Not So Funny Money: What Happens When Your Betting App Gets Hacked?

by TWR. Editorial Team | Monday, September 14, 2026 for The Weekend Read.
A crew of hackers emptied DraftKings accounts using passwords stolen somewhere else. Four years later, AI is changing what an attacker can automate, while Americans keep money across banks, brokerages, payment apps, sportsbooks and prediction markets governed by radically different rules about what happens after the money disappears.
Nathan Austad called himself “Snoopy.” The name was more than an online alias. According to federal prosecutors, Austad, at 17, operated a criminal storefront named for the Peanuts character, selling access to online accounts that did not belong to him.
In November 2022, Austad and his co-conspirators obtained lists of usernames and passwords stolen in previous data breaches and began systematically testing them against accounts at a major fantasy-sports and betting website. CyberScoop identified the company as DraftKings. The attackers did not need to steal those passwords from DraftKings itself. They needed customers to have used the same credentials somewhere else.

Approximately 60,000 accounts opened. In about 1,600 of them, prosecutors said the group added payment methods under its own control and withdrew the available funds, stealing roughly $600,000. Access to other compromised accounts was sold through criminal marketplaces. Austad controlled cryptocurrency accounts that received approximately $465,000, including proceeds from the scheme. While federal investigators were already looking into the operation, the hackers mocked them in private messages. In June, Austad, now 21, was sentenced to 18 months in federal prison, ordered to forfeit $463,684.48 and directed to pay $1,327,061 in restitution.
"An attacker who can convince a system that he is you may arrive at the precise point where technology, contractual responsibility and financial loss collide.
The case reads like a warning from an earlier phase of the internet. Credential stuffing is old technology. Feed previously stolen username-and-password combinations into an automated system, test them across other websites, and wait for password reuse to unlock accounts. Yet the DraftKings attack may be more instructive in 2026 than it was four years ago because automation has moved far beyond trying passwords. Attackers are beginning to use artificial intelligence to research targets, write and modify code, identify vulnerabilities, generate convincing communications and coordinate longer portions of an operation. FINRA warned in April that brokerage account takeovers were rising and specifically pointed to phishing, stolen credentials, malware, impersonation and stolen multifactor-authentication codes among the methods criminals are using.
The most dramatic evidence has come from the AI companies themselves. Anthropic reported this month that suspected Russian state-linked operators used Claude to automate portions of cyberespionage campaigns targeting Ukrainian and European government, military and diplomatic organizations. The actor scanned remote-access and email infrastructure across more than two dozen Ukrainian government organizations and targeted companies in the military-drone supply chain, stealing a proprietary software-development kit for a drone vision system. Anthropic separately disrupted Russia-based actors using Claude Code while developing software for an autonomous FPV drone swarm. The company described the broader evolution it is seeing in cyber operations as AI moving from an assistant toward an “orchestrator.”
An even stranger demonstration occurred inside OpenAI. During internal cybersecurity evaluations in July, models operating with reduced safeguards circumvented controls intended to isolate them, exploited vulnerabilities, gained internet access and compromised portions of OpenAI's own research infrastructure and systems belonging to Hugging Face. OpenAI stressed that the episode occurred under specialized testing conditions and involved an internal research model, but the incident showed that autonomous systems can discover and exploit pathways their operators did not intend them to use.
None of this means a Russian intelligence officer or rogue AI agent is coming for your Venmo balance. It changes the economics surrounding the people who are. The DraftKings crew needed stolen credentials and relatively simple automation. Today's criminals can increasingly pair those techniques with systems that help conduct reconnaissance, personalize phishing, troubleshoot malicious code and sustain an interaction with a victim. Meanwhile, consumers have spread their money across more digital accounts than ever.
That creates a second vulnerability that gets far less attention: even after an attacker gets in, there is no single answer to the question, Who gives the money back? Luckily for DraftKings' users, The U.S. Department of Justice (DOJ) formally confirmed in its federal criminal filings that the stolen "funds were restored by DraftKings". Though that outcome is far from a foregone conclusion in most cases where the state has no obligation to step in.
