THE DIGITAL PLAYGROUND IN THE CROSSHAIRS

Forensic Transparency Portal · Roblox Corp. MDL 3166
CASE STATUS: ACTIVE / EXPANDING
⚠ DISCLAIMER: Allegations described herein are unproven claims in pending litigation. Roblox denies wrongdoing. This is a journalistic analysis, not legal advice. Read full disclaimer & sources →
IN RE: MDL No. 3166 · N.D. CAL.

A platform built for play, now under forensic scrutiny for youth-safety failures.

The year 2026 marks a watershed in the governance of immersive digital platforms. Roblox Corporation — host to 144M Q4 2025 / 132M Q1 2026 daily active users[1][Q1] — sits at the center of federal multidistrict litigation, coordinated state enforcement, sovereign bans, and short-seller financial investigations. This portal renders the consolidated record into a structured, navigable forensic dataset, mapped directly to the source report.

ROBLOX CORPORATION (NYSE: RBLX) Subject platform of MDL 3166 and 12+ state enforcement actions. Wordmark reproduced as a public-domain text logo (per WP:PD-textlogo on Wikimedia Commons).
[4]✓
148
Active lawsuits in MDL 3166 (May 2026)
[4]✓
162+
Total abuse lawsuits pending
[4]✓
$35.8M
State AG settlements (NV+AL+WV)
[NEW]✓
12+
U.S. states now suing / probing Roblox
[UK1][UK2]✓
28 mo
UK sentence — Tritta, Apr 9 2026
[18]✓
6-Bracket
Global age-gate structure (Persona FAE)

⚠ Legal & Editorial Disclaimer — Read First

Nature of claims. The lawsuits and allegations summarized on this portal are unproven claims asserted in active, ongoing litigation (MDL 3166 and parallel state actions). As of this build, no global settlement and no court verdict on the merits has been reached in the federal MDL. Roblox Corporation has publicly and comprehensively denied wrongdoing and characterized the financial allegations as a short-seller's stock-manipulation effort.

Not legal advice. This is an analytical / journalistic visualization of a third-party report cross-checked against public sources. It does not constitute legal advice, does not create an attorney–client relationship, and should not be relied upon for any legal decision. Anyone affected should consult a licensed attorney and verify the live court docket.

  • Data integrity: Several figures were REDACTED in the original source. Where independent reporting supplies them, the verified value is shown and flagged [VERIFIED]; otherwise the gap is preserved honestly.
  • Victim sensitivity: Cases involve minors and alleged child sexual abuse. Names are pseudonymous ("Jane Doe") as filed. No identifying victim detail beyond the public record is reproduced.
  • Currency: Litigation is fast-moving; verify the latest status via the linked primary sources in the Evidence & Sources tab.
📞 If a child is in immediate danger, contact local emergency services. U.S. reports of online child exploitation: NCMEC CyberTipline — report.cybertip.org or 1-800-843-5678.
SYNTHESIS

The Convergence of Five Crises

VECTOR 01

Federal MDL

In re: Roblox Corporation Child Sexual Exploitation and Assault Litigation, MDL 3166, before Chief Judge Richard Seeborg — alleging design negligence, product liability, deceptive marketing, and failure to warn. 148 active cases (May 2026), 162+ total pending.[5][4]✓

VECTOR 02

State Enforcement

AG investigations and suits across 12+ states: FL, NV, OK, AL, WV, TX, LA, NE, IN, SC, GA, IA, TN — including a $35.8M state-settlement cluster and Nebraska AG Hilgers' "no bigger playground for predators" complaint.[4][N1][N5][N7]✓

VECTOR 03

Financial Investigation

Hindenburg Research (Oct 8, 2024) alleged systematic inflation of DAUs/engagement while cutting trust-and-safety spend. Q1 2026 (audited): $1.44B revenue (+39%), $57M legal accrual, RBLX down ~71.5% from 52-wk high.[3][Q1]✓

VECTOR 04

Sovereign Bans

Turkey, Algeria, Egypt, Russia, China and others have moved from oversight to full platform bans. Russia's Dec 2025 Roskomnadzor block and Egypt's Feb 2026 ban triggered the Q1 2026 guidance cut.[14][15][Q1]✓

