← Back to Delta Incident Archive

VERIFIED SECURITY INCIDENT · DCI-2026-056

Robinhood CEO Vlad Tenev’s X account was taken over to promote a fake VLAD token

Robinhood confirmed that Vlad Tenev’s X account was compromised and used to promote a fake token. Access was later restored and Vlad denied that Robinhood had issued any token; no user loss, intrusion vector, or attacker profit was officially confirmed.

Incident date2026-07-24 Attack typeAccount takeover SeverityHigh Involved chainsRobinhood Chain

Incident overview

Vlad Tenev’s X account was accessed without authorization. The attacker used the credibility of a prominent account to describe VLAD as an official Robinhood token or mascot and encourage trading. Public evidence does not disclose the intrusion vector, so SIM swapping, phishing, session theft, endpoint compromise, or a platform-side failure cannot be asserted.

Incident sequence

  1. The fake VLAD token and its principal WETH liquidity pool were created at approximately 00:38:35 on July 24, 2026.
  2. The compromised @vladtenev account posted false promotional content.
  3. At 02:05:24, Robinhood Comms confirmed the compromise, said the malicious post had been removed, and stated that it was working with X to restore access.
  4. At 10:42:28, Vlad Tenev confirmed that access had been restored and stated that Robinhood had not issued any coin or token.

Fund flow

The fake VLAD token contract and two liquidity pools can be identified, but public material is insufficient to attribute a complete receipt or profit-consolidation wallet to the attacker. The token contract and DEX pools are promotion or trading infrastructure and are not labeled as hacker wallets.

Amount basis

Community claims of approximately 650 ETH or $1.0 million to $1.3 million in attacker profit lack an official conclusion and a complete attributable path. They are not recorded as confirmed profit or user loss, and lossUsd remains null.

Addresses and transactions

  1. `0x92D176ccBeEffeCd8089e841D09ea17b6C22D969` — fake VLAD token contract.
  2. `0xac870e97FC1FE981F4D887e5f453203745A15EF4` — VLAD/WETH liquidity pool.
  3. `0xd556163Edd5d44797bfC767FD85Ac17819C5310d` — VLAD/USDG liquidity pool.

Evidence boundary

Official statements confirm the account takeover, malicious promotion, post removal, and access restoration. Dexscreener supports the existence of the token and pools. Community claims of 650 ETH in profit are not treated as confirmed, and market peak, fee revenue, attacker profit, and victim net loss are kept distinct.

Current status

The account was restored, the malicious post was deleted, and Vlad publicly denied that Robinhood had issued a token. The fake token and pools remain discoverable through chain-data services; no victim amount, intrusion vector, attacker wallet, or compensation plan was officially disclosed.