FULLTEXT DEL 3 AV 4

10-Q – 2026-07-30 – hood-20260630.htm

Föregående del · Dokumentindex · Nästa del

Additionally, in order to deliver a high-quality mobile experience for our customers, it is important that our products and services work well with a range of mobile technologies, products, systems, networks, hardware and standards that we do not control. We need to continuously modify, enhance, and improve our products and services to keep pace with changes in internet-related hardware, mobile operating systems and other software, communication, browser, and database technologies. We might not be successful in developing products that operate effectively with these technologies, products, systems, networks or standards or in bringing them to market quickly or cost-effectively in response to market demands. If our customers choose to not update our app to the latest version, or if it is otherwise difficult for them to access or use our app on their mobile devices, or if they use mobile products that do not offer access to our app, our customer growth and engagement could be adversely affected and our revenues might decline. In addition, if our customers use older versions of our app it may result in customer complaints and regulatory inquiries that could lead to arbitration claims or regulatory sanctions.

We rely on third parties to perform some key functions, and their failure to perform those functions could adversely affect our business, financial condition, and results of operations.

We rely on certain third-party computer systems or third-party service providers, including several cloud technology providers such as AWS (on which we primarily rely to deliver our services to customers on our platforms), internet service providers, payment services providers, market and third-party data providers, regulatory services providers, clearing systems, Liquidity Providers, securities and cryptocurrency exchanges, facilitators of cryptocurrency staking services, the U.S. government and its financial agents, alternative trading systems (such as BOATS, Moon ATS, and Bruce ATS with respect to Robinhood 24 Hour Market), exchange systems (such as ForecastEx, LLC and KalshiEx LLC, with respect to certain event contracts), banking systems, payment gateways that link us to the payment card and bank clearing networks to process transactions, co-location facilities, communications facilities, and other third-party facilities to run our platforms, facilitate trades by our customers (such as Wells Fargo Clearing Services, LLC for TradePMR customers), provide the technology we use to manage some of our cryptocurrency custody, transfer, and settlement operations and support or carry out some regulatory obligations. In addition, external content providers provide us with financial information, market news, charts, option and stock quotes, cryptocurrency quotes, research reports, and other fundamental data that we provide to our customers. These providers have been and are susceptible to processing, operational, technological and security vulnerabilities, including security breaches, which might impact our
105

Table of Contents

business. Our ability to monitor our third-party service providers’ data security is limited. In addition, these third-party service providers might rely on subcontractors to provide services to us that face similar risks.

We face a risk that our third-party service providers might be unable or unwilling to continue to provide these services to meet our current needs in an efficient, cost-effective manner or to expand their services to meet our needs in the future. Any failures by our third-party service providers that result in an interruption in service, unauthorized access, misuse, loss or destruction of data or other similar occurrences could interrupt our business, cause us to incur losses, result in decreased customer satisfaction and increase customer attrition, subject us to customer complaints, significant fines, litigation, disputes, claims, regulatory investigations or other inquiries and harm our reputation. Regulators might also hold us responsible for the failures of our providers. For example, after BOATS, the trading venue that primarily supports overnight trading on Robinhood 24 Hour Market (8:00 pm - 4:00 am ET), experienced disruptions during the overnight trading session on August 4-5, 2024, we received requests for information from certain regulators.

We continue to incorporate AI technologies into some of our products and processes. These technologies may present business, compliance, legal, and reputational risks.

We currently use machine learning and AI to improve our products and processes in certain circumstances, such as to increase the efficiency of our in-app chat support, customer support workflows, fraud detection systems, and software coding optimization, as well as to improve the customer experience in our newsfeed, and to allow customers to connect third party AI agents to our Agentic Trading feature, which we currently offer to U.S. customers, in order to execute trades. We have plans to continue to expand our use of AI in the future. Our research and development of such technology also remains ongoing. As with many new and emerging technologies, AI presents numerous risks and challenges that could adversely affect our business. If we fail to keep pace with rapidly evolving AI technological developments, especially in the financial technology sector, our competitive position and business results may suffer. At the same time, use of AI has recently become the source of significant media attention and political debate. The introduction and use of AI technologies, particularly generative AI, into new or existing offerings may result in new or expanded risks and liabilities, including due to enhanced governmental or regulatory scrutiny, litigation, compliance issues, ethical concerns, confidentiality or security risks, as well as other factors that could adversely affect our business, reputation, and financial results. For example, AI technologies can lead to unintended consequences, including generating content that appears correct but is factually inaccurate, misleading or otherwise flawed, or that results in unintended biases and discriminatory outcomes.

In addition, the use of third-party AI agents and adoption of agentic commerce, such as our Agentic Trading feature in which autonomous third-party AI agents initiate and execute transactions on behalf of users, presents novel and complex regulatory, privacy and cybersecurity risks. Legal frameworks governing such autonomous agents remain nascent, with limited direct guidance specific to trading. The interplay between payments regulations, data privacy and cybersecurity laws and new and developing AI regulations is evolving and may create risk and uncertainty around compliance obligations and potential liability exposure, particularly as more participants (including sellers, fintechs, AI developers and enablers) enter the agentic commerce ecosystem. The market is still assessing how regulators may apply existing consumer protection and other laws in the context of AI. Further, agentic AI such as our Agentic Trading feature may misinterpret instructions or behave in unexpected ways to execute trades without direct customer input, or such agents, or the tools and integrations that support them, may become unavailable or malfunction in a manner that prevents customers from executing transactions, which could negatively impact our customers, harm our reputation and business, and expose us to liability. In addition, our Agentic Trading feature also depends on the continued availability of, and our customers’ compliance with the terms of service of, various independent third-party agentic AI platforms and providers, which may restrict or prohibit use of their services. If such a provider were to restrict or disable customer access, our Agentic Trading feature and the customers who rely on it could be adversely affected. Further,
106

Table of Contents

agentic AI features, including those offered by independent third-party AI platforms and providers on which our Agentic Trading feature relies, may be targeted, misused, or produce outputs or inferences that implicate personal data in ways that are difficult to anticipate or control, potentially resulting in significant reputational harm, litigation or regulatory scrutiny. Reliance on agentic AI also introduces challenges in monitoring cross-border, prohibited or high-risk transactions, where conflicting regulatory requirements may apply.

Laws, regulations or industry standards that develop in response to the use of AI may be burdensome or may restrict our ability to use, develop, or deploy AI, particularly generative AI technologies, in our products or processes, or our efforts to expand our business. For example, the EU's AI Act, which became effective on August 1, 2024, governs the development, marketing and use of AI in the EU and could impose significant additional costs on us to comply or significant fines for failing to comply. In the U.S., a patchwork of emerging AI-related laws and regulations could also require us to modify our practices or increase compliance costs. For example, at the state-level, numerous states including California, Colorado and Texas have enacted laws regulating AI safety protocols, reporting, and transparency. At the federal level, on December 11, 2025, the President issued an executive order to establish a national policy framework for AI intended to preempt state AI laws and regulations. Among other things, the executive order directs the Federal Communications Commission to initiate a proceeding to determine whether to adopt a federal reporting and disclosure standard for AI models, which could impose significant additional costs on us to comply or significant fines for failing to comply.

We also use AI technologies from third parties, which may include open source software. If we are unable to maintain rights to use these AI technologies on commercially reasonable terms, we may be forced to acquire or develop alternate AI technologies, which may limit or delay our ability to provide competitive offerings and may increase our costs. These AI technologies also may incorporate data from third-party sources, publicly available sources, or other datasets. We may not always be aware of the provenance, ownership, or licensing status of data used in connection with our AI technologies, which may expose us to risks associated with data rights and protection. The increased adoption of AI technologies by us, by our employees, contractors, and others including use of third-party AI platforms, increases the risk that confidential, proprietary, or sensitive information, including customer data, trade secrets, and security credentials, may be inadvertently disclosed to or retained by third-party AI service providers outside of our controlled systems, which could result in the unauthorized exposure of such information, expose us to legal and regulatory claims, compromise our intellectual property, and harm our competitive position or reputation. In addition, AI models we develop, or use may generate outputs that reproduce, closely resemble, or are derived from third-party copyrighted, proprietary, or otherwise protected content, which could expose us to infringement or misappropriation claims with respect to such outputs. The legal and regulatory landscape surrounding AI technologies is rapidly evolving and uncertain, including with respect to intellectual property ownership and license rights, cybersecurity, and data protection laws, among others, and has not yet been fully addressed by courts or regulators. The use, development, or adoption of AI technologies into our products may result in exposure to claims by third parties of copyright infringement or other intellectual property misappropriation, which may require us to pay compensation or license fees to third parties. The evolving legal, regulatory and compliance framework for AI technologies may also impact our ability to protect our own data and intellectual property against infringing use.

Risks Related to Cybersecurity and Data Privacy

Our business could be materially and adversely affected by a cybersecurity or data breach or other attack involving our computer systems or data or those of our customers or third-party or fourth-party service providers.

107

Table of Contents

Our systems, including those of companies we have acquired or may seek to acquire in the future, and those of our customers and third-party service providers have been and might in the future be vulnerable to cybersecurity issues. We, like other financial technology organizations, routinely are subject to cybersecurity threats and our technologies, systems, and networks have been and might in the future be subject to attempted cybersecurity attacks. We are also susceptible to inadvertent compromises of our systems and data, including those arising from process, coding, or human errors. Such issues are increasing in frequency and evolving in nature, including employee and contractor theft or misuse, denial-of-service attacks, and sophisticated nation-state and nation-state-supported actors engaging in attacks. The operation of our platforms involves the use, collection, storage, sharing, disclosure, transfer, and other processing of customer information, including personal data. Security breaches and other incidents could expose us to a risk of loss or exposure of this information, which could result in potential liability, investigations, regulatory fines, penalties for violation of applicable laws or regulations, litigation, and remediation costs, as well as reputational harm. As the breadth and complexity of the technologies we use and the software and platforms we develop continue to grow, the potential risk of security or data breaches and cybersecurity attacks increases.

Cybersecurity attacks and other malicious internet-based activity continue to increase, and financial technology platform providers have been and expect to continue to be targeted. In light of media attention, we might be a particularly attractive target of attacks seeking to access customer data or assets and have experienced negative publicity in connection with previous security incidents and might in the future experience similar adverse effects relating to real or perceived security incidents, whether or not related to the security of our platforms or systems. We have also received customer complaints and been subject to litigation and regulatory inquiries, examinations, enforcement actions, and investigations by various state and federal regulatory bodies, including the SEC, FINRA, and certain state regulators, including the NYDFS and the New York Attorney General, related to these events. The increasing sophistication and resources of cybercriminals and other non-state threat actors and increased actions by nation-state actors make it difficult to keep up with new threats and could result in a breach of security. For example, as AI technologies, including generative AI models and machine learning, develop rapidly, threat actors are using these technologies to rapidly identify currently unknown vulnerabilities and create new sophisticated attack methods that are increasingly automated, targeted, coordinated, and more difficult to defend against. In addition, the increasing sophistication and use of AI poses a greater risk of security breaches and incidences of fraudulent activity, including identity fraud, as malicious actors may exploit various AI technologies to create increasingly convincing false identities, transaction records, or attempt to manipulate our verification processes. This has necessitated and will continue to necessitate ongoing enhancements to our verification systems and security protocols. We have been and may continue to be required to expend significant additional resources to continue to modify or enhance these systems and protocols or to investigate and remediate any information security vulnerabilities.

Additionally, there is an increased risk that we might experience cybersecurity-related incidents as a result of any of our employees, service providers, or other third parties working remotely on less secure systems and environments. While we take significant efforts to protect our systems and data, including establishing internal processes and implementing technological measures designed to provide multiple layers of security, our safety and security measures might be insufficient to prevent damage to, or interruption or breach of, our information systems, data (including personal data), and operations, such as the November 2021 Data Security Incident.

Furthermore, to the extent the operation of our systems relies on our third-party service providers, through either a connection to, or an integration with, third parties’ systems, the risk of cybersecurity attacks and loss, corruption, or unauthorized access to or publication of our information or the confidential information and personal data of customers and employees is increased. Third-party risks include insufficient security measures, data location uncertainty, vulnerabilities, and the possibility of data storage in inappropriate jurisdictions where laws or security measures might be inadequate. Our ability to monitor, and our resources to optimize integration with, third-party service providers’ data security practices are
108

Table of Contents

also limited. These third-party risks might be exacerbated as our resources are spread across multiple public cloud service providers. Although we generally have agreements relating to cybersecurity and data privacy in place with our third-party service providers, such agreements might not prevent the accidental or unauthorized access to or disclosure, loss, destruction, disablement or encryption of, use or misuse of, or modification of data (including personal data) and/or might not enable us to obtain adequate (or any) reimbursement from our third-party service providers in the event we should suffer any such incidents. For example, in late October 2024, a cyberattack occurred on our Newsroom in which a cyber attacker gained access to our Newsroom website, control of which is subcontracted to a third-party vendor, for a limited number of hours. The cyberattack did not result in any unauthorized access of customer information. In addition, in December 2024, a cyberattack occurred at Cyberhaven, a data protection company we utilize as a third-party vendor, creating the potential for attackers to steal sensitive data through a malicious version of a Google Chrome extension. Although we do not believe that this third-party vulnerability impacted us, the attack highlights the growing risk from cybersecurity threats against third-party service providers. Due to applicable laws and regulations or contractual obligations, we could be held responsible for any information security failure or cybersecurity attack attributed to our vendors as they relate to the information we share with them. A vulnerability in a third-party service provider’s software or systems, a failure of our third-party service providers’ safeguards, policies or procedures, or a breach of a third-party service provider’s software or systems has in the past and may in the future result in the compromise of the confidentiality, integrity, or availability of our systems or the data housed in our third-party solutions. Additionally, we could also be exposed to information security vulnerabilities or failures at third parties’ common suppliers or vendors (known as “fourth parties”) that could also impact the security of our data, and we may not be able to effectively directly monitor or mitigate such fourth-party risks, in particular as such risks relate to the use of common suppliers or vendors by the third parties that perform functions and services for us and our limited ability to assess the fourth party’s operational controls.

A core aspect of our business is the reliability and security of our platforms. Any unauthorized or inadvertent access to or disclosure, loss, destruction, disablement or encryption of, use or misuse of or modification of data, including personal data, cybersecurity breach, data breach, or other security or similar incident that we, our customers or our third-party or fourth-party service providers experience or the perception that one has occurred or might occur, could harm our reputation, reduce the demand for our products and services and disrupt normal business operations. In addition, it might require us to expend significant financial and operational resources in response to a security or data breach, including repairing system damage, increasing security protection costs by deploying additional personnel and modifying or enhancing our protection technologies, investigating, remediating, or correcting the breach and any security vulnerabilities, defending against and resolving legal and regulatory claims, and preventing future security breaches and incidents, all of which could expose us to uninsured liability, increase our risk of regulatory scrutiny, expose us to legal liabilities, including litigation, regulatory enforcement, indemnity obligations, or damages for contract breach, divert resources and the attention of our management and key personnel away from our business operations, and cause us to incur significant costs, any of which could materially adversely affect our business, financial condition, and results of operations. Moreover, our and our third-party partners’ efforts to improve security and protect data from compromise has in the past identified and might in the future identify previously undiscovered security breaches or vulnerabilities. There could be public announcements regarding any security incidents or vulnerabilities and any steps we take to respond to or remediate such incidents, and if securities analysts or investors perceive these announcements to be negative, it could have an adverse effect on the trading price of our Class A common stock.

While we maintain cybersecurity insurance, our coverage may be insufficient to cover all liabilities resulting from a cybersecurity incident. We cannot be certain that our insurance coverage will be adequate to address the results of regulatory or civil investigations or any liabilities resulting from a cybersecurity incident, that adequate insurance will be available to us on economically reasonable terms, or that our insurer will cover all cybersecurity incident-related claims. The successful assertion of one or
109

Table of Contents

more significant claims against us or changes in our cybersecurity insurance coverage, premiums, or deductibles may adversely affect our reputation, business, financial condition or results of operations.

We are subject to stringent laws, rules, regulations, policies, industry standards and contractual obligations regarding data privacy and security and might become subject to additional related laws and regulations in jurisdictions into which we expand. Many of these laws and regulations are subject to change and reinterpretation and could result in claims, changes to our business practices, monetary penalties, increased cost of operations, or other harm to our business.

