Crypto NewsSecurity

Robinhood's CEO was hacked to shill a coin on Robinhood's own chain

Robinhood confirmed CEO Vlad Tenev's X account was hijacked to promote a fake 'official Robinhood chain' memecoin. It spiked near $8 million in minutes, and a cluster of wallets funded two hours earlier walked away with about $1.2 million.

Listen to this article

--:--
Editorial collage: the Robinhood feather logo and a portrait of CEO Vlad Tenev beside a phone showing a deleted memecoin promotion, with a blockchain explorer readout of the $VLAD contract.

On Thursday 23 July 2026, hours before Robinhood was due to report earnings, the verified X account of its chief executive, Vlad Tenev, started promoting a memecoin. At 17:24 UTC the post pitched a token called $VLAD as the official mascot of Robinhood Chain, the company’s own blockchain, complete with the contract address and a claim that the coin would be listed in the Robinhood app. None of it was real. Inside 20 minutes it had 175,000 views.

At 18:05 UTC, about 41 minutes after the post, Robinhood’s communications account confirmed the account had been taken over: “Our CEO Vlad Tenev’s X account was compromised and posted a fake promotion for a meme coin. We’re working with X to restore access and the post has been removed.” Robinhood has never launched an official memecoin.

That is the confirmed part, and it is a textbook attack: seize a trusted account, point its followers at a fresh token, and let the buying do the rest. The rest is on a public ledger, so we traced it.

The coin, on Robinhood’s own chain

The token is Vladhood, ticker VLAD, an ERC-20 at 0x92D176ccBeEffeCd8089e841D09ea17b6C22D969, deployed through a memecoin launcher called the PonsLaunchFactory. It ran not on Ethereum or Solana but on Robinhood Chain, the Arbitrum-based network Robinhood opened at the start of July 2026 and marketed for tokenised stocks and real-world assets. Within three weeks the chain had turned into a memecoin casino, with billions in cumulative trading volume. That is the detail the attacker exploited: a coin claiming to be the mascot of Robinhood’s real chain sounds plausible in a way a random token never could. The chain’s own Blockscout explorer flagged VLAD as a potential scam almost immediately.

The clearest tell was the timing. The VLAD trading pool, a Uniswap pair against wrapped ether, was created at 16:38 UTC, 46 minutes before Tenev’s account posted a word.

YFarmX on-chain check of the VLAD contract: Vladhood on Robinhood Chain, contract 0x92D1…D969 deployed via PonsLaunchFactory, a peak fully-diluted value near 8 million dollars, 21 million dollars of volume, and about 1.2 million dollars extracted by a pre-funded wallet cluster.

What the chain shows

The numbers are large and fast. VLAD spiked to a fully-diluted value near $8 million at 17:24 UTC, the exact minute the post landed. It traded roughly $21 million across about 78,900 transactions among more than 5,000 holders, then fell as quickly as it rose, collapsing toward $2.6 million by later the same day. This was never an investment. It was a two-hour window.

The on-chain investigator Bubblemaps flagged the account as likely hacked at 17:53 UTC, 12 minutes before Robinhood did, and named the reason: around 70 per cent of the supply was already bundled into a tight cluster of wallets. Its trace showed roughly ten addresses funded through the Relay bridge about two hours before the post, which bought VLAD within minutes of the announcement and then sold into the crowd they had drawn in. Trackers cross-referencing those wallets put the profit at roughly 650 ether, about $1.2 million.

Fraud, not laundering, and not a Robinhood breach

Two things this was not. It was not a breach of Robinhood itself: no company funds and no user balances were touched, and the brokerage’s systems were never in play. And it was not laundering in the strict sense, which is about disguising the origin of money that already exists. What the VLAD record shows is a manufactured market. A hijacked account of a named executive, a token minted to impersonate an official product, liquidity added before the promotion, and a wallet cluster pre-funded through a bridge and positioned to sell. That is market manipulation and fraud, run in under an hour and preserved on the chain that hosted it.

The uncomfortable footnote is that Robinhood Chain worked exactly as built. It let anyone deploy a token and open a market in minutes, with no gatekeeper to ask whether “official Robinhood mascot” was true. Robinhood had spent the month telling users the chain worked great for memes. An attacker agreed, and used the company’s own brand as the bait.

The receipt outlives the tweet

The promotional post is gone, deleted the moment it had done its work. The contract is not. It sits on Robinhood Chain with its 16:38 pool creation, its 70 per cent cluster, its 78,900 trades and every exit intact, which is the one thing a scam gives up when it runs on a blockchain: the evidence is permanent and public. Robinhood has its account back and its statement out. The harder question belongs to the chain, and it will keep coming as the platform pushes users to mint and trade whatever they like. When the brand and the rails both belong to you, a hack of the first becomes a run on the second.

Sources

  1. Robinhood Chain explorer (Blockscout), the VLAD tokenrobinhoodchain.blockscout.com
  2. GeckoTerminal, VLAD/WETH pool on Robinhood Chaingeckoterminal.com
  3. DexScreener, VLAD/WETH pool on Robinhood Chaindexscreener.com
  4. Bubblemaps on X, the on-chain investigationx.com
  5. Robinhood communications on X, the confirmationx.com
  6. Arbitrum, Robinhood Chain mainnet launchblog.arbitrum.io