When hackers broke into Robinhood’s CEO’s X (formerly Twitter) account, they didn’t simply steal information or money. Instead, they created a new digital token with its funds permanently locked – meaning it can’t be fraudulently taken. Now, the hackers are continuously collecting fees from trades of this token. Essentially, the classic ‘rug pull’ scam has been transformed into something that generates ongoing income for them, and the security systems designed to prevent scams inadvertently enabled it.
Summary
- Hackers compromised Robinhood CEO Vlad Tenev’s X account on Thursday and promoted Vladhood ($VLAD) as the “official mascot” of Robinhood Chain, drawing 175,000 views in under 20 minutes and $22 million in trading volume.
- The operation was premeditated, not opportunistic: the token contract deployed 46 minutes before the hacked post, through the Pons launchpad, with Tenev’s own X profile listed as the token’s official website.
- The mechanism is the story: Pons locks a token’s liquidity permanently, making rug pulls impossible, but lets creators claim trading fees, so the attacker farms income from every trade, roughly $59,000 claimed in the first hours and still accruing, atop total proceeds estimated at $1.2-1.3 million.
- The design inverts a decade of scam economics: instead of one exit event, the scammer holds a perpetual annuity on victim activity, and the anti-rug protection that legitimizes the launchpad is precisely what guarantees the income.
- It is the second executive-account token scam on Robinhood Chain in eleven days, six days before the company’s earnings call, and it poses a question the industry has not answered: who is liable when scam-proofing infrastructure becomes the scam’s business model.
For years, crypto scams have followed a predictable pattern: launch a new digital token, build up its reputation, attract investors, and then disappear with the money – known as a ‘rug pull.’ But a recent hack of Robinhood’s CEO’s social media account took a different approach. Hackers promoted a memecoin called Vladhood to 15 million followers, creating initial excitement, but with no clear plan for what would happen next, seemingly abandoning the typical scam structure.
As a crypto investor, I was really disturbed by what happened with $VLAD. It launched on a platform that’s supposed to prevent ‘rug pulls’ – where creators run off with investors’ money – by permanently locking up the token’s liquidity. Ironically, this feature *enabled* the scam! Instead of being a one-time theft, it became a continuous income stream for the hacker. The locked pool keeps collecting fees from every trade, and those fees are automatically sent directly to the creator… who is, of course, the attacker. They siphoned off funds six times within the first two hours, and there’s absolutely no incentive for them to stop. It wasn’t just a robbery; it was like building a toll booth on a road paved with stolen trust, openly collecting money with every transaction, all shielded by the very security measure designed to protect us. The Defiant quickly traced everything on the blockchain, but this situation raises serious questions about how these launchpads work, and what it means for the future of scamming in crypto – especially considering this is the second token impersonating someone important on this particular chain in just eleven days.
Robinhood CEO Vlad Tenev’s X (formerly Twitter) account was briefly hacked. The hackers used the account to promote a fake cryptocurrency token called $VLAD, falsely presenting it as an official token for the Robinhood Chain, before the account was secured.
— crypto.news (@cryptodotnews) July 24, 2026
The operation, reconstructed
Based on a review of blockchain data by The Defiant and Onchain Lens, it’s clear this wasn’t a random hack followed by a scam. Instead, the evidence shows a carefully planned, coordinated operation centered around gaining control of an account.
On Thursday at 12:38 pm Eastern Time, a new cryptocurrency token called Vladhood was released through Pons, one of the most active launchpads on the Robinhood Chain. Interestingly, the token’s setup revealed that its creators had planned this in advance – they linked the token’s website to an X (formerly Twitter) profile they didn’t yet publicly own. Just forty-six minutes later, a post appeared on that account, belonging to Vlad Tenev, Robinhood’s CEO. The post playfully introduced $VLAD as the official mascot of Robinhood Chain and falsely suggested it would be listed on the main Robinhood app, signing off with “Welcome to the Hood” and including the token’s contract address. This created a convincing appearance of legitimacy: a verified account, endorsement from the CEO, a blockchain he helped create, and a believable (though ultimately false) promise of an official app listing.
The market reacted predictably to a fabricated sense of trustworthiness. A recent post gained over 175,000 views in less than 20 minutes, causing the token’s value to surge by more than 90,000% since its launch. Trading volume hit $22 million with around 85,000 transactions in the primary trading pool, and the token’s market value peaked between $4 million and $10 million. The contract, created that same day, had 5,266 owners and saw 137,000 transactions. About 41 minutes after the post appeared, Robinhood confirmed a security breach and worked with X (formerly Twitter) to remove it. Blockchain analysis tools quickly identified the contract as a probable scam. Those behind the scheme made off with an estimated 650 to 690 ETH—roughly $1.2 to $1.3 million—by having early wallets, which controlled about 70% of the token supply, sell their holdings during the price spike.