We are subject to a variety of federal, state, local, and non-U.S. laws, directives, rules, policies, industry standards and regulations, as well as contractual obligations, relating to privacy and the collection, protection, use, retention, security, disclosure, transfer and other processing of personal data and other data, including the Gramm-Leach-Bliley Act of 1999, Section 5 of the Federal Trade Commission Act, and state laws such as the California Consumer Privacy Act, which provides consumers with the right to know what personal data is being collected, know whether their personal data is sold or disclosed and to whom and opt out of the sale of their personal data, among other rights. We also face particular privacy, data security and data protection risks in connection with our expansion into the U.K. and the EU and other jurisdictions in connection with the General Data Protection Regulation, the Digital Operational Resilience Act, the ePrivacy Directive (including its national implementations), and other data protection regulations including but not limited to facing complexity in interpreting, applying, implementing and complying with such regulations. The regulatory framework for data privacy and security worldwide is also evolving and, as a result, interpretation, implementation standards and enforcement practices are likely to remain uncertain for the foreseeable future. New laws, amendments to or reinterpretations of existing laws, regulations, standards and other obligations might require us to incur additional costs and restrict our business operations, and might require us to change how we use, collect, store, transfer or otherwise process certain types of personal data, to implement new processes to comply with those laws and our customers’ exercise of their rights thereunder, and could greatly increase the cost of providing our offerings, require significant changes to our operations, or even prevent us from providing some offerings in jurisdictions in which we currently operate and in which we might operate in the future or incur potential liability in an effort to comply with certain legislation. For instance, with respect to our Agentic Trading feature, the interplay between payments regulations, data privacy laws and evolving AI regulations may create uncertainty around compliance obligations and potential liability exposure as more participants (including sellers, fintechs, AI developers and enablers) enter the agentic commerce ecosystem. There is a risk of enforcement actions in response to rules and regulations promulgated under the authority of federal and international agencies and state attorneys general and legislatures and consumer protection agencies. For instance, we have in the past (as discussed in Note 15 - Commitments & Contingencies to our unaudited condensed consolidated financial statements in this Quarterly Report) and may in the future be subject to investigations and examinations regarding, among other things, our cybersecurity practices. In addition, if we fail to follow these security standards, even if no customer information is compromised, we might incur significant fines or experience a significant increase in costs. Following the November 2021 Data Security Incident, we received requests for information from regulatory authorities regarding, among other things, the adequacy of our information security measures, and as part of the January 2025 SEC Settlement, RHF and RHS paid penalties for violating Regulation S-P.

Any failure or perceived failure by us or our third-party service providers to comply with our posted privacy policies or with any applicable federal, state or similar foreign laws, rules, regulations, industry standards, policies, certifications or orders relating to data privacy and security, contractual obligations, or any compromise of security that results in the theft, unauthorized or inadvertent access, acquisition, use, disclosure, or misappropriation of personal data or other customer data, could result in significant awards, fines, civil and/or criminal penalties or judgments, proceedings or litigation by governmental agencies or customers, including class action privacy litigation in certain jurisdictions and negative publicity and reputational harm, one or all of which could have an adverse effect on our reputation, business, financial
110

Table of Contents

condition and results of operations. For example, the operation of Robinhood Social involves processing and displaying customer performance statistics, join dates, and selected account-level trade data of participating customers. Any failure in the platform’s privacy and content settings (such as a failure to properly execute a user’s account deactivation or content deletion request) could violate state data privacy laws, rules and regulations and subject us to investigations, examinations, regulatory fines and class-action privacy litigation.

Risks Related to Our Brokerage Products and Services

If we do not maintain the net capital levels required by regulators, our broker-dealer business may be restricted, and we may be fined or subject to other disciplinary or corrective actions.

The SEC, FINRA, and various state regulators impose requirements with respect to the maintenance of specific levels of net capital by securities broker-dealers. For example, our broker-dealer subsidiaries are each subject to the SEC Uniform Net Capital Rule, which specifies minimum capital requirements intended to ensure the general financial soundness and liquidity of broker-dealers, and our clearing and carrying broker-dealer subsidiary is subject to Rule 15c3-3 under the Act, which requires broker-dealers to maintain a reserve account to ensure customer securities are protected and accessible, even in cases of firm insolvency. Our failure to maintain the required net capital levels and protect customer assets could potentially result in immediate suspension of securities activities, suspension or expulsion by the SEC or FINRA, restrictions on our ability to expand our existing business or to commence new businesses, and could ultimately lead to the liquidation of our broker-dealer entities and winding down of our broker-dealer business. If such net capital rules are changed or expanded, if there is a large operating loss, or an unusually large charge against net capital, or if we make changes in our business operations that increase our capital requirements, operations that require an intensive use of capital could be limited and have adverse effects on our ability to maintain or expand our business. For example, in December 2024, the SEC adopted amendments to Rule 15c3-3, which require certain broker-dealers, including RHS, by June 2026 to increase the frequency with which they perform computations of the net cash they owe to customers from weekly to daily. We proactively started implementing these daily computations and began making any required deposits in January 2026.

Our compliance and risk management policies and procedures as a regulated financial services company might not be fully effective in identifying or mitigating compliance and risk exposure in all market environments or against all types of risk.

As a financial services company, our business exposes us to a number of heightened risks. We have devoted significant resources to develop our compliance and risk management policies and procedures and will continue to do so, but our efforts might be insufficient. Our previous and continued expanded operations, evolving business, and unpredictable periods of rapid growth make it difficult to predict all of the risks and challenges we might encounter and therefore increase the risk that our policies and procedures for identifying, monitoring, and managing compliance risks might not be fully effective in mitigating our exposure in all market environments or against all types of risk. Further, some controls are manual and are subject to inherent limitations and errors in oversight, which could cause our compliance and other risk management strategies to be ineffective. Other compliance and risk management methods depend upon the evaluation of information regarding markets, customers, catastrophe occurrences, or other matters that are publicly available or otherwise accessible to us, which might not always be accurate, complete, up-to-date, or properly evaluated. Insurance and other traditional risk-shifting tools might be held by or available to us in order to manage some exposures, but they are subject to terms such as deductibles, coinsurance, limits, and policy exclusions, as well as risk of counterparty denial of coverage, default, or insolvency. Any failure to maintain effective compliance and other risk management strategies could have an adverse effect on our business, financial condition, and results of operations.
111

Table of Contents

We are also exposed to heightened regulatory risk because our business is subject to extensive regulation and oversight by a number of regulators and SROs in a variety of areas and geographies and such regulations are subject to revision, supplementation, or evolving interpretations and application, and it can be difficult to predict how they might be applied to our business, particularly as we introduce new products and services and expand into new jurisdictions. For example, in December 2022, RHF and RHS received investigative requests from the SEC Division of Enforcement regarding their record keeping and preservation practices, including use of personal devices for brokerage communications. RHF and RHS settled the SEC’s investigation into these practices as part of the January 2025 SEC Settlement, paying penalties totaling $8 million and agreeing to complete an internal audit review of electronic communications retention.

We are subject to potential losses as a result of our clearing and execution activities.

We provide clearing and execution services for our securities brokerage business. Clearing and execution services include the confirmation, receipt, settlement and delivery functions involved in securities transactions. Clearing brokers also assume direct responsibility for the possession or control of customer securities and other assets, the clearing of customer securities transactions and lending money to customers on margin. Self-clearing securities firms are subject to substantially more regulatory control and examination than introducing brokers that rely on others to perform clearing functions. Errors in performing clearing functions, including clerical and other errors related to the handling of funds and securities on behalf of customers, (i) could lead to civil penalties, as well as losses and liability as a result of related lawsuits brought by customers and others and any out-of-pocket costs associated with remediating customers for losses, and (ii) have led to, and could in the future lead to the risk of, fines or other actions by regulators. For example, as part of the January 2025 SEC Settlement, RHS settled investigations with the SEC related to suspicious activity reporting, identity theft protection, unauthorized access to Robinhood systems, off-channel communications, retention of brokerage data, failure to maintain certain templated customer communications, EBS submissions and Regulation SHO in connection with fractional share trading and stock lending, which resulted in RHS paying combined monetary penalties of $33.5 million and agreeing to certain undertakings. Furthermore, as part of the March 2025 FINRA Settlement, RHS resolved multiple matters with FINRA, including RHS’s supervision of its clearing system technology, improper rejection of certain ACATS requests, improper effectuation of trades in securities during trading halts, execution of trades during extraordinary market volatility at prices that were above or below specified price bands, and the maintenance and reporting of inaccurate or incomplete trade, order, and position data to FINRA, FINRA TRF, CAT, and OCC, and RHS’s AML program, registration of required personnel, and supervision of trading in associated persons’ brokerage accounts. RHS, along with RHF, paid a penalty totaling $26 million and agreed to pay restitution and to certain undertakings to resolve these investigations, among others.

All customers can place limit orders to buy whole shares of the most traded exchange-traded funds and individual stocks - 24 hours a day, five days a week - through Robinhood 24 Hour Market. Offering U.S. stock trading overnight has heightened risks related to our clearing and execution activities as we do not have previous experience operating or staffing our systems for around-the-clock coverage and may not be able to accurately anticipate the volume of trading activity that will occur outside of regular market hours. Overnight trading on Robinhood 24 Hour Market is primarily supported by BOATS, an alternative trading system that offers certain overnight electronic access, price discovery, trade reporting and clearing connectivity services with respect to exchange-listed securities. If BOATS becomes unwilling or unable to do business with us or one of our Liquidity Providers in the future, we may be unable to find another trading platform to support Robinhood 24 Hour Market, which could negatively impact our transaction-based revenue and generate negative publicity. Additionally, any disruptions in the services provided by BOATS, whether due to technical malfunctions, operational mishaps, or external factors such as regulatory changes or market volatility, have in the past, and may in the future impair our ability to execute our clients’ orders. Should BOATS experience downtime or diminished performance (as it has in
112

Table of Contents

the past and could again in the future), particularly during overnight trading hours, our ability to execute customer orders through Robinhood 24 Hour Market could be compromised and could have an adverse impact on our business, financial condition, results of operations, and/or brand and reputation. For example, on August 5, 2024, BOATS did not open for overnight trading and as a result, Robinhood customers were unable to execute any trades during that overnight session.

Our clearing operations (including for TradePMR customers through TradePMR’s contract with its clearing firm, Wells Fargo Clearing Services, LLC) also require a commitment of our capital and, despite safeguards implemented through both manual and automated controls, involve risks of losses due to the potential failure of our customers or counterparties to perform their obligations under these transactions and margin loans. If our customers default on their obligations, including failing to pay for securities purchased, deliver securities sold, or meet margin calls, we remain financially liable for such obligations, and although these obligations are collateralized, we are subject to market risk in the liquidation of customer collateral to satisfy those obligations. While we have established systems and processes designed to manage risks related to our clearing and execution services, we face a risk that such systems and processes might be inadequate. Any liability arising from clearing and margin operations could have an adverse effect on our business, financial condition, and results of operations.

In addition, as a clearing member firm of securities and derivatives clearinghouses in the U.S., we are also exposed to credit risk of other clearing members. Securities and derivatives clearinghouses require member firms to deposit cash, stock and/or government securities for margin requirements and for clearing funds. If a clearing member defaults in its obligations to the clearinghouse in an amount larger than its own margin and clearing fund deposits, the shortfall is absorbed pro rata from the deposits of the other clearing members. Many clearinghouses of which we are members also have the authority to assess their members for additional funds if the clearing fund is depleted. A large clearing member default could result in a substantial cost to us if we are required to pay such assessments. Furthermore, in the event that a significant amount of our customers’ open trades fail to settle, we might be exposed to potential loss of the capital we committed to meet our deposit requirements.

Our exposure to credit risk with customers, Liquidity Providers, and other counterparties could result in losses.

We extend margin credit and leverage to customers, which are collateralized by customer assets. By permitting customers to engage in margin transactions, we are subject to risks inherent in extending credit. Rapid changes in market conditions or in the trading price of individual securities may cause the value of collateral to fluctuate, potentially resulting in the value of the collateral held by us falling below the amount of a customer’s indebtedness. We also lend and borrow securities in connection with our broker-dealer business. In accordance with regulatory guidelines, we hold cash as collateral when we lend securities, and likewise, we collateralize our borrowings of securities by depositing cash with lenders. Sharp changes in market values of substantial amounts of securities in a short period of time and the failure by parties to the lending or borrowing transactions to honor their commitments could result in substantial losses. Such changes could also adversely impact our capital because our clearing operations require a commitment of our capital and, despite safeguards implemented by our software, involve risks of losses due to the potential failure of our customers to perform their obligations under these transactions and margin loans.

We are also exposed to credit risk in our dealings with the Liquidity Providers to which we route cryptocurrency orders. Unlike equities and option trades, cryptocurrency trades do not settle through any central clearinghouses but rather are conducted under bilateral agreements between us and each crypto Liquidity Provider (the risk of the Liquidity Provider’s default therefore falls upon us rather than being distributed among a clearinghouse’s members). The terms of these bilateral agreements vary, but spot transactions are generally aggregated and settled on a net basis once per business day (with the crypto deliveries occurring first and the net cash moving within 24 hours thereafter) and payment obligations are
113

Table of Contents

generally unsecured during the interval between delivery and payment. It is not uncommon for us to have an intraday outstanding net receivable of $100 million that we are owed by any one cryptocurrency Liquidity Provider. Similarly, we routinely have unsecured PFOF receivables from equities and options Liquidity Providers, as well as credit risk from our on-exchange lending and post-trade settlement services. Any payment default by a Liquidity Provider could have adverse effects on our financial condition and results of operations. Our acquisition of Bitstamp has resulted in increased credit risk associated with certain Liquidity Providers, given that some of these firms are also customers of Bitstamp.

Additionally, RHD is obligated to establish and maintain an appropriate RITA, which is the amount of RHD’s own capital held in segregation in excess of the amount required to be segregated based on customer positions. RHD also maintains additional firm capital in segregation greater than the established RITA amount, (i.e., excess segregated funds). If the aggregate customer margin deficiency amount on any day exceeds the excess segregated funds amount to the point where RHD breaches its RITA, RHD would be in violation of CFTC rules and would potentially be subject to monetary penalties, sanctions, or other disciplinary actions for failing to maintain an appropriate RITA.

As a result of our acquisition of Bitstamp, we now provide additional cryptocurrency products and services to institutional customers both in parts of the U.S. and internationally, including products and services such as retail lending, on-exchange lending, off-exchange settlement, post-trade settlement, and perpetual futures exchange. These offerings to certain institutional clients expose us to risks we have not historically faced at scale, including credit risk.

We have policies and procedures designed to manage credit risk, but we face a risk that such policies and procedures might not be fully effective. We regularly update our risk management framework and practices, but eliminating credit risk entirely is difficult.

Providing investment advice and recommendations could subject us to investigations, penalties, and liability for customer losses if we fail to comply with applicable regulatory standards, and providing investment education tools could subject us to additional risks if such tools are construed to be investment advice or recommendations.

Risks associated with providing investment advice and recommendations include those arising from how we disclose and address possible conflicts of interest, inadequate due diligence, inadequate disclosure, and human error. The Advisers Act and its related rules and interpretations impose a fiduciary duty on our provision of investment advisory services to advisory clients. Other regulations, such as the SEC’s Regulation Best Interest and certain state broker-dealer regulations, impose heightened conduct standards and requirements on recommendations to retail investors. For example, the NASAA (an association of state securities administrators) has adopted amendments to the NASAA model rule regarding Dishonest or Unethical Business Practices of Broker-Dealers and Agents, which are intended to address Regulation Best Interest and other developments in the securities industry. In addition, the SEC and various states have considered or are considering potential regulations or have already adopted certain regulations that could impose additional standards of conduct or other obligations on us to the extent we provide investment advice or recommendations to our customers or use certain covered technologies while communicating with existing or prospective customers.

