain of our product features and marketing strategies amount to investment recommendations. Changes in law or changes in interpretations of existing law might also require us to modify the nature of these services or discontinue them altogether, one or more of which could have an adverse effect on our ability to attract and retain customers. To the extent our investment education tools, news and information, or digital engagement practices are determined to constitute investment advice or recommendations and to the extent those recommendations fail to satisfy regulatory requirements, or we fail to know our customers, or improperly advise our customers, or if risks associated with advisory services otherwise materialize, we could be found liable for losses suffered by such customers, or could be subject to regulatory fines, penalties, and other actions such as business limitations, any of which could harm our reputation and business. Our wholly-owned subsidiary, RHV, serves as the investment adviser to RVI, a closed-end investment company, which will subject us to additional burdens and risks and could subject us to potential liability. RHV, an investment adviser registered with the SEC under the Advisers Act, serves as the investment adviser to RVI (the “Fund”). The Fund is a recently organized Delaware statutory trust registered under the 1940 Act, as an externally managed, non-diversified, closed-end investment company. RHV is responsible for making investment decisions for the Fund’s portfolio. RHV was formed in August 2025 and has limited investing history. RHV’s service as an investment adviser to the Fund will subject us to additional burdens risks and could subject us to potential liability, including but not limited to: • We will become further subject to additional regulatory and compliance burdens. For example, the Fund is registered under the 1940 Act as an investment company. The Fund and its investment adviser, RHV, are subject to the 1940 Act and the rules thereunder, which, among other things, regulate the relationship between a registered investment company and its investment adviser and their respective affiliates and prohibit or severely restrict principal transactions and joint transactions. 67 Table of Contents • RHV was recently formed and while its personnel have investment experience, RHV and its management have limited experience managing a closed-end investment company registered under the 1940 Act. • RHV or its directors, officers or employees and its affiliates, successors or other legal representatives may be liable for any error of judgment, for any mistake of law or for certain types of acts or omissions by such person. • RHV provides certain investment advisory, management and administrative services to the Fund pursuant to an investment advisory agreement but its provision of those services to the Fund can be terminated without penalty as specified in the investment advisory agreement. In addition, if the investors in the Fund were to be dissatisfied with the investment performance or disagree with investment strategies employed by RHV, they may seek to cause the board of directors of the Fund to terminate its investment management agreement with us or change the terms of such agreement in a manner that is less favorable to us. • The timing and amount of management fees generated by the Fund are uncertain and depend on the success of the Fund’s initial public offering and the Fund’s investment performance. • Shareholder activism involving closed-end funds has increased, including public campaigns to demand that a fund consider significant transactions such as a tender offer, merger or liquidation or seek other actions such as the termination of the fund’s investment management contract. • Investments held by the Fund are illiquid, private investments and thus have no readily ascertainable market prices. The actual results related to any particular investment often vary materially. Because there is significant uncertainty in the valuation of, or in the stability of the value of, illiquid investments, the fair values of such investments as reflected in the Fund’s NAV do not necessarily reflect the prices that would actually be obtained by the Fund when such investments are realized and may contribute to a disconnect between NAV and the market price of the Fund’s shares, volatility in the Fund’s NAV or market price, negative investor perceptions of the Fund’s performance and reduced investor confidence in us or the Fund, which could in turn result in difficulty in raising additional funds, reputational harm, and increased risk of litigation or other claims against us, RHV, or the Fund. • The Fund is subject to conflicts of interest. Our business activities in the management of, or our interest in, our own business and accounts, may present conflicts of interest that could disadvantage the Fund and its shareholders. We provide brokerage services to retail investors that may follow investment programs similar to that of the Fund. RHV and its affiliates will be permitted to market, organize, sponsor, act as general partner or as the primary source for transactions for other pooled investment vehicles and other accounts, which may be offered on a public or private placement basis, and to engage in other investment and business activities. Some of these funds and accounts may have investment strategies that overlap with the investment strategies of the Fund. Such activities may raise conflicts of interest for which the resolution may not be determinable. • If the Fund performs poorly or does not achieve expected returns, investors may decline to invest in any future closed-end funds we may raise or otherwise attribute the Fund’s performance to Robinhood more generally. Any of these additional burdens and risks could subject us to potential liability and could harm our reputation and business. Our provision of brokerage and custodial services to RIAs exposes us to operational, regulatory and reputational risks. 