How Prop Firm Fraud Actually Works: 9 Patterns

Nine patterns, and the first thing to say about all of them is that most prop firm fraud is invisible if you look at one account at a time. That single fact is why so many firms buy monitoring and still pay out to coordinated groups.

This is written for people running firms. Each pattern below is described at the level you need to recognise it in your own data: what it looks like from the desk, why somebody does it, which signals expose it, and what it costs if it goes unnoticed. None of it is described at the level somebody would need to run it while avoiding detection. That is a deliberate choice, and it means a few details are named as signals without their tolerances.

None of this is clever. It is a transfer from your firm and from the traders who passed honestly, and the alternative to understanding it is enforcement by hunch. For the operating structure around this work rather than the patterns themselves, how risk actually runs day to day is the parent piece.

Why prop firm fraud is invisible inside one account

Look at a single account and you see a strategy. A hedge looks like risk management. A cluster of matched entries looks like a trader who reads the same chart as everybody else. A grid looks like discipline until the last position.

The patterns only resolve when accounts are compared against each other and against their own history. Two accounts holding opposite sides of the same instrument at similar size is not two strategies, it is one position. Eleven accounts opening the same trade inside the same short window is not eleven traders. One person behind four verified identities is not four customers.

So the architecture of your detection decides what you can ever see. A system watching equity curves account by account cannot find most of what follows, no matter how good the interface is.

The nine patterns

Ordered from what happens inside one account, through coordination between accounts, to the payment and identity layer where the money actually leaves.

PatternWhat the firm seesSignal family that exposes itCost if missed
Grid and martingale structuresSize rising after losses, a pass arriving inside one sessionPosition sizing against the trader’s own baselineFunded accounts whose pass rate says nothing about skill
Scheduled event exposureOutsized positions around known eventsInstrument and timing against baseline behaviourPasses indistinguishable from luck, and disputes over vague rules
Hedged pairs across accountsOpposite sides, same instrument, similar sizeMatched trade characteristics plus account relationshipsA target paid that was never earned
Copy clustersThe same instrument, direction and size across many accountsMatched trade characteristics plus device and network overlapCorrelated exposure you never priced
Account sharing and passingBehaviour changing mid account, payer and trader mismatchDevice and network fingerprints, behavioural baselinesYou do not know who you funded
Cross firm mirroringBehaviour that only makes sense as one leg of something largerBehavioural baselines and payout rhythmYou are the leg that pays
Payout ringsUnrelated accounts resolving to one payment beneficiaryPayment beneficiary and detail reuseMoney already gone rather than risk carried
Evaluation fee disputesChargebacks concentrated on failed evaluationsDispute history read against account outcomeFees clawed back, and the merchant account itself at risk
KYC circumventionOne person behind several verified identitiesDocument reuse, liveness and device signalsBans that cannot be enforced

Grid and martingale structures. An equity curve that climbs in small steady increments and then moves violently, position size rising after losses rather than with any visible conviction, and a pass that arrives in one session. It is rational for the buyer because an evaluation fee is small against a funded account, so a strategy with a small chance of a large drawdown is worth buying repeatedly. It exposes itself against the trader’s own sizing baseline. Miss it and you fund accounts whose pass rate carries no information about the person.

Scheduled event exposure. Positions taken around known calendar events at a size out of proportion to how that account normally trades, occasionally with the offsetting risk held somewhere the rulebook does not look. A binary event turns an evaluation into a coin flip for the price of one fee. Instrument and timing read against the account’s own history is what surfaces it. Missed, you get passes that are indistinguishable from luck, plus arguments whenever your rules say no news trading without defining it.

Hedged pairs across accounts. Two accounts, opposite sides of the same instrument at similar size. Neither is doing anything visibly wrong. One is close to guaranteed to reach target while the other is written off as the cost of the attempt. This is one sided betting, and in our experience it is one of the two biggest generators of disputes in this industry, because the rule against it is usually written loosely enough to argue with. The pair is the signal, never either account alone.

Copy clusters. Many accounts entering the same instrument, direction and size within a short window of one another. Sometimes it is one trader monetising an edge across accounts belonging to other people. Sometimes it is a single operator running a farm behind different names. Matched trade characteristics plus device and network overlap resolve it into one group. The cost is correlated exposure nobody priced: a single strategy failing across many funded accounts on the same afternoon.

Account sharing and account passing. The person who bought the evaluation is not the person trading it, or the account changes hands after it gets funded. The skill and the capital separate, and whoever has the skill takes a share without carrying the loss. Device and network fingerprints, a behavioural break mid account, and mismatches between payer, trader and payee are what show it. Miss it and your KYC file describes somebody who never traded.

