# The Axiom Insider Trading Scandal, Explained: What February 2026 Revealed

> What ZachXBT's February 2026 investigation alleged about an internal Axiom support dashboard, what Axiom said in response, and what the incident did not touch.

Source: https://axiompedia.com/security/axiom-trade-insider-trading-scandal-explained

On 26 February 2026, on-chain investigator [ZachXBT](https://x.com/zachxbt) published a ten-post investigation into Axiom. It alleged that an employee had spent roughly ten months using an internal customer-support dashboard to watch user wallets, compile a list of prominent traders' private addresses, and trade ahead of them.

Axiom confirmed that internal customer support tools had been abused.

This page is the record: what the investigation says the dashboard could do, what Axiom said word for word, and what the incident did not touch. We cover it because leaving it out of a site that recommends Axiom would be dishonest, and because the version you will find on competitors' comparison pages omits the nuance in both directions.

No breach and no key compromise has been publicly reported. The investigation describes privilege abuse instead: a member of staff using access the company had already granted, with lookups the investigation says were not logged. That reads as a privacy and governance problem rather than a custody one, which is a meaningful distinction and not an excuse.

## First, the framing correction

Two labels get attached to this incident, and both are slightly wrong in ways that matter.

**"The Axiom hack."** No intrusion has been reported. The dashboard was an internal tool that staff could open, not something an outsider defeated. If you are searching for whether Axiom was breached, no public evidence of one exists as of August 2026, and nothing published points at [Axiom's custody model](/security/is-axiom-trade-safe).

**"Insider trading."** Closer, and defensible as a description of the alleged conduct: staff are said to have used non-public customer information to trade ahead of identified wallets, which is front-running. Whether any securities law reaches that is not something this site can determine, and no regulator has publicly charged anyone.

The accurate description is duller and worse: **according to the investigation, business-development staff held real-time visibility into customer wallets, those lookups were not logged, and the pattern ran for roughly ten months before an outsider published it.**

## What the dashboard could actually do

This is the part that deserves attention, because it is the part that generalizes to every terminal you might use instead.

The internal customer-support tool, described in the reporting as "god mode," let staff look up **any user** by referral code, wallet address, or UID, according to the investigation, and see:

- Wallet addresses
- The user's tracked-wallet lists, meaning the wallets that user was themselves watching
- Full transaction history
- Nicknames and linked accounts
- All of it in real time

The investigation reported that the tool sat with business-development staff, that lookups were not logged, and that nothing gated a lookup behind an approval step. We have no way to inspect a private company's internal controls, so read that as the investigation's account rather than as an established fact. What is on the public record is that a ten-month pattern surfaced through an outside investigator rather than through Axiom.

*Source: [Turnkey](https://www.turnkey.com/), used under fair use for educational purposes*

Worth being precise:  Turnkey holds the keys and states that Axiom "never controls user funds or keys." Nothing in the published reporting describes keys or funds moving. The investigation describes visibility **into** wallet data rather than control **over** the wallets themselves. A staffer could see what you held and what you were watching.

## What the investigation found

ZachXBT's investigation named a senior Axiom business-development employee, **Broox Bauer**, posting as @WheresBroox, along with several associates. We name the one because the allegation is about the seniority of the access; the associates add nothing a reader needs and we leave them out. No charges have been filed against anyone, and every claim in this section is ZachXBT's allegation rather than an adjudicated finding.

The reported specifics:

- Abuse running **more than ten months**, beginning shortly after Axiom's launch
- Dashboard screenshots dated **April and August 2025**
- A **Google Sheet** said to compile the private wallets of KOLs, the prominent traders whose positions move markets
- Front-running profits the investigation put in the **low six figures**
- A recording from **early February 2026**, published as part of the investigation, in which the employee discusses a **$200,000** plan and researching wallets gradually

Axiom's own statement, quoted in full below, confirms that internal tools were abused. It does not confirm any of the specifics above, and neither does any court or regulator.

*Reported by The Block, CoinDesk, Forbes, crypto.news and FinanceFeeds, following ZachXBT's investigation of 26 February 2026.*

##  What Axiom said

Axiom's public response, as published:

> "We are surprised and disappointed to hear that someone on our team abused internal customer support tools to look up user wallets. We have removed access to these tools and will continue to investigate and hold the offending parties responsible."

Read it carefully, because both what it does and does not contain matter.

It **confirms the abuse** rather than disputing the investigation, which is more than many platforms manage. It states a concrete remediation: access removed. It commits to continuing.

It also does not name anyone, does not say how many users were affected, does not say whether anyone was dismissed, does not address logging, and does not mention compensation. One outlet reported that staff were fired; the primary reporting supports only the removal of tool access, so treat a firing as unconfirmed.