We also provide customers with a variety of educational materials in various jurisdictions, investment tools, and financial news and information, such as our “Snacks” newsletter (which is offered by Sherwood Media), the suite of other editorial offerings that Sherwood Media has launched and will continue to launch, and the Robinhood Investor Index. Additionally, Robinhood Gold Subscribers have access to AI-generated explanations of stock and portfolio performance and a conversational AI feature that analyzes customer accounts and holdings, helps manage watchlists and alerts, and executes certain supported transactions. TradePMR offers a version of these features to RIAs. We also offer an Agentic Trading
114

Table of Contents

feature, that allows customers to connect independent third-party AI agents to dedicated agentic trading accounts. We also provide our customers with access to the Robinhood Social platform, that allows eligible customers to share executed trades, performance statistics, commentary, and manually initiate trades shared by others. While we explicitly disclose that posts within Robinhood Social reflect only the opinions of individual customers and do not constitute investment advice, recommendations, or solicitations by Robinhood, we face a risk that regulators or courts might interpret these platform features and mechanics as constituting regulated investment advice or recommendations. If Robinhood Social is deemed to violate Regulation Best Interest or state fiduciary standards, we could face investigations, significant fines, penalties, and liability for customer losses. Based on current law and regulations, we believe these services do not constitute investment advice or investment recommendations. If the law were to change or if a court or regulator were to interpret current law and regulations in a novel manner, we face a risk that these services could come to be considered as investment advice. In addition, providing customers access to third party products and services (e.g., tax services) could subject us to liabilities if customers lose money as a result of using such products and services, or if we improperly use customer information in violation of privacy laws.

In connection with our acquisition of TradePMR, and through our subsidiary investment adviser RAM, we launched the Robinhood Adviser Network (“RAN”), a referral program that connects eligible Robinhood customers with independent RIAs who custody assets with TradePMR. We are responsible for the initial and ongoing vetting of RIAs in the network. If an RIA we refer a customer to later engages in certain activities such as fraud, a breach of fiduciary duty, or significant mismanagement of client funds, we may face "negligent referral" claims or reputational damage, even if we did not provide the underlying investment advice. If the SEC or other regulators were to deem RAM to be acting as a “promoter” or “endorser” within the meaning of the SEC Rule 206(4)-1 under the Advisers Act (the “Marketing Rule”), we would be required to comply with additional, and potentially overlapping, requirements under the Advisers Act and related rules (including the Marketing Rule, as well as any analogous regulatory regimes promulgated by states or self-regulatory organizations), with respect to the structure, documentation, and disclosure of the program, the content and presentation of our communications, and our due diligence and oversight of participating advisers and promoters. The transition of a self-directed retail customer to a third-party RIA also involves sharing sensitive financial data and integrating our platform with TradePMR’s Fusion platform. Operational failures during this transition-such as data breaches, incorrect asset transfers, or poor communication from the referred RIA, could alienate our core user base and lead to higher churn rates. In addition, our agreements with RIAs include "termination fees" if an RIA exits the program but retains the referred clients. Collecting these fees may lead to contractual disputes or litigation with partner firms, which could disrupt the network's stability and discourage new RIAs from joining.

If services that we do not consider to be recommendations (such as educational materials, and our editorial offerings, including Robinhood Snacks) are construed as constituting investment advice or recommendations, we have been and could be in the future subject to investigations by regulatory agencies. For example, in December 2020, the Enforcement Section of MSD filed a complaint against us alleging that a fiduciary conduct standard applies to us under Massachusetts securities law by claiming that certain of our product features and marketing strategies amount to investment recommendations. Changes in law or changes in interpretations of existing law might also require us to modify the nature of these services or discontinue them altogether, one or more of which could have an adverse effect on our ability to attract and retain customers.

To the extent our investment education tools, news and information, or digital engagement practices are determined to constitute investment advice or recommendations and to the extent those recommendations fail to satisfy regulatory requirements, or we fail to know our customers, or improperly advise our customers, or if risks associated with advisory services otherwise materialize, we could be found liable for losses suffered by such customers, or could be subject to regulatory fines, penalties, and other actions such as business limitations, any of which could harm our reputation and business.

115

Table of Contents

Our wholly-owned subsidiary, RHV, serves as the investment adviser to registered investment companies and business development companies, and expects to advise additional investment vehicles in the future, which subjects us to additional burdens and risks and could subject us to potential liability.

RHV, an investment adviser registered with the SEC under the Advisers Act, serves as the investment adviser to RVI. RVI is a Delaware statutory trust registered under the 1940 Act, as an externally managed, non-diversified, closed-end investment company. RHV also serves as investment adviser to RVII, a newly organized, externally-managed and diversified closed‑end fund that has elected to be regulated as a business development company (“BDC”). RHV expects to serve as investment adviser to additional investment vehicles regulated under the 1940 Act in the future (collectively with RVI and RVII, the “Funds”), where the structure of additional Funds may differ, potentially significantly, from that of RVI and RVII.

RHV is responsible for making investment decisions for RVI and RVII’s portfolios, and in the future may be responsible for making investment decisions for additional Funds’ portfolios should it serve as their investment adviser. RHV was formed in August 2025 and has limited investing history. RHV’s service as an investment adviser to RVI and RVII, and future service as an investment adviser to the Funds subjects us to additional burdens and risks and could subject us to potential liability, including but not limited to:

• We are subject to additional regulatory and compliance burdens. For example, RVI is registered under the 1940 Act as an investment company. RVI and its investment adviser, RHV, are subject to the 1940 Act and the rules thereunder, which, among other things, regulate the relationship between a registered investment company and its investment adviser and their respective affiliates and prohibit or severely restrict principal transactions and joint transactions. RVII is subject to regulation under the 1940 Act as well, including provisions specifically applicable to BDCs. Additional Funds may be subject to varying requirements under the 1940 Act or other regulatory regimes, which will increase the complexity and cost of our compliance programs.

• RHV was recently formed and while its personnel have investment experience, RHV and its management have limited experience managing closed-end investment companies and other potential investment vehicles. Different fund structures and investment strategies may also require specialized expertise, including with respect to investing and administration, that RHV may be unable to scale effectively.

• RHV or its directors, officers or employees and its affiliates, successors or other legal representatives may be liable for any error of judgment, for any mistake of law or for certain types of acts or omissions by such person. As the number and scope of Funds increase, the risk of litigation and regulatory scrutiny will also increase.

• RHV provides to RVI and RVII, and expects in the future to provide to the Funds, certain investment advisory, management and administrative services pursuant to investment advisory agreements. Its provision of those services to the Funds can be terminated without penalty as specified in the investment advisory agreement. In addition, if the investors in a Fund were to be dissatisfied with the investment performance or disagree with investment strategies employed by RHV, they may seek to cause the board of directors of the Fund to terminate its investment advisory agreement with us or change the terms of such agreement in a manner that is less favorable to us.

• The timing and amount of management fees generated by RVI, and expected to be generated by additional future Funds, are uncertain and depend on the success of capital raising efforts and the Funds’ investment performance, and revenue derived from such management fees generally will be recognized only after a Fund is deconsolidated from our balance sheet (RVI, which was
116

Table of Contents

previously consolidated in our financial statements, was deconsolidated as of June 30, 2026; RVII is currently consolidated in our financial statements). Different Funds may have different fee structures, including performance-based incentive fees, which are more volatile than base management fees. RHV also may from time to time waive and/or reimburse all or a portion of its management fees for RVI or RVII or one or more additional future Funds when it deems appropriate.

• RVI and RVII hold, and additional future Funds are expected to hold, illiquid, private investments that have no readily ascertainable market prices. The actual results related to any particular investment often vary materially. Because there is significant uncertainty in the valuation of, or in the stability of the value of, illiquid investments, the fair values of such investments as reflected in a Fund’s NAV do not necessarily reflect the prices that would actually be obtained by such Fund when such investments are realized and may contribute to a disconnect between NAV and the market price of such Fund’s shares, volatility in such Fund’s NAV or market price, negative investor perceptions of such Fund’s performance and reduced investor confidence in us or such Fund, which could in turn result in difficulty in raising additional funds, reputational harm, and increased risk of litigation or other claims against us, RHV, RVI, RVII, or any additional future Fund.

• We have made balance sheet investments to provide seed capital to RVI and RVII and expect to continue making balance sheet investments to provide seed or other capital to certain Funds during their early fundraising stages. Such investments have been and may in the future be illiquid, long-term in nature and subject to significant valuation uncertainty, and may decline in value. There can be no assurance as to the timing or amount of any returns on such investments, and we may be required to hold such investments for extended periods. In addition, we may determine to commit additional capital to such Funds. As a result, these activities may expose us to investment losses and could adversely affect our financial condition, results of operations, liquidity and capital resources.

• The Funds are subject to conflicts of interest. Our business activities in the management of, or our interest in, our own business and accounts, may present conflicts of interest that could disadvantage the Fund and its shareholders. We provide brokerage services to retail investors that may follow investment programs similar to that of a Fund. RHV and its affiliates will be permitted to market, organize, sponsor, act as general partner or as the primary source for transactions for other pooled investment vehicles and other accounts, which may be offered on a public or private placement basis, and to engage in other investment and business activities. Some of these vehicles and accounts may have investment strategies that overlap with the investment strategies of the Funds. In addition, to the extent permitted under applicable law, our employees and their family members can own investments in companies in which the Funds invest. Such activities may raise conflicts of interest for which the resolution may not be determinable.

• As the number and scope of Funds expands, we will increasingly confront potential conflicts of interest, relating to our and the Funds’ investment activities. For example, potential conflicts may arise with respect to our decisions regarding how to allocate investment opportunities. RHV may allocate an investment opportunity in a manner that excludes one or more Funds or results in a disproportionate allocation based on factors or criteria that RHV determines. In addition, conflicts of interest may exist in the valuation of investments (which can affect fees), timing of transactions, and regarding the allocation of fees and costs among Funds and their portfolio companies.

• If a Fund performs poorly or does not achieve expected returns, investors may decline to invest in any future Funds, and such poor performance may be attributed to Robinhood more generally.

117

Table of Contents

Any of these additional burdens and risks could subject us to potential liability and could harm our reputation and business.

Our provision of brokerage and custodial services to RIAs exposes us to operational, regulatory and reputational risks.

Our provision of brokerage and custodial services through TradePMR to RIAs and their clients is subject to extensive federal and state regulation, including oversight by the SEC, FINRA, and applicable state securities regulators. Regulatory changes or enhanced enforcement activity may require significant system changes, and increased compliance resources, which could materially affect our business operations and results of operations. Non-compliance with applicable regulations by us or by TradePMR’s clearing firm, Wells Fargo Clearing Services, LLC, could result in censures, fines, or reputational harm.

We rely heavily on proprietary and third-party technology platforms to provide brokerage, custodial, and administrative services. A failure in these systems, including outages, cyberattacks, data breaches, or programming errors, could interrupt our operations or those of our RIA clients, resulting in financial losses, regulatory exposure, or damage to our relationships with advisors and end clients.

Possessing client assets and sensitive personal information exposes us to cybersecurity threats and data privacy obligations. A breach of our systems or those of our vendors could result in unauthorized access to confidential information, potentially triggering legal liabilities, regulatory investigations, remediation costs, and reputational harm. Continued investment in information security infrastructure and incident response protocols is necessary to mitigate this risk.

We may be subject to regulatory actions, legal claims, and arbitration proceedings arising from the actions or omissions of RIAs to whom we provide custodial support. We provide investment advice to end clients through RAM and RHV, and although we do not provide such investment advice through TradePMR, disputes may nevertheless arise regarding account management, trade execution, or data integrity. Any such claims could result in costly litigation, adverse judgments, or settlements.

Our revenue from custodial relationships is largely dependent on assets under custody, cash balances, and the trading activity of advisory clients. Adverse market conditions, rising interest rate volatility, or shifts in client behavior may reduce trading volumes or asset levels, which could negatively impact our fee-based and spread income.

Our ability to retain and grow our RIA client base depends in part on our reputation for service quality, platform stability, and regulatory compliance. Negative publicity, including but not limited to negative publicity arising from operational failures, regulatory sanctions, or advisor misconduct, may harm our brand and result in the loss of key relationships or reduced advisor onboarding.

Risks Related to Cryptocurrency Products and Services

The loss, destruction or unauthorized use or access of a private key required to access any of the cryptocurrencies we hold on behalf of customers could result in irreversible loss of such cryptocurrencies. If we are unable to access the private keys or if we experience a hack or other data loss relating to the cryptocurrencies we hold on behalf of customers, our customers might be unable to trade their cryptocurrency, our reputation and business could be harmed, and we might be liable for losses in excess of our ability to pay.

As we expand our cryptocurrency product and service offerings, the risks associated with failing to safeguard and manage cryptocurrencies we hold on behalf of our customers increase. Our success and
118

Table of Contents

the success of our offerings require significant public confidence in our ability to properly manage customers’ balances and handle large transaction volumes and amounts of customer funds. Any failure by us to maintain the necessary controls or to manage the cryptocurrencies we hold on behalf of our customers and funds appropriately and in compliance with applicable regulatory requirements could result in reputational harm, significant financial losses, lead customers to discontinue or reduce their use of our services, and result in significant penalties and fines and additional restrictions.

We hold all settled cryptocurrencies in custody on behalf of customers in two types of wallets: (i) hot wallets, which are managed online, and (ii) cold wallets, which are managed entirely offline and require physical access controls. With the exception of Bitstamp (discussed below), Robinhood does not utilize third-party custodians for settled cryptocurrencies, but does integrate proprietary technology from a third-party industry-standard vendor into the systems Robinhood uses to support the custody, transfer and settlement operations of its wallets. As noted, Bitstamp does use third-party custodians. Failures, problems or issues at these third-party custodians could subject Bitstamp to various forms of risk and may have a significant impact on Bitstamp’s business and reputation, which, in turn, could harm Robinhood’s business and reputation more broadly.

In general, the overwhelming majority of cryptocurrency coins on our platforms are held in cold storage, though some coins are held in hot wallets to support day-to-day operations. As a public company, we are required to comply with the Sarbanes-Oxley Act of 2002. As part of this, we are required to establish and maintain adequate internal control over financial reporting and evaluate the effectiveness of our internal control over financial reporting. The effectiveness of Robinhood’s internal control over financial reporting and our financial statements and related notes are audited by Ernst & Young LLP, our independent registered public accounting firm. Under blockchain protocol, in order to access or transfer cryptocurrency stored in a wallet, we need to use a private key. Robinhood maintains backup copies of private keys in multiple separate locations. Bitstamp safeguards its private keys internally and with custodians. We have several layers of cybersecurity defense in place to protect our omnibus wallets. However, to the extent any private keys are lost, destroyed, unable to be accessed by us, or otherwise compromised and all of their backups are lost, we will be unable to access the assets held in the related hot or cold wallet. Further, we cannot provide assurance that any or all of our wallets will not be hacked, exposed, or compromised such that cryptocurrencies are sent to one or more private addresses that we do not control, which could result in the loss of some or all of the cryptocurrencies that we hold in custody on behalf of customers. Any such losses could be significant, and we may not be able to obtain insurance coverage for some or all of those losses. Cryptocurrencies and blockchain technologies have been, and might in the future be, subject to security breaches, hacking, or other malicious activities, including targeted physical attacks. For example, in August 2021, hackers were able to momentarily take over the BSV network, allowing them to spend coins they did not have and prevent transactions from completing. Any exposure or loss of private keys relating to, or hack or other compromise of, the hot wallets or cold wallets we use to store our customers’ cryptocurrencies could result in total loss of customers’ cryptocurrencies (because customers’ cryptocurrency balances are not protected by the SIPC) or adversely affect our customers’ ability to sell their assets, and could result in our being required to reimburse customers for some or all of their losses, subjecting us to significant financial losses. Because many insurance carriers do not provide insurance coverage for crypto-related risks, comprehensive coverage for such events is not readily available on commercially reasonable terms. Our current coverage is limited and may not cover the extent of loss, nor the nature of such loss, in which case we may be liable for the full amount of losses suffered, which could be greater than all of our remaining assets. The total value of cryptocurrencies under our control on behalf of customers is significantly greater than the current total value of insurance coverage that would compensate us in the event of theft or other loss of such assets. Furthermore, the term of our current insurance policy expires in the third quarter of 2026, with our option to renew annually or for the carrier to terminate coverage with advance written notice. Any loss of our insurance coverage would impede our ability to mitigate any losses our customers might suffer if we are unable to access private keys. Additionally, any such security compromises or any business continuity issues affecting our cryptocurrency Liquidity Providers might affect the ability or willingness of
119

Table of Contents

our customers to trade or hold cryptocurrencies on our platforms, might result in litigation and regulatory enforcement actions, and could harm customer trust in us and our products generally.

