How $VLAD turned locked liquidity into a fee-farming scam on Robinhood Chain
Key Takeaways
- •The $VLAD token contract was deployed through the Pons launchpad 46 minutes before the fraudulent post appeared on Tenev's account, indicating the token launch and account compromise were coordinated parts of a single operation.
- •The scam generated approximately $1.2 million to $1.3 million in direct proceeds from early-wallet sales and an additional $59,000 in creator-claimable trading fees within the first hours, with the fee stream continuing as long as the token trades.
- •The Pons launchpad's anti-rug design, which permanently locks liquidity to prevent classic pool drainage, paradoxically enabled a continuing income mechanism because the locked pool still generates fees that the token creator can claim on every swap.
- •This was the second executive-account token fraud on Robinhood Chain within eleven days, following the SCATMAN operation that used hijacked SpaceX accounts and extracted roughly $135,000 through a more traditional pump-and-dump structure.
- •The incident raises unresolved liability questions for launchpad operators and blockchain providers, as anti-fraud infrastructure designed to protect users can simultaneously create a sustainable revenue model for malicious actors.

Hackers who took over Robinhood CEO Vlad Tenev’s X account on Thursday did not execute a conventional rug pull. They promoted Vladhood ($VLAD), a token whose liquidity was locked permanently through the Pons launchpad, making the pool impossible for its creator to drain while still allowing the creator to claim trading fees indefinitely.
The post, which presented $VLAD as the “official mascot” of Robinhood Chain, drew more than 175,000 views in under 20 minutes and helped drive $22 million in trading volume. On-chain records cited by The Defiant and Onchain Lens show the token contract was deployed 46 minutes before the hacked post appeared, and the launch configuration listed Tenev’s own X profile as the token’s official website.
The result was a scam structure that used anti-rug infrastructure as a revenue mechanism. Pons locks token liquidity permanently, but creator wallets can claim fees from trading activity. In the first hours, the $VLAD creator wallet claimed roughly $59,000 in fees, on top of total proceeds estimated at $1.2 million to $1.3 million from early-wallet sales.
The incident was the second executive-account token scam on Robinhood Chain in eleven days and occurred six days before Robinhood’s earnings call. It raises a question that crypto infrastructure providers have not resolved: who is responsible when systems designed to prevent one type of fraud create a business model for another.
Crypto crime has long followed a familiar pattern: create a token, manufacture credibility, attract buyers, drain liquidity, and disappear. That structure gives a rug pull a beginning, middle, and end. The $VLAD incident had the first two parts, but its design gave it no clear endpoint.
Because the token was launched through a platform whose core safety feature locks liquidity permanently, the creator could not remove the liquidity pool. Instead, every swap generated fees that were claimable by the token creator. The Defiant’s on-chain analysis showed that the wallet called the fee-collection function six times in roughly the first two hours.
LATEST: Robinhood CEO Vlad Tenev X account hacked to promote fake memecoin Hackers pushed a purported official $VLAD token as the Robinhood Chain mascot before the account was secured pic.twitter.com/kuMduz7Vbv — crypto.news (@cryptodotnews) July 24, 2026
LATEST: Robinhood CEO Vlad Tenev X account hacked to promote fake memecoin Hackers pushed a purported official $VLAD token as the Robinhood Chain mascot before the account was secured pic.twitter.com/kuMduz7Vbv
The operation, reconstructed
The timeline assembled from on-chain records and reporting by The Defiant and Onchain Lens indicates that the account takeover and token launch were part of one coordinated operation, not an opportunistic response to a lucky compromise.
At 12:38 p.m. ET on Thursday, a wallet with no prior history launched Vladhood through Pons, one of the busiest Pump.fun-style launchpads on Robinhood Chain during the network’s first month. Pump.fun, the Solana-based launchpad that popularized the bonding-curve token model, has spawned imitators across nearly every major chain since its breakout in 2024; Pons is Robinhood Chain’s equivalent, and its locked-liquidity-plus-creator-fee design is a variation on that template. The token’s launch settings included Tenev’s X profile URL in the official website field. That detail suggests the token was configured around an account the creators did not yet publicly control.
Forty-six minutes later, the fraudulent post appeared on Tenev’s verified X account. It asked whether Robinhood loved memes, answered yes, introduced $VLAD as the official mascot of Robinhood Chain, falsely promised a listing in the Robinhood app, signed off with “Welcome to the Hood,” and included the contract address.
The credibility stack was powerful: a verified executive account, the voice of Robinhood’s CEO, a chain Tenev had launched three weeks earlier, and a claim about an app listing that appeared plausible enough to attract immediate trading.
