The Hack Is Over. The Money Printer Is Still Running.
Someone hijacked Robinhood CEO Vlad Tenev's X account, promoted a fake memecoin called 'Vladhood,' and walked away. But here's the part nobody is talking about: the scammer never left. Onchain records reviewed by The Defiant confirm the attacker is still collecting trading fees from the fraudulent token — without ever pulling the liquidity.
A Attack Planned 46 Minutes in Advance
This was not a spontaneous smash-and-grab. Blockchain data shows the fake Vladhood token was deployed a full 46 minutes before the compromised post appeared on Tenev's X account. That gap tells a clear story: the contract was live, the liquidity was seeded, and the trap was set well before the social engineering piece even dropped.
The playbook is disturbingly familiar. A high-profile account gets compromised, a token gets shilled to millions of followers, retail buyers pile in chasing the hype, and the deployer profits. What makes this case different is the exit strategy, or rather, the lack of one.
No Rug Pull. Just a Slow Drain.
Most memecoin scammers rug pull fast: dump tokens, drain liquidity, disappear. The Vladhood attacker chose a quieter, more patient approach. By keeping liquidity in the pool and simply harvesting the trading fees generated by every swap, the hacker turned a one-time hack into a recurring revenue stream.
Every time a confused trader buys or sells the worthless token, the deployer skims a percentage. It is a self-sustaining mechanism that requires zero further action and leaves far less of an onchain footprint than a sudden liquidity withdrawal would.
This kind of fee-farming exit is increasingly attractive to sophisticated bad actors precisely because it avoids the dramatic onchain signals that alert blockchain security firms and exchanges. There is no single transaction to flag. Just a slow, steady drip.
Why This Should Worry the Broader Crypto Market
The Vladhood incident highlights a compounding vulnerability at the intersection of social media security and onchain infrastructure. Decentralized exchanges and automated market makers are permissionless by design, which is their strength. But that same openness means a fraudulent token can be deployed, promoted, and monetized indefinitely with no mechanism to claw fees back from a confirmed bad actor.
For retail participants, the lesson is blunt: even after a hack is publicly confirmed and the post is deleted, the onchain damage continues. Tokens do not get delisted. Liquidity pools do not auto-close. Fees keep flowing.
As high-profile account compromises become a standard vector for crypto fraud, the industry faces a harder question: when the rug never gets pulled, who is responsible for protecting users from a scam that never technically ends?