The prices of most cryptocurrencies are extremely volatile. Fluctuations in the price of various cryptocurrencies might cause uncertainty in the market and could negatively impact trading volumes of cryptocurrencies, and we may not effectively identify, prevent or mitigate cryptocurrency market risks, any of which would adversely affect the success of our business, financial condition, and results of operations.

The prices of most cryptocurrencies are based in part on market adoption and future expectations, which might or might not be realized. As a result of these and other factors, the prices of cryptocurrencies are highly speculative. The prices of cryptocurrencies have been subject to dramatic fluctuations (including as a result of prior bear market cycles), which have impacted, and will continue to impact, our trading volumes and operating results and might adversely impact our growth strategy and business. Several factors could affect a cryptocurrency’s price, including, but not limited to:

• Global cryptocurrency supply, including various alternative currencies which exist, and global cryptocurrency demand, which can be influenced by the growth or decline of retail merchants’ and commercial businesses’ acceptance of cryptocurrencies as payment for goods and services, the security of online cryptocurrency exchanges and digital wallets that hold cryptocurrencies, the perception that the use and holding of digital currencies is safe and secure, and regulatory restrictions on their use.

• Changes in the software, software requirements or hardware requirements underlying a blockchain network, such as a fork. Forks have occurred and are likely to occur again in the future and could result in a sustained decline in the market price of cryptocurrencies.

• Changes in the rights, obligations, incentives, or rewards for the various participants in a blockchain network.

• The maintenance and development of the software protocol of cryptocurrencies.

• Cryptocurrency exchanges’ deposit and withdrawal policies and practices, liquidity on such exchanges, and interruptions in service from or failures of such exchanges.

• Regulatory measures, if any, that affect the use and value of cryptocurrencies or regulatory or judicial assertions or determinations that certain cryptocurrencies are securities.

• Competition for and among various cryptocurrencies that exist and market preferences and expectations with respect to adoption of individual currencies.

• Actual or perceived manipulation of the markets for cryptocurrencies.

• Actual or perceived connections between cryptocurrencies (and related activities such as mining) and adverse environmental effects or illegal activities.

120

Table of Contents

• Social media posts and other public communications by high-profile individuals relating to specific cryptocurrencies, or listing or other business decisions by cryptocurrency companies relating to specific cryptocurrencies.

• Expectations with respect to the rate of inflation in the economy, monetary policies of governments, trade restrictions, and currency devaluations and revaluations.

• Developments in mathematics, technology, digital computing, algebraic geometry, and quantum computing that could result in the cryptography that is used by many cryptocurrencies becoming insecure or ineffective.

While we have observed a positive trend in the total market capitalization of cryptocurrency assets over the long term, driven by increased adoption of cryptocurrency trading by both retail and institutional investors as well as continued growth of various non-investing use cases, historical trends are not indicative of future adoption, and it is possible that the rate of adoption of cryptocurrencies might slow or decline, which would negatively impact our business, financial condition, and results of operations.

While we currently support several cryptocurrencies for trading, market interest in particular cryptocurrencies can also be volatile and there are many cryptocurrencies in the market that we do not support. Our business could be adversely affected, and growth in our net revenue earned from cryptocurrency transactions could slow or decline, if the markets for the cryptocurrencies we support deteriorate or if demand moves to other cryptocurrencies not supported by our platforms. The listing committees of RHC and RHEU conduct regular reviews of the cryptocurrencies available on our platforms to ensure that they continue to meet our requirements under our internal policies and procedures (collectively, the “Crypto Listing Frameworks”) for continued support on our platforms and possess the authority to delist and cease support for any asset based on various factors. Bitstamp also conducts similar reviews of cryptocurrencies available on its platform in accordance with its internal listing procedures and processes. Ceasing support for a cryptocurrency with substantial market interest (or if our consideration to cease supporting such a cryptocurrency becomes known) has in the past exposed, and may continue to expose us to negative attention, adversely impacting our business, including revenue loss from no longer supporting a cryptocurrency or customer reaction to such a decision. For instance, in the past we have encountered an influx of customer complaints related to our decisions to cease support for certain cryptocurrencies.

Volatility in the values of cryptocurrencies caused by the factors described above or other factors might impact our regulatory net worth requirements as well as the demand for our services and therefore have an adverse effect on our business, financial condition and results of operations.

Although neither our board of directors nor management have to date identified any material gaps or weaknesses with respect to our existing risk management processes and policies in light of recent cryptocurrency market conditions, we remain subject to cryptocurrency market risks. If we are unable to effectively identify, prevent or mitigate such risks, the success of our business, our financial condition and results of our operations may be adversely affected. As part of our overall risk management processes, the ERM team maintains an enterprise wide risk management standard to ensure risks are evaluated in a clear and transparent manner and partners with various front-line risk teams and risk owners across Robinhood to foster consistent risk management practices across Robinhood. In particular, the ERM team provides governance over risk management practices and reports top risks to the Safety Committee, along with planned mitigants and monitoring procedures. The Safety Committee reviews management’s exercise of its responsibility to identify, assess, manage, monitor and mitigate material risks not specifically allocated to the board of directors or another of its committees. In addition to RHM-level processes, entity-level risk teams affiliated with our operating subsidiaries, including one at RHC, perform
121

Table of Contents

ongoing risk operations, including risk and control self-assessments and maintaining risk and control registers. As management identifies operational risks, the entity-level risk team tracks the risk drivers and planned mitigating measures and escalates such risks, as needed, to the ERM team.

In light of events in 2022, cryptocurrency market risks were identified as a key risk to the Company and management has accordingly implemented certain measures, including enhanced monitoring for cryptocurrency markets (such as reducing net open position limits with liquidity partners through more frequent settlement; adding additional banking and liquidity partners; monitoring on-platform trading activity, coin deposits and withdrawals; and ongoing diligence for listings and banking relationships). The ERM team has also provided quarterly updates to the Safety Committee with respect to such risks and responses. In addition, RHC and RHEU maintain listing committees as described above.

In June 2025, we started offering leverage to customers of RHEU and Bitstamp Financial Services Ltd investing in crypto-asset perpetuals. By permitting customers to invest in crypto-asset perpetuals with the use of leverage, both our customers and we are subject to certain risks, especially during periods of extreme volatility in the crypto-asset markets.

In the U.S., any particular cryptocurrency’s status as a “security” and cryptocurrency transaction’s status as an “investment contract” is subject to a high degree of uncertainty and if we have not properly characterized one or more cryptocurrencies or cryptocurrency transactions, we might be subject to legal and regulatory scrutiny, investigations, fines, and other penalties.

We currently facilitate customer trades for certain cryptocurrencies that we have analyzed under applicable internal policies and procedures and, for cryptocurrencies supported on our RHC and Bitstamp
US platforms, that we believe are not securities under relevant U.S. federal and state securities laws. Determining whether any given cryptocurrency is a security is a highly complex, fact-specific analysis, which may change over time based on changes in the cryptocurrency and its related ecosystem and on legal and regulatory developments. Different parties may reach different conclusions about the outcome of this analysis based on the same facts. The SEC has stated that the security (or non-security) status of a given crypto asset depends on the facts and circumstances and must be analyzed appropriately in light of the asset’s characteristics, uses, and functions. The SEC, individual Commissioners and the SEC Staff have previously taken positions that certain cryptocurrencies are “securities” in the context of settled or litigated enforcement actions. Although the SEC has not historically provided advance confirmation on the status of any particular cryptocurrency as a security, on March 17, 2026, the SEC issued an interpretation clarifying how the federal securities laws apply to certain crypto assets and transactions involving crypto assets. In this interpretive release, the SEC classified crypto assets into five categories based on their characteristics, uses, and functions. The first four: (i) “Digital commodities,;” (ii) “digital collectibles;” (iii) “digital tools;” and (iv) “stablecoins,” are not themselves securities according to the SEC. By contrast, the SEC classified “digital securities” (commonly known as “tokenized” securities) as financial instruments enumerated in the definition of a “security.” In the interpretive release, the SEC also specifically identified the following examples of digital commodities: Aptos (APT); Avalanche (AVAX); Bitcoin (BTC); Bitcoin Cash (BCH); Cardano (ADA); Chainlink (LINK); Dogecoin (DOGE); Ether (ETH); Hedera (HBAR); Litecoin (LTC); Polkadot (DOT); Shiba Inu (SHIB); Solana (SOL); Stellar (XLM); Tezos (XTZ); and XRP (XRP). However, the SEC clarified in the interpretive release that a non-security crypto asset may nevertheless be offered and sold subject to an investment contract, which is a security. Moreover, the SEC’s interpretation is not binding on any court or other agency.

Staff of the SEC’s Division of Corporation Finance have also published statements clarifying that the Division does not view the offers and sales of certain “stablecoins” and “meme coins” to constitute securities transactions. Moreover, SEC Staff have authored informal, non-binding “no-action” letters to the promoters of certain digital assets stating that the Staff would not recommend enforcement action to the SEC on the basis that transactions in such digital assets, as described to the Staff by their respective promoters, are securities transactions, including with respect to the issuance of tokens in connection with
122

Table of Contents

internet and energy decentralized physical infrastructure projects and a consumer finance rewards program. However, such statements and views are not official policy statements by the SEC and reflect only the SEC Staff’s and speakers’ views, which are not binding on the SEC or any court or other agency (including, for instance, the NYDFS, which published a consumer alert in January 2025 concerning meme coins that did not opine on whether meme coins constituted securities but warned consumers of the risks of such coins), may be withdrawn at any time without notice or comment by the SEC or its senior officials, cannot be generalized to any other cryptocurrency, and might evolve (including, for instance, recently enacted legislation provides guidelines for the regulation of stablecoins in the U.S., which may differ from the views set forth in the SEC Staff statement regarding stablecoins). Additionally, U.S. regulators have in the past expressed concerns about cryptocurrency platforms adding multiple new coins, some of which they may view as unregistered securities. Although our policies and procedures are intended to enable us to make risk-based assessments regarding the likelihood that a particular cryptocurrency could be deemed a security under applicable laws, including federal securities laws, our assessments are not definitive legal determinations as to whether a particular digital asset is a security under such laws. Accordingly, regardless of our conclusions, we could be subject to legal or regulatory action in the event the SEC, a state regulator, or a court were to assert or determine that a cryptocurrency supported by our RHC or Bitstamp US platforms is a “security” under U.S. law.

For example, in June 2023, the SEC charged Binance and, separately, Coinbase with operating their respective cryptocurrency trading platforms as unregistered national securities exchanges, brokers, and clearing agencies, and in doing so, the SEC alleged that certain cryptocurrencies supported on their respective platforms are securities. The charges also implicated Coinbase’s staking-as-a-service program and its non-custodial wallet. In November 2023, the SEC brought similar charges against Kraken, alleging that it operated as an unregistered securities exchange, brokerage and clearing agency. In February 2025, March 2025, and May 2025, each of Coinbase, Kraken, and Binance, respectively, entered into a court-approved joint stipulation with the SEC to dismiss each of the SEC’s lawsuits against such parties with prejudice. Several other cryptocurrency market participants, including us, have also announced that the SEC informed them that the SEC was terminating its investigation or enforcement action into their firm. Also, in April 2025, the Office of the Deputy Attorney General issued a memorandum (the “April DOJ Memo”), setting out new enforcement priorities for digital asset-related investigations and prosecutions by the DOJ. The April DOJ Memo directed prosecutors not to “target virtual currency exchanges, mixing and tumbling services, and offline wallets for the acts of their end users or unwitting violations of regulations.” The April DOJ Memo explained that the DOJ will instead prioritize cases against individuals who cause financial harm to digital asset investors and consumers and/or use digital assets in furtherance of other criminal conduct. The decisions by regulators not to bring enforcement actions provide, and any other action, settlement, or related investigation by regulators, might provide, additional guidance on the legal status of cryptocurrencies as securities more generally, which has affected and might significantly affect the actual or perceived regulatory status and value of cryptocurrencies we currently support or might support in the future. On January 21, 2025, the SEC announced that then-Acting Chairman Mark Uyeda “launched a crypto task force dedicated to developing a comprehensive and clear regulatory framework for crypto assets.” The task force is focused on helping the SEC “draw clear regulatory lines, provide realistic paths to registration, craft sensible disclosure frameworks, and deploy enforcement resources judiciously.” The SEC formed the Crypto Task Force to provide clarity on the application of the federal securities laws to the crypto asset market and to recommend practical policy measures that aim to foster innovation and protect investors. Since its formation, the Crypto Task Force has accepted written submissions on various cryptocurrency-related topics from industry participants; hosted roundtables on topics relating to security status, trading, custody, tokenization, DeFi, and financial surveillance and privacy; and has held meetings with interested stakeholders. On July 31, 2025, SEC Chairman Paul Atkins announced the launch of “Project Crypto,” described as “a Commission-wide initiative to modernize the securities rules and regulations to enable America’s financial markets to move on-chain.” In connection with this initiative, Chairman Atkins indicated that he has asked the Crypto Task Force to develop proposals to implement recommendations in the July 30, 2025, President’s Working Group on Digital Asset Markets Report, as well as a potential innovation exemption. While these developments are
123

Table of Contents

positive, the Crypto Task Force’s work remains in the early stages, and no formal rulemaking or exemptions have been proposed or adopted to date. In addition, notwithstanding recent positive developments involving the SEC, DOJ, and other federal regulators, state regulators retain independent authority to enforce their own securities laws, which may differ from or be interpreted more expansively than federal law. As a result, a state regulator could determine that a particular digital asset, product, or service constitutes a security under state law, even if the SEC has elected not to pursue enforcement action, the SEC has provided informal guidance or assurances to the contrary, or the asset, product, or service is otherwise excluded from the definition of a security at the federal level. Moreover, private litigants may assert claims under federal or state securities laws based on similar theories, regardless of the positions taken by federal regulators.

From time to time, we have received with respect to our RHC platform, and might in the future receive, SEC inquiries regarding specific cryptocurrencies supported on our RHC or Bitstamp US platforms and added features. Since December 2022, we have received investigative subpoenas from the SEC regarding, among other topics, RHC’s supported cryptocurrencies, custody of cryptocurrencies, and platform operations. During our discussions with the SEC Staff in the fourth quarter of 2023, the Staff stated that they were considering whether to recommend that the SEC find that certain cryptocurrencies supported by our RHC platform are securities. In the second quarter of 2024, we received a “Wells Notice” stating that the SEC Staff made a “preliminary determination” to recommend that the SEC file an enforcement action against RHC alleging violations of Sections 15(a) and 17A of the Exchange Act. On February 21, 2025, the SEC Division of Enforcement closed the investigation, advising RHC in writing that it had concluded its investigation and did not intend to move forward with recommending an enforcement action.

To the extent that the SEC or a court asserts or determines that any cryptocurrencies supported by our RHC or Bitstamp US platforms are securities, that assertion or determination could prevent us from continuing to facilitate trading of those cryptocurrencies (including ceasing support for such cryptocurrencies on our RHC or Bitstamp US platforms) or offering those services. It could also result in regulatory enforcement penalties and financial losses in the event that we have liability to our customers and need to compensate them for any losses or damages. We could be subject to judicial or administrative sanctions, including disgorgement or penalties which could be material, for failing to offer or sell the cryptocurrency in compliance with securities registration requirements, or for acting as a securities broker or dealer, national securities exchange, clearing agency, or other regulated entity without appropriate registration. Such an action could result in injunctions and cease and desist orders, as well as civil monetary penalties, fines, and disgorgement, criminal liability, and reputational harm. Customers that traded such supported cryptocurrency through our RHC or Bitstamp US platforms and suffered trading losses might also seek to rescind transactions that we facilitated on the basis that they were conducted in violation of applicable law, which could subject us to significant liability and losses. We might also be required to cease facilitating transactions in the supported cryptocurrency, which could negatively impact our business, operating results, and financial condition. Further, if any supported cryptocurrency is deemed to be a security, it might have adverse consequences for such supported cryptocurrency. For instance, all transactions in such supported cryptocurrency would have to be registered with the SEC or other foreign authority, or conducted in accordance with an exemption from registration, which could severely limit its liquidity, usability, and transactability. Moreover, the networks on which such supported cryptocurrencies are used might be required to be regulated as securities intermediaries, and subject to applicable rules, which could effectively render the network impracticable for its existing purposes. In addition, our growth might be adversely affected if we are not able to expand our RHC platform to include additional cryptocurrencies that the SEC has determined to be securities or that we believe are likely to be determined to be securities.