68 Table of Contents Our provision of brokerage and custodial services through TradePMR to RIAs and their clients is subject to extensive federal and state regulation, including oversight by the SEC, FINRA, and applicable state securities regulators. Regulatory changes or enhanced enforcement activity may require significant system changes, and increased compliance resources, which could materially affect our business operations and results of operations. Non-compliance with applicable regulations by us or by TradePMR’s clearing firm, Wells Fargo Clearing Services, LLC, could result in censures, fines, or reputational harm. We rely heavily on proprietary and third-party technology platforms to provide brokerage, custodial, and administrative services. A failure in these systems, including outages, cyberattacks, data breaches, or programming errors, could interrupt our operations or those of our RIA clients, resulting in financial losses, regulatory exposure, or damage to our relationships with advisors and end clients. Possessing client assets and sensitive personal information exposes us to cybersecurity threats and data privacy obligations. A breach of our systems or those of our vendors could result in unauthorized access to confidential information, potentially triggering legal liabilities, regulatory investigations, remediation costs, and reputational harm. Continued investment in information security infrastructure and incident response protocols is necessary to mitigate this risk. We may be subject to regulatory actions, legal claims, and arbitration proceedings arising from the actions or omissions of RIAs to whom we provide custodial support. We provide investment advice to end clients through RAM and RHV, and although we do not provide such investment advice through TradePMR, disputes may nevertheless arise regarding account management, trade execution, or data integrity. Any such claims could result in costly litigation, adverse judgments, or settlements. Our revenue from custodial relationships is largely dependent on assets under custody, cash balances, and the trading activity of advisory clients. Adverse market conditions, rising interest rate volatility, or shifts in client behavior may reduce trading volumes or asset levels, which could negatively impact our fee-based and spread income. Our ability to retain and grow our RIA client base depends in part on our reputation for service quality, platform stability, and regulatory compliance. Negative publicity, including but not limited to negative publicity arising from operational failures, regulatory sanctions, or advisor misconduct, may harm our brand and result in the loss of key relationships or reduced advisor onboarding. Risks Related to Cryptocurrency Products and Services The loss, destruction or unauthorized use or access of a private key required to access any of the cryptocurrencies we hold on behalf of customers could result in irreversible loss of such cryptocurrencies. If we are unable to access the private keys or if we experience a hack or other data loss relating to the cryptocurrencies we hold on behalf of customers, our customers might be unable to trade their cryptocurrency, our reputation and business could be harmed, and we might be liable for losses in excess of our ability to pay. As we expand our cryptocurrency product and service offerings, the risks associated with failing to safeguard and manage cryptocurrencies we hold on behalf of our customers increase. Our success and the success of our offerings require significant public confidence in our ability to properly manage customers’ balances and handle large transaction volumes and amounts of customer funds. Any failure by us to maintain the necessary controls or to manage the cryptocurrencies we hold on behalf of our customers and funds appropriately and in compliance with applicable regulatory requirements could result in reputational harm, significant financial losses, lead customers to discontinue or reduce their use of our services, and result in significant penalties and fines and additional restrictions. We hold all settled cryptocurrencies in custody on behalf of customers in two types of wallets: (i) hot wallets, which are managed online, and (ii) cold wallets, which are managed entirely offline and require physical access controls. With the exception of Bitstamp (discussed below), Robinhood does not utilize third-party custodians for settled cryptocurrencies, but does integrate proprietary technology from a third-party industry-standard vendor into the systems Robinhood uses to support the custody, transfer and 69 Table of Contents settlement operations of its wallets. As noted, Bitstamp does use third party custodians. Failures, problems or issues at these third party custodians could subject Bitstamp to various forms of risk and may have a significant impact on Bitstamp’s business and reputation, which, in turn, could harm Robinhood’s business and reputation more broadly. In general, the overwhelming majority of cryptocurrency coins on our platforms are held in cold storage, though some coins are held in hot wallets to support day-to-day operations. As a public company, we are required to comply with the Sarbanes-Oxley Act of 2002. As part of this, we are required to establish and maintain adequate internal control over financial reporting and evaluate the effectiveness of our internal control over financial reporting (in accordance with guidance issued by the staffs of the SEC’s Office of the Chief Accountant and the Division of Corporation Finance, companies are permitted to exclude acquisitions from their assessment of internal control over financial reporting for the first fiscal year in which the acquisition occurred, and we currently expect to exclude Bitstamp, which we acquired in June 2025, from such assessment for 2025). The effectiveness of Robinhood’s internal control over financial reporting and our financial statements and related notes are audited by Ernst & Young LLP, our independent registered public accounting firm. Under blockchain protocol, in order to access or transfer cryptocurrency stored in a wallet, we need to use a private key. Robinhood maintains backup copies of private keys in multiple separate locations. Bitstamp