Robinhood Chain has now generated over $2 million in revenue since its launch. A portion of this, $200,000 in AEP fees, will be returned to the Arbitrum ecosystem.
— crypto.news (@cryptodotnews) July 23, 2026
What really sets this apart is that the sale wasn’t the final result – it was just the first payment towards something bigger.
The mechanism: anti-rug as annuity
Understanding any new advancement begins with recognizing what it safeguards, as this safeguard is genuine and the advancement relies on that existing security.
Pump.fun-style launchpads address the problem of ‘rug pulls’ by automatically locking the funds in a special contract once a token starts trading. This prevents the creator from withdrawing the funds and crashing the price, which is the main appeal for traders who might otherwise be wary of anonymous tokens. Pons operates like these other platforms, offering the benefit of locked funds while still allowing the token creator to earn fees from trades. This incentivizes genuine developers to build successful tokens that maintain trading activity.
Now, let’s look at how the $VLAD scheme works. The attacker didn’t need to steal funds and disappear – in fact, they didn’t even try. Instead, every transaction involving the token triggers a fee that automatically goes to the creator’s wallet. This includes panicked selling after the scam was revealed, people trying to recover their losses by buying more, day traders capitalizing on price swings, and automated bots taking advantage of the confusion. Starting just seven minutes after the initial fake announcement, the attacker’s wallet collected these fees six times over two hours, earning around $59,000 (31.6 ETH), and it’s still accumulating money with every trade. As The Defiant pointed out, this scheme is unique because the creator didn’t need to remove funds from the trading pool; the token wasn’t manipulated in a typical ‘rug pull’. It simply continues to generate revenue through fees.
It’s important to understand the economic strategy behind these scams. A typical ‘rug pull’ steals money once and then shuts down, prompting authorities to investigate. However, newer scams are different: they lock up stolen funds to create a continuous revenue stream. This means the scam continues as long as people trade the token, with victims unknowingly funding the scammer every time they try to sell. Essentially, the scam has become a sustainable business model, ironically enabled by the tools designed to prevent them. A similar operation just eleven days prior, called SCATMAN, stole $135,000 and quickly ended. But this new scam, involving the token $VLAD, made ten times that amount in its first few hours and shows no signs of stopping. This isn’t just a theft; it’s an evolution into a scalable, ongoing fraud.
NEW: RelayProtocol warns of scam tokens on Robinhood Chain that disappear after purchase
— crypto.news (@cryptodotnews) July 10, 2026
The venue, the timing, and the liability question
The situation adds another layer of complexity to the story, as the cryptocurrency exchange where this is happening is part of a publicly traded brokerage firm that will be announcing its financial results in just six days.
Robinhood Chain had a strong start, attracting $700 million in assets and 300,000 daily users in its first month. It quickly became a popular platform for trading, ranking third in weekly revenue among similar chains. However, the activity is heavily dominated by speculative “memecoins,” while the real-world asset tokens the chain was designed to support represent only about $13 million worth of trades.
A major issue is the prevalence of scams on the platform. Recent examples include fraudulent activity linked to hijacked social media accounts and a launchpad that disappeared with around $12 million in user fees. Most concerningly, a scam token even uses the chain’s founder’s image – and while the chain identifies it as fraudulent, it still profits from trading fees generated by it.
This creates an awkward situation for Robinhood Chain, which aims to be a regulated platform for digital assets. The company is now earning revenue, albeit small, from a scam impersonating its CEO, and will need to address this issue during their upcoming earnings call with analysts and investors. This incident sets the stage for a difficult conversation about the chain’s first month of performance.
According to Zach Brenner, Robinhood’s blockchain platform is showing promising developments in areas like real-world asset tokens, NFTs, memecoins, and traditional stocks. The platform is actively testing various uses for digital assets.
— crypto.news (@cryptodotnews) July 20, 2026
The biggest unresolved issue in the crypto space is who’s responsible when things go wrong, and the $VLAD token highlights this problem by making it real. The way these ‘launchpads’ work – designing a system that unintentionally funds scammers – creates a difficult situation. Pons, the platform profiting from launch fees, faces scrutiny because of its connection to flagged tokens. Is it simply a neutral service provider, or does enabling a system easily exploited by thieves create legal obligations? Should they freeze payments on suspicious tokens, require users to verify their identity to receive funds, or implement a ‘kill switch’ to stop scams? Each solution has drawbacks: freezing fees would reintroduce centralized control, requiring IDs undermines the open nature of these launches, and inaction allows fraud to continue. This same challenge extends to the blockchain itself, and even to platforms like X, where compromised accounts have been used in recent large-scale token frauds. Essentially, social media executive accounts are now acting as financial infrastructure, but aren’t being secured with sufficient safeguards.
