Bitcoin
Bitcoin (BTC)
$64,939.00 -0.9034
Bitcoin price
Ethereum
Ethereum (ETH)
$1,878.82 -2.40617
Ethereum price
XRP
XRP (XRP)
$1.10 -2.59674
XRP price
BNB
BNB (BNB)
$565.63 -0.76362
BNB price
Solana
Solana (SOL)
$75.14 -3.209
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.45 -1.37255
Hyperliquid price
Cardano
Cardano (ADA)
$0.165861 -4.81857
Cardano price
Chainlink
Chainlink (LINK)
$8.44 -2.15995
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.077952 -0.14792
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.46 -3.40152
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000618 -3.25019
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$64,939.00 -0.9034
Bitcoin price
Ethereum
Ethereum (ETH)
$1,878.82 -2.40617
Ethereum price
XRP
XRP (XRP)
$1.10 -2.59674
XRP price
BNB
BNB (BNB)
$565.63 -0.76362
BNB price
Solana
Solana (SOL)
$75.14 -3.209
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.45 -1.37255
Hyperliquid price
Cardano
Cardano (ADA)
$0.165861 -4.81857
Cardano price
Chainlink
Chainlink (LINK)
$8.44 -2.15995
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.077952 -0.14792
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.46 -3.40152
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000618 -3.25019
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$64,939.00 -0.9034
Bitcoin price
Ethereum
Ethereum (ETH)
$1,878.82 -2.40617
Ethereum price
XRP
XRP (XRP)
$1.10 -2.59674
XRP price
BNB
BNB (BNB)
$565.63 -0.76362
BNB price
Solana
Solana (SOL)
$75.14 -3.209
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.45 -1.37255
Hyperliquid price
Cardano
Cardano (ADA)
$0.165861 -4.81857
Cardano price
Chainlink
Chainlink (LINK)
$8.44 -2.15995
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.077952 -0.14792
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.46 -3.40152
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000618 -3.25019
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$64,939.00 -0.9034
Bitcoin price
Ethereum
Ethereum (ETH)
$1,878.82 -2.40617
Ethereum price
XRP
XRP (XRP)
$1.10 -2.59674
XRP price
BNB
BNB (BNB)
$565.63 -0.76362
BNB price
Solana
Solana (SOL)
$75.14 -3.209
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.45 -1.37255
Hyperliquid price
Cardano
Cardano (ADA)
$0.165861 -4.81857
Cardano price
Chainlink
Chainlink (LINK)
$8.44 -2.15995
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.077952 -0.14792
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.46 -3.40152
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000618 -3.25019
Asteroid Shiba price

The scam that doesn’t rug: How $VLAD farms its victims

Olivia Stephanie
Edited by
Feature
The scam that doesn't rug: How $VLAD farms its victims

When hackers hijacked Robinhood’s CEO’s X account, they did not run the usual smash-and-grab. They launched a token whose liquidity is locked forever, un-ruggable by design, and are collecting trading fees from it in perpetuity. The rug pull just evolved into a yield product, and the anti-scam infrastructure built the machine.

Summary
  • Hackers compromised Robinhood CEO Vlad Tenev’s X account on Thursday and promoted Vladhood ($VLAD) as the “official mascot” of Robinhood Chain, drawing 175,000 views in under 20 minutes and $22 million in trading volume.
  • The operation was premeditated, not opportunistic: the token contract deployed 46 minutes before the hacked post, through the Pons launchpad, with Tenev’s own X profile listed as the token’s official website.
  • The mechanism is the story: Pons locks a token’s liquidity permanently, making rug pulls impossible, but lets creators claim trading fees, so the attacker farms income from every trade, roughly $59,000 claimed in the first hours and still accruing, atop total proceeds estimated at $1.2-1.3 million.
  • The design inverts a decade of scam economics: instead of one exit event, the scammer holds a perpetual annuity on victim activity, and the anti-rug protection that legitimizes the launchpad is precisely what guarantees the income.
  • It is the second executive-account token scam on Robinhood Chain in eleven days, six days before the company’s earnings call, and it poses a question the industry has not answered: who is liable when scam-proofing infrastructure becomes the scam’s business model.