The post received more than 175,000 views in under 20 minutes. The token rose more than 90,000% from launch. Trading volume reached $22 million across roughly 85,000 swaps in the main pool. Its market capitalization reached between $4 million and $10 million, depending on the snapshot. The contract accumulated 5,266 holders and 137,000 transfers on the same afternoon it was deployed.
Robinhood’s communications team confirmed the compromise roughly 41 minutes after the post and worked with X to delete it. Robinhood Chain’s explorer flagged the contract as a likely scam. On-chain monitors estimated that wallets tied to the operation extracted about 650 to 690 ETH, or roughly $1.2 million to $1.3 million, largely through early wallets that reportedly held 70% of supply and sold into the price spike.
JUST IN: Robinhood Chain surpasses 2 million dollars in cumulative revenue since launch 200,000 dollars in AEP fees will flow back to the Arbitrum ecosystem pic.twitter.com/1t260Hkogi — crypto.news (@cryptodotnews) July 23, 2026
JUST IN: Robinhood Chain surpasses 2 million dollars in cumulative revenue since launch 200,000 dollars in AEP fees will flow back to the Arbitrum ecosystem pic.twitter.com/1t260Hkogi
Robinhood Chain is built on Arbitrum’s technology stack, and the AEP fee arrangement referenced above means a portion of chain revenue flows back to the Arbitrum ecosystem — linking the fraud’s trading activity, however indirectly, to broader Layer-2 economics.
But the early sales were not the end of the scheme. They were the first layer of proceeds.
The mechanism: anti-rug protection as an annuity
The central feature of the incident is the way it used a legitimate anti-rug mechanism. Launchpads in the Pump.fun model try to prevent classic rug pulls by locking a token’s liquidity in a contract that the creator cannot drain after the token graduates to a trading pool. Because the creator cannot remove the pool, the traditional exit scam of pulling liquidity and collapsing the market is mechanically blocked.
Pons uses that standard structure with a related incentive: the locked liquidity pool continues to generate trading fees on swaps, and those fees can be claimed by the token creator. In legitimate launches, that design rewards creators whose tokens maintain trading volume.
In the $VLAD case, the same design allowed the attacker to continue earning after the fraud was exposed. The creator could not rug the pool, but did not need to. Panic selling, attempts by holders to exit, speculative trading, arbitrage, and volatility trading all generated fees. Those fees flowed to the creator wallet whenever it called the claim function.
Starting seven minutes after the fake post, the wallet called the locker’s fee-collection function six times over about two hours, receiving about 31.6 ETH, or roughly $59,000. The balance continues to grow for as long as the token trades. As The Defiant framed it, the wallet did not have to pull liquidity to cash out. The token did not rug; it collected.
That changes the economics of the scam. A rug pull monetizes credibility once, in a single extractive event that ends the fraud. A locked-liquidity fee stream turns the same stolen credibility into an income-producing asset: a continuing claim on trading activity in a token whose creator cannot kill the pool, whose notoriety may itself sustain volume, and whose victims’ attempts to trade can pay the creator.
Crypto.news covered a predecessor eleven days earlier: the SCATMAN operation, which used hijacked SpaceX accounts to promote a token on the same chain and extracted about $135,000 in a more traditional pump-and-dump structure. $VLAD’s operators took roughly ten times that amount in the opening hours and, structurally, the fee stream did not end.
NEW: RelayProtocol warns of scam tokens on Robinhood Chain that disappear after purchase pic.twitter.com/QpwHTBVWbJ — crypto.news (@cryptodotnews) July 10, 2026
NEW: RelayProtocol warns of scam tokens on Robinhood Chain that disappear after purchase pic.twitter.com/QpwHTBVWbJ
The venue, timing, and liability question
The venue matters because Robinhood Chain is operated by a licensed brokerage and the incident occurred six days before the company’s earnings call.
During its first month, Robinhood Chain recorded $700 million in assets, 300,000 daily active addresses, high decentralized-exchange volume, third place in seven-day chain revenue, and a composition problem: memecoins drove most of the activity, while tokenized real-world assets, the category the chain was built to support, accounted for about $13 million.
The scam wave sharpened that issue. On July 12, SCATMAN used hijacked SpaceX accounts on the same chain. A launchpad later went dark during the chain’s memecoin boom after collecting an estimated $12 million in fees. Then a token using the face of the chain’s founder became the network’s most sophisticated fraud, even as the chain’s explorer flagged the token as a scam.