safeguards its private keys internally and with custodians. We have several layers of cybersecurity defense in place to protect our omnibus wallets. However, to the extent any private keys are lost, destroyed, unable to be accessed by us, or otherwise compromised and all of their backups are lost, we will be unable to access the assets held in the related hot or cold wallet. Further, we cannot provide assurance that any or all of our wallets will not be hacked, exposed, or compromised such that cryptocurrencies are sent to one or more private addresses that we do not control, which could result in the loss of some or all of the cryptocurrencies that we hold in custody on behalf of customers. Any such losses could be significant, and we may not be able to obtain insurance coverage for some or all of those losses. Cryptocurrencies and blockchain technologies have been, and might in the future be, subject to security breaches, hacking, or other malicious activities, including targeted physical attacks. For example, in August 2021, hackers were able to momentarily take over the BSV network, allowing them to spend coins they did not have and prevent transactions from completing. Any exposure or loss of private keys relating to, or hack or other compromise of, the hot wallets or cold wallets we use to store our customers’ cryptocurrencies could result in total loss of customers’ cryptocurrencies (because customers’ cryptocurrency balances are not protected by the SIPC) or adversely affect our customers’ ability to sell their assets, and could result in our being required to reimburse customers for some or all of their losses, subjecting us to significant financial losses. Because many insurance carriers do not provide insurance coverage for crypto-related risks, comprehensive coverage for such events is not readily available on commercially reasonable terms. Our current coverage is limited and may not cover the extent of loss, nor the nature of such loss, in which case we may be liable for the full amount of losses suffered, which could be greater than all of our remaining assets. The total value of cryptocurrencies under our control on behalf of customers is significantly greater than the current total value of insurance coverage that would compensate us in the event of theft or other loss of such assets. Furthermore, the term of our current insurance policy expires in the third quarter of 2026, with our option to renew annually or for the carrier to terminate coverage with advance written notice. Any loss of our insurance coverage would impede our ability to mitigate any losses our customers might suffer if we are unable to access private keys. Additionally, any such security compromises or any business continuity issues affecting our cryptocurrency Liquidity Providers might affect the ability or willingness of our customers to trade or hold cryptocurrencies on our platforms, might result in litigation and regulatory enforcement actions, and could harm customer trust in us and our products generally. The prices of most cryptocurrencies are extremely volatile. Fluctuations in the price of various cryptocurrencies might cause uncertainty in the market and could negatively impact trading volumes of cryptocurrencies, and we may not effectively identify, prevent or mitigate cryptocurrency market risks, any of which would adversely affect the success of our business, financial condition and results of operations. The prices of most cryptocurrencies are based in part on market adoption and future expectations, which might or might not be realized. As a result of these and other factors, the prices of cryptocurrencies are highly speculative. The prices of cryptocurrencies have been subject to dramatic fluctuations 70 Table of Contents (including as a result of prior bear market cycles), which have impacted, and will continue to impact, our trading volumes and operating results and might adversely impact our growth strategy and business. Several factors could affect a cryptocurrency’s price, including, but not limited to: • Global cryptocurrency supply, including various alternative currencies which exist, and global cryptocurrency demand, which can be influenced by the growth or decline of retail merchants’ and commercial businesses’ acceptance of cryptocurrencies as payment for goods and services, the security of online cryptocurrency exchanges and digital wallets that hold cryptocurrencies, the perception that the use and holding of digital currencies is safe and secure, and regulatory restrictions on their use. • Changes in the software, software requirements or hardware requirements underlying a blockchain network, such as a fork. Forks have occurred and are likely to occur again in the future and could result in a sustained decline in the market price of cryptocurrencies. • Changes in the rights, obligations, incentives, or rewards for the various participants in a blockchain network. • The maintenance and development of the software protocol of cryptocurrencies. • Cryptocurrency exchanges’ deposit and withdrawal policies and practices, liquidity on such exchanges and interruptions in service from or failures of such exchanges. • Regulatory measures, if any, that affect the use and value of cryptocurrencies or regulatory or judicial assertions or determinations that certain cryptocurrencies are securities. • Competition for and among various cryptocurrencies that exist and market preferences and expectations with respect to adoption of individual currencies. • Actual or perceived manipulation of the markets for cryptocurrencies. • Actual or perceived connections between cryptocurrencies (and related activities such as mining) and adverse environmental effects or illegal activities. • Social media posts and other public communications by high-profile individuals relating to specific cryptocurrencies, or listing or other business decisions by cryptocurrency companies relating to specific cryptocurrencies. • Expectations with respect to the rate of inflation in the economy, monetary policies of governments, trade restrictions, and currency devaluations and