Crypto crime has a classical form, refined over a decade: create a token, manufacture credibility, collect the victims’ money, and vanish, the rug pull, a crime with a beginning, a middle, and above all an end. What happened on Thursday, when hackers seized the X account of Robinhood’s chief executive and pointed 15 million followers at a memecoin called Vladhood, had the beginning and the middle and then, deliberately, no end. 

The attackers launched $VLAD through a launchpad whose signature safety feature locks a token’s liquidity forever, which means the token cannot be rugged, which means, and here is the inversion worth an entire article, the scam never has to stop. The locked pool collects trading fees on every swap, the launchpad pays those fees to the token’s creator, and the creator is the hacker, who called the fee-collection function six times in the first two hours and has no reason ever to stop calling it. The rug pull was a robbery. This is a toll booth, built on stolen credibility, operated in public, generating income for its architect with every trade, protected by the exact mechanism the industry built to protect traders. The Defiant’s on-chain forensics documented the machine within hours; what the machine means, for scam economics, for the launchpads, and for the brokerage whose chain now hosts its second executive-impersonation token in eleven days, is the subject here.

The operation, reconstructed

The timeline, assembled from on-chain records and the forensic work of The Defiant and Onchain Lens, settles the fact that reframes everything else: this was a single coordinated operation, planned around the account takeover, not a scammer riding a lucky hack.

At 12:38 pm ET on Thursday, a wallet with no prior history launched Vladhood through Pons, the busiest of the Pump.fun-style launchpads that colonized Robinhood Chain in its first month. The launch parameters included a detail that functions as a confession of premeditation: the token’s official website field listed Tenev’s X profile URL, meaning the creators configured the token around an account they did not yet publicly control. Forty-six minutes later, the post appeared on that account: Does Robinhood love memes? The answer is yes, introducing $VLAD as the official mascot of Robinhood Chain, falsely promising a Robinhood app listing, signed off, Welcome to the Hood, with the contract address attached. The credibility stack was complete: a verified account, a CEO’s voice, a chain the CEO actually launched three weeks earlier, and a claim, app listing, that sat exactly on the boundary of plausible.

The market did what engineered credibility makes it do. The post drew more than 175,000 views in under 20 minutes; the token ran up more than 90,000% from launch; volume reached $22 million across roughly 85,000 swaps in the main pool; the market cap touched somewhere between $4 million and $10 million depending on the snapshot; 5,266 holders and 137,000 transfers accumulated on a contract deployed that afternoon. Robinhood’s communications team confirmed the compromise roughly 41 minutes after the post and worked with X to delete it; the chain’s own explorer flagged the contract as a likely scam. On-chain monitors estimate wallets tied to the operation extracted around 650 to 690 ETH, between $1.2 million and $1.3 million, through the classic half of the play, early wallets, holding a reported 70% of supply, selling into the spike.

And then the part that makes this a new genre: the sale was not the payday’s end. It was the down payment.

The mechanism: anti-rug as annuity

To see the innovation, start with the protection it exploits, because the protection is real and the exploitation is parasitic on its virtue.

Launchpads in the Pump.fun lineage answered the rug pull structurally: when a token graduates to a trading pool, the platform locks the liquidity in a locker contract the creator cannot drain. The creator cannot pull the pool, so the classic exit, remove liquidity, collapse the price to zero, vanish, is mechanically impossible, which is the safety pitch that lets these platforms describe themselves as scam-resistant and lets traders ape into anonymous tokens with one category of fear removed. Pons implements the standard design with the standard incentive attached: locked liquidity still generates trading fees on every swap, and those fees are claimable by the token’s creator, a reasonable arrangement meant to reward legitimate builders whose tokens sustain volume.