The economics of borrowed trust, quantified
Looking beyond the details of what happened reveals something valuable: a clear understanding of how much damaged trust costs each minute, and how the market assigns a price to that loss.
Analyzing the attack as a sales funnel reveals its efficiency. The compromised account had around 15 million followers, and the malicious post remained visible for about 20 minutes, garnering 175,000 views. Within hours, the associated token processed $22 million in transactions and attracted 5,266 holders. The attackers directly profited between $1.2 and $1.3 million, with additional revenue from ongoing fees. This translates to roughly $65,000 in profit per minute the post was live, about $7.40 per view, and around $250 in transaction volume per view. These figures demonstrate why hacking executive accounts has become a highly organized business with a clear structure: some individuals provide access to accounts, others set up the token infrastructure beforehand, and still others time the release of the post. The 46 minutes of preparation before the post went live indicates a pre-planned operation. The ‘SCATMAN’ attack, which used smaller accounts and a less sophisticated method, generated about a tenth of the revenue, which aligns with what we’d expect from a growing industry – better accounts and more advanced techniques lead to higher returns. Both audience quality and the complexity of the attack are increasing, driving greater profits.
Our analysis shows that the biggest problems aren’t happening where most of the industry focuses its efforts. We can quickly detect and address issues like fraudulent accounts – within an hour – and this operation became profitable in just seven minutes. However, blocking distribution after content is already extracted isn’t effective. The real bottlenecks are at the beginning: securing accounts before they distribute content and having the necessary systems ready to launch monetization anonymously. That’s why the most impactful solutions—requiring hardware security keys and strong account login practices for popular accounts—are often overlooked. These would treat large, verified accounts as critical financial infrastructure. Another helpful step is delaying access to fees on new platforms, giving time to flag fraudulent activity without disrupting permissionless launches. This could have prevented a specific case ($VLAD) from continuing to profit from harmful content. Importantly, these solutions don’t rely on identifying individuals; they focus on limiting the speed at which problems can occur, rather than cleaning up after them. The current system, where high-profile accounts have weak security and scammers receive payments instantly, isn’t a policy—it’s an open invitation for abuse that bad actors exploit daily.
What to watch
The amount of fees collected is key. The creator’s wallet publicly shows how much is being earned, and how long that earning continues – even if it reaches a substantial sum – will be the clearest sign of whether this situation is seen as a one-time event or a new standard for the industry. From the very beginning, the system was designed without any way to halt these payments.
Pons, a platform for launching new projects, is grappling with a difficult choice: limit how projects function, require strict identity verification, or remain completely neutral. This decision, and how much pressure it faces from Robinhood Chain, will essentially set the standard for how future projects operate, and others will likely follow suit. Because the system is easily copied on any platform that offers locked-liquidity launches – and they all do – this is a crucial moment.
As a researcher, I’m closely watching the upcoming earnings call on July 29th. It will be significant if analysts or those asking questions push management to publicly acknowledge the recent surge in scams happening on their platform. Even more importantly, I’ll be looking for how they respond – whether they talk about simply identifying these issues, actively moderating content, or taking stronger enforcement actions. If this happens, it would be the first time a brokerage has clearly stated its responsibility for fraudulent activity occurring through the services it provides and profits from.
A review of the security breach revealed how attackers gained access – through SIM swapping, stealing active login sessions, and potentially with help from someone inside the company. This should concern all industry leaders because the $VLAD operation uniquely combined careful planning with direct account takeovers. The 46-minute delay between when the malicious code was launched and when it posted its results is a key indicator that this attack wasn’t random; it was deliberately constructed, and that means it can be replicated.
As I’ve been researching fraudulent activity in crypto, it’s become clear that the traditional ‘rug pull’ is changing. It’s not disappearing, but *evolving* into something new – a type of financial exploitation that current laws don’t quite address. The creators of the $VLAD token demonstrated a deep understanding of how these systems work. They exploited the very mechanisms designed to build trust and turned them into a source of ongoing income, operating in a legal gray area and proving incredibly difficult to stop. While the initial reported losses of around $59,000 seem relatively small, the underlying *design* is the real problem. It shows that any locked liquidity pool on any launchpad across all blockchains is now potentially vulnerable – anyone who can convincingly fake trust for just an hour can create a continuous stream of income for themselves. Critically, the industry focused so much on *creating* these locking mechanisms but hasn’t developed effective ways to prevent payouts to those who exploit them.