The uncomfortable point is that chain fee mechanics still collect revenue on trading activity, including trades in flagged scam tokens, and the sequencer’s operator also benefits from activity. Robinhood did not authorize $VLAD, but a brokerage presenting itself as a compliant bridge to digital assets is now connected to protocol revenue from a fraud impersonating its own CEO.
JUST IN: Zach Brenner says Robinhood Chain sees cool innovation in RWAs stock tokens NFTs and memecoins The ecosystem is experimenting with a wide range of digital asset applications pic.twitter.com/Zlx4PH2vht — crypto.news (@cryptodotnews) July 20, 2026
JUST IN: Zach Brenner says Robinhood Chain sees cool innovation in RWAs stock tokens NFTs and memecoins The ecosystem is experimenting with a wide range of digital asset applications pic.twitter.com/Zlx4PH2vht
The liability question is no longer hypothetical. Pons designed the locker; the locker guarantees the fee stream; and a design choice that prevents liquidity removal also funds the creator of a fraudulent token. The unresolved issue is whether Pons is merely a neutral tool provider or whether operating a system that lets any account thief create a fee-generating token creates obligations to freeze creator-fee claims on flagged tokens, require identity for fee withdrawals, or add a kill switch to infrastructure designed to be permissionless.
Each option carries trade-offs. Freezable fees reintroduce a trusted operator. Identity requirements weaken the permissionless launch model that drives volume. Inaction leaves the fee annuity running.
The same problem applies to the chain and to X. Verified-account security has now been the entry point for two large-audience token frauds in eleven days on Robinhood Chain, part of a broader pattern that includes the 2024 celebrity-account wave and this month’s fake Armstrong coin — a fraudulent token promoted through the compromised account of Coinbase CEO Brian Armstrong. Executive social accounts have become a form of financial infrastructure while often remaining secured like ordinary consumer accounts.
The economics of borrowed trust
The incident also provides a measurement of the value of stolen credibility. Tenev’s compromised account had roughly 15 million followers. The post remained in primary distribution for about 20 minutes and drew 175,000 views. The token processed $22 million in volume and reached 5,266 holders within hours. Operators extracted $1.2 million to $1.3 million in direct proceeds, plus the ongoing creator-fee stream.
That equates to roughly $65,000 of extraction per minute of post uptime, about $7.40 per view, and around $250 of eventual trading volume per view. Those figures help explain why executive account compromise has become more professionalized, with access brokers sourcing credentials, operators preparing token infrastructure in advance, and distribution specialists timing posts.
The 46-minute gap between token deployment and the hacked post is significant. The attack was not assembled after the account was taken over publicly; the token was ready before the distribution event. Compared with SCATMAN, which used a smaller account constellation and a less complex mechanism, the $VLAD incident produced about ten times more in proceeds, reflecting how returns scale with audience quality and mechanism sophistication.
The timeline also shows where defenses failed to bind. Explorer flags, account restoration, and post deletion all occurred within the hour, but the operation became profitable within seven minutes. By the time the post was deleted, the main extraction window had already occurred.
The strongest defensive measures would operate upstream. Large verified accounts could be treated as financial infrastructure, with hardware-key requirements and stricter session hygiene for accounts above a certain audience threshold. Launchpads could also impose creator-fee escrow periods, delaying fee claims long enough for scam flags to propagate. Such a delay could have turned the $VLAD fee stream into a frozen exhibit without preventing permissionless token launch itself.
Neither measure requires identifying every creator. Both reduce the throughput of the fraud funnel rather than focusing only on its aftermath. The current posture, in which a high-reach account is secured according to the owner’s chosen practices and a flagged token’s fees flow to its operator in real time, effectively creates a public bounty schedule.
What to watch
The first issue is the fee meter. The creator wallet’s claims are public and ongoing. Whether the balance crosses six figures, and whether Pons, Robinhood Chain, a court, or another actor interrupts it, will show whether the industry treats the incident as an isolated case or a precedent. As of the first day, the architecture itself did not stop the payments.
The second issue is the launchpad response. Pons faces the trilemma first: freeze mechanics, identity gates, or explicit neutrality. Its decision, and whether Robinhood Chain pressures it, will help define the first rules for fee-annuity scams. The structure is readily replicable on any chain with a locked-liquidity launchpad.
The third issue is Robinhood’s July 29 earnings call. If analysts or Say-platform retail questioners press management to address the scam wave on the record, the company’s response could be an early public statement by a brokerage on responsibility for fraud conducted on infrastructure it operates and profits from.
The fourth issue is the security postmortem. Whether the account takeover involved SIM swapping, session theft, insider access, or another method matters for executives across the industry. The $VLAD operation’s key innovation was the pairing of planned token engineering with account compromise. The 46-minute gap between deployment and posting shows that the operation was manufactured in advance.