revaluations. While we have observed a positive trend in the total market capitalization of cryptocurrency assets over the long-term, driven by increased adoption of cryptocurrency trading by both retail and institutional investors as well as continued growth of various non-investing use cases, historical trends are not indicative of future adoption, and it is possible that the rate of adoption of cryptocurrencies might slow or decline, which would negatively impact our business, financial condition, and results of operations. While we currently support several cryptocurrencies for trading, market interest in particular cryptocurrencies can also be volatile and there are many cryptocurrencies in the market that we do not support. Our business could be adversely affected, and growth in our net revenue earned from cryptocurrency transactions could slow or decline, if the markets for the cryptocurrencies we support deteriorate or if demand moves to other cryptocurrencies not supported by our platforms. The listing committees of RHC and RHEU conduct regular reviews of the cryptocurrencies available on our platforms to ensure that they continue to meet our requirements under our internal policies and procedures (collectively, the “Crypto Listing Frameworks”) for continued support on our platforms and possess the authority to delist and cease support for any asset based on various factors. Bitstamp also conducts similar reviews of cryptocurrencies available on its platform in accordance with its internal listing 71 Table of Contents procedures and processes. Ceasing support for a cryptocurrency with substantial market interest (or if our consideration to cease supporting such a cryptocurrency becomes known) has in the past exposed, and may continue to expose us to negative attention, adversely impacting our business, including revenue loss from no longer supporting a cryptocurrency or customer reaction to such a decision. For instance, in the past we have encountered an influx of customer complaints related to our decisions to cease support for certain cryptocurrencies. Volatility in the values of cryptocurrencies caused by the factors described above or other factors might impact our regulatory net worth requirements as well as the demand for our services and therefore have an adverse effect on our business, financial condition and results of operations. Although neither our board of directors nor management have to date identified any material gaps or weaknesses with respect to our existing risk management processes and policies in light of recent cryptocurrency market conditions, we remain subject to cryptocurrency market risks. If we are unable to effectively identify, prevent or mitigate such risks, the success of our business, our financial condition and results of our operations may be adversely affected. As part of our overall risk management processes, the ERM team maintains an enterprise wide risk management standard to ensure risks are evaluated in a clear and transparent manner and partners with various front-line risk teams and risk owners across Robinhood to foster consistent risk management practices across Robinhood. In particular, the ERM team provides governance over risk management practices and reports top risks to the Safety Committee, along with planned mitigants and monitoring procedures. The Safety Committee reviews management’s exercise of its responsibility to identify, assess, manage, monitor and mitigate material risks not specifically allocated to the board of directors or another of its committees. In addition to RHM-level processes, entity-level risk teams affiliated with our operating subsidiaries, including one at RHC, perform ongoing risk operations, including risk and control self-assessments and maintaining risk and control registers. As management identifies operational risks, the entity-level risk team tracks the risk drivers and planned mitigating measures and escalates such risks, as needed, to the ERM team. In light of events in 2022, cryptocurrency market risks were identified as a key risk to the Company and management has accordingly implemented certain measures, including enhanced monitoring for cryptocurrency markets (such as reducing net open position limits with liquidity partners through more frequent settlement; adding additional banking and liquidity partners; monitoring on-platform trading activity, coin deposits and withdrawals; and ongoing diligence for listings and banking relationships). The ERM team has also provided quarterly updates to the Safety Committee with respect to such risks and responses. In addition, RHC and RHEU maintain listing committees as described above. In June 2025, we started offering leverage to customers of RHEU and Bitstamp Financial Services Ltd investing in crypto-asset perpetuals. By permitting customers to invest in crypto-asset perpetuals with the use of leverage, both our customers and we are subject to certain risks, especially during periods of extreme volatility in the crypto-asset markets. In the U.S., any particular cryptocurrency’s status as a “security” is subject to a high degree of uncertainty and if we have not properly characterized one or more cryptocurrencies, we might be subject to regulatory scrutiny, investigations, fines, and other penalties. We currently facilitate customer trades for certain cryptocurrencies that we have analyzed under applicable internal policies and procedures and, for cryptocurrencies supported on our RHC and Bitstamp US platforms, that we believe are not securities under relevant U.S. federal and state securities laws. Determining whether any given cryptocurrency is a security is a highly complex, fact-driven analysis, which may change and evolve over time based on changes in the cryptocurrency and its related ecosystem and on evolving legal and regulatory developments. Different parties may reach different conclusions about the outcome of this analysis based on the same facts. The analysis may become clearer depending on the outcome in certain cases currently pending in varying stages of litigation. The SEC Staff has indicated that the