Kalshi received a warning about manipulation from Spotify prior to settling a $3.3 million agreement

cryptonews.ruОпубліковано о 2026-07-28Востаннє оновлено о 2026-07-28

Анотація

Kalshi, a prediction market platform, settled contracts worth over $3.3 million for a market based on Spotify's US daily chart, despite receiving a warning about potential manipulation of the underlying streaming data. Trader Caleb Davis alerted Kalshi in late June about anomalous streaming surges for specific songs, like Malcolm Todd's "Earrings," which saw an improbable spike to number one. Spotify later confirmed it removed hundreds of thousands of fake streams for that song, though it did not revise the original chart used for settlement. Kalshi proceeded with the payout after its compliance officer stated only Spotify could confirm manipulation and that no evidence was found of traders suspiciously profiting. Davis disputes this, pointing to unusual position buildups. Following the incident, Spotify asked Kalshi to remove its branding and clarify no partnership exists. The controversy emerges as the CFTC issues guidance urging prediction markets to better vet data sources for reliability and manipulation risks. Kalshi has halted new Spotify-related contracts but an existing July contract remains active.

As revealed in correspondence published on Sunday by trader Caleb Davis, the company Kalshi received a warning that the streaming data underlying one of its prediction markets on Spotify appeared to have been manipulated, after which the exchange settled contracts worth more than $3.3 million. The June market posed the question of which artists would take the number one spot in the daily US Spotify chart, and trading volume reached $3,320,917.

Davis lost $4,500 at settlement, personally published information about the exchange in an authored article, and appears under the pseudonym "Informant" in a Netflix documentary about prediction markets. The manipulation was first reported by the Financial Times, and Wired obtained confirmation from Spotify that the listening data had been falsified.

Davis recounted that he first contacted Kalshi CEO Tarek Mansour after noticing, towards the end of June, an anomalous surge in streams for several songs exclusively in the US. Mansour directed him to Robert DeNault, head of compliance and legal counsel at Kalshi, and Davis sent the company his analysis of the listening activity and related trading positions.

Davis asked Kalshi to "suspend payouts on the market pending the investigation's completion." DeNault, responding that the exchange was reviewing the information received and investigating suspicious trading on its platform, noted that "the main dispute concerns Polymarket, not Kalshi."

The final market surprise was related to the song "Earrings" by Malcolm Todd, which rose approximately 70% in a day to take the number one spot on the US Spotify chart of June 29. Davis calculated that the surge from Sunday to Monday corresponded to an 11.24 sigma event, meaning the probability of it occurring randomly was approximately one in 77 octillion. Of about 200 songs that charted on both days, 195 decreased in price and four increased—two of them were the tracks he had already flagged. In the previous week, traders had estimated the probability of "Earrings" reaching number one at about 2.5%, implying roughly a 20-fold profit for those who bet on that outcome.

Davis informed DeNault that Polymarket had not even offered an outcome for "Earrings" and that Kalshi's internal records could reveal who had been accumulating positions on Todd ahead of the surge. DeNault replied six hours later that "only Spotify could confirm" whether the data reflected genuine streams or manipulation, adding that other market participants had identified "some plausible reasons" why the numbers could be natural. Kalshi settled the market just minutes after sending this reply.

DeNault also wrote that Kalshi had found no evidence that traders had suspiciously profited from these numbers. Davis counters that the open position in the "Earrings" category grew from $2,000 to over $70,000 in the days leading up to the controversial streams, while no such growth was observed in comparable low-probability-to-win categories. He also notes that the exchange did not exhibit similar urgency with indisputable results: a winning bet on Olivia Rodrigo was not paid out until he pointed it out three days later, and a payout for a bet on Michael Jackson took over a week.

The following day, Spotify removed 523,000 streams from the total count for the song "Earrings"—enough for the song to rank fourth, not first, for June 29. However, Spotify does not retroactively revise its published daily charts, so the original chart, upon which Kalshi settled the dispute, remains unchanged—a distinction several media outlets mistakenly reported as a chart adjustment.

Spotify did not determine who generated the artificial streams, nor did it prove that this activity was aimed at manipulating the prediction market. There is no evidence pointing to the involvement of Todd or his team, so any claims that a Kalshi trader purchased streams remain unproven.

According to Bloomberg, Spotify subsequently asked both Kalshi and Polymarket to remove its branding and state that neither company has any partnership with the streaming service. Kalshi removed the logo and changed wording that created the impression that Spotify had verified the validity of its markets. Spokesperson Elizabeth Diana stated that the company "is in contact with Spotify" and is actively investigating; Kalshi has not published the investigation's results, canceled the trade, or announced any refunds. Davis claims that no one from the exchange has contacted him since Spotify confirmed the fraud.

Kalshi has stopped listing new contracts related to Spotify; however, its July contract for artists reaching the number one spot in the US remains open and actively traded, having attracted about $894,000 by Monday.

This dispute occurs against the backdrop of increased federal scrutiny over event contract settlement practices. CFTC guidance issued in March already required exchanges to specify the concrete data sources upon which settlement depends and to assess their reliability, objectivity, and resistance to manipulation, and contained a warning that cash-settled contracts can create incentives to influence the data determining payouts. A second advisory letter, published on Friday, further narrowed the scope of this practice, instructing exchanges to stop self-certifying generic template contracts that bundle options with different settlement sources within a single application. Neither advisory letter mentions Kalshi, Spotify, or "Earrings."

Kalshi has strengthened oversight of its sports vertical through a partnership with Sportradar, but entertainment markets may depend on third-party sources lacking similar data-sharing systems. A similar vulnerability manifested when someone allegedly manipulated a Paris weather sensor used to settle Polymarket contracts.

Пов'язані питання

QWhat was the nature of the warning received by Kalshi regarding its Spotify prediction market?

AKalshi received a warning that the streaming data underlying one of its Spotify prediction markets appeared to be manipulated. This manipulation involved artificial plays on the song 'Earrings' by Malcolm Todd, which was flagged by trader Caleb Davis. Spotify later confirmed the data was falsified.

QHow much money was involved in the settlement of the disputed Spotify market contract on Kalshi?

AThe Kalshi exchange settled the contracts on the disputed market for over $3.3 million. The total trading volume for that June market, which asked which artist would be number one on the US daily Spotify chart, was $3,320,917.

QWhat action did Spotify take after confirming the data manipulation related to the song 'Earrings'?

ASpotify removed 523,000 plays from the aggregate total for the song 'Earrings'—enough to drop it from first to fourth place for June 29th. However, Spotify does not revise its published daily charts retroactively, so the original chart used by Kalshi to settle the contract remained unchanged.

QWhat were the key points of the CFTC advisory letters mentioned in the article regarding event contracts?

AThe March CFTC advisory required exchanges to specify the data sources used for contract settlement and assess their reliability, objectivity, and resistance to manipulation. It also warned that cash-settled contracts could create incentives to influence payout data. A second letter in July further restricted the practice by instructing exchanges to stop self-certifying generic contracts that bundle options with different settlement sources in a single filing.

QHow did Kalshi respond to the situation and Spotify's subsequent request?

AKalshi removed Spotify's branding and changed wording that implied Spotify had vouched for its markets' validity. It stated it was in contact with Spotify and actively investigating but had not published results, reversed the settlement, or announced refunds. While it stopped listing new Spotify-related contracts, a July contract for artists reaching number one in the US remained open and actively traded.

Пов'язані матеріали

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ru2 год тому

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ru2 год тому

Торгівля

Спот
活动图片