The broader significance is that a scam can now use anti-rug infrastructure to create continuing income. $VLAD’s operators showed that a locked-liquidity system can convert stolen credibility into a mechanically persistent fee stream. The roughly $59,000 in early claimed fees is a small figure compared with the design it demonstrates: every locked pool on every launchpad can become a potential annuity for whoever can manufacture a short period of borrowed trust.
There is also a legal naming problem. Existing law has familiar vocabulary for rug pulls, including theft, wire fraud, and market manipulation, each tied to an exit event. A fee annuity is less straightforward. The initial impersonation is plainly criminal in the account takeover and false listing claim, and any eventual defendant could face those counts. The ongoing income stream is more difficult to classify.
After exposure, later traders in $VLAD may know the token is flagged, the fee mechanism is visible, and the creator earns from trading. The operator extracts value not necessarily by deceiving those later traders, but because the earlier deception created the pool and its notoriety. Whether collecting contract-defined fees from informed speculators is ongoing fraud, unjust enrichment, or lawful but objectionable conduct is a question courts have not answered.
That answer matters because it will determine whether the fee stream can be seized, whether launchpads face liability for paying it out, and whether the model spreads. Enforcement history suggests the question may be resolved only after a later incident at larger scale forces legal doctrine to catch up. Until then, the $VLAD wallet can continue calling its function, the locker can continue paying, and the gap between what the mechanism permits and what the law has named can continue collecting fees.
Frequently asked questions
What happened to Vlad Tenev’s X account?
Hackers took control of Robinhood CEO Vlad Tenev’s verified X account on Thursday, July 23, and posted a promotion for a fake memecoin called Vladhood ($VLAD). The post presented the token as the official mascot of Robinhood Chain and falsely claimed it would be listed on the Robinhood app. It drew more than 175,000 views in under 20 minutes before removal. Robinhood confirmed the compromise about 41 minutes after the post and said it was working with X to restore access.
Was this an opportunistic hack?
No. On-chain records show the token contract was deployed through the Pons launchpad 46 minutes before the fraudulent post appeared. The launch configuration listed Tenev’s own X profile as the token’s official website, indicating that the token launch and account compromise were coordinated parts of a single operation.
How much did the attackers make?
On-chain monitors estimate total proceeds of roughly 650 to 690 ETH, or about $1.2 million to $1.3 million, largely from early wallets that reportedly held 70% of supply and sold into the price spike. Separately, the locked liquidity pool paid the creator wallet about $59,000 in trading fees in the first hours, claimed across six withdrawals, and that stream continues to accrue with every trade.
Why is the token impossible to rug pull, and why does that matter?
The Pons launchpad locks a token’s liquidity in a contract the creator cannot drain. That prevents a classic liquidity-removal rug pull. However, the locked pool still generates trading fees that the creator can claim. In this case, the attacker gained a continuing income stream from trades in the token.
How does this compare with the SCATMAN incident?
SCATMAN, eleven days earlier, used hijacked SpaceX and Starlink accounts to promote a token on the same chain and extracted roughly $135,000 in a traditional pump-and-dump structure. $VLAD extracted about ten times more in its opening hours and has a continuing fee stream because of the locked-liquidity mechanism.
Does Robinhood bear responsibility for scams on its chain?
That remains unresolved. Robinhood did not authorize the token and the chain is permissionless, but the network and its sequencer earn revenue from activity, including fraudulent activity. The explorer’s scam flag cannot stop trading or fee claims. Launchpads face a related dilemma: freezing fees or requiring identity would compromise permissionless design, while doing nothing leaves the annuity running.
What should users take from this?
Verified executive accounts have become a major fraud vector. Two incidents in eleven days used hijacked official accounts. Posts announcing surprise tokens should be checked against official company channels. Locked liquidity means a token cannot be rugged through liquidity removal; it does not mean the token is legitimate. In this design, trading a flagged token can pay its creator.
Could this scam model spread?
Yes. Any launchpad that combines locked liquidity with creator-claimable fees can host the same structure. The required ingredient is a brief period of borrowed credibility from a compromised account with reach. Until platforms create mechanisms to interrupt fee claims on flagged tokens, each such pool can become a continuing payout for the creator.
Disclaimer: This article is for information and educational purposes only and does not constitute financial, investment, or legal advice. It describes an ongoing security incident based on on-chain data and reporting available at the time of writing, and figures may change as investigations continue. Never interact with tokens promoted through unverified or compromised channels. Always do your own research. Information is accurate as of July 24, 2026.