VECTOR 05

Regulatory Re-Engineering

COPPA 2.0 (effective Apr 22, 2026) and the KIDS Act / KOSA impose design-level duties on youth platforms. Roblox's Jan 7, 2026 global age-check mandate (Persona + Paravision) was the operational response.[21][23][N10]✓

VECTOR 06 · NEW

Biometric Liability Transformation

Mandatory facial age estimation (100M+ daily users) replaced grooming liability with biometric-data liability under COPPA 2.0's expanded "personal data" definition. The Feb 2026 Discord-Persona backlash is a leading indicator of regulatory and public risk.[N11]✓

VECTOR 07 · NEW

UK Criminal-Civil Convergence

First major UK criminal conviction directly tied to Roblox-groomed contact — Carlo Tritta, 28 months (Apr 9, 2026) — at Manchester Minshull Street Crown Court. UK NSPCC issued safety-by-design statement; the UK Online Safety Act (Ofcom enforcement) applies extraterritorially. UK criminal courts are now treating Roblox-groomed contact as a primary evidentiary basis for conviction, with a second 4-year sentence (Sheffield) on Apr 10, 2026.[UK1][UK2][UK3]✓

VECTOR 08 · NEW

The Moderator Math

LeadIQ counts Roblox at ~9,200 total employees (April 2026) — of which Highperformr data places ~539 in "Other Department" (the bucket that "likely encompasses community moderation, user support, content review"). Against 144M Q4 2025 / 132M Q1 2026 DAU and Roblox's own claim of 6B+ daily chat messages scanned by Sentinel, the implied ratio is ~1 trust-and-safety headcount per 244,000–267,000 active users — and the math gets worse when the ~5,000 daily server shutdowns (RM3, May 2026) and the still-unreplaced manual moderator workforce from 2022 layoffs are factored in.[N26][N15][N10][Q1]✓

VECTOR 09 · NEW

2026 Platform Update Chronology

Roblox's defensive platform-engineering program accelerated through 2026: Jan 7 — global mandatory facial age verification (Persona) for chat access; Jan 24 — six-bracket age-cohort system detailed; Apr 14 — Roblox Kids (5-8) + Roblox Select (9-15) announced; May 19 — Social Hangouts, Free-form User Creation, Sensitive Issues content restricted to 16+; IARC framework integration later in 2026. Each update was a post-litigation response, not a pre-emptive engineering choice.[N10][N16][N17][N18]✓

Headcount composition Highperformr / LeadIQ / Unify — Apr 2026
Engineering
~1,168
IT
~411
Operations
~361
Other (mod, support, review)
~539*
Product / Design / Exec
~457
Other / not classified
~858
TOTAL
~9,200

* "Other Department" per Highperformr/LeadIQ "likely encompasses crucial functions such as community moderation, user support, and content review." Roblox does not publicly disclose a discrete trust-and-safety headcount.

Implied moderator:user ratio derived (see text)
Q4 2025 DAU
144,000,000
Q1 2026 DAU
132,000,000
Sentinel chat scans/day
6,000,000,000+
Mod bucket headcount
~539
DAU per mod head
~244,000–267,000 : 1
Sentinel scans per mod head / day
~11.1M : 1

Caveat: ratio assumes ALL 539 "Other" employees are moderators. Real moderator count is lower; some T&S work is contract/outsourced. The headline point — orders of magnitude more users and chat messages than human moderators — survives any reasonable correction.

UPDATES

Roblox 2026 Platform Updates (defensive cadence)

A forensic chronology of Roblox's 2026 platform changes — each released after a corresponding lawsuit, sovereign ban, or state-AG filing. Pattern, not coincidence.