We continue to analyze the cryptocurrencies supported on the RHC and Bitstamp US platforms under our Crypto Listing Frameworks and Bitstamp’s similar internal policies, respectively, on a periodic basis to ensure that they continue to meet the applicable internal requirements for continued support on the RHC
124

Table of Contents

and Bitstamp US platforms which include, among other factors, that we continue to believe they are not securities under relevant U.S. federal and state securities laws. We may make the determination to cease support for a cryptocurrency for any one or a variety of factors based on a totality of the circumstances under our Crypto Listing Frameworks and Bitstamp’s similar internal policies, as applicable. However, an assertion or determination by the SEC or a court that a cryptocurrency supported by our RHC or Bitstamp US platforms constitutes a security could also result in our determination that it is advisable to remove that cryptocurrency and others with similar characteristics to the cryptocurrency that was asserted or determined to be a security from our RHC or Bitstamp US platforms. If we proactively remove certain cryptocurrencies from our RHC or Bitstamp US platforms because the SEC, a state, or a court has asserted or determined they constitute securities or because they share similarities with such cryptocurrencies or otherwise do not meet our Crypto Listing Frameworks and Bitstamp’s similar internal policies, as applicable, it has and could in the future negatively impact customer sentiment and our business, operating results, and financial condition, especially to the extent that our competitors continue to support such cryptocurrency on their platforms.

In addition, in June 2025, we launched “Classic Stock Tokens” (formerly “Robinhood Stock Tokens”) in certain jurisdictions in the EEA, which are designed to provide eligible customers in the EEA with exposure to certain U.S. exchange-listed stocks and ETPs. While we currently only offer Classic Stock Tokens in the EEA, because the assets underlying the tokens are certain U.S. stocks and ETPs, the SEC could assert jurisdiction over our Classic Stock Token offering and claim that transactions in our Classic Stock Tokens must be conducted in compliance with applicable federal laws and regulations. See “-Our launch of Stock Tokens globally, continued offering of Classic Stock Tokens and perpetual futures trading in the EEA, and updates to Robinhood Wallet to allow eligible users in selected jurisdictions to access Stock Tokens and decentralized perpetual futures via a third party decentralized exchange within the Robinhood Wallet may expose us to significant regulatory, litigation, contractual, operational, and reputational risks” for more information.

If the SEC, a state regulator or a private litigant alleges that staking or onchain lending services we offer in the U.S. involve unregistered offers and sales of securities or unregistered securities broker-dealer activity in violation of federal securities laws or applicable state laws or regulations, and the courts agree with such plaintiff, we may be required to cease our staking or onchain lending activities and may be subject to monetary penalties and other sanctions.

In July 2026, we launched Robinhood Earn. In several enforcement actions filed by the SEC under the prior Chair, the SEC alleged that certain companies had offered retail crypto lending products as unregistered securities. For example, in February 2022, the SEC settled charges against BlockFi Lending LLC for failing to register its BlockFi Interest Accounts and in January 2023, the SEC settled charges against Nexo Capital Inc. In January 2023, the SEC filed a complaint against Genesis Global Capital, LLC (“Genesis”) and Gemini Trust Company, LLC (“Gemini”) for failing to register the Gemini Earn program, which was followed by several related actions by New York regulators against Genesis and Gemini. The SEC settled its charges against Genesis in March 2024, followed by Genesis’ May 2024 settlement with the New York Attorney General. Gemini entered settlements with the New York State Department of Financial Services and the New York Attorney General in February and June of 2024, respectively, after which the SEC exercised its discretion to dismiss its charges against Gemini in January 2026. On July 22, 2026, SEC Commissioner Hester M. Peirce released a public statement highlighting that crypto vaults and lending strategies may, depending on the specific facts and circumstances, implicate the federal securities laws. Commissioner Peirce’s statement also encouraged engagement from market participants and the public on whether modifications to SEC rules may be necessary to accommodate crypto vaults, onchain lending, or other innovations, while still “ensuring that investors are protected, markets are fair, orderly, and efficient, and capital formation is facilitated.”

In June 2025, we launched crypto staking services to eligible customers in certain jurisdictions in the U.S. In several enforcement actions filed by the SEC under the prior administration, the SEC alleged that
125

Table of Contents

certain companies had offered staking services to retail customers for various digital assets as unregistered securities or acted as unregistered securities broker-dealers in facilitating offers or sales of third-party staking services in violation of the registration provisions of the Securities Act or the Exchange Act. For example, as described under “-Risks Related to Cryptocurrency Products and Services-In the U.S., any particular cryptocurrency’s status as a “security” and cryptocurrency transaction’s status as an “investment contract” is subject to a high degree of uncertainty and if we have not properly characterized one or more cryptocurrencies or cryptocurrency transactions, we might be subject to legal and regulatory scrutiny, investigations, fines, and other penalties.” In 2023, the SEC charged Kraken, Coinbase and Binance with offering and selling digital asset staking-as-a-service programs to retail customers as unregistered investment contract schemes in violation of the Securities Act. In June 2024, the SEC charged Consensys Software Inc. with acting as an underwriter of unregistered securities in violation of the Securities Act and as an unregistered broker in violation of the Exchange Act by marketing the Lido and Rocket Pool third-party liquid staking-as-a-service programs to retail customers through Consensys’ “Metamask Staking” platform. In March 2025, the SEC filed a joint stipulation with Consensys to dismiss, with prejudice, the Commission’s enforcement action against it. As noted above, the litigation against Binance, Coinbase and Kraken has also been dismissed.

We believe that our staking and onchain lending services do not offer or sell any “securities” subject to the securities laws or SEC regulations. We also believe that the structure, terms, and other characteristics of the staking services offered by RHC generally align with those described in the SEC’s March 2026 interpretation clarifying how the federal securities laws apply to certain types of crypto assets and certain transactions involving crypto assets, wherein the SEC stated that protocol staking activities of the nature described therein do not involve the offer and sale of a security. However, the SEC’s interpretation is not binding on any court or other agency and there is no guarantee that the SEC will agree with our assessment of our staking services. Accordingly, we do not know if the SEC or the courts will ultimately agree with our interpretation of the applicable federal laws or regulations.

In addition, there is no guarantee that state regulators will agree with our interpretation of applicable state laws or regulations. For example, several state regulators have issued cease and desist orders to, or filed lawsuits against, Coinbase with respect to its staking services, alleging that Coinbase’s staking services constitute unregistered securities offerings under applicable state laws and regulations. While certain of the state regulators have since dismissed their lawsuits against Coinbase with respect to its staking services, not all state regulators have done so.

If the SEC, a state regulator, or a private litigant were to prevail on claims that our staking or onchain lending services offered in the U.S. violate the Securities Act, Exchange Act or applicable state laws and regulations, we may be subject to monetary penalties, liabilities, reputational harm, and may be required to cease offering these services.

Cryptocurrency laws, regulations, regulatory guidance, regulatory interpretations, and accounting standards are often difficult to interpret and are rapidly evolving in ways that are difficult to predict. Changes in these laws and regulations, or our failure to comply with them, could negatively impact cryptocurrency trading on our platforms.

Domestic and foreign regulators and governments are increasingly focused on the regulation of cryptocurrencies. In the U.S., cryptocurrencies are regulated by both federal and state authorities, depending on their use. For example, on October 13, 2023, California enacted the DFAL, which became effective on July 1, 2026, and prohibits any person or entity from engaging in, or holding itself out as engaging in, digital financial asset business activity with or on behalf of a California resident (including businesses with a place of business in California) unless that person or entity (i) holds a license under the DFAL, (ii) has submitted a license application on or before July 1, 2026 and is awaiting approval or denial, or (iii) is exempt from licensure. Once licensed, a licensee must comply with requirements related to
126

Table of Contents

record maintenance, fee and risk disclosures, cybersecurity, customer protection, anti-fraud, and AML. We have submitted applications for licenses under DFAL in connection with our cryptocurrency trading operations in California. In addition, the NYDFS requires any person or entity engaging in virtual currency activity for third parties in or involving New York, excluding merchants and consumers, to obtain a license, commonly referred to as a “BitLicense”, from the NYDFS and to comply with AML, cybersecurity, consumer protection, and financial and reporting requirements, among others, or, alternatively, to be chartered under the New York Banking Law and be approved by the NYDFS to engage in virtual currency business activity. We will continue to monitor developments in state-level legislation, guidance, and regulations applicable to us. Cryptocurrency market disruptions and resulting governmental interventions are unpredictable, and may render cryptocurrencies, or certain cryptocurrency business activities, illegal. As regulation of cryptocurrencies continues to evolve, there is a substantial risk of inconsistent regulatory guidance among federal and state agencies and among state governments which, along with potential accounting and tax issues and other requirements relating to cryptocurrencies, could impede the growth of our cryptocurrency operations. Additionally, regulation in response to the climate impact of cryptocurrency mining could negatively impact cryptocurrency trading on our platforms.

The cryptocurrency accounting rules and regulations that we must comply with are complex and subject to interpretation by the FASB, the SEC, and various bodies that promulgate and interpret accounting principles. A change in these rules, regulations, or interpretations could significantly impact our reported results of operations and financial condition, and could also affect the reporting of transactions completed before the announcement or effectiveness of a change. Further, there are limited precedents for the financial accounting treatment of cryptocurrency assets, including valuation and revenue recognition. While the staff of the SEC’s Division of Trading and Markets provided certain limited FAQ guidance on May 15, 2025 with respect to net capital considerations, no formal guidance has been provided by the FASB or the SEC. Accordingly, there remains significant uncertainty regarding the appropriate accounting for cryptocurrency asset transactions, cryptocurrency assets, and related revenues. Uncertainties in, or changes to regulatory or financial accounting standards could require us to change our accounting methods or restate our financial statements, and could impair our ability to provide timely and accurate financial information, which could adversely affect our financial statements, and result in a loss of investor confidence.

In addition, future regulatory actions or policies, including, the assertion of jurisdiction by domestic and foreign regulators and governments over cryptocurrency and cryptocurrency markets could limit or restrict cryptocurrency usage, custody, or trading, or the ability to convert cryptocurrencies to fiat currencies. This includes recent legislative actions related to the CLARITY Act, and the GENIUS Act. See “-Risks Related to Regulation and Litigation-Our business is subject to extensive, complex, and changing laws and regulations, and related regulatory proceedings and investigations. Changes in these laws and regulations, or our failure to comply with these laws and regulations, could harm our business.” Additionally, some lawmakers and regulators have raised questions about Transaction Rebates from cryptocurrency trading. Transaction Rebates from cryptocurrency trading have historically comprised, and might continue to comprise, a significant percentage of our total net revenues. The current presidential administration and the control of Congress also present considerable uncertainty regarding such regulatory actions or policies. Any future regulatory actions or policies could reduce demand for cryptocurrency trading and might materially decrease our revenue derived from Transaction Rebates in absolute terms and as a proportion of our total revenues.

The legal framework governing the characterization of cryptocurrencies held “in custody,” including whether and how such assets are treated as customer property versus property of an insolvency estate, remains evolving and may differ by jurisdiction and by product structure, contractual terms, and operational facts. In certain prior bankruptcy proceedings, cryptocurrencies held in custody on behalf of customers have become subject to the claims of creditors, the automatic stay, court-supervised distribution processes, or other restrictions, and customers have been treated as general unsecured creditors with respect to some or all of their cryptocurrency entitlements. However, based on the terms of
127

Table of Contents

our user agreement, the structure of our crypto offerings, and applicable law, and, although we have not obtained a formal legal opinion on this matter, after consultation with internal and external legal counsel, we believe that the cryptocurrency we hold in custody for users of our platforms should be respected as users’ property (and should not be available to satisfy the claims of our general creditors) in the event we were to enter bankruptcy. Although we are well-capitalized, to the extent users are concerned that cryptocurrencies might not be secure in a bankruptcy generally, their willingness to hold crypto in custodial accounts and their general interest in trading cryptocurrencies might decline.

The Infrastructure Investment and Jobs Act significantly changes the tax reporting requirements applicable to brokers and holders of cryptocurrency and digital assets. On August 25, 2023, the U.S. Department of the Treasury and the Internal Revenue Service released proposed regulations on the sale and exchange of digital assets by brokers. On June 28, 2024, final regulations were issued that require information reporting by digital asset brokers on certain digital asset sales or exchanges that occur on or after January 1, 2025, and basis tracking for digital assets that are treated as “covered securities” if acquired on or after January 1, 2026. Starting on or after January 1, 2027, backup withholding will be required on certain sales and exchanges of cryptocurrency and digital assets where customer tax documentation is missing or invalid. Implementing these requirements, and any further legislative changes or related guidance from the Internal Revenue Service and the U.S. Department of the Treasury, might significantly impact our tax reporting and withholding processes and result in increased compliance costs. Failure to comply with these new information reporting and withholding requirements might subject us to significant tax liabilities and penalties. Similarly, the OECD has published final guidance on a new “crypto-asset reporting framework” and amendments to the existing global “common reporting standard” that might apply to our international operations. These new rules might give rise to potential liabilities or disclosure requirements, and implementation may have a significant impact on our operations and result in increased costs.

Our continued efforts to expand our business internationally also subject us to additional laws, regulations, and other governmental or regulatory scrutiny as discussed in “-Risks Related to Our Business-We currently operate in certain international markets and plan to further expand our international operations, which exposes us to significant new risks, and our international expansion efforts might not succeed” and “-Risks Related to Regulation and Litigation-Our business is subject to extensive, complex and changing laws and regulations, and related regulatory proceedings and investigations. Changes in these laws and regulations, or our failure to comply with these laws and regulations, could harm our business.” Various foreign jurisdictions have adopted, and may continue to adopt laws, regulations or directives that affect crypto-asset industry participants, the crypto-asset markets, and their users, particularly trading platforms and service providers that fall within such jurisdictions’ regulatory scope. For example, the provisions of MiCA went into effect as of December 30, 2024, and the FCA announced new proposals for certain aspects of the prudential requirements for crypto firms. See “Risks Related to Our Business- We have in the past needed, and may in the future need, additional capital to provide liquidity and support business growth and objectives, and this capital might not be available to us on reasonable terms, if at all, might result in stockholder dilution, or might be delayed or prohibited by applicable regulations” for more information. Accordingly, in addition to the licenses RHEU and Bitstamp Financial Services Ltd. obtained under MiFID, RHEU and Bitstamp Europe S.A. have obtained licenses to operate as crypto asset service providers under MiCA. As noted above, monitoring and maintaining our compliance with the laws and regulations to which we are subject is complex and requires significant resources. Any failure to comply with applicable laws and regulations could result in regulatory fines, suspensions of personnel or other sanctions, including revocation of our registration or that of our subsidiaries, which could, among other things, require changes to our business practices and scope of operations or harm our reputation, and, in turn could have a material adverse effect on our results of operations, financial condition or business. New laws or regulations, or new interpretations of existing laws or regulations, could have a materially adverse impact on our ability to operate as currently intended, or require us to obtain additional or newly created registrations or licenses and incur significant expense in order to ensure compliance. Additionally, under recommendations from FinCEN, and the Financial
128

Table of Contents

Action Task Force, the United States and several international jurisdictions in which RHEU or Bitstamp operate have imposed the Funds Travel Rule and the Funds Transfer Rule (collectively the “Travel Rule”) on financial service providers in the cryptoeconomy. We may incur high costs to implement and comply with the Travel Rule, could face penalties for technical violations, and could lose customers if compliance negatively affects customer service experience.

Our Crypto Transfers, crypto staking and onchain lending, Robinhood Wallet, Robinhood Connect, and Robinhood Earn features could result in loss of customer assets, customer disputes, and other liabilities, which could harm our reputation and adversely impact trading volumes and transaction-based revenues.

In the U.S., we allow customers to deposit and withdraw cryptocurrencies to and from our RHC and Bitstamp platforms through our Crypto Transfers feature in the states in which RHC or Bitstamp operates. We also allow customers of RHEU to deposit and withdraw crypto to and from our RHEU platform. Bitstamp also allows its customers to deposit and withdraw crypto to and from the Bitstamp platform. Crypto Transfers are processed using Robinhood’s or Bitstamp’s general custodial infrastructure in which we hold some cryptocurrencies on behalf of customers; when transactions are completed, coins are allocated to and from individuals’ accounts in our customer records. Additionally, RHC U.S. customers have access to Robinhood Connect, allowing their customers to use their RHC accounts to buy and transfer crypto, and fund their self-custody wallets.