determination of whether or not a cryptocurrency is a security depends on the characteristics and use of that particular asset. The SEC, individual Commissioners and the SEC Staff have previously taken positions that certain cryptocurrencies are “securities” in the context of settled or litigated enforcement actions. Although the SEC had not historically provided advance confirmation on 72 Table of Contents the status of any particular cryptocurrency as a security, speeches by senior officials at the SEC have indicated that the SEC generally does not consider Bitcoin or Ether to be securities and Staff of the SEC’s Division of Corporation Finance published statements clarifying that the Division does not view the offers and sales of certain “stablecoins” and “meme coins” to constitute securities transactions. Moreover, SEC Staff have authored informal, non-binding “no-action” letters to the promoters of a handful of digital assets to the effect that the Staff would not recommend enforcement action to the SEC on the basis that transactions in such digital assets, as described to the Staff by their respective promoters, are securities transactions, including with respect to the issuance of tokens in connection with internet and energy decentralized physical infrastructure projects and a consumer finance rewards program. However, such statements and views are not official policy statements by the SEC and reflect only the SEC Staff’s and speakers’ views, which are not binding on the SEC or any court or other agency (including, for instance, the NYDFS, which recently published a consumer alert concerning meme coins that did not opine on whether meme coins constituted securities but warned consumers of the risks of such coins), may be withdrawn at any time without notice or comment by the SEC or its senior officials, cannot be generalized to any other cryptocurrency, and might evolve (including, for instance, recently enacted legislation provides guidelines for the regulation of stablecoins in the U.S., which may differ from the views set forth in the SEC Staff statement regarding stablecoins). With respect to all cryptocurrencies other than Bitcoin and Ether, there is less certainty about whether they would be viewed as securities under the applicable federal and state securities laws. However, on November 12, 2025, SEC Chairman Paul Atkins stated during a speech that it is his view that “most crypto tokens trading today are not themselves securities,” further specifying his view that, subject to certain qualifications, he does not believe certain “digital commodities,” “network tokens,” “digital collectibles,” or “digital tools” constitute securities and that he anticipates the Commission will consider establishing a clear token taxonomy in the coming months. However, such statement is not binding on the SEC or any court or other agency. Additionally, U.S. regulators have expressed concerns about cryptocurrency platforms adding multiple new coins, some of which they may view as unregistered securities. Additionally, the current presidential administration and control of Congress in the U.S. present considerable uncertainty as to cryptocurrency regulations and how regulators will apply the securities laws to cryptocurrencies and what changes Congress may enact with respect to cryptocurrencies. Although our policies and procedures are intended to enable us to make risk-based assessments regarding the likelihood that a particular cryptocurrency could be deemed a security under applicable laws, including federal securities laws, our assessments are not definitive legal determinations as to whether a particular digital asset is a security under such laws. Accordingly, regardless of our conclusions, we could be subject to legal or regulatory action in the event the SEC, a state regulator, or a court were to assert or determine that a cryptocurrency supported by our RHC or Bitstamp US platforms is a “security” under U.S. law. For example, in June 2023, the SEC charged Binance and, separately, Coinbase with operating their respective cryptocurrency trading platforms as unregistered national securities exchanges, brokers, and clearing agencies, also alleging that certain cryptocurrencies supported on their respective platforms are securities. The charges also implicated Coinbase’s staking-as-a-service program and its non-custodial wallet. In November 2023, the SEC brought similar charges against Kraken, alleging that it operated as an unregistered securities exchange, brokerage and clearing agency. In February 2025, March 2025, and May 2025, each of Coinbase, Kraken, and Binance, respectively, entered into a court-approved joint stipulation with the SEC to dismiss each of the SEC’s lawsuits against such parties with prejudice. Several other digital assets market participants, including us, have also announced that the SEC informed them that the SEC was terminating its investigation or enforcement action into their firm. Also, in April 2025, the Office of the Deputy Attorney General issued a memorandum (the “April DOJ Memo”), setting out new enforcement priorities for digital asset-related investigations and prosecutions by the DOJ. The April DOJ Memo directed prosecutors not to “target virtual currency exchanges, mixing and tumbling services, and offline wallets for the acts of their end users or unwitting violations of regulations”. The April DOJ Memo explained that the DOJ will instead prioritize cases against individuals who cause financial harm to digital asset investors and consumers and/or use digital assets in furtherance of other criminal conduct. The decisions by regulators not to bring enforcement actions provides, and any other action, settlement, or related investigation by regulators, might provide, additional guidance on the legal status of cryptocurrencies as securities more generally, which has affected and might significantly affect the actual or perceived regulatory status and value of cryptocurrencies we currently support or might support in the future. On January 21, 2025, the SEC announced that then-Acting Chairman Mark Uyeda “launched a 73 Table of Contents