NewsCryptoFake 'Vladhood' Token Operator Still Collecting Fees After Hack of Robinhood CEO's X Account

Fake 'Vladhood' Token Operator Still Collecting Fees After Hack of Robinhood CEO's X Account

Author: CryptoNewsNet·

Key Takeaways

  • Robinhood said Vlad Tenev’s X account was hacked and used to publish a fake promotion for the Vladhood memecoin.
  • VLAD recorded more than $22 million in trading volume and about 85,000 swaps in its primary Uniswap pool within hours.
  • Onchain records show the deployer claimed about 31.6 ETH and roughly 72 million VLAD through trading-fee collection while liquidity remained locked.
  • The fraudulent post drew more than 175,000 views in under 20 minutes before it was removed after user reports.
  • The breach is at least the third recent memecoin-related social media scam connected to Robinhood Chain.
Fake 'Vladhood' Token Operator Still Collecting Fees After Hack of Robinhood CEO's X Account

Fake 'Vladhood' Token Operator Still Collecting Fees After Hack of Robinhood CEO's X Account

The X account of Robinhood CEO Vlad Tenev was compromised on Thursday and used to promote a fraudulent memecoin built on Robinhood Chain, the company confirmed. Onchain records reveal that the scheme was orchestrated hours before the post went live and was structured to monetize the resulting trading frenzy without the operators ever needing to pull liquidity. The incident fits a broader pattern in which compromised accounts of prominent figures and brands on X are used to promote fraudulent tokens to their followers before the activity can be halted.

"Heads up: Our CEO Vlad Tenev's X account was compromised and posted a fake promotion for a meme coin," Robinhood's communications team stated in a post on X roughly 41 minutes after the fraudulent promotion appeared. "We're working with X to restore access and the post has been removed."

The token, dubbed Vladhood (VLAD), generated more than $22 million in trading volume and approximately 85,000 swaps in its primary Uniswap pool within hours of the post, according to DexScreener data. As of 3:55 pm ET, VLAD was trading near $0.0026 with a fully diluted valuation of roughly $2.6 million — down about 20% over the preceding hour but still up more than 90,000% from its launch price. The contract had attracted 5,266 holders and recorded over 137,000 transfers on Robinhood Chain's block explorer, which has since flagged it as a scam.

A Token Purpose-Built for the Hack

The wallet responsible for deploying Vladhood, identified as 0xD706…438D, was created specifically for the operation. Onchain records indicate it received its sole funding of 0.2955 ETH at 11:25 am ET on Thursday from a wallet that block explorers identify as the solver for Relay, a cross-chain bridging service — a routing method that obscures the originating chain.

At 12:38 pm ET, the wallet executed its first transaction: launching Vladhood through Pons, the most active of the Pump.fun-style token launchpads that have emerged on Robinhood Chain. Pump.fun, originally launched on Solana, popularized a model in which tokens are created via bonding curves without requiring creators to seed liquidity pools, lowering the barrier to deploying new tokens and contributing to the proliferation of memecoins across chains. The launch parameters listed https://x.com/vladtenev — Tenev's official X profile — as the token's designated website. The fraudulent promotion appeared on that account 46 minutes later, indicating that the token launch and the account compromise were components of a single coordinated effort rather than opportunistic exploitation of an unrelated breach.

The wallet did not need to withdraw liquidity to realize profits. Pons locks a launched token's liquidity inside a locker contract but permits creators to claim the trading fees their token generates. This mechanism distinguishes the scheme from the more common rug-pull pattern in which operators withdraw liquidity from a pool, rendering the token untradeable and collapsing its price — and makes the scam harder to detect, since the token remains fully functional and the pool stays funded.

Beginning seven minutes after the fake post appeared, the wallet invoked the locker's fee-collection function six times over approximately two hours, accumulating about 31.6 ETH — worth roughly $59,000 — along with roughly 72 million VLAD, equal to approximately 7% of the total supply and valued at about $188,000 at current prices, according to Blockscout data.

The proceeds were subsequently distributed across three newly created wallets. The wallet's most recent fee claim occurred at 3:33 pm ET, indicating the operation was still active at press time. Because the liquidity remains locked, the token continues to be fully tradable despite the scam designation from the block explorer.

'Welcome to the Hood'

The fraudulent post was crafted to mimic a legitimate corporate announcement.

"Ahead of earnings, we've seen a lot of people asking… Does Robinhood love memes? The answer is yes," the post read, per screenshots captured before its deletion. "So today we're introducing Vladhood ($VLAD), the official Robinhood chain mascot."

The post asserted that the token would "also be listed in the Robinhood app," included the token's contract address, and concluded with the phrase "Welcome to the Hood," accompanied by a meme image depicting Tenev wearing a Robin Hood cap and selecting between buttons labeled "MEMES" and "RWA."

The contract address contained in the post corresponds to the scam-flagged Vladhood contract onchain. The post amassed more than 175,000 views in under 20 minutes before users reported it. Approximately 30 copycat VLAD pools materialized within hours; at least three were drained to zero.

Third Incident in Three Weeks

The breach marks at least the third social media scam connected to memecoins on Robinhood Chain — the Arbitrum-based Layer 2 network that Robinhood launched on July 1 to host tokenized stocks and other real-world assets, and where memecoins have accounted for the majority of activity since inception. On July 12, hijacked SpaceX and Starlink X accounts were used to promote a Robinhood Chain memecoin that reached a $2 million market capitalization before its creators pulled liquidity. Days later, a viral X post alleged that Tenev had accidentally exposed his wallet's seed phrase during a livestream — a claim consistent with a honeypot scam pattern that was never corroborated.

The series of scams has not materially slowed the network, which surpassed Base in daily active users three weeks after its launch. Whether the repeated incidents prompt changes to how token launchpads on the network handle creator fee claims or scam flagging remains an open question for platform operators.