JAN 7, 2026
Global mandatory facial age verification for chat

TechCrunch confirmed: all users worldwide must complete facial age estimation (Persona vendor) or government-ID verification to access chat. Roblox "the first major gaming platform" to require this. Same week as Anapol Weiss's "biometric-first security architecture" analysis.[N10][N16]✓

JAN 24, 2026
Six age brackets detailed (5-8, 9-12, 13-15, 16-17, 18-20, 21+)

Anapol Weiss analysis confirms the six-cohort social-experiment design; biometric data and images "deleted immediately after the age estimation is processed." PII (email, phone) removed from accounts estimated as 5-8 or 9-12.[N16]✓

FEB 9 — 24, 2026
Discord-Persona age-check rollout → pause

Discord announced global teen-by-default age checks via Persona, then paused Feb 24 after a Verge investigation into Persona's data practices and public backlash. Roblox — Persona's other major customer — inherits the regulatory and reputational exposure.[N11]✓

APR 14, 2026
Roblox Kids (5-8) + Roblox Select (9-15) announced

Two new age-based account tiers with required age verification, distinct visual branding, and automatic transition to standard accounts at 16. Communication disabled by default on Kids accounts. Roblox Kids accounts limited to Minimal/Mild content; Select accounts to Moderate.[N17]✓

APR 27, 2026
Anapol Weiss Castillo federal suit (Roblox + Discord + Uber)

Not a Roblox platform update but a forcing function: federal suit alleges Roblox continued paying developer revenue tied to Arnold Castillo's games "— funds that ultimately helped facilitate his crimes."[N9]✓

MAY 12 — 19, 2026
Content maturity updates — Social Hangouts / Free-form / Sensitive Issues → 16+

Per the Roblox Developer Forum (May 12, 2026 update): any game that qualifies as a Social Hangout, has Free-form User Creation, or includes content on Sensitive Issues is now restricted to 16+ (was 13+). Single-occupancy logic recommended for private spaces (toilets, beds) — Roblox shuts down servers when violations occur.[N18]✓

MAY 31, 2026
RM3 real-time multimodal moderation (5,000 servers/day shut down)

Khaleej Times: Roblox deploys RM3 in "shadow mode" testing — real-time multimodal moderation shutting ~5,000 violating servers daily. Critically: this is post-hoc detection, not pre-publication filtering.[S2]✓

LATER 2026 (PLANNED)
IARC framework integration + Trusted Connections (July 2026)

Transition to International Age Rating Coalition (IARC) ratings (ESRB US, PEGI EU/UK). Trusted Connections feature (July 2026) limits age-checked communication to user-nominated connections. Social media link sharing restricted to 13+ age-checked users with same/cohort viewing.[N17][N19]✓

01

Litigation & Enforcement Chronology

Procedural and substantive milestones for MDL 3166 and parallel state actions, August 2025 – June 2026. Filter by event type, year, and severity.

All Events
Filings
State / Investigation
MDL Procedure
Settlements
Platform Update
Financial
2025
2026
⚠ Urgent
02

High-Profile Case Profiles

Individual complaints illustrating the cross-platform "off-platform migration" harm pattern. Search by alias, jurisdiction, or defendant.

All Regions
U.S. Federal / State
United Kingdom
Multi-Platform
03

The Grooming Pipeline

The consistent, structured five-phase sequence described by civil complaints and law enforcement, exploiting Roblox's default-open social settings and low-friction signup (username, password, self-reported birthday — no identity verification).[4][11]

Inter-platform mechanism. Predators establish initial contact in-game, build trust by bribing children with Robux or rare items, then migrate the interaction off Roblox to less-moderated services (Discord, Snapchat, Instagram) supporting unmonitored voice/video — completely evading Roblox's automated text filters.[4][7][9]
03b

Organized Exploitation Networks

Moderation deficits allowed organized groups to establish operations coordinating grooming and blackmail of underage players.[13]

NETWORK

"764" / "CVLT" / "The Com"

Affiliated organized child-exploitation groups that systematically coordinate grooming and blackmail of minors on the platform.[13]

CASE STUDY

Sonic Eclipse Online

A 12-year-old girl was groomed by a 24-year-old developer. Roblox terminated the developer's account but initially refused to remove the game; assets were transferred to a friend's account to keep earning revenue. The experience was only permanently removed after Sega issued a DMCA notice.[13]

04

Rule Violations: Hangout & Dating Games [ROBLOX TOS BREACHES]

A documented subset of the most-visited Roblox experiences that systematically violate Roblox's own Community Standards — specifically the prohibitions on romantic/dating content between users, off-platform contact, and real-world meetups — yet remain live and monetized. These are the games most frequently cited in MDL 3166 plaintiff complaints and Hindenburg's 2024 short-seller report as grooming-conducive infrastructure.[3][4][5][7][8][13]

