Verified X accounts belonging to SpaceX and Starlink were briefly compromised on July 12 and used to amplify promotions for a memecoin called SCATMAN, according to the source report. The posts were removed and the accounts were restored the same evening, but not before the token surged and the alleged attacker sold newly minted supply for about 73.7 ETH, roughly $135,000.
A short-lived breach with fast market impact
The reposts appeared within the normal flow of the two accounts, without obvious signs of defacement or takeover. That made the messages look like legitimate posts from SpaceX-related brands with a combined following of about 3.6 million. Buyers reacted quickly. In the first 20 minutes after the promotions appeared, SCATMAN reportedly climbed 575%.
By the time the posts were deleted, the move had reversed. The report says buyers who entered on the strength of the reposts were left holding a worthless token. While the financial haul was small compared with major crypto hacks, the incident showed how a compromised social media login can be turned into a trading event within minutes.
How the scheme unfolded
According to the report, an account calling itself Sam Catman appeared as part of the setup. It allegedly carried a fraudulent affiliation badge that falsely linked it to SpaceX’s AI work. The name also appeared to spoof Sam Altman, using the public association between Elon Musk and OpenAI-related disputes to add plausibility.
The SCATMAN token was then deployed on Robinhood Chain, described in the source as a permissionless layer-2 network. The compromised SpaceX and Starlink accounts reposted promotional material that included the token ticker and contract address, giving the project an appearance of institutional endorsement.
The attacker is reported to have minted 10 trillion SCATMAN and sold the tokens through two wallets. One wallet allegedly sold 10 trillion tokens for 59 ETH, worth about $108,000 at the time, while a second wallet sold 59.28 million tokens for 14.7 ETH, or about $27,000. Together, those sales totaled around 73.7 ETH.
Why the incident matters
The case points to a type of crypto crime that does not depend on breaking smart contracts or exploiting protocol code. Instead, the source argues, the key asset stolen was credibility. By gaining access to verified brand accounts for less than an hour, the attacker was able to borrow public trust long enough to create exit liquidity.
That makes the attack surface very different from a typical on-chain exploit. There was no contract audit issue at the center of the event. The vulnerable point was a consumer platform login attached to a high-profile institutional identity. In that sense, the losses were not limited to the money extracted from buyers; the report argues that trust in verified accounts was also damaged.
Robinhood Chain and the brand-token setup
The source also places the episode in the context of Robinhood Chain’s early trading environment. It describes the network as permissionless, retail-heavy and crowded with newly launched memecoins. In that setting, the barriers to launching a token were low, while the appearance of endorsement from a major brand could draw immediate attention before users had time to assess authenticity.
One warning sign, according to the report, was that the Sam Catman account was new and its affiliation badge was fraudulent. But spotting that in real time required familiarity with platform mechanics and a quick judgment during a roughly 20-minute window, something many users were unlikely to manage before the market moved.
The broader takeaway from the incident is that verified social media accounts can function as a powerful distribution channel for token scams when they are compromised, especially on fast-moving, permissionless networks. Public blockchain records may make proceeds traceable, but the source says meaningful remedies for affected buyers remain limited.
Source: crypto.news