Now run the $VLAD operation through that machinery. The attacker cannot rug, and does not need to. Every trade in the pool, the panic selling after the exposure, the bagholders averaging down, the day traders playing the volatility, the bots arbitraging the chaos, pays a fee, and the fee flows to the creator wallet on demand. Starting seven minutes after the fake post, the wallet called the locker’s fee-collection function six times over roughly two hours, netting about 31.6 ETH, roughly $59,000, and the meter is still running: the balance grows as long as anyone, for any reason, trades the token. The Defiant’s framing captures the inversion precisely: the wallet did not need to pull liquidity to cash out. The token never rugged. It just collects.

The economics deserve to be stated as the design they are. A rug pull monetizes credibility once, in a single extractive event that ends the scam and starts the manhunt. The locked-liquidity structure converts the same stolen credibility into an income-producing asset: a perpetual claim on the trading activity of a token that cannot die by its creator’s hand, whose infamy itself sustains volume, and whose victims’ every attempt to trade out of their position pays the person who put them in it. The scam has acquired a business model, and the business model was donated by the anti-scam infrastructure. Eleven days earlier, crypto.news covered the predecessor eleven days earlier, the SCATMAN operation, run through SpaceX’s hijacked accounts onto this same chain, which took $135,000 in the classical style and ended. $VLAD’s operators took ten times that in the opening hours and, structurally, have not ended at all. That delta, between a robbery and a franchise, is the evolution this incident marks.

The venue, the timing, and the liability question

The setting compounds the story, because the chain hosting this evolution belongs to a licensed brokerage six days from its earnings call.

Robinhood Chain’s first month, as this publication has documented in the venue’s first-month composition problem, delivered $700 million in assets, 300,000 daily active addresses, top-tier DEX volume, third place in seven-day chain revenue, and a composition problem: memecoins driving the overwhelming majority of activity against roughly $13 million in the tokenized real-world assets the chain was built for. The scam wave is the composition problem’s sharpest edge, SCATMAN through hijacked SpaceX accounts on July 12, a launchpad going dark mid-boom with an estimated $12 million in fees, and now the chain’s own founder’s face on its most sophisticated fraud, a token the chain’s explorer flags as a scam while the chain’s fee mechanics, this is the uncomfortable part, collect revenue on every one of its trades, as does the sequencer’s operator. A brokerage whose regulatory identity is bringing compliant rails to digital assets is earning protocol revenue, however small, on a fraud impersonating its own CEO, and its earnings call, where management must frame the chain’s first month for analysts and its Say-platform retail questioners, now has its opening exhibit. That is the earnings call this incident now precedes.

The liability question is the one the industry has not answered, and $VLAD converts it from hypothetical to operational. The launchpad designed the locker; the locker guarantees the scammer’s income; the design choice that prevents one crime funds another. Is Pons, which profits from launch fees and whose factory contract the explorer flagged, a neutral tool provider, the Section 230 of token creation, or does operating a fee-annuity machine that any account thief can drive create obligations, to freeze creator-fee claims on flagged tokens, to require identity for fee withdrawal, to build the kill switch the anti-rug design deliberately omitted? Every answer has a cost: freezable fees reintroduce the trusted operator the architecture exists to remove, identity requirements gut the permissionless launch model that generates the volume, and doing nothing leaves the annuity running. The same trilemma applies one level up, to the chain, and one level higher, to X, whose verified-account security has now been the entry point for two nine-figure-audience token frauds in eleven days on the chain the scams chose alone, part of a lineage running from the 2024 celebrity-account wave through this month’s fake Armstrong coin. Executive social accounts have become, functionally, financial infrastructure, secured like consumer products.

The economics of borrowed trust, quantified

Step back from the mechanism and the incident yields something rarer than a forensic timeline: a clean measurement of what stolen credibility is worth per minute, and a market structure that prices it.

