They Hacked Robinhood's CEO and Had a Fake Coin Trading in Minutes
Attackers took over Vlad Tenev's verified X account, launched a fake memecoin claiming to be Robinhood Chain's official mascot, and cashed out before most of the 175,000 people who saw the post knew it wasn't real.

On July 23, 2026, someone took over the verified X account of Robinhood CEO Vlad Tenev and used it to post that Robinhood was launching its own memecoin. The post named the token Vladhood, ticker VLAD, called it the "official mascot" of Robinhood Chain, and claimed it would be listed inside the Robinhood app. None of that was true. It didn't need to be, for as long as it stayed up.
The token had been created just 46 minutes before the hack, through a contract deployer operating under the name PonsLaunchFactory. The post went up, and in the next 20 minutes it racked up more than 175,000 views before anyone at Robinhood caught it. Robinhood's own accounts stayed silent through the entire window, which was itself the first real clue something was wrong: a company launching an official token does not let the CEO announce it solo while the corporate account says nothing.
By the time Robinhood's communications team posted that Tenev's account had been "compromised" and got the post taken down, the damage had a specific shape. Robinhood Chain's own blockchain explorer flagged the VLAD contract as a likely scam almost immediately. On-chain trackers estimated the attacker walked away with somewhere between 650 ETH and low seven figures, with reporting on the exact number ranging from roughly $59,000 in trading fees up to $1.2 to $1.3 million depending on what window and wallet activity was counted. What isn't in dispute: Uniswap trading volume on the token topped $22 million in the first few hours, and the contract logged more than 13,000 transactions before most buyers understood what they were holding.
Blockchain trackers followed the proceeds into three newly created wallets, split between the ETH taken and roughly 72 million VLAD tokens still sitting unsold in the attacker's addresses as of publication. Whether that remainder ever gets liquidated depends on whether anyone is still willing to buy a token that Robinhood's own network explorer has already labeled a scam.
The timing made the hack unusually effective. Robinhood Chain, an Ethereum layer-2 network built for tokenized stocks and real-world assets, had launched just three weeks earlier, on July 1, and had already pulled in more than $700 million in assets and over 300,000 daily active addresses, processing roughly 10 million transactions in a single day at its peak. It was designed as serious infrastructure for regulated products. In practice, meme coins had already overtaken tokenized stocks as the dominant activity on the network before this hack ever happened, and Robinhood Chain had already drawn its share of unrelated scams and rug pulls riding on the launch hype. That backdrop is exactly the environment a fake "official mascot" token needed to look plausible for twenty minutes: a network genuinely flooded with speculative new tokens, where one more launch from a seemingly credible source didn't stand out until it was too late.
This is not a new playbook. Verified accounts belonging to Sydney Sweeney, Doja Cat, and 50 Cent were all hijacked during the 2024 meme coin frenzy to push the same kind of fake-launch scam, and the mechanics barely change: take a trusted, high-follower account, post something that sounds like real news, and extract value from everyone who trades on the headline before they check a second source. Tenev's account has since been restored. How the attackers actually got in was never publicly detailed by Robinhood or X. For a hack that ran its entire course in under half an hour, that gap in disclosure may end up mattering more than the dollar figure.
The Aftermath
Vlad Tenev's X account was restored the same day, and the fraudulent post was removed. Robinhood has not disclosed how the attackers gained access to the account. Roughly 72 million VLAD tokens remain unsold in the attacker's wallets, and no law enforcement action or named suspect had been reported as of publication.
COMMENTS