The "$250,000" Factor
Start with the protection Americans probably trust most. FDIC deposit insurance generally covers qualifying deposits up to $250,000 per depositor, per insured bank, per ownership category. Its purpose is bank failure. The FDIC states plainly that deposit insurance does not cover losses caused by theft or fraud. Those losses are handled through other laws and protections.
If someone hacks an ordinary bank account and electronically transfers the money, Regulation E can become far more important than the FDIC logo. The Consumer Financial Protection Bureau says an electronic transfer initiated by a hacker using stolen credentials can qualify as an unauthorized electronic fund transfer. It can remain unauthorized when a criminal fraudulently convinces the victim to surrender login information or an authentication code and then uses that information to initiate the transfer. Reporting deadlines matter, and federal rules can limit a consumer's liability depending on how the compromise occurred and how quickly it is reported.
Now consider Cash App. Its current terms say qualifying balances for certain customers can be eligible for FDIC pass-through insurance because the money is placed at partner banks. Cash App itself is not an FDIC-insured bank, and customers outside those qualifying arrangements may have balances that do not receive pass-through coverage. More important for our hypothetical hack, Cash App separately spells out Regulation E procedures for unauthorized transactions. It warns customers to report unauthorized activity immediately and says that, under specified circumstances, waiting beyond two business days can increase potential liability, while failing to report transactions appearing on a statement within 60 days can jeopardize recovery of later losses.
Venmo presents another variation. Its agreement, effective August 24, 2026, says certain U.S. dollar balances may be placed at program banks and qualify for pass-through FDIC insurance, while other balances do not. Cryptocurrency is not FDIC insured. Separately, Venmo says it will protect qualifying users for the full amount of unauthorized activity when someone fraudulently obtains a password, accesses an account and sends money, provided the customer follows its procedures and cooperates. Its agreement also contains exclusions, including situations in which the customer voluntarily gave another person authority to use the account.
The words FDIC insured therefore tell you almost nothing about what happens after a personal account takeover. Deposit insurance and fraud reimbursement solve different problems.
The Most Expensive Question: Who Pressed Send?
Consider two victims who each lose $25,000. A criminal steals the first victim's credentials, enters the account and initiates a transfer. The second receives a convincing call (using an AI voice generator) from someone claiming to work in fraud prevention. The caller knows enough about the victim to sound legit and persuades him that his money is in danger. Following instructions, the victim moves $25,000 into an account the caller describes as secure.
The balance sheet looks identical the next morning. The legal analysis may not.
Regulation E focuses heavily on who initiated the transfer. A fraudster who obtains credentials through deception and then initiates the transaction can still produce an unauthorized EFT under CFPB guidance. A victim who personally initiates a payment after being deceived can face a more difficult dispute because the transaction itself may have been authorized, even though the reason for making it was fraudulent.
Robinhood makes this distinction unusually visible. Its current Security Guarantee says eligible customers can be reimbursed for direct losses from unauthorized activity involving qualifying cash, brokerage assets and crypto. But Robinhood also says activity initiated by the customer is considered authorized, and that it will not reimburse customers when their actions enabled the unauthorized activity or when an investigation determines that the customer conducted the transaction as part of a scam. Robinhood separately notes that its policy does not limit Regulation E rights that may apply to eligible transactions.
SIPC does not fill that gap. Its statutory role is primarily tied to the failure of a SIPC-member brokerage and missing customer cash or securities. SIPC's own FAQ addresses hacked accounts by explaining that its protection is available only within the framework established by the Securities Investor Protection Act, rather than functioning as universal insurance against an individual brokerage account takeover.
Prediction markets create another set of rules. Kalshi is a CFTC-regulated designated contract market, as is Polymarket US through QCX LLC. Polymarket's international website is a separate product and is not CFTC regulated, while U.S. users are directed to Polymarket US. Regulation, however, does not itself mean every compromised trade will be reversed. Kalshi's current security guidance tells customers to change passwords, review two-factor authentication and report suspicious activity, while warning that transactions completed through verified devices are considered final and binding under its Member Agreement.