Cross firm mirroring. The same approach run at several firms at once so that at least one of them pays. You cannot see the other legs, which makes this the hardest pattern here. What you can see is behaviour that only makes sense as part of something larger, and a payout rhythm that fits a schedule rather than a strategy. Baselines and withdrawal patterns carry it, not trade matching. Missed, you are simply the firm that paid.

Payout rings. Many accounts, unrelated on paper, resolving to one payment beneficiary. This is the cash out stage of everything above, which is why it is the most expensive one to miss: at this point the money has left rather than sitting on your book as risk. Beneficiary reuse, shared banking or wallet details and the timing of withdrawal requests are the signals, and they belong at the payout gate rather than in a monthly report.

Evaluation fee disputes. Chargebacks used as a free option on a failed attempt: keep the account if it passes, dispute the charge if it does not. Dispute history read against what happened to the account is the tell. The cost is worse than the fees: a rising dispute ratio puts the merchant account under review, and losing your payment route stops the whole firm.

KYC circumvention. Reused or rented documents, mismatches between the payer, the trader and the payee, and one person standing behind several verified identities. It is the pattern that makes every other pattern repeatable, because a ban you cannot enforce is not a ban. Document reuse, liveness and device signals, and the relationship graph between accounts over time are what break it.

The signal families that expose them

Not tools. Families of evidence, which run together because almost none of them decide anything alone.

Matched trade characteristics across the whole book: direction, instrument, size and entry timing compared account against account rather than inside one. Device and network fingerprints, so accounts that claim to be unrelated stop claiming it. Payment beneficiary and payment detail reuse, which is the layer that connects trading behaviour to a person. Behavioural baselines per trader, because the useful question is usually not whether a trade looks odd but whether it looks odd for that account. And relationships between accounts tracked over time, since a group that formed slowly is invisible to anything that only looks at today.

Run separately they produce noise. Run together they produce a case, which is the standard continuous cross account fraud detection has to meet before anybody acts on it.

False positives, and the honest traders you will hurt

This is the part most posts on this subject skip, so read it as the important half.

Two honest traders can trade the same release, the same way, within minutes of each other, because they read the same calendar and the same chart. A father and son can share a house, a network and a broadband connection. A profitable trader can size up after a loss because their plan says to. Correlation is not collusion, a shared device is not proof of a shared person, and an unusual week is not evidence of anything.

A firm that closes accounts on a single signal will punish innocent people, and it will deserve the reputation it earns for it. The person on the other end of that decision has usually done nothing wrong, has told a community about it before your reply lands, and cannot be compensated afterwards with an apology.

So the standard is not a score above a threshold. It is an evidence pack that a reviewer can put in front of the trader and defend line by line: these trades, these timings, these matches, this rule. If the pack does not hold up when read by somebody sympathetic to the trader, it does not hold up. And where the rule itself is ambiguous, the trader is often right to argue, which is why writing rules that survive contact with funded traders does more for your dispute rate than any detection engine.

What to do with a flag

A flag is not a decision. It is a queue item with evidence attached, and somebody has to work it.

That somebody needs training, because reading a matched trade list and deciding whether it is coordination or coincidence is judgement, not data entry. It needs cover across the trading week too, since flags arrive while positions are open. Whether you build that or buy it as a trained operations desk, the requirement does not change.

Then split the decisions. Holding a payout pending review sits with a reviewer. Closing a funded account for abuse, or reversing a decision in a trader’s favour, needs a named person and a record of who decided what, on what evidence. The three tier structure for that sits in our guide to escalation and sign off, and it matters here because an override with no audit trail turns your fraud policy into whoever was on shift.

Who this actually protects

The framing that gets this wrong is firm against trader. It is not.

Every payout that goes to a coordinated group is money that left your firm without anybody earning it, and it leaves from the same place the honest traders get paid from. Every hour your reviewers spend on a farm is an hour not spent clearing a legitimate withdrawal. Every rule you tighten because a group exploited a loose one lands on traders who were never the problem.

Detection done properly is what lets you keep the rules loose enough for real traders to work inside, pay quickly because the checks are already done, and defend the decisions you do make. Done badly it is a tax on honest customers.

If you want your own book reviewed against these patterns, book a scoping call and bring your rulebook and your payout policy. Both of them are usually where the first fix is.

Share

Keep reading

All posts

Next step

Talk to the people who run one

Thirty minutes on your model and setup. You leave with a written plan and a fixed price.

Prop FinTech provides technology and operational services to proprietary trading firms.