THE RULE GAP. Roblox's published Community Standards (ToS §3) explicitly forbid: (a) romantic or sexual content between players, (b) sharing personal contact information, (c) organising or suggesting real-world meetups, and (d) content that "appeals to children" with mature themes. The games below directly violate these rules. Their continued presence — some for over a decade — is itself the central product-defect allegation in MDL 3166.
[VERIFIED]
10
Documented rule-violating experiences (this section — re-verified Jun 2026)
[PLAT][V1-V10]
243B+
Aggregate visits across the 10 listed violations (visits re-verified Jun 2026)
[N23][V10]
1
Experience publicly removed (Club Iris — Aug 15, 2025, post-Revealing Reality / BBC, Apr 14, 2025)
[VERIFIED]
6+
Years the worst offenders (MeepCity, Royale High) have hosted dating mechanics
All
Dating / Marriage
Hangout / Social
Exploit / Bot Hub
Status: Active
Status: Removed
Sort: Visits ▾
ExperienceDeveloperRule ViolationVisitsStatus
Why this matters to the litigation. MDL 3166 plaintiffs allege Roblox knowingly permitted these mechanics to persist because they drive the engagement metrics (DAUs, hours, Robux spend) that underpin its $1.44B quarterly revenue. The dating/hangout games are not edge cases — they are the most-visited experiences on the platform. The same games that maximise Roblox's commercial metrics are, per the lawsuits, the ones that maximise predator-to-child contact opportunity.
Compare to Roblox's own statements. Roblox told Hindenburg (Oct 2024) that it "invests heavily in moderation" and uses "industry-leading AI to detect and remove child-endangerment content."[6] The continued, decade-long operation of explicit dating mechanics in the platform's flagship games is direct evidence plaintiffs cite against that claim.
05

Metric Manipulation Allegations

The Hindenburg Research report (Oct 8, 2024) alleged systematic inflation of DAUs (25–42%+) and engagement hours (100%+) while reducing child-safety expenditures; Roblox shares fell ~9% on publication. Roblox issued a comprehensive rejection, calling the financial claims "misleading."[3][6] [VERIFIED — CNBC]

Reported vs. Audited Daily Engagement

Hindenburg's technical consultant monitored 7,200 top games across 2.1M servers; audit of 30.4M unique daily users.[3]
2.4 hrs
Reported avg. daily hours per user (2023)
~22 min
Audited avg. actual in-game time per player

Insider Cash-Outs Since 2021 Direct Listing

Stock sold by corporate insiders. CEO David Baszucki portion shown separately.[3]
Total insiders
$1.7B
CEO (Baszucki)
~$115M
12-mo net loss
$1.07B

State AG Settlements — $35.8M Total [VERIFIED]

Government enforcement settlements (April 2026). Roblox admitted no wrongdoing; funds go to states/youth programs, not individual families.[4]
Nevada
$12.5M
Alabama
$12.2M
West Virginia
$11.1M
ALLEGATION

"People" vs. Accounts

Marketing cited tens of millions of "people" daily; SEC disclosures admit DAUs measure active accounts, which can include alternate/bot accounts run by one individual.[3]

ALLEGATION

The "De-Alting" Double Standard

Roblox told the SEC (2023) it could not identify multi-account users, yet former data scientists revealed an internal "de-alting" process and two sets of records. Source value redacted; independent reporting puts the DAU inflation at 25–42%+, with engagement hours inflated 100%+. [VERIFIED — CNBC/Hindenburg][3]

ALLEGATION

Automated Botting Traffic

Adopt Me! (#7) drew an 83,000-signature petition over bot farms; Blox Fruits (#2) was dominated by Vietnamese bot traffic running 20+ automated tabs.[3]

ALLEGATION

AFK / Engagement Incentive

Developer payouts tied to total playtime incentivize "Away From Keyboard" games; users run macros (e.g. "Tiny Task") to avoid idle kicks. A small sample of accounts generated REDACTED of engagement hours by staying logged in 24h+.[3]

ALLEGATION

Safety-Spend Tradeoff

Leadership reportedly resisted robust parental controls to protect session length; a 2% YoY decline in trust-and-safety spend in Q2 2024 [VERIFIED — Financial Express]; moderation outsourced to Asian call centers paid as little as $12/day.[2][3]

