NewsCryptoRobinhood CEO Vlad Tenev's X Account Compromised in Fake VLAD Token Scheme Netting $1.3M

Robinhood CEO Vlad Tenev's X Account Compromised in Fake VLAD Token Scheme Netting $1.3M

Author: Cryptopolitan·

Key Takeaways

  • Robinhood said it was working with X to regain access to Vlad Tenev’s compromised account and remove the unauthorized content.
  • The fraudulent VLAD post falsely claimed the token was linked to Robinhood Chain and would be listed on Robinhood’s platform.
  • On-chain monitor MLM estimated that wallets connected to the incident extracted roughly 650 ETH, valued at about $1.2 million to $1.3 million.
  • The scam token recorded about 1,868 transactions after deployment by a contract later flagged as fraudulent by Robinhood Chain’s explorer.
  • The incident occurred shortly after Robinhood Chain launched as an Ethereum Layer 2 network using the Arbitrum Orbit stack.
Robinhood CEO Vlad Tenev's X Account Compromised in Fake VLAD Token Scheme Netting $1.3M

An unauthorized post appeared on Robinhood CEO Vlad Tenev's verified X account on July 24, promoting a fraudulent memecoin called VLAD and sharing a scam token contract address. The post remained visible for fewer than 20 minutes, amassing over 175,000 views before users flagged it as suspicious. Robinhood subsequently confirmed the account had been compromised and stated it was coordinating with X to restore access and remove the unauthorized content.

On-chain monitoring services estimated that wallets connected to the incident extracted approximately 650 Ether (ETH), valued between $1.2 million and $1.3 million. The attack underscores how compromised verified accounts of high-profile executives can lend false legitimacy to fraudulent token promotions, even when the posts are live for only a short window.

Fake VLAD Token Promotion

The unauthorized post falsely claimed that VLAD was the official mascot token of Robinhood Chain and included a contract address for users to purchase it. The post also stated that the token would be listed on Robinhood's trading platform, though Robinhood had made no such announcement.

Onchain Lens first reported the account compromise. Robinhood Chain's blockchain explorer subsequently flagged the contract as a scam. Robinhood confirmed the incident via its Robinhood Comms account on X, stating it was working with X to regain access. The unauthorized post had already been removed by that time.

According to on-chain monitor MLM, wallets associated with the incident extracted roughly 650 ETH, worth approximately $1.2 million to $1.3 million. Wu Blockchain also shared the reported findings on X.

An online investigator identified as Jeff reported that a wallet believed to be linked to the attackers spent approximately $126.81 to acquire 47.2 million VLAD tokens. Based on quoted market prices at the time, the holding showed an unrealized value of approximately $159,000. However, that estimate did not indicate the full amount could have been sold, as liquidity for scam tokens is typically limited.

Robinhood Chain Activity

The fake promotion emerged shortly after Robinhood Chain's launch on July 1. The blockchain is built as an Ethereum Layer 2 (L2) network using the Arbitrum Orbit stack, processing approximately 6 million transactions per day and supporting both tokenized real-world assets and active memecoin trading.

Blockchain data showed the fraudulent token recorded approximately 1,868 transactions shortly after deployment by a contract called PonsLaunchFactory, which the blockchain explorer later flagged as a scam.

The incident coincided with the announcement that Robinhood Chain would launch V2, one of its token launch platforms. The roadmap includes an ETH-based bonding curve, integration with Uniswap V4, creator payouts in ETH or selected assets, support for custom trading pairs corresponding to assets such as USDG, AAPL, NVDA, and HOOD, and optional reflection token features. The site noted that the new contracts are still undergoing audits and have not yet been implemented.

Pattern of Social Media Compromises

Although the unauthorized post was live only briefly, transaction data indicated continued interaction with the token prior to its removal. The message leveraged the existing activity around Robinhood Chain memecoins and used the false claim of an official token listing to attract buyers.

The incident adds to a growing series of attacks in which compromised social media accounts have been used to promote fraudulent tokens or distribute malicious contract addresses. Security researchers note that while losses from certain types of phishing attacks have diminished, others have escalated into more sophisticated cryptocurrency fraud schemes. The tactic follows a well-documented pattern seen in prior high-profile account takeover incidents, where attackers exploit the credibility of verified accounts belonging to public figures and corporate executives to amplify scams before platform moderation can intervene.