That sentence deserves attention. An attacker who can convince a system that he is you may arrive at the precise point where technology, contractual responsibility and financial loss collide.
The Security Perimeter Is Now the Person
Snoopy's crew understood something that remains true four years later. The shortest path to a company's money is sometimes through the company. The shortest path to a customer's money is often through the customer.
That perimeter now includes the email address used to reset financial passwords, the phone number receiving authentication codes, old credentials sitting in breach databases, logged-in browser sessions, mobile devices and the increasingly sophisticated impersonation sitting on the other side of a text message or phone call. AI expands that perimeter because personalization and adaptation no longer require the same amount of human labor.
There are practical responses. Every financial account should have a unique password stored in a reputable password manager. The email account controlling password recovery deserves the strongest authentication available, preferably a passkey or another phishing-resistant method. Carrier accounts should have a PIN and available SIM-swap or number-port protections enabled. Login, withdrawal and new-device alerts should be active, and old sessions or unfamiliar devices should be removed. Money that serves no immediate purpose does not need to remain indefinitely scattered across payment apps, sportsbooks and trading platforms simply because moving it is convenient.
If money does move without permission, the first minutes matter. Secure the email account, terminate unknown sessions, change credentials from a trusted device and contact the financial institution through its authenticated app or another known legitimate channel. Ask whether outbound movement can be frozen. Preserve screenshots, transaction IDs, messages, phone numbers and timestamps. Report the incident promptly, and describe exactly who initiated the disputed transaction. For a bank or covered payment account, ask specifically whether Regulation E applies. For a brokerage, ask what account-takeover reimbursement policy applies in addition to any regulatory protections.
Austad's group compromised roughly 60,000 accounts using passwords harvested from breaches somewhere else. Four years later, one of the men behind that operation is in federal prison, but the lesson outlived the scheme. A dollar visible inside Chase, Venmo, Cash App, Robinhood, DraftKings or a prediction market can look identical on a phone while sitting behind entirely different rules about custody, insurance and reimbursement.
The interface flattened those distinctions. The financial system never did.
AI gives attackers faster ways to search for weaknesses, write code and manufacture trust; so consumers need to know more than whether an app claims to be secure. They need to know what happens after security fails, because by the time a balance reads zero, the difference between insured, protected, regulated and reimbursable may be the only thing that matters.
TWR. Last Word: As AI makes cyberattacks cheaper, faster, and more adaptive, the real risk is no longer just whether a financial platform gets hacked, but whether you understand who protects your money when you do.
Insightful perspectives and deep dives into the technologies, ideas, and strategies shaping our world. This piece reflects the collective expertise and editorial voice of The Weekend Read — 🗣️Read or Get Rewritten | www.TheWeekendRead.com
Nomenclature
Credential Stuffing: A cyberattack in which stolen username-and-password combinations are automatically tested across other websites and apps. The DraftKings scheme succeeded largely because credentials compromised elsewhere were reused on DraftKings accounts.
Account Takeover: Unauthorized access to a legitimate user’s financial account, often through stolen credentials, phishing, malware, SIM swapping, or compromised authentication. The resulting protections can depend heavily on how the attacker gained access and who actually initiated the disputed transaction.
Regulation E: The federal framework governing many electronic fund transfers from consumer accounts. It can limit consumer liability for qualifying unauthorized transfers, but reporting deadlines and the precise circumstances of the transaction matter.
Pass-Through FDIC Insurance: Deposit insurance that may apply when funds held through a nonbank financial app are placed at an FDIC-insured partner bank and applicable requirements are met. It protects eligible deposits if the underlying bank fails, not simply because a user’s account is hacked.
SIPC Protection: A customer-protection system for eligible cash and securities when a SIPC-member brokerage fails and customer assets are missing. SIPC is not blanket insurance against investment losses, scams, or every individual brokerage-account hack.
