Robinhood CEO Vlad Tenev’s verified X account briefly became the launchpad for a fake memecoin promotion, and traders moved fast enough to send the token’s market value close to $10 million.
The attackers used Tenev’s account to advertise a token called Vladhood, trading under the ticker VLAD. The post attempted to make the project look connected to Robinhood and its recently launched blockchain network.
It was not.
Robinhood later confirmed that Tenev’s account had been compromised. The company removed the post and said it was working with X to restore access.
Hackers Presented Vladhood as a Robinhood-Backed Memecoin
The fake post appeared on Tenev’s account at around 17:24 UTC on July 23, 2026.
It introduced Vladhood as the supposed “official Robinhood Chain mascot” and claimed the token would eventually become available through the Robinhood trading app. The attackers also changed Tenev’s profile image to a doctored picture showing him wearing a feathered cap, playing on the Robin Hood name.
That branding did much of the work.
Robinhood Chain had already attracted attention from traders, while Tenev’s position gave the announcement an appearance of credibility. Anyone scrolling quickly could have mistaken the post for a strange but genuine company promotion.
There was one obvious warning sign, though. Robinhood’s main corporate account and its official crypto account did not publish matching announcements. No legitimate listing notice appeared either.
Vladhood Reached a $10 Million Market Cap Within Minutes
The compromised post included a contract address beginning with 0x92d. It pointed users toward a token created only minutes earlier through a contract called PonsLaunchFactory.
Trading activity picked up almost immediately.
Vladhood’s market capitalization climbed to roughly $10 million before Robinhood publicly confirmed the account breach. Once the warning spread and the promotional post disappeared, the token fell below $5 million.
On-chain data cited by crypto.news indicated that wallets identified as insiders secured more than $1 million in profits during the sudden price increase. The owners of those wallets had not been identified at the time of reporting, and no evidence directly connected them to the person or group that hacked Tenev’s account.
That distinction matters. Suspicious wallet activity can show who benefited from a launch, but it does not automatically prove who carried out the social media breach.
Robinhood Chain Flagged the Token as a Potential Scam
Robinhood Chain’s block explorer later placed a “potential scam” warning on the token after recording more than 1,800 transactions.
By then, the damage had already started.
Removing a fraudulent social media post does not remove the token from a blockchain. Vladhood remained tradable even after Robinhood denied any involvement, leaving late buyers exposed to a market built around a false endorsement.
Robinhood had not announced plans to list Vladhood, recognize it as an official mascot or support it in any other form.
The token simply borrowed the company’s name, its chief executive’s identity and the momentum surrounding Robinhood Chain.
The Timing Made the Fake Promotion More Convincing
The attack landed while Robinhood Chain was experiencing a surge in speculative trading following its July 1 mainnet launch.
Robinhood built the Ethereum layer-2 network using Arbitrum technology, with the broader goal of supporting tokenized assets, decentralized finance and continuous trading. Memecoins, however, became a major part of its early decentralized exchange activity.
Entropy Advisors estimated that Robinhood Chain had processed around $9 billion in cumulative decentralized exchange volume by July 23, with speculative memecoin trading responsible for much of that activity.
One early token, CashCat, reportedly reached a market capitalization of approximately $150 million. Daily trading volume on the network also jumped from slightly more than $200,000 on July 1 to over $500 million nine days later.
Against that backdrop, a surprise Robinhood-themed memecoin did not look completely impossible. That was probably the point.
Crypto Scammers Keep Targeting Trusted Social Accounts
The Robinhood incident follows a familiar pattern.
Hackers compromise a high-profile account, publish a token contract address and rely on the account owner’s reputation to create urgency. Traders rush in, the price rises and wallets positioned early can sell into the demand.
Binance co-founder Changpeng Zhao warned about the tactic in 2025, noting that hackers increasingly targeted social media profiles because those accounts often had weaker security than crypto trading platforms.
Similar campaigns have targeted the X account of BNB Chain and a WeChat account previously associated with Binance co-CEO Yi He. Other journalists, companies and public figures have also had compromised accounts used to promote fraudulent or unauthorized crypto tokens.
The formula is not complicated. It does not need to be.
A verified account, a familiar brand and a contract address can be enough to move millions of dollars before anyone checks whether the announcement is real.
Sudden Token Announcements Need More Than a Blue Check
The Vladhood scam showed how little time traders may have to verify a supposed launch before the market moves.
A verified profile is not proof that the person behind the post still controls the account. Neither is a polished image, a company logo or a promise of an exchange listing.
Official announcements should appear across several verified company channels. Contract addresses should match information published on the project’s website or documentation. A token promoted through one executive’s account, with no supporting announcement elsewhere, deserves immediate suspicion.
In this case, Robinhood denied the promotion quickly. Vladhood still reached a multimillion-dollar valuation before the warning caught up.
That gap—only a few minutes long—is where these scams make their money.
