Robinhood CEO's X Account Hijacked to Pump Fake Token; Attackers Clear ~$1.3M via Fraudulent Post
Vlad Tenev confirmed on July 28 or 29 that a social engineering attack on X's customer support gave hackers control of his account, enabling a fraudulent memecoin promotion that generated $22 million in trading volume before the post was removed.
Robinhood CEO Vlad Tenev's X account was compromised on July 23, 2026 at approximately 17:24 UTC. The attacker used the access to post a fabricated announcement promoting a token called "Vladhood" ($VLAD), falsely describing it as the official mascot of Robinhood Chain and suggesting it would be listed on the Robinhood app. The post reached more than 175,000 views in roughly 20 minutes before Robinhood had it taken down. Attackers ultimately extracted an estimated 650 to 690 ETH, worth approximately $1.2 to $1.3 million, through a fee-farming structure that continued generating revenue well after the fraudulent post was deleted.
Robinhood acknowledged the breach quickly. The company stated: "Our CEO Vlad Tenev's X account was compromised and posted a fake promotion for a meme coin. We're working with X to restore access and the post has been removed." The account was fully restored the same day. Tenev later confirmed the method in a personal update. "A fraudster socially engineered X customer support to gain access, bypassing standard security features like 2FA and login notifications," he wrote. He added that X has since applied additional account protections. The breach did not involve a compromised device or password. The attacker persuaded X's human support staff to grant unauthorized access, which neutralized two-factor authentication entirely.
The Attack Was Premeditated
On-chain data shows this was not an opportunistic strike. The $VLAD token contract was deployed on Robinhood Chain 46 minutes before the hacked post went live. The token's creator began claiming trading fees just seven minutes after the post appeared. In the first two hours, fee income to the creator reached approximately $59,000. The token peaked at a market cap of around $10 million and was still trading above $4 million after the fraudulent post was deleted.
The launchpad used to deploy $VLAD was Pons, a platform on Robinhood Chain that uses a locked-liquidity model. Locked liquidity prevents a creator from withdrawing the underlying funds in a single transaction (the classic "rug pull"), but trading fees remain permanently routed to the creator. The result is a continuous revenue stream for as long as the token trades. The Robinhood Chain explorer flagged the $VLAD contract as a "possible scam" shortly after launch. Beyond the immediate on-chain damage, the incident carried a conventional market penalty as well: HOOD shares fell 2.78% in the aftermath.
Reports indicate this was the second executive account token scam on Robinhood Chain within eleven days, though details of the earlier incident had not been fully disclosed at the time of publication.
A Systemic Flaw, Not an Individual Failure
The vector used here mirrors the January 2025 breach of the U.S. Securities and Exchange Commission's X account, in which a SIM swap attack combined with a support-level security lapse allowed a fraudster to post a fake Bitcoin ETF approval announcement. Eric Council Jr. was later convicted for that attack.
The Tenev incident is worth understanding in that context. Security analysts note that enabling 2FA on a personal account does not protect against an attacker who can convince a platform's customer support team to override it. This represents a platform-level vulnerability that applies to any high-value account on X, including crypto exchanges, protocol teams, and project founders.
"A scam posted from a random account is easy to ignore," NewsBTC noted in its analysis. "A scam posted from the personal account of a CEO, founder, exchange leader, or major investor feels different." That credibility gap is precisely what made the VLAD promotion effective enough to generate $22 million in volume inside 20 minutes.
Regional Exposure Is Significant
For investors in South Asia and Sub-Saharan Africa, this incident carries direct financial stakes. Robinhood Chain launched its public mainnet on July 1, 2026, on an Ethereum Layer-2 network built on the Arbitrum Orbit stack. It now supports tokenized stock trading across more than 120 countries, with a total value locked above $600 million and more than 300,000 daily active addresses. Robinhood's broader platform serves approximately 28 million users globally. Countries such as India, Nigeria, Kenya, and South Africa rank among the highest in per-capita crypto adoption worldwide, and users in those markets frequently rely on influencer and executive announcements on X as a primary source of financial information, making them particularly exposed to this category of attack.
India offers the most direct precedent. In July 2025, crypto exchange CoinDCX lost $44.2 million after attackers posed as job recruiters, persuaded an engineer to install malware, and drained liquidity wallets. The Lazarus Group, also linked to the 2024 WazirX hack worth $234 million, was attributed.
Social engineering accounted for 65% of all crypto security incidents in 2025. The Asia-Pacific region absorbs 34% of global social engineering attacks, the highest share of any region.
X is the primary crypto information channel across much of Sub-Saharan Africa, where mobile-first internet access means many users encounter and act on announcements without cross-referencing other sources. The VLAD scam compressed its critical victim-entry window into less than 20 minutes, a period that falls entirely within a gap between time zones, work schedules, and secondary verification habits. As the Pons fee-farming structure makes clear, however, financial harm to retail traders who bought $VLAD continued well beyond that window, with fees accruing to the token's creator for as long as trading persists.
What to Watch
Robinhood Chain's growth trajectory makes its brand a target. More than $700 million in total assets now sit on the network, daily DEX volume regularly exceeds $600 million, and weekly volume reached $1.23 billion in mid-July.
That activity level, combined with an active memecoin culture the platform did not fully anticipate at launch, creates fertile conditions for further impersonation attempts. Tenev himself had described assets without underlying utility as "a dead end," yet later acknowledged that "the chain works great for memes too," a concession reported by Decrypt that illustrates how quickly retail demand reshaped the platform's original identity.
Users and developers maintaining high-value X accounts should request elevated protections directly from X, independent of whatever 2FA settings they already have in place.