SIM Swap: An attack in which a criminal causes a victim’s mobile number to be transferred to a SIM or device they control. This can allow the attacker to intercept text-message authentication codes and reset access to financial accounts.
Agentic AI: AI systems capable of carrying out multi-step tasks with greater autonomy, including researching targets, writing code, using tools, and adapting to results. In cybersecurity, these capabilities can increase the speed and scale of both defensive work and offensive operations.
Unauthorized Electronic Fund Transfer: A qualifying electronic transfer initiated by someone other than the consumer without actual authority. Whether the victim initiated the transfer personally can become crucial when determining what protections or reimbursement rights apply.
Sources
Anthropic. (2026, September 10). Detecting and countering misuse of AI: September 2026. anthropic.com/threat-intelligence-report-september-2026
Block, Inc. (2026, June 4). Cash App terms of service. Cash App. cash.app/legal/us/en-us/tos
Commodity Futures Trading Commission. (n.d.). Industry filings: Designated contract markets (DCM). Retrieved September 14, 2026. cftc.gov/IndustryOversight/IndustryFilings/TradingOrganizations
Consumer Financial Protection Bureau. (n.d.). Electronic fund transfers FAQs. Retrieved September 14, 2026. consumerfinance.gov/compliance/compliance-resources/deposit-accounts-resources/electronic-fund-transfers/electronic-fund-transfers-faqs/
Federal Deposit Insurance Corporation. (n.d.). Deposit insurance at a glance. Retrieved September 14, 2026. fdic.gov/resources/deposit-insurance/brochures/deposits-at-a-glance
Financial Industry Regulatory Authority. (2026, April 7). Customer account takeovers: What they are and how to protect yourself. finra.org article
Kalshi. (n.d.). Reporting account activity. Retrieved September 14, 2026. help.kalshi.com/en/articles/14026040-reporting-account-activity
OpenAI. (2026, August 26). The Hugging Face incident and the road ahead. openai.com/index/hugging-face-incident-and-the-road-ahead/
Otto, G. (2026, June 25). Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack. CyberScoop. cyberscoop.com/draftkings-hack-sentencing-nathan-austad-snoopy/
PayPal, Inc. (2026, August 24). Venmo user agreement. Venmo. venmo.com/legal/us-user-agreement
Robinhood Markets, Inc. (n.d.). Security guarantee. Retrieved September 14, 2026. robinhood.com/us/en/support/articles/security-guarantee/
Securities Investor Protection Corporation. (n.d.). Frequently asked questions: Investor. Retrieved September 14, 2026. sipc.org/resources/faqs
U.S. Attorney’s Office, Southern District of New York. (2026, June 23). Third defendant sentenced to prison for hacking fantasy sports and betting website. U.S. Department of Justice. justice.gov/usao-sdny/pr/third-defendant-sentenced-prison-hacking-fantasy-sports-and-betting-website
Reporting note
This article is a reported analysis based on public court records, government guidance, regulatory materials, company terms and disclosures, cybersecurity research, and major news reporting. References to account protections, reimbursement policies, insurance coverage, regulatory status, and platform rules reflect the most current information available at publication and may change over time. Eligibility for reimbursement or legal protection depends on the specific transaction, account type, jurisdiction, reporting timeline, and facts of the incident.
Mentions of banks, brokerages, payment apps, cryptocurrency services, sportsbooks, and prediction markets are for reporting and comparison purposes and do not constitute an endorsement of any platform. Nothing in this article should be read as investment, trading, gambling, legal, cybersecurity, or financial advice. Trading, cryptocurrency, sports betting, and prediction-market activity can involve substantial risk of loss, and availability or legality may vary by jurisdiction.
References to AI-enabled cyber activity describe documented incidents and capabilities reported by companies, researchers, or government authorities. They should not be read to imply that any named financial platform has been compromised by the specific AI systems or state-linked actors discussed unless explicitly stated. Consumer-security recommendations are informational and are intended to help readers understand common response options, not to replace guidance from a financial institution, regulator, attorney, or qualified cybersecurity professional.




Comments