Crypto Transfers initiated by users are subject to a heightened risk of user error. Under blockchain protocol, recording a transfer of cryptocurrency on the blockchain involves both the private key of the sending wallet and the unique public key of the receiving wallet. Such keys are strings of alphanumeric characters. For a customer to receive cryptocurrency on our platforms, the customer needs to arrange for the owner of an external source wallet to “sign” a transaction with the private key of that external wallet, directing a transfer of the cryptocurrency to our receiving custodial wallet by inputting the public key (which we provide to the customer) of our custodial wallet. Similarly, in order to withdraw cryptocurrency from our platforms, the customer needs to provide us with the public key of the external wallet to which the cryptocurrency is to be transferred, and we “sign” the transaction using the private key of our wallet. Some crypto networks might require additional information to be provided in connection with any transfer of cryptocurrency to or from our platforms. A number of errors could occur in the process of depositing or withdrawing cryptocurrencies to or from our platforms, such as typos, mistakes, or the failure to include information required by the blockchain network. For instance, a user might include typos when entering our custodial wallet’s public key or the desired recipient’s public key when depositing to and withdrawing from our platforms, respectively. Alternatively, a user could mistakenly transfer cryptocurrencies to a wallet address that he or she does not own or control, or for which the user has lost the private key. In addition, each wallet address is compatible only with the underlying blockchain network on which it is created. For instance, a Bitcoin wallet address can be used to send and receive Bitcoin only. If any Ethereum, Dogecoin, or other cryptocurrency is sent to a Bitcoin wallet address, for example, or if any of the other foregoing errors occur, such cryptocurrencies could be permanently and irretrievably lost with no means of recovery.

We also provide crypto staking services through our RHC, RHEU and Bitstamp platforms in which eligible customers of RHC, RHEU and Bitstamp are given the option to “stake” eligible crypto-assets. Staking allows customers to earn rewards by locking up the cryptocurrencies, subject to the network and cryptocurrency’s requirements and bonding periods, and so limits customers’ access to their funds during such time. Once a customer chooses to opt in to our staking services, we delegate the amount of crypto-assets identified by such customer for staking to a validator operated by either (i) RHC, RHEU or Bitstamp, as applicable, or (ii) a third-party service provider we engage in connection with such services. Some networks may further require customer assets to be transferred into smart contracts on the underlying blockchain networks not under our or anyone’s control. If our third-party service provider or any such smart contracts fail to behave as expected, suffer cybersecurity attacks, experience security
129

Table of Contents

issues, or encounter other problems, customers’ assets may be irretrievably lost. In addition, certain blockchain networks dictate requirements for participation in the relevant decentralized governance activity, and may impose penalties, or “slashing,” if the relevant activities are not performed correctly, such as if the staker, delegator, or baker acts maliciously on the network, “double signs” any transactions, or experiences extended downtimes. If we or our third-party service provider is slashed by the underlying blockchain network, customers’ assets may be confiscated, withdrawn, or burnt by the network, resulting in losses for which we may be responsible. Furthermore, certain types of staking require the payment of transaction fees on the underlying blockchain network, and such fees can become significant as the amount and complexity of the transaction grows, depending on the degree of network congestion and the price of the network token. If we experience a high volume of such staking requests from customers on an ongoing basis, we could incur significant costs.

Bitstamp Europe S.A., Bitstamp Limited and Bitstamp Global Limited market crypto-asset lending services which are provided directly to customers by a third-party service provider. Customers lend their crypto-assets directly to a third party and the third party then on-lends to borrowers. Customer crypto-assets leave the custody of Bitstamp when customers access these services. There is a risk that borrowers may default on loans by the third-party service provider causing a financial loss to customers and in a worst case scenario the insolvency of the third-party service provider or its related group companies. Any of these risks could negatively impact our reputation, business, financial condition, and results of operations and discourage existing and future customers from utilizing our products and services.

With Robinhood Wallet, our self-custody, web3 wallet, users have sole access and control over their cryptocurrencies on certain networks and personally hold and maintain their private keys. Additionally, Robinhood Earn, provides a software interface allowing customers to create and manage a self-custody wallet to engage in onchain lending. Although we do not custody cryptocurrencies held in a user’s Robinhood Wallet or self-custody wallet created in connection with Robinhood Earn, and do not have access to users’ private keys, users who lose their private keys, and thus access to their Robinhood Wallet or self-custody wallet balances, may react negatively. Although our account agreements for Crypto Transfers, licensing agreements for Robinhood Wallet, and the Robinhood Onchain Lending Disclosure disclaim responsibility for losses caused by user errors, such incidents could result in user disputes, damage to our brand and reputation, legal claims against us, and financial liabilities.

Additionally, allowing customers to deposit and withdraw cryptocurrencies to and from our platforms increases the risk that our platforms might be exploited to facilitate illegal activity such as fraud, gambling, money laundering, tax evasion, and scams. Crypto Transfers, Robinhood Wallet, Robinhood Connect, and Robinhood Earn also expose us to heightened risks related to potential violations of trade sanctions, including OFAC regulations, and AML and counter-terrorist financing laws, which among other things impose strict liability for transacting with prohibited persons. We engage blockchain analytics vendors to help determine whether the external wallets involved in Crypto Transfers are controlled by persons on prohibited lists or involved in fraudulent or illegal activity. However, fraudulent and illegal transactions and prohibited status could be difficult or impossible for us and our vendors to detect in some circumstances. The use of our platforms for illegal or improper purposes could subject us to claims, individual and class action lawsuits, and government and regulatory investigations, prosecutions, enforcement actions, inquiries, or requests that could result in significant liabilities and reputational harm for us and could cause cryptocurrency trading volumes and transaction-based revenues to decline.

A temporary or permanent blockchain “fork” could adversely affect our business.

Most blockchain protocols, including Bitcoin and Ethereum, are open source. Any user can download the software, modify it and then propose that users and miners of Bitcoin, Ethereum or other blockchain protocols adopt the modification. When a modification is introduced and a substantial majority of miners consent to the modification, the change is implemented and the Bitcoin, Ethereum or other blockchain
130

Table of Contents

protocol networks, as applicable, remain uninterrupted, although such modifications might cause certain cryptocurrencies to fail our Crypto Listing Frameworks. However, if less than a substantial majority of users and miners consent to the proposed modification, and the modification is not compatible with the software prior to its modification, the consequence would be what is known as a “fork” (i.e., “split”) of the impacted blockchain protocol network and respective blockchain with one prong running the pre-modified software and the other running the modified software. The effect of such a fork would be the existence of two versions of the Bitcoin, Ethereum or other blockchain protocol network, as applicable, running simultaneously, but with each split network’s cryptocurrency lacking interchangeability.

Both Bitcoin and Ethereum protocols have been subject to “forks” that resulted in the creation of new networks, including, among others, Bitcoin Cash, BSV, Bitcoin Diamond, Bitcoin Gold, Ethereum Classic, and Ethereum Proof-of-Work. Some of these forks have caused fragmentation among platforms as to the correct naming convention for forked cryptocurrencies. Due to the lack of a central registry or rulemaking body in the cryptocurrency market, no single entity has the ability to dictate the nomenclature of forked cryptocurrencies, causing disagreements and a lack of uniformity among platforms on the nomenclature of forked cryptocurrencies, and which results in further confusion to customers as to the nature of cryptocurrencies they hold on platforms. In addition, several of these forks were contentious and as a result, participants in certain communities might harbor ill will towards other communities. As a result, certain community members might take actions that adversely impact the use, adoption and price of Bitcoin, Ethereum or any of their forked alternatives.

Furthermore, forks can lead to disruptions of networks and our information technology systems, cybersecurity attacks, replay attacks, or security weaknesses, any of which can further lead to temporary or even permanent loss of customer cryptocurrencies. For instance, when the Ethereum and Ethereum Classic networks split in July 2016, replay attacks, in which transactions from one network were rebroadcast on the other network to achieve “double-spending,” plagued platforms that traded Ethereum through at least October 2016, resulting in significant losses to some cryptocurrency platforms. Another possible result of a fork is an inherent decrease in the level of security due to the splitting of some mining power across networks, making it easier for a malicious actor to gain the majority of the mining power of that network. Such disruption and loss could cause our company to be exposed to liability, even in circumstances where we have no intention of supporting a cryptocurrency compromised by a fork.

Moreover, we might decide not to or not be able to support a cryptocurrency resulting from the fork of a network which might cause our customers to lose confidence in us or reduce their engagement on our platforms. In assessing whether we will support a cryptocurrency resulting from the fork of a network, among our top priorities is to safeguard our customers’ assets, and we spend extensive time designing, building, testing, reviewing and auditing our systems to check whether the cryptocurrencies we support remain safe and secure. There are several considerations that we consider as part of our Crypto Listing Frameworks (including security or infrastructure concerns that might arise with the integration of any new cryptocurrency into the technical infrastructure that allows us to secure customer cryptocurrencies and to transact securely in corresponding blockchains), which might operate to limit our ability to support forks. Further, we generally do not support a forked cryptocurrency that does not have support from a majority of the affiliated third-party miner and developer community. To the extent that we decide not to support, or to cease support of, certain forked cryptocurrencies, it could negatively impact customer sentiment and our business, operating results, and financial condition, especially to the extent that our competitors continue to support such forked cryptocurrencies on their platforms.

Whether we are obligated to provide services for a new and previously unsupported cryptocurrency is a question of contract, as recognized in recent published rulings of the California appellate courts and federal district courts. The user agreement each customer enters into in order to trade cryptocurrencies on our platforms clearly indicates that we have the sole discretion to determine whether we will support a forked network and the approach to such forked cryptocurrencies and that we may temporarily suspend trading for a cryptocurrency whose network is undergoing a fork without advance notice to the customer.
131

Table of Contents

Regardless of the foregoing, we might in the future be subject to claims by customers arguing that they are entitled to receive certain forked cryptocurrencies by virtue of cryptocurrencies that they hold with us. If any customers succeed on a claim that they are entitled to receive the benefits of a forked cryptocurrency that we do not or are unable to support, we might be required to pay significant damages, fines or other fees to compensate customers for their losses.

Any inability to maintain adequate relationships with third-party banks, Liquidity Providers, and cryptocurrency exchanges with respect to, and any inability to settle customer trades related to, our cryptocurrency offerings, would disrupt our ability to offer cryptocurrency trading to customers.

We rely heavily on third-party banks, Liquidity Providers, and cryptocurrency exchanges in connection with our provision of cryptocurrency products and services to our customers, with the exception of a cryptocurrency exchange operated by Bitstamp and acquired by Robinhood in June 2025. The cryptocurrency market operates 24 hours a day, seven days a week. The cryptocurrency market does not have a centralized clearinghouse, and the transactions in cryptocurrencies on our platforms rely on direct settlements between us and our customers and direct settlements between us and our Liquidity Providers or cryptocurrency exchanges after customer trades are executed. Accordingly, we rely on third-party banks to facilitate cash settlements with customers’ brokerage accounts, and we rely on the ability of Liquidity Providers and Bitstamp, where applicable, to complete cryptocurrency settlements with us to obtain cryptocurrency for customer accounts. In addition, we must maintain cash assets in our bank accounts sufficient to meet the working capital needs of our business, which includes deploying available working capital to facilitate cash settlements with our customers, Liquidity Providers and cryptocurrency exchanges (as well as maintaining the minimum capital required by regulators). If we, third-party banks, Liquidity Providers, or cryptocurrency exchanges have operational failures and cannot perform and facilitate our routine cash and cryptocurrency settlement transactions, we will be unable to support normal trading operations on our cryptocurrency trading platforms, and these disruptions could have an adverse impact on our business, financial condition and results of operations. Similarly, if we fail to maintain cash assets in our bank accounts sufficient to meet the working capital needs of our business and necessary to complete routine cash settlements related to customer trading activity, such failure could impair our ability to support normal trading operations on our cryptocurrency platforms, which could cause cryptocurrency trading volumes and transaction-based revenues to decline significantly.

We might also be harmed by the loss of any of our banking partners and Liquidity Providers. As a result of the risks of cryptocurrencies generally, many financial institutions have decided, and other financial institutions might in the future decide, not to provide bank accounts (or access to bank accounts), payments services, or other financial services to companies providing cryptocurrency products, including us. For instance, in May 2023, two prominent Liquidity Providers announced their respective decisions to limit their offerings in cryptocurrency trading within the U.S. If we, our cryptocurrency exchanges or our Liquidity Providers cannot maintain sufficient relationships with the banks that provide these services, if banking regulators restrict or prohibit banking of cryptocurrency businesses, if these banks impose significant operational restrictions, or if these banks were to fail or be taken over by the FDIC, such as occurred in the 2023 Banking Events, it could be difficult for us to find alternative business partners for our cryptocurrency offerings, which would disrupt our business and could cause cryptocurrency trading volumes and transaction-based revenues to decline significantly.

We might also be harmed by the loss of any of our liquidity partners. Unlike our customers’ orders for other cryptocurrencies, which are currently fulfilled by Liquidity Providers, our RHC customers’ orders for USDC and USDG, stablecoins backed by dollar denominated assets held by their respective issuer in segregated accounts with U.S. regulated financial institutions, are fulfilled directly from Circle, the original issuer and main liquidity provider of USDC, and Paxos, the issuer and main liquidity provider of USDG. If we cannot maintain sufficient relationships with Circle, Paxos, or any other Liquidity Providers, it could be difficult for us to find alternative liquidity partners for our stablecoin offerings, including our support of
132

Table of Contents

USDG in connection with Robinhood Earn, which would disrupt our business and could cause cryptocurrency trading volumes and transaction-based revenues to decline significantly.

From time to time, we might encounter technical issues in connection with changes and upgrades to the underlying networks of supported cryptocurrencies, which could cause revenues to decline and expose us to potential liability for customer losses.

Any number of technical changes, software upgrades, soft or hard forks, cybersecurity incidents or other changes to the underlying blockchain networks might occur from time to time, causing incompatibility, technical issues, disruptions or security weaknesses to our platforms. If we are unable to identify, troubleshoot and resolve any such issues successfully, we might no longer be able to support such cryptocurrency, our customers’ assets might be frozen or lost, the security of our hot or cold wallets might be compromised and our platforms and technical infrastructure might be affected, all of which could cause trading volumes and transaction-based revenue to decline and expose us to potential liability for customer losses.

Robinhood Chain is a permissionless, open blockchain network, and its failure to achieve sufficient adoption, technical vulnerabilities or protocol failures affecting the network, and the exploitation of the network for illicit activity could each adversely affect our business, financial condition, and results of operations.

In July 2026, we launched the Robinhood Chain, a permissionless, Ethereum-compatible Layer 2 blockchain built for financial services and tokenized real-world assets. Robinhood Chain is designed to be permissionless and developer-friendly, meaning that, in supported jurisdictions, developers can deploy or build smart contracts and applications and users can access, or transfer on Robinhood Chain, in each case without our approval. As a result, much of the activity that occurs on Robinhood Chain is conducted by independent third parties—including developers, applications, and users—and may be difficult or impossible for us to monitor, influence, prevent, or reverse. Nevertheless, we may bear reputational, legal, financial, and regulatory consequences arising from activity on Robinhood Chain even where the underlying conduct, code, or decision is that of a third party.

Robinhood Chain may fail to achieve sufficient adoption to support a viable, self-sustaining ecosystem. The market for blockchain infrastructure is highly competitive and rapidly evolving. Robinhood Chain competes for developers, applications, transaction volume, and users against a large number of established and emerging blockchain networks, many of which may benefit from greater brand recognition and broader integrations with third-party infrastructure and applications with which to attract developers and users. If Robinhood Chain fails to attract and retain a sufficient base of developers, applications, and active users relative to these competing networks, it may not achieve the transaction volume, liquidity, or network effects needed to support a viable, self-sustaining ecosystem. Our ability to generate revenue from Robinhood Chain depends significantly on the level of adoption and developer activity on the network. If Robinhood Chain fails to achieve sufficient adoption or loses market share to competing networks, our investment in developing and maintaining Robinhood Chain may fail to generate an adequate return, we may be required to recognize impairments related to that investment, and our financial condition and results of operations could be adversely affected. Insufficient adoption could also weaken the value of other products we build on or integrate with Robinhood Chain, including Stock Tokens, Robinhood Earn, Robinhood Wallet, and other digital asset offerings, compounding any adverse impact on our business.