## Where it stands now

**Unresolved, as of August 2026.**

We found no reported firings, criminal charges, lawsuits or user compensation on the public record. Axiom said it would continue to investigate, and no outcome of that investigation has been published. Coin Bureau's review of 9 June 2026, more than three months after the story broke, still listed the incident as a standing concern.

There is also a footnote worth recording. Two  Polymarket traders staked roughly $60,000 and $65,800 on a ZachXBT reveal in the hours before publication, and those positions returned around $109,000 and $411,000. Polymarket's markets are public and the trades were noted in the coverage of the investigation. Who those traders were, and what they knew, is not something we can establish, and we draw no conclusion from the timing.

## What this should and should not change for you

**It should not change your read on custody.** Axiom describes itself as non-custodial, the keys sit with  Turnkey, and your seed phrase is exportable from settings at any time. That was true before February 2026 and it is true now. If you have not exported yours, do that regardless of this story; the [signup guide](/guides/getting-started/how-to-sign-up-for-axiom) covers it, and the August 2025 selling outage is the better argument for it.

**It should change your assumptions about privacy.** The lesson generalizes past Axiom: you have no way to audit what a trading terminal's staff can see about your activity, at any terminal, and the interface will not tell you. If your strategy depends on your wallet activity going unobserved, that is a real exposure everywhere, not a problem unique to this one. Axiom's multi-wallet feature, which lets you run many addresses and hot-switch between them, is documented partly as an on-chain privacy tool, and spreading activity is a reasonable response.

**It should factor into a comparison, honestly.** If you are weighing terminals, this belongs in the assessment alongside fees and features rather than instead of them. Our [comparison guides](/compare) name it. So do competitors', usually with the nuance removed in whichever direction suits them.

Axiom's statement described removing access to the tools involved. We have not seen a further public statement from Axiom about logging or access controls, which is not the same as saying nothing changed internally, because internal changes are not something an outside site can see. If that detail matters to your decision, the honest position is that it is not on the public record either way.

## Related reading

For the broader safety picture, including the non-custodial model, MEV protection and current phishing campaigns, read [is Axiom Trade safe](/security/is-axiom-trade-safe). If you arrived here from token or airdrop speculation, [there is no Axiom token](/ecosystem/is-there-an-axiom-token) and any contract claiming otherwise should be treated as a scam. For the incident's practical takeaway about seed phrases, the [terminal walkthrough](/guides/getting-started/how-to-trade-on-axiom) covers the setup step that matters most.

## FAQ

### Was Axiom hacked?

No breach of Axiom's systems has been publicly reported, and no private keys were reported compromised. The February 2026 incident was a different thing: on-chain investigator ZachXBT published an investigation alleging that a member of staff used an internal customer-support dashboard to view user wallet data, and Axiom confirmed that someone on its team abused internal customer support tools. A hack means an outside attacker defeated a platform's security. Nothing published about this incident describes key custody being involved.

### Did anyone lose funds in the Axiom insider trading incident?

No user funds were reported taken from wallets. The reporting describes a dashboard that exposed information rather than control. The allegation is that staff traded ahead of wallets they were watching, which ZachXBT's investigation put at six figures in profit. Those figures come from that investigation and have not been tested by any court or regulator. No user compensation has been reported.

### What did Axiom say about the scandal?

Axiom's public statement, as published, read: 'We are surprised and disappointed to hear that someone on our team abused internal customer support tools to look up user wallets. We have removed access to these tools and will continue to investigate and hold the offending parties responsible.' It confirmed the abuse and the tool removal, and it did not dispute the investigation's findings.

### Has the Axiom insider trading case been resolved?

Not on the public record as of August 2026. We found no reported firings, criminal charges, lawsuits or user compensation. Coin Bureau's June 2026 review still listed the incident as a standing concern. Axiom said it would continue investigating, and no follow-up outcome has been published.

### Is it safe to use Axiom after the insider trading scandal?

The custody model is unchanged, and nothing published about the incident points at it. Axiom describes itself as non-custodial through Turnkey, and your seed phrase stays exportable from Settings. What the incident should change is your assumptions about privacy rather than custody. Anyone whose strategy depends on their wallet activity not being observed should assume that support staff at any terminal may see more than the interface suggests, and should spread activity across multiple wallets accordingly.

### Did Axiom name anyone or confirm any consequences?

Axiom confirmed that someone on its team abused internal customer support tools, but it has not publicly named an individual. ZachXBT's investigation did name people. This page does not repeat those names, because no charges have been filed, no regulator has publicly acted, and the allegations have not been tested anywhere. The investigation is public if you want to read the primary source, and it is linked in the article.