The way we define what happened with $VLAD will significantly impact how the legal system responds. While terms like theft or fraud easily apply to typical ‘rug pulls,’ the $VLAD situation is different. Initial actions, like identity theft and false claims, are clearly illegal. However, the ongoing collection of fees is a gray area. After the issue was revealed, anyone trading $VLAD knew about the flagged token and disclosed fees. The creator isn’t deceiving current traders, but profiting from past deception. It’s unclear whether legally collecting these fees from informed traders is fraud, unfair gain, or simply an unpleasant but legal practice. No court has addressed this yet, and the answer will determine if the funds can be seized, if launchpads are liable for distributing them, and whether similar designs will proliferate. This highlights the challenge of applying legal frameworks to novel mechanisms. History suggests this issue won’t be resolved until a much larger, more blatant fraud forces a legal precedent. Until then, $VLAD continues to operate, the fees continue to be paid, and a gap remains between what the mechanism allows and what the law defines as illegal.
Frequently asked questions
What happened to Vlad Tenev’s X account?
On Thursday, July 23rd, hackers gained access to the verified X (formerly Twitter) account of Robinhood’s CEO. They used the account to promote a fraudulent cryptocurrency called Vladhood ($VLAD), falsely presenting it as an official part of Robinhood and claiming it would be available on the Robinhood app. The misleading post quickly received over 175,000 views before being taken down. Robinhood confirmed the hack about 41 minutes later and stated they were working with X to regain control of the account.
Was this an opportunistic hack?
This wasn’t a spontaneous event; it was carefully planned and executed. Blockchain data reveals the token contract was created almost an hour before the fake post went live. Crucially, the launch details linked the token’s official website to Tenev’s X profile, indicating the entire scheme depended on hacking his account – something that hadn’t been publicly announced yet. The account takeover and token launch were clearly part of a single, coordinated plan.
How much did the attackers make?
Initial analysis shows the exploit resulted in around 650 to 690 ETH – roughly $1.2 to $1.3 million – being stolen. Most of this came from early investors who held about 70% of the token supply and quickly sold during the price surge. Additionally, the creator’s wallet has already earned approximately $59,000 in trading fees from the locked liquidity pool within just a few hours, with more fees continuing to accumulate with each transaction.
Why is the token impossible to rug pull, and why does that matter?
Pons launchpads protect investors by locking a token’s funds in a secure contract that the creator can’t access, preventing them from simply running off with the money. While this stops immediate scams, the locked funds still earn trading fees which the creator can continue to collect. This turns a potential one-time theft into a continuous income for the attacker, and ironically, the security measure designed to prevent the scam actually ensures this ongoing profit.
How does this compare to the SCATMAN incident?
As a crypto investor, I’ve been watching this closely. About eleven days ago, someone calling themselves SCATMAN hacked into SpaceX and Starlink accounts to pump up a token – a classic pump-and-dump that netted them around $135,000, but it was a one-time thing. Now, with $VLAD, we’re seeing something different. It pulled in about ten times *more* money in just the first few hours, and unlike SCATMAN’s scheme, this one isn’t designed to finish; it keeps generating fees as long as people are trading. Basically, these two events show how quickly things are changing – someone tried a simple pump-and-dump, then immediately followed it up with something much more persistent.
Does Robinhood bear responsibility for scams on its chain?
This whole situation really highlights a big problem in crypto. Because blockchains are open to everyone, Robinhood didn’t approve this token, but the network itself *and* the people who process transactions still profit from everything happening on it – even if it’s fraudulent. Simply flagging it on a block explorer doesn’t stop anyone from trading or claiming fees. The platform that launched this token is stuck too – if they freeze fees or require ID, they ruin the open, permissionless nature of the blockchain. But if they do nothing, the problem continues. Honestly, it feels like no one has figured out who’s responsible for dealing with issues like this yet.
What should users take from this?
Compromised accounts belonging to company executives are now a main way scammers operate. Recent events show that hackers are quickly taking over these accounts to announce fake tokens. If you see a new token announced this way, assume the account has been hacked and verify the information through official company sources – which, in recent cases, haven’t said anything about these announcements. While ‘locked liquidity’ can prevent a scam where the token creator runs away with the money, it doesn’t guarantee the token is real, and the current system actually rewards the token’s creator when someone trades a flagged token.
Could this scam model spread?
The key issue is how easily this can be exploited. Any platform that uses locked funds and allows creators to collect fees – a common setup across many blockchains – can be set up this way. All it takes is briefly using a compromised account with some influence. Until platforms can stop payments to flagged tokens, these pools could become a constant source of funds for those who create the initial impression of trust. Please remember this is just an explanation of how things work, and not financial or legal advice.
2026-07-24 13:59