Robinhood Chain may also be subject to technical risks, including software vulnerabilities, bugs, and failures that could result in loss of assets or network downtime. Furthermore, Robinhood Chain may contain coding errors, security flaws, or other defects that have not yet been identified. Because blockchain security practices are still maturing, even extensive audits may not catch every vulnerability. Should bad actors identify and exploit such vulnerabilities, or otherwise successfully attack the network,
133

Table of Contents

the consequences could include loss or theft of digital assets held on or transacted through Robinhood Chain, reputational harm, legal liability, and erosion of user confidence in the network. Because Robinhood Chain is a Layer 2 network built on the Ethereum blockchain, its security and operation depend in part on Ethereum itself. As a result, disruptions or vulnerabilities at the Ethereum layer, including bugs, consensus failures, network congestion, or advances in computing technology such as quantum computing that could undermine the cryptography underlying Ethereum, could adversely affect Robinhood Chain. We do not control, and have limited ability to influence, Ethereum's security or development. Any such event could result in loss or theft of digital assets, network downtime, and reputational harm. We expect that Robinhood Chain's underlying protocol will need to be upgraded from time to time to remediate newly discovered vulnerabilities, improve network performance, add new functionality, or comply with evolving regulatory requirements. Implementing such upgrades is inherently complex and carries meaningful execution risk: an upgrade could be delayed, fail to achieve its intended purpose, introduce unforeseen bugs or incompatibilities, or require coordinated action by third-party node operators, validators, or other ecosystem participants outside our control. Any failure to execute a necessary protocol upgrade effectively, or any adverse consequence resulting from an upgrade, could disrupt Robinhood Chain, harm our reputation, and adversely affect our business, financial condition, and results of operations. Further, because Robinhood Chain is designed to support smart contracts deployed both by us and by independent third parties, coding errors or security flaws in any such contract—regardless of who authored it—could cause users to suffer losses and harm our reputation. In these circumstances, we may face reputational harm, user attrition, or legal exposure even where the underlying flaw originated in code we did not author.

In addition, Robinhood Chain may be exploited for illicit activity, including fraud, scams, money laundering, sanctions evasion, and other illicit conduct, exposing us to liability, regulatory action, and reputational harm. Blockchain networks and digital assets have historically been targeted by bad actors for these purposes. Because Robinhood Chain is permissionless, third parties can deploy applications, tokens, and other activity on the network, and some of that activity may be unlawful, deceptive, or otherwise harmful to users—conduct we do not control and may not be able to prevent. Any illegal or improper uses of Robinhood Chain by users might subject us to claims, individual and class action lawsuits, and government and regulatory requests, inquiries, or investigations that could result in liability, restrict our operations, require us to change our business practices, harm our reputation, increase our costs, and negatively impact our business.

Our launch of Stock Tokens globally, continued offering of Classic Stock Tokens and perpetual futures trading in the EEA, and updates to Robinhood Wallet to allow eligible users in selected jurisdictions to access Stock Tokens and decentralized perpetual futures via a third-party decentralized exchange within the Robinhood Wallet may expose us to significant regulatory, litigation, contractual, operational, and reputational risks.

We launched Stock Tokens in July 2026, which are tokenized debt securities issued by Robinhood Assets (Jersey) Limited (“RHJ”), a private limited company incorporated in Jersey. Stock Tokens provide economic exposure to underlying securities but do not grant investors any legal or beneficial rights in, or against the issuer of, those underlying securities. In connection with the issuance of Stock Tokens, RHJ has obtained certain consents in Jersey. However, such consents do not constitute prudential supervision of RHJ or an endorsement of Stock Tokens. The Financial Market Authority Liechtenstein, as competent authority under the EU Prospectus Regulation, has approved the Base Prospectus relating to RHJ's Tokenised Products Programme as meeting the standards of completeness, comprehensibility and consistency imposed by the EU Prospectus Regulation. Such approval is not to be considered as an endorsement of RHJ or the quality of its products. Stock Tokens are not registered under U.S. securities laws and are subject to restrictions in several jurisdictions, including, without limitation, the U.S., Canada, the United Kingdom, and Switzerland. Additionally, we updated the Robinhood Wallet in July 2026 to allow eligible users in selected jurisdictions to access Stock Tokens and decentralized perpetual futures via a third-party decentralized exchange within the Robinhood Wallet.
134

Table of Contents

In June 2025, we launched Classic Stock Tokens for eligible customers in certain EEA jurisdictions. These products are designed to provide economic exposure to the price performance of certain U.S. stocks issued by publicly-listed U.S. companies and certain U.S. ETPs, without conveying legal ownership or shareholder rights, such as voting rights, related to such underlying stocks and ETPs. From time to time, we have offered, and may offer, token products that reference privately-held U.S. companies in connection with certain limited promotional initiatives in certain EEA jurisdictions (the “Private Company Stock Token Promotion”). Such tokens and Classic Stock Tokens do not represent, or entitle the holder to receive or convert into, actual securities of the referenced companies, and the value of the tokens is based on a defined reference price such as the market price of those securities or the price of those securities upon a liquidity event.

The cryptocurrency industry is rapidly evolving, and the tokenization of real-world assets is a nascent development in the industry. Accordingly, there remains considerable regulatory uncertainty regarding how transactions, products, blockchain infrastructure, services or offerings involving tokenized real-world assets, including tokenized financial instruments, are or should be regulated. Similarly, there is considerable regulatory uncertainty regarding whether services available through Robinhood Non-Custodial Ltd. relating to tokenized real-world assets are or should be regulated. While certain lawmakers, regulators and other public officials in the U.S. and in foreign jurisdictions have previously made statements or issued guidance relating to the legal and regulatory framework applicable to tokenized real-world assets, the legal and regulatory framework is still in the early stages, is continuing to evolve rapidly and remains uncertain and fragmented across jurisdictions. For example, in July 2025, SEC Commissioner Hester M. Peirce issued a statement noting that tokenized securities are still securities, and therefore transactions involving tokenized securities are subject to federal securities laws. Advisory committees and staff of the CFTC have also discussed exploring a potential regulatory framework for tokenization of assets, including tokenized collateral.

Regulatory approaches to tokenized real-world assets and self-custody wallets outside of the U.S. are similarly in the early stages and vary by jurisdiction. For example, in the EU, MiCA and MiFID operate as complementary regimes within the EU’s financial regulatory framework, with MiCA governing crypto-assets that do not qualify as financial instruments and MiFID continuing to apply to crypto-assets that meet the definition of financial instruments. Accordingly, the application of MiCA or MiFID depends on the characteristics of the specific tokenized real-world asset. In Singapore, the MAS has issued guidance stating that a crypto-asset may constitute, among other things, a “share” where it confers or represents ownership interest in a corporation or a “securities-based derivatives contract” where the underlying asset is a share, debenture or unit in a business, which would require transactions in such crypto-assets to be conducted in compliance with applicable law and the applicable licenses.

We have offered Classic Stock Tokens and the Private Company Stock Token Promotion to eligible customers of RHEU in certain jurisdictions in the EEA and may offer similar tokens or promotions in the same or different jurisdictions in the future, and while we believe that such operations are, were, and will be in compliance with MiFID requirements applicable to derivatives (or other applicable requirements to the extent we offer similar tokens or promotions in different jurisdictions in the future), we cannot ensure that regulators would agree with our conclusions. For example, we have received requests for clarifications from the Bank of Lithuania, which has issued RHEU licenses under MiCA and MiFID, regarding our Classic Stock Tokens and the Private Company Stock Token Promotion in connection with the launch of that offering. Responding to such requests may divert management attention and require us to expend additional resources. If the Bank of Lithuania determines that our Classic Stock Token offering or the Private Company Stock Token Promotion is not being conducted in compliance with applicable laws or regulations, such determination could result in financial penalties or other non-monetary penalties, limitation of certain of our business activities (including with respect to our Classic Stock Token offering), loss or non-renewal of existing licenses or authorizations, increased scrutiny from other regulators, loss of our customers and reputational harm.
135

Table of Contents

In addition, any change in applicable laws or regulations, or change in interpretations of existing laws or regulations, could have a materially adverse impact on our ability to operate our Stock Tokens and Classic Stock Token offerings as currently intended. In addition, because the assets underlying our Stock Tokens, Classic Stock Tokens, and the Private Company Stock Token Promotion are certain U.S. securities, the SEC or other U.S. regulators, including the CFTC, could assert jurisdiction over our Stock Token offering or Classic Stock Token offering or the Private Company Stock Token Promotion and claim that transactions in related tokens must be conducted in compliance with applicable U.S. laws and regulations. Such a determination could result in lawsuits, regulatory action and enforcement proceedings that result in injunctions, fines, penalties and other monetary damages, and could require us to obtain additional registrations or licenses in the future and cause us to incur significant expenses in order to ensure compliance with applicable laws and regulations.

We may also face contractual or legal challenges from the issuers of the referenced securities. Some companies, particularly private companies with transfer restrictions, may object to the creation of synthetic instruments such as tokens which reference the companies’ securities and are facilitated by Robinhood or one of its affiliates holding an interest in a SPV that holds the referenced securities or instruments representing a contingent interest in the referenced securities. In such cases, the issuer may assert that our interest in the SPV is invalid, void or otherwise unenforceable, or that we have violated or induced or assisted in the violation of, applicable transfer restrictions, which could result in a loss or impairment of the SPV’s rights to the underlying securities, which could in turn prevent us from effectively hedging our exposure to the associated tokens held by our customers. For example, OpenAI has publicly stated that OpenAI tokens issued in connection with the Private Company Stock Token Promotion are not OpenAI equity, that they did not partner with us and did not endorse the OpenAI tokens, and that any transfer of OpenAI equity requires OpenAI’s approval and OpenAI did not approve such transfer. Accordingly, Robinhood or our affiliates may be exposed to risks relating to litigation, reputational harm, or the need to suspend or revise affected offerings.

The Stock Token offering, Classic Stock Token offering, and the Private Company Stock Token Promotion also involved, and could involve, operational risks, in addition to existing cryptocurrency risks. They have relied on, and could rely on, accurate and timely price data, functioning systems for custody and valuation, and clear communication to customers about how the tokens work. If these systems fail, or if customers misunderstand that the tokens do not represent actual securities, we could face regulatory action, legal exposure, or reputational harm.

If we are unable to adequately manage these risks, or if regulators, issuers, or other counterparties take adverse action, our Stock Token, Classic Stock Token, or similar initiatives in the future could be curtailed or terminated, which could adversely affect our crypto and international business operations, expose us to significant liability and harm our brand.

Risks Related to Our Spending and Payments Products and Services

Our spending, payments and banking products and services subject us to risks related to bank partnerships, FDIC pass-through insurance and other regulatory obligations.

We offered a Spending Account (in connection with a partnership with J.P. Morgan Chase Bank, N.A.), and partnered, on a non-exclusive basis, with Sutton Bank (“Sutton”), an Ohio-chartered bank, pursuant to a license from Mastercard International Incorporated, to offer the Robinhood Cash Card. Under the terms of our program agreement with Sutton, Robinhood Cash Card accounts for our users were opened and maintained by Sutton. We act as the service provider to, among other things, facilitate communication between our users and Sutton for which we receive compensation from Sutton. We began
136

Table of Contents

winding down the Spending Account product in 2025 by closing inactive, unfunded accounts. The product is expected to be fully wound down by the third quarter of 2026. In the fourth quarter of 2025, we began (on an invite-only basis) offering external customers the Robinhood Banking product, which offers depository accounts and related banking services through our partner bank, Coastal Bank. Similar to the structure of the Spending Account program, we act as the service provider for Robinhood Banking to, among other things, facilitate communication between our users and Coastal Bank for which we receive compensation. Additionally, Robinhood branded credit cards are issued by Coastal Bank, a Washington-chartered bank, pursuant to a partnership with Visa U.S.A. Inc. Our partner banks are members of the FDIC.

We believe our record keeping for our users’ funds held in Robinhood Cash Card accounts at Sutton, held in a Spending Account at our other partner bank, and held in Robinhood Banking branded deposit accounts at Coastal Bank complies with all applicable requirements for each participating user’s deposits to be eligible for FDIC pass-through insurance coverage, up to the applicable maximum deposit insurance amount. However, if the FDIC were to disagree, the FDIC might not recognize users’ claims as covered by deposit insurance in the event of bank failure and bank receivership proceedings under the Federal Deposit Insurance Act. If the FDIC were to determine that our users’ funds held at our partner banks are not covered by deposit insurance, participating users might decide to withdraw their funds, which could adversely affect our brand and our business. Due to the fact that we are deemed a service-provider to our partner banks, we are subject to audit standards for third-party vendors in accordance with bank regulatory guidance and examinations by federal bank regulatory authorities and the CFPB.

As a result of the stored value Spending Account program, the Robinhood Cash Card and the Robinhood Banking program, we are subject to federal and state consumer protection laws and regulations, including the Electronic Fund Transfer Act and Regulation E as implemented by the CFPB. As a result of Robinhood Credit, we are also subject to a number of state licensing and other regulatory requirements and to payment card association operating rules, including data security rules and certification requirements, which could change or be reinterpreted to make it difficult or impossible for us to comply. Robinhood Credit is in the process of acquiring licenses in all states where required to do so. Failure to obtain or maintain these licenses, failure to comply with these rules or requirements, or conducting such activity without a license, as well as any breach, compromise, or failure to otherwise detect or prevent fraudulent activity involving our data security systems, could result in our being liable for card issuing banks’ costs, and subject to regulatory fines, penalties, or criminal charges. For example, in December 2024, Robinhood Credit paid a penalty of $200,000 to the Massachusetts Division of Banks for previously engaging in the business of a third party loan servicer in Massachusetts without the appropriate registration. Violations of any of these requirements could result in the assessment of significant actual damages or statutory damages or penalties (including treble damages in some instances) and plaintiffs’ attorneys’ fees.

The offering of consumer credit cards through Robinhood Credit increases our exposure to customer defaults and credit risk and could result in losses.

We market consumer credit cards, such as the Robinhood Gold Card and Robinhood Platinum Card, originated by our partner bank, Coastal Bank, pursuant to the Program Agreement, and indemnify Coastal Bank for certain losses under the Program Agreement. We partner with Coastal Bank to develop proprietary scoring models and other analytical techniques that are designed to set terms and credit limits to appropriately compensate for credit risk in connection with selecting customers, managing accounts and establishing terms and credit limits. The revenue generated from the Program Agreement and the extent of credit losses incurred, as well as our ability to offer competitive features such as the Robinhood Gold Card and Robinhood Platinum Card Rewards Programs, depends in part on managing credit risk while attracting new customers with profitable usage patterns. The models and approaches used to manage credit risk may not accurately predict future charge-offs and our ability to avoid high charge-off rates also may be adversely affected by general economic conditions including unemployment, the
137

Table of Contents

availability of consumer credit and the competitive environment, as well as events that may be difficult to predict, such as a general downturn in economic conditions (like the one that occurred in 2022), public health threats (like the COVID-19 pandemic), or political developments and legislative proposals targeting interest rate caps and fee and revenue restrictions. Additionally, if any of these factors make it economically unfeasible for us to continue to offer the Robinhood Gold Card and Robinhood Platinum Card Rewards Programs and we cease to offer such rewards, it might make Robinhood Credit products less desirable to customers. Any material increases in credit losses and defaults or inability to retain existing or attract new Robinhood Credit customers could have adverse effects on our financial condition and results of operations.

Use of our spending, payments, banking and other services for illegal activities or improper purposes could harm our business .

