Robinhood says chief executive Vlad Tenev’s X account was compromised and used to promote a fraudulent memecoin called VLAD, in a brief social media breach that appears to have generated roughly $1.2 million to $1.3 million for wallets linked to the scheme.

The unauthorized post was live for less than 20 minutes before being removed, but it still drew heavy attention and circulated widely enough to fuel trading in the fake token.

How the fake token was promoted

According to the source report, the post on Tenev’s account described VLAD as the official mascot token of Robinhood Chain and included a contract address for users to buy it. The message also falsely implied that the token would be listed on Robinhood’s platform.

Users flagged the post as suspicious, and it was eventually taken down after attracting thousands of views. The already approved summary of the incident said the post drew more than 175,000 views before removal. Robinhood later confirmed that the account had been breached and said it worked with X to restore access and delete the unauthorized content.

Estimated proceeds from the scam

Blockchain monitors cited in the report estimated that wallets connected to the operation extracted about 650 ETH. Based on values referenced in the source article, that amounted to roughly $1.2 million to $1.3 million.

The report also said an online investigator identified a wallet associated with the attackers that spent funds to buy VLAD tokens. On paper, those holdings briefly showed unrealized values in the tens of thousands of dollars. Even so, the source noted that scam tokens often have thin liquidity, meaning such paper gains may be difficult or impossible to realize.

Robinhood Chain background

The fake token pitch leaned on the recent launch of Robinhood Chain, which debuted on July 1. The network is an Ethereum Layer 2 built with Arbitrum Orbit. According to the source article, it processes millions of transactions a day and is designed to support both tokenized real-world assets and memecoin trading.

That context appears to have made the fraudulent claim more believable, at least briefly, because the attackers framed VLAD as tied to Robinhood’s new blockchain push. The contract linked in the post quickly came under scrutiny, and the blockchain explorer marked it as a scam, the report said.

A familiar crypto security pattern

The incident highlights a recurring tactic in crypto fraud: hijacked social media accounts are used to lend credibility to fake token launches, often by pairing a known public figure with a contract address and a false promise of exchange support. In this case, the claim that VLAD would be listed on Robinhood was not genuine.

While the post was removed quickly, the short window was still enough to trigger substantial activity around the token, according to on-chain estimates cited in the report. The episode adds to a broader pattern of security breaches and social engineering attacks that continue to affect the digital asset sector.

Source: Cryptopolitan