COMPANY RESPONSE

Roblox Rejection

Roblox called the report a financially motivated stock manipulation attempt, citing its "Special Note Regarding Operating Metrics" and audited GAAP Q2 2024: bookings of $955.2M and $440.3M trailing free cash flow.[6]

Current Financials — Q1 2026 (audited / SEC) [VERIFIED]

The "resilient business vs. inflated metrics" tension, updated. Strong cash flow alongside continuing losses and a self-imposed guidance cut tied to safety friction.[Q1]
$1.44B
Revenue (+39% YoY)
$1.73B
Bookings (+43% YoY)
$596M
Free cash flow (+40%)
–$248M
Net loss (still unprofitable)
$57M
Accrual for state youth-safety settlements
–71.5%
RBLX vs. 52-wk high (May 15, 2026)

DAU Trajectory — Peak, Ban & Age-Check Friction [VERIFIED]

Roblox's own shareholder letter attributes the Q1 2026 deceleration to the Dec 2025 Russia ban and "greater-than-expected" age-check headwinds.[Q1]
Q1 2025
97.8M
Q3 2025 (peak)
152M
Q4 2025
144M
Q1 2026
132M
06

Sovereign Bans & Regulatory Pushback

Emerging markets transitioned from soft oversight to complete platform bans. Filter by access status.

All
Banned
Cleared
Under Review
JurisdictionAccess StatusCore RationaleReinstatement Dynamic
07

Vigilante Hunters, Whistleblowers & the Suppression Question

A parallel controversy — not in the original source report but central to the public record — concerns Roblox's response to independent "predator hunters" and critics who documented exploitation. Roblox argues unauthorized stings bypass its safety systems and endanger investigations; critics argue the bans suppressed accountability. Both framings are presented below. [ADDED VIA RESEARCH]

Why this matters to the litigation. WIRED reported (Nov 25, 2025) that the crackdown unfolded "as law firms across the country are prepping hundreds of lawsuits" — the same MDL 3166 wave catalogued elsewhere in this portal. The dispute became a reputational flashpoint cited by plaintiffs and commentators alike.[W1]
7b

Two Framings — Side by Side

Roblox's position

Chief Safety Officer Matt Kaufman stated vigilante groups "on multiple occasions" withheld reports from Roblox until after posting on social media to boost followings; updated ToS to prohibit unauthorized "vigilante groups" that bypass its safety systems and alleged impersonation of children.[W1]

Critics' position

Schlep says identities used were all adults "pretending" to be minors (not real children), that evidence was handed to police, and that he began only because Roblox ignored the problem. He frames it as "David vs. Goliath." Ruben Sim rejected the "vigilantism" label.[W1][W2]

Editorial caution. Predator-hunting is legally and ethically contested. Of six alleged predators arrested following Schlep's stings, none had been convicted as of WIRED's reporting; at least one was not prosecuted. The genre's prototype, To Catch a Predator, was cancelled after a $105M NBC settlement following a sting target's suicide. This portal documents the dispute; it does not endorse vigilante methods.[W1][W3]
08

Technical Remediation & Platform Restructuring

2025–2026

Led by Nicky Jackson Colaco, Head of Global Public Policy, Roblox introduced an age-calibrated three-tier account structure and biometric age estimation via partner Persona.[15][18]

Three-Tier Account Structure & Cohort Controls

Biometric Age Estimation (Persona). Users capture a selfie video in-app; Persona's AI estimates an age cohort (Under 9, 9–12, 13–15, 16–17, 18–20, 21+). Roblox states it does not receive or store raw biometric data — processed and deleted by Persona immediately. If estimated under 13, Roblox auto-purges previously collected emails and phone numbers.[18][19] Roblox also committed to the IARC standard (aligning with PEGI / ESRB).[15]
The liability transformation. By collecting facial data to enforce age verification, Roblox has effectively replaced child-grooming liability with biometric data liability under the expanded definitions of COPPA 2.0.[21]
8b

AI Moderation Stack added via research · 2025–2026

Beyond age tiers, Roblox deployed several AI safety systems documented after the source report. These are company-stated capabilities; independent efficacy remains contested in litigation.