The highly automated nature of, and liquidity offered by, our spending, payments and other services to move money make us and our customers a target for illegal or improper uses, including scams and fraud directed at our stored value Spending Account, Robinhood Cash Card, Robinhood Banking accounts (including the cash delivery feature, which allows customers in supported jurisdictions to order cash directly to their residences), and Robinhood Credit customers, fraud in connection with the services we provide to the U.S. government, money laundering, terrorist financing, sanctions evasion, illegal online gambling, fraudulent sales of goods or services, illegal telemarketing activities, illegal sales of prescription medications or controlled substances, piracy of software, movies, music, and other copyrighted or trademarked goods (in particular, digital goods), bank fraud, child pornography, human trafficking, prohibited sales of alcoholic beverages or tobacco products, securities fraud, pyramid or ponzi schemes, or the facilitation of other illegal or improper activity. Moreover, certain activity that is legal in one jurisdiction might be illegal in another jurisdiction, and a customer might be found responsible for intentionally or inadvertently importing or exporting illegal goods, resulting in liability for us. Owners of intellectual property rights or government authorities might seek to bring legal action against providers of payments solutions, including Robinhood, that are peripherally involved in the sale of infringing or allegedly infringing items. While we invest in measures intended to prevent and detect illegal activities with respect to our spending, payments, and other services, these measures require continuous improvement and might not be effective in detecting and preventing illegal activity or improper uses.

Any illegal or improper uses of our spending, payments, and other services by our users might subject us to claims, individual and class action lawsuits, and government and regulatory requests, inquiries, or investigations that could result in liability, restrict our operations, require us to change our business practices, harm our reputation, increase our costs, and negatively impact our business. For example, government enforcement or regulatory authorities could seek to impose additional restrictions or liability on us arising from the use of our spending, payments, and other services for illegal or improper activity, and our failure to detect or prevent such use. Illegitimate transactions can also prevent us from satisfying our contractual obligations to our third-party partners, which might cause us to be in breach of our obligations.

Risks Related to Our Intellectual Property

Any failure to obtain, maintain, protect, defend or enforce our intellectual property rights could adversely affect our business.

Our success and ability to compete depend in part upon our ability to obtain, maintain, protect, defend and enforce our intellectual property rights and technology. The steps we take to protect our intellectual property rights might not be sufficient to effectively prevent third parties from infringing, misappropriating, diluting, or otherwise violating our intellectual property rights or to prevent unauthorized disclosure or unauthorized use of our trade secrets or other confidential information. We make business decisions
138

Table of Contents

about when to seek patent protection for a particular technology, obtain trademark or copyright protection and when to rely upon trade secret protection, and the approach we select might ultimately prove to be inadequate. We will not be able to protect our intellectual property rights, however, if we do not detect unauthorized use of our intellectual property rights. We also might fail to maintain or be unable to obtain adequate protections for some of our intellectual property rights in the U.S. and some non-U.S. countries, and our intellectual property rights might not receive the same degree of protection in non-U.S. countries as they would in the U.S. because of the differences in non-U.S. patent, trademark, copyright, and other laws concerning intellectual property and proprietary rights. In addition, if we do not adequately protect our rights in our trademarks from infringement and unauthorized use, any goodwill that we have developed in those trademarks could be lost or impaired, which could harm our brand and our business. Our trademarks might also be opposed, contested, circumvented or found to be unenforceable, weak or invalid, and we might not be able to prevent third parties from infringing or otherwise violating them or using similar marks in a manner that causes confusion or dilutes the value or strength of our brand. Similarly, our patent applications might not result in issued patents, and any patents that are issued might be opposed, challenged, or subjected to administrative proceedings, such as inter partes review or post-grant review, and could be narrowed, invalidated, or held unenforceable, which could limit our ability to prevent others from using, copying, or competing with our technology. We also hold, or may seek to obtain, design patents covering the ornamental appearance of our user interfaces and other aspects of our products. Design patents provide narrower protection than utility patents because they cover only ornamental appearance and not underlying functionality, and competitors may be able to design around them by making minor visual changes to a similar user interface while still competing effectively against us.

In addition to registered intellectual property rights, we rely on non-registered proprietary information and technology, such as trade secrets, confidential information and know-how. We attempt to protect our intellectual property, technology, and confidential information by requiring our employees, contractors, consultants, corporate collaborators, advisors and other third parties who develop intellectual property on our behalf to enter into agreements relating to confidentiality and invention assignments, and third parties we share information with to enter into nondisclosure and confidentiality agreements. However, we might not have any such agreements in place with some of the parties who have developed intellectual property on our behalf and/or with some of the parties that have or might have had access to our confidential information, know-how, and trade secrets. Even where these agreements are in place, they might be insufficient or breached, or might not effectively prevent unauthorized access to or unauthorized use, disclosure, misappropriation, or reverse engineering of our confidential information, intellectual property, or technology. Moreover, these agreements might not provide an adequate remedy for breaches or in the event of unauthorized use or disclosure of our confidential information or technology, or infringement of our intellectual property. If any of our trade secrets were to be lawfully obtained or independently developed by a competitor or other third party, we would have no right to prevent them from using that technology or information to compete with us, and our competitive position could be materially and adversely harmed.

The loss of trade secret protection could make it easier for third parties to compete with our products and services by copying functionality. Additionally, individuals not subject to invention assignment agreements might make adverse ownership claims to our current and future intellectual property, and, to the extent that our employees, independent contractors, or other third parties with whom we do business use intellectual property owned by others in their work for us, disputes might arise as to the rights in related or resulting know-how and inventions.

In addition, we might need to expend significant resources to apply for, maintain, enforce and monitor our intellectual property rights and such efforts might be ineffective and could result in substantial costs and diversion of resources. An adverse outcome in any such litigation or proceedings might expose us to a loss of our competitive position, significant liabilities, and damage to our brand, or require us to seek licenses that might not be available on commercially acceptable terms, if at all.
139

Table of Contents

We have been, currently are, and might in the future be, subject to claims that we violated third-party intellectual property rights, which, even where meritless, can be costly to defend and could materially adversely affect our business, results of operations, and financial condition.

Our success depends, in part, on our ability to develop and commercialize our products and services without infringing, misappropriating or otherwise violating the intellectual property rights of third parties. However, we might not be aware that our products, services, or marketing materials are infringing, misappropriating or otherwise violating third-party intellectual property rights and such third parties might bring claims alleging such infringement, misappropriation or violation. As we face increasing competition and become increasingly high profile, the possibility of receiving a larger number of intellectual property claims against us grows. In addition, various “non-practicing entities,” and other intellectual property rights holders have in the past and might in the future attempt to assert intellectual property claims against us or seek to monetize the intellectual property rights they own to extract value through licensing or other settlements.

Our use of third-party software and other intellectual property rights might be subject to claims of infringement or misappropriation. The vendors who provide us with technology that we incorporate in our product offerings also could become subject to various infringement claims. We may also face claims that the look and feel of our user interfaces or other product designs infringe design patents held by competitors or other third parties, and defending against such claims could require us to redesign our user interfaces, which could be costly, time-consuming, and disruptive to our business.

From time to time, our competitors or other third parties have in the past claimed, currently claim, and might in the future claim, that we are infringing upon, misappropriating or otherwise violating their intellectual property rights. We cannot predict the outcome of lawsuits and cannot ensure that the results of any such actions will not have an adverse effect on our business, financial condition, results of operations, cash flows or prospects. Any claims or litigation, even those without merit and regardless of the outcome, could cause us to incur significant expenses and, if successfully asserted against us, could require that we pay substantial costs or damages, obtain a license, which might not be available on commercially reasonable terms or at all, pay significant ongoing royalty payments, settlements or licensing fees, satisfy indemnification obligations, prevent us from offering our products or services or using certain technologies, force us to implement expensive and time-consuming work-arounds or re-designs, distract management from our business or impose other unfavorable terms.

We expect that the occurrence of infringement claims is likely to grow as the market for financial services grows and as we introduce new and updated products and services, and the outcome of any allegation is often uncertain. Accordingly, our exposure to damages resulting from infringement claims could increase and this could further exhaust our financial and management resources. Even if intellectual property claims do not result in litigation or are resolved in our favor, these claims, and the time and resources necessary to resolve them, could divert the resources of our management and require significant expenditures.

Some of our products and services contain open source software, which could pose particular risks to our proprietary software, products, and services in a manner that could harm our business.

We use open source software in our products and services (as well as in some of our internally developed systems) and we anticipate using open source software in the future. Some open source software licenses require those who distribute open source software as part of their own software product to publicly disclose all or part of the source code to such software product or to make available any derivative works of the open source code on unfavorable terms or at no cost, and we might be subject to such terms. The terms of many open source licenses to which we are subject have not been interpreted
140

Table of Contents

by U.S. or foreign courts, and there is a risk that open source software licenses could be construed in a manner that imposes unanticipated conditions or restrictions on our ability to provide or distribute our products or services. We could face claims from third parties claiming ownership of, or demanding release of, the open source software or derivative works that we developed using such software, which could include our proprietary source code, or otherwise seeking to enforce the terms of the applicable open source license. These claims could result in litigation and could require us to make our proprietary software source code freely available, purchase a costly license, or cease offering the implicated products or services unless and until we can offer a different solution, which might be a costly and time-consuming process. While we monitor our use of open source software and try to ensure that none is used in a manner that would require us to disclose our proprietary source code or that would otherwise breach the terms of an open source agreement, such use could inadvertently occur, or could be claimed to have occurred, in part because open source license terms can be ambiguous, vague, or subject to various interpretations, especially given the absence of controlling case law in the U.S. or other courts. Additionally, we may open source some of our own proprietary source code and/or may make contributions to open source software. There is a risk that our proprietary software or contributions may be used in such a manner that we may need to enforce our rights to ownership of such open source software, including seeking proper usage, compliance with our license terms, or through litigation. Any actual or claimed requirement to disclose our proprietary source code or pay damages for breach of license terms, or failure to enforce our ownership rights over the use of our proprietary source code could harm our business and could help third parties, including our competitors, develop products and services that are similar to or better than ours.

Risks Related to Finance, Accounting and Tax Matters

Covenants in our credit agreements could restrict our operations and if we do not effectively manage our business to comply with these covenants, our financial condition could be adversely impacted.

We have entered into certain credit agreements and other borrowing arrangements, including $2.2 billion aggregate principal amount of 0.00% convertible senior notes due 2029 that we issued in June 2026, and might enter into additional agreements for other borrowing in the future. These agreements contain various restrictive covenants, including, among other things, minimum liquidity and tangible net worth requirements, restrictions on our ability to dispose of assets, make acquisitions or investments, incur debt or liens, make distributions to our stockholders, or enter into certain types of related person transactions. These agreements also contain financial covenants, including obligations to maintain certain capitalization amounts and other financial ratios. The indenture governing the Convertible Notes does not contain financial maintenance covenants of this kind, but does restrict our ability to consolidate, merge with, or sell substantially all of our assets unless certain conditions are satisfied. These restrictions might restrict our current and future operations, including our ability to incur debt to increase our liquidity position.

Our ability to meet these restrictive covenants can be impacted by events beyond our control that could cause us to be unable to comply. The credit agreements provide that our breach or failure to satisfy some of these covenants constitutes an event of default. Upon the occurrence of an event of default, our lenders could elect to declare all amounts outstanding under our debt agreements to be immediately due and payable. In addition, our lenders might have the right to proceed against the assets we provided as collateral pursuant to the agreements. A default under our credit agreements that results in the acceleration of indebtedness in excess of $150 million would also constitute an event of default under the indenture governing the Convertible Notes, and a similar default under the indenture could constitute an event of default under our credit agreements, which could compound the consequences of any such default. If the debt under the credit agreements were to be accelerated, and if we did not have sufficient
141

Table of Contents

cash on hand or be able to sell sufficient collateral to repay it, it would have an immediate adverse effect on our business, financial condition and results of operations.

Our insurance coverage might be inadequate or expensive.

We use a combination of third-party insurance and self-insurance mechanisms, including a wholly owned captive insurance subsidiary. We are subject to claims in the ordinary course of business. These claims can involve substantial amounts of money and involve significant defense costs. It is not possible to prevent or detect all activities giving rise to claims and the precautions we take might not be effective in all cases. We maintain voluntary and required insurance coverage, including, among others, general liability, property, director and officer, excess-SIPC, cyber and data breach, crime, and fidelity bond insurance. Our insurance coverage is expensive and maintaining or expanding our insurance coverage might have an adverse effect on our results of operations and financial condition.

Our insurance coverage is subject to terms such as deductibles, coinsurance, limits and policy exclusions, as well as risk of counterparty denial of coverage, default or insolvency, and might be insufficient to protect us against all losses and costs stemming from processing, operational, and technological failures. Furthermore, for certain lines of coverage, continued insurance coverage might not be available to us in the future on economically reasonable terms, or at all. The successful assertion of one or more large claims against us that exceed available insurance coverage, or the occurrence of material changes in our insurance policies, including premium increases or the imposition of large deductible or co-insurance requirements, could have an adverse effect on our business, financial condition, and results of operations.

Changes in U.S. and foreign tax laws and policies could adversely impact our tax liabilities.

We are, and may in the future become, subject to complex and evolving U.S. and foreign tax laws and regulations, which might in the future make changes to corporate income tax rates, the treatment of foreign earnings, or other income tax laws that could have an adverse impact on our business, result of operations, financial condition and cash flows.

Our determination of our tax liability is subject to review by applicable tax authorities. The determination of our tax liabilities requires significant judgment, and, in the ordinary course of business, there are transactions and calculations where the ultimate tax determination is complex and uncertain. Although we believe our determinations are reasonable, the ultimate amount of our tax obligations owed might differ from the amounts recorded in our financial statements in the event of a review by applicable tax authorities and any such difference could have an adverse effect on our results of operations. Tax authorities might also disagree with certain positions we have taken or might take in the future, which could subject us to additional tax liabilities.

Our corporate structure and associated transfer pricing policies also contemplate future growth in international markets, and consider the functions, risks, and assets of various entities involved in intercompany transactions. The taxing authorities of the jurisdictions in which we operate may challenge our methodologies for valuing intercompany transactions pursuant to our intercompany arrangements or disagree with our determinations as to the income and expenses attributable to specific jurisdictions.

In addition, from time to time, proposals are introduced in the U.S. Congress and state legislatures, as well as by foreign governments, to impose new taxes on a broad range of financial transactions, including transactions that occur on our platforms, such as the buying and selling of stocks, derivative transactions, and cryptocurrencies. If enacted, such financial transaction taxes could increase the cost to customers of investing or trading on our platforms and reduce or adversely affect U.S. market conditions and liquidity, general levels of interest in investing, and the volume of trades and other transactions from
142

Table of Contents

which we derive transaction-based revenues. Any financial transaction tax implemented in any jurisdiction in which we operate could materially and adversely affect our business, financial condition, or results of operations, and as a retail brokerage we could be impacted to a greater degree than other market participants.

We also are subject to non-income taxes, such as payroll, sales, use, value-added, net worth, excise, goods and services, and property taxes in the U.S. and various foreign jurisdictions. Specifically, we might be subject to “digital service taxes” or new allocations of tax as a result of increasing efforts by certain jurisdictions to tax cross border activities that might not have been subject to tax under existing international tax principles. Companies such as ours could be adversely impacted by such taxes.

Our ability to use our net operating losses to offset future taxable income could be subject to certain limitations.

As of June 30, 2026, we have U.S. federal, state and non-U.S. NOLs available to reduce future taxable income subject to certain limitations. Under Sections 382 and 383 of the Code, a corporation that undergoes an “ownership change” (as defined by the Code) may be subject to limitations on its ability to utilize its pre-change NOLs and other tax attributes such as research tax credits to offset future taxable income. If it is determined that we have in the past experienced an ownership change, or if we undergo one or more ownership changes as a result of future transactions in our stock, then our ability to utilize NOLs and other pre-change tax attributes could be limited by Sections 382 and 383 of the Code, and similar state provisions. Future changes in our stock ownership, many of which are outside of our control, could result in an ownership change under Section 382 or 383 of the Code. Furthermore, our ability to utilize NOLs of any companies that we acquire in the future may be subject to limitations. In addition, there may be periods during which the use of NOLs is suspended or otherwise limited. For these reasons, we might not be able to utilize our NOLs, even if we maintain profitability.

Our tax information reporting obligations are subject to change.

Although we believe we are compliant with the tax reporting and withholding requirements with respect to our customers’ transactions in the jurisdictions in which we operate, various U.S., state or foreign tax authorities might significantly change applicable tax reporting requirements or disagree with the exact application of new or existing requirements. If the taxing authorities determine that we are not in compliance with our tax reporting or withholding requirements with respect to customer asset transactions, we may be exposed to additional withholding obligations, which could increase our compliance costs and result in penalties.

We track certain operational metrics, which are subject to inherent challenges in measurement, and real or perceived inaccuracies in such metrics could harm our reputation, adversely affect our stock price, and result in litigation.