Robinhood CEO Vlad Tenev's X Account Hacked to Promote VLAD Memecoin
Key Takeaways
- •Robinhood said Vlad Tenev’s X account was compromised after it posted a fraudulent promotion for a VLAD memecoin.
- •The fake token generated more than 10,000 contract transactions, and the contract currently shows a balance of zero.
- •Onchain investigator MLM reported that the hacker withdrew about 650 ETH, valued at approximately $1.2 million, across six addresses.
- •Robinhood Chain’s block explorer flagged the VLAD contract as a scam and warned users not to interact with it.
- •Robinhood Chain has seen daily transactions exceed 10 million on multiple days, with most activity tied to memecoin trading.

A hacker compromised the X (formerly Twitter) account of Robinhood CEO Vlad Tenev to promote a fraudulent memecoin named VLAD, generating approximately 650 ETH in proceeds valued at around $1.2 million.
A now-deleted post from Tenev's account claimed that Robinhood had officially launched a token called VLAD, describing it as the official mascot of the recently launched Robinhood Chain. The post included a contract address and asserted that Robinhood would list VLAD on its trading platform.
Robinhood's communications team subsequently confirmed that the post was fraudulent, stating that Tenev's account had been compromised and that the company was working to recover access. Robinhood Chain's block explorer also flagged the VLAD contract address as a scam, warning users against interacting with it. The false listing claim was significant because token promotions tied to official corporate accounts can appear credible before companies have time to publicly disavow them.
Hacker Extracts 650 ETH From VLAD Token
Although the fraudulent post has been removed, the promotion achieved the attacker's objective. Robinhood's block explorer records over 10,000 transactions on the token contract, while the contract address currently shows a balance of $0.
According to onchain investigator MLM, the hacker successfully withdrew approximately 650 ETH, valued at roughly $1.2 million, from the token. The funds were distributed across six separate addresses.
The incident underscores the persistent threat of social media account compromises used to promote fake tokens. While this tactic is not new, the attacker leveraged heightened interest in Robinhood's cryptocurrency initiatives. Similar scams often rely on urgency, executive impersonation, and contract-address posts to push users toward interacting with unaudited or malicious tokens before warnings circulate.
Memecoin Activity Surges on Robinhood Chain
Robinhood launched its Ethereum Layer 2 network, Robinhood Chain, on July 1, joining Coinbase and Kraken, both of which have also deployed Ethereum L2 networks. These exchange-backed networks are part of a broader effort by trading platforms to bring more crypto activity, including decentralized applications and tokenized assets, onto lower-cost Ethereum scaling infrastructure.
Since launch, Robinhood Chain has experienced significant activity, with daily transaction volume exceeding 10 million on multiple days. The majority of this volume stems from memecoin trading on the network.
Tenev himself acknowledged this trend, noting that the network performs well for memecoins despite being primarily designed for real-world asset (RWA) tokenization.
According to DefiLlama, Robinhood Chain currently has a total value locked (TVL) of $308 million, with bridged TVL approaching $1 billion. Average daily decentralized exchange volume has surpassed $500 million over the past two weeks.
Despite the memecoin dominance, Robinhood Chain continues to emphasize RWA as its core focus. The network recently integrated the decentralized perpetuals exchange Lighter, enabling users to use their stock tokens as collateral on the platform's Perps DEX. The contrast between Robinhood Chain's stated RWA focus and its current memecoin-heavy activity makes security warnings, official communications, and contract verification especially important for users following new token launches on the network.