SKILL 43: Whistleblower Exposure
Purpose
Understand SEC and CFTC whistleblower programs, how they affect operations, and how to build internal processes that reduce external reporting risk.
SEC Whistleblower Program (Dodd-Frank §21F)
- Who can report: ANY person — employees, contractors, ex-partners, competitors, users
- Reward: 10–30% of sanctions collected if tip leads to enforcement action over $1M
- Total awards to date: Over $2 billion since 2012 (as of 2024)
- Protected activity: Retaliation against a whistleblower is ILLEGAL under §21F(h)
- Wrongful termination remedy: reinstatement, double back pay, attorneys' fees
CFTC Whistleblower Program
- Same structure: 10–30% of sanctions over $1M
- Covers: Commodity Exchange Act violations, market manipulation, fraud, unregistered activities
- Key for Perlantir: prediction market CFTC violations → someone reports → earns 10–30% of any fine
- CFTC program has paid out hundreds of millions; awards are publicly announced
What This Means Operationally
- Every employee, contractor, and business partner is a potential whistleblower
- If they observe what they believe is a securities or CFTC violation → financial incentive to report
- You cannot contract away whistleblower rights (NDAs cannot prohibit SEC/CFTC reporting)
- SEC has brought enforcement actions against companies that tried to silence whistleblowers with NDAs
Proactive Risk Reduction
Internal Reporting Culture
- Create internal compliance reporting channel: "If you have a legal or compliance concern, report it to [designated contact]"
- Document that concerns are taken seriously and investigated
- Fix problems internally BEFORE the SEC/CFTC hears about them → no enforcement action → no whistleblower award → less incentive to report externally
- The math: internal fix costs $0 in fines. External enforcement = fine + 10–30% whistleblower award + litigation costs + reputational damage
What NOT to Do
- Never retaliate against someone who raises legal concerns internally — EVER
- Never pressure employees to do things they're legally uncomfortable with
- Never include NDA language that purports to prohibit government agency reporting (illegal under Dodd-Frank)
- Never discuss regulatory gray areas casually in Slack/Discord where employees can screenshot
- Never suggest that "no one is going to find out"
Attorney-Client Privilege Protection
- Legal strategy discussions: always have counsel present or involved to preserve privilege
- Slack messages about legal risk are NOT privileged
- Emails to your attorney ARE privileged (attorney-client)
- If you write a legal risk memo without an attorney → it's discoverable
Internal Investigation Protocol
When an employee or contractor raises a legal concern:
- Acknowledge: "Thank you for raising this. We take compliance seriously."
- Document: Write down exactly what was said, by whom, and when
- Escalate: Notify your compliance lead or outside counsel immediately
- Investigate: Outside counsel conducts privileged investigation (if counsel leads → privileged)
- Remediate: If a violation is found, fix it. Document the fix.
- Report back: Inform the employee that the concern was investigated and addressed (without revealing privileged details)
- Never: Suggest the employee was wrong to raise the concern, even if the concern was unfounded
Red Flags That Trigger Whistleblower Reports
- Running a prediction market without CFTC designation or exemption
- Offering tokens that could be securities without registration
- Telling users a platform is "compliant" when legal review hasn't been completed
- Collecting funds from users without proper money transmission licensing
- Any statement that implies you're "above" regulatory requirements
Privilege Log
Maintain a privilege log of all attorney-client communications regarding legal risk. This demonstrates good faith compliance effort.
This is legal research and intelligence, not legal advice. Consult qualified legal counsel before taking action.