Run the numbers as a conversion funnel. The hijacked account held roughly 15 million followers; the post survived approximately 20 minutes in primary distribution and drew 175,000 views; the token processed $22 million in volume and accumulated 5,266 holders within hours; the operators extracted $1.2 to $1.3 million in direct proceeds plus the ongoing fee stream. That is roughly $65,000 of extraction per minute of post uptime, about $7.40 per view, and around $250 of eventual volume per view, numbers that explain, better than any security advisory, why executive account compromise has become a professionalized industry with its own supply chain: access brokers who source the credentials, operators who build the token infrastructure in advance, and distribution specialists who time the post. The 46-minute pre-deployment is the industrial tell, the attack was inventory waiting for its distribution moment, and the same funnel mathematics applied to the SCATMAN operation, a smaller account constellation and a cruder mechanism, yielded a tenth of the proceeds, which is exactly the relationship a maturing industry’s cohort analysis would predict: returns scale with audience quality and mechanism sophistication, and both are improving.

The funnel also identifies where defense actually binds, and it is not where the industry spends. Post-hoc measures, explorer flags, account restoration, post deletion, all activated within the hour here, and the operation was profitable within seven minutes; the deletion ended distribution after the extraction window had already closed. The binding constraint is upstream: the account security that gates the distribution moment, and the launch infrastructure that lets the monetization machine be assembled anonymously in advance. Which is why the two reforms with actual leverage are unfashionable ones, hardware-key mandates and session-hygiene requirements for accounts above an audience threshold, effectively treating large verified accounts as the financial infrastructure they now are, and creator-fee escrow periods on launchpads, a delay between fee accrual and fee claim long enough for flags to propagate, which would have converted $VLAD’s annuity into a frozen exhibit without touching the permissionless launch itself. Neither reform requires identifying anyone; both attack the funnel’s throughput rather than its aftermath. The industry’s current posture, in which a nine-figure-audience account is secured by whatever its owner chose and a flagged scam’s fees flow to its operator in real time, is not a policy. It is a bounty schedule, published daily, and Thursday’s operators simply read it.

What to watch

The fee meter. The creator wallet’s claims are public and ongoing. Whether the balance crosses six figures, and whether anyone, Pons, the chain, a court, ever interrupts it, is the cleanest measure of whether the industry treats this as an incident or a precedent. As of the first day, nothing in the architecture can stop it.

The launchpad’s response. Pons faces the trilemma first: freeze mechanics, identity gates, or explicit neutrality. Its choice, and whether Robinhood Chain pressures it, writes the first draft of the fee-annuity era’s rules, and every copycat is watching. The design is trivially replicable on any chain with a locked-liquidity launchpad, which is all of them.

The earnings call, July 29. Whether analysts or Say questioners force management to address the scam wave on the record, and whether the answer gestures at curation, moderation, or enforcement, would mark the first time a public brokerage defines its responsibility for frauds conducted on infrastructure it operates and profits from.

The security postmortem. How the attackers took the account, SIM swap, session theft, insider access, matters for every executive in the industry, because the $VLAD operation’s real innovation was pairing patient token engineering with account compromise as a single planned instrument. The 46-minute gap between deployment and post is the tell: this was manufactured, and manufacturing scales.

The rug pull is dying the way all crimes die, by evolving into something the law has not named yet. $VLAD’s architects understood what the industry’s own safety engineering had built: a machine that converts stolen credibility into permanent income, legally ambiguous, mechanically unstoppable, and hosted on the most scrutinized new chain in crypto. The $59,000 in claimed fees is a small number. The design it proves out is not, because every locked pool on every launchpad on every chain is now, visibly, a potential annuity for whoever can manufacture one hour of borrowed trust, and the industry that built the locks has not built the thing that comes after: a way to stop paying the thief.

A closing note on the naming problem, because it will shape the response. The legal system has vocabulary for the rug pull: theft, wire fraud, market manipulation, each with elements prosecutors know how to plead against an exit event. The fee annuity fits none of them cleanly. The initial impersonation is straightforwardly criminal, identity theft and securities-adjacent fraud in the account takeover and the false listing claim, and any eventual defendant will face those counts. But the ongoing income stream is stranger: after the exposure, every subsequent trader in $VLAD acts with full knowledge that the token is flagged, the fees are disclosed by the mechanism itself, and the operator extracts value not by deceiving anyone still present but by having once deceived people no longer trading. Whether collecting contractually-defined fees from a pool of informed speculators constitutes ongoing fraud, unjust enrichment, or merely distasteful legality is a question no court has answered, and the answer determines whether the annuity can be seized, whether launchpads face aiding liability for paying it out, and whether the design spreads with impunity. It is another case of when mechanism design meets adversaries. The industry’s enforcement history suggests the question gets answered slowly and by the worst possible case: some future iteration of this design, at ten times the scale, attached to a fraud egregious enough to force the doctrine. Until then, the $VLAD wallet keeps calling its function, the locker keeps paying, and the gap between what the mechanism permits and what the law has named sits open, collecting fees.