AI · GROOMING DETECTION

Roblox Sentinel

A contrastive-learning system that captures text chat in one-minute snapshots to detect early grooming/child-endangerment signals across 6 billion+ chat messages daily, escalating to human analysts and law enforcement. Open-sourced Aug 2025.[S1]

AI · REAL-TIME

RM3 (Real-time Multimodal Moderation)

Evaluates speech, avatar behavior, and on-screen scenes together to shut down individual violating servers (not whole experiences) — reportedly ~5,000 servers/day. Tested in "shadow mode" first.[S2]

SOCIAL GRAPH

Trusted Connections

The former "Friends" system, rebuilt around age estimation. A trusted contact can be added via QR code or phone contacts to confirm an offline relationship, narrowing who minors can reach.[18]

METRIC · ADOPTION

Age-Check Coverage

Roblox reported age-checked users reached ~51% of global DAUs by the end of Q1 2026 — and openly attributed slower growth to friction from the rollout.[Q1]

VENDOR RISK · PERSONA

The Discord Backlash Spillover added Feb 2026

Roblox's age-verification vendor Persona came under heavy public attack in Feb 2026 when Discord announced (Feb 9) a global teen-by-default rollout powered by Persona, then paused the rollout on Feb 24 after a Verge investigation and community backlash. Roblox (Persona's other major customer alongside Reddit and OpenAI) faces renewed scrutiny over biometric-data handling — a concrete post-COPPA-2.0 risk.[N11]

09

The Evolving U.S. Regulatory Landscape

Roblox's 2026 structural shifts occur alongside a major legislative overhaul of youth privacy and online-safety law.[21][23]

FEDERAL · KIDS ACT

Algorithmic Disconnection

Platforms must give minors clear options to opt out of personalized algorithmic recommendations.[23]

FEDERAL · KIDS ACT

Addictive Feature Restrictions

Addictive features such as autoplay and auto-rewards must be disabled by default for minors.[23]

FEDERAL · KIDS ACT

"Actual Knowledge" Standard

The House version scales back the broader "duty of care," triggering requirements only on empirical evidence or direct user declaration of minority.[22]

KOSA

Senate Passage

The Kids Online Safety Act passed the Senate 91–3 on July 30, 2024; its core provisions are incorporated into Rep. Bilirakis's KIDS Act.[23]

COPPA 2.0 · APR 22 2026

No Bundled Consent

First major COPPA overhaul since 2013. Platforms must obtain separate, granular opt-in for targeted advertising and third-party data sharing.[21]

COPPA 2.0

Biometrics = Personal Data

"Personal data" now includes biometric identifiers — bringing facial estimation and voice chat under FTC oversight.[21]

COPPA 2.0

Mixed-Audience Eliminated

If a game's audio/visual style/themes appeal to children, it is legally child-directed regardless of adult userbase — ToS disclaimers no longer shield liability.[21]

10

Evidence, Verified Sources & Disclaimer

The portal's claims were cross-checked against live, public sources (court dockets, wire reporting, regulators, and the original investigators). Links open in a new tab. Tier tags indicate source authority.

⚠ Full Legal & Editorial Disclaimer

1. Unproven allegations. Every abuse, design-negligence, and metric-manipulation claim described here is an allegation in pending civil litigation or a short-seller report. They have not been adjudicated. Roblox Corporation denies the allegations. A defendant is presumed not liable unless and until proven otherwise in a court of law.

2. No settlement of the MDL. As of June 2026, plaintiffs' firms publicly dispute reports of active MDL settlement talks; what exists is a court notice of intent to appoint a settlement master (Thomas J. Perrelli). The $35.8M in settlements are state government enforcement settlements (Nevada, Alabama, West Virginia) in which Roblox did not admit wrongdoing — they are not payments to individual families.

3. Not advice. Informational/journalistic use only. Not legal, financial, or investment advice. Verify everything against primary sources before acting. Figures change frequently.

4. Child-safety reporting. If you believe a child is being exploited online, report to the NCMEC CyberTipline at report.cybertip.org (US) or contact local law enforcement.

9a

External Corroboration of Source Claims cross-checked

Source-report claimIndependent findingStatus
9b

Verified Sources & Further Reading

All
Court / Primary
News / Wire
Company / Regulator
Investigation