Frequently asked questions

What happened to Vlad Tenev’s X account?

Hackers took control of the Robinhood CEO’s verified X account on Thursday, July 23, and posted a promotion for a fake memecoin called Vladhood ($VLAD), presenting it as the official mascot of Robinhood Chain and falsely claiming it would be listed on the Robinhood app. The post drew over 175,000 views in under 20 minutes before removal. Robinhood confirmed the compromise about 41 minutes after the post and said it was working with X to restore access.

Was this an opportunistic hack?

No, it was premeditated and coordinated. On-chain records show the token contract was deployed through the Pons launchpad 46 minutes before the fraudulent post appeared, and the launch configuration listed Tenev’s own X profile as the token’s official website, meaning the operation was built around an account takeover that had not yet happened publicly. The account compromise and token launch were parts of a single planned instrument.

How much did the attackers make?

Two figures describe it. On-chain monitors estimate total proceeds of roughly 650 to 690 ETH, about $1.2 to $1.3 million, largely from early wallets, holding a reported 70% of supply, selling into the spike. Separately, the locked liquidity pool has paid the creator wallet approximately $59,000 in trading fees in the first hours, claimed across six withdrawals, and that stream continues to accrue with every trade.

Why is the token impossible to rug pull, and why does that matter?

The Pons launchpad locks a token’s liquidity in a locker contract the creator cannot drain, a standard anti-rug protection. That makes the classic exit scam impossible, but the locked pool still generates trading fees that the creator can claim. The attacker therefore holds a perpetual income stream from all trading in the token, converting a one-time scam into an ongoing annuity that the protection itself guarantees.

How does this compare to the SCATMAN incident?

SCATMAN, eleven days earlier, used hijacked SpaceX and Starlink accounts to promote a token on the same chain and extracted roughly $135,000 in the traditional pump-and-dump style, an operation with an end. $VLAD extracted roughly ten times more in its opening hours and structurally has no end, because the fee stream persists. The two incidents mark an evolution in method on the same venue within two weeks.

Does Robinhood bear responsibility for scams on its chain?

That is the unresolved question the incident sharpens. The chain is permissionless, and Robinhood did not authorize the token, but the network and its sequencer earn revenue on all activity, including fraud, and the chain’s explorer flagging cannot stop trading or fee claims. The launchpad faces the same trilemma: freezing fees or requiring identity would compromise the permissionless model, while inaction leaves the annuity running. No platform has yet defined its obligations.

What should users take from this?

That verified executive accounts are now a primary fraud vector: two major incidents in eleven days used hijacked official accounts, and posts announcing surprise tokens should be treated as compromises by default, checked against official company channels, which stayed silent in both cases. Locked liquidity means a token cannot be rugged; it does not mean the token is legitimate, and in this design, trading a flagged token pays its creator.

Could this scam model spread?

Easily, which is its significance. Any launchpad that combines locked liquidity with creator-claimable fees, the dominant design across chains, can host the same structure, and the required ingredient, an hour of borrowed credibility, can come from any compromised account with reach. Until platforms build mechanisms to interrupt fee claims on flagged tokens, each such pool is a potential perpetual payout for whoever manufactures the trust. This is educational analysis, not financial or legal advice.

Disclaimer: This article is for information and educational purposes only and does not constitute financial, investment, or legal advice. It describes an ongoing security incident based on on-chain data and reporting available at the time of writing, and figures may change as investigations continue. Never interact with tokens promoted through unverified or compromised channels. Always do your own research. Information is accurate as of July 24, 2026.