Blockchain analysis reveals the creator of a fraudulent token capitalizing on the compromise of Robinhood CEO Vlad Tenev's X account deployed the contract nearly an hour before the malicious post went live, and continues to extract trading fees from the liquidity pool without removing the underlying assets.
Onchain records examined by The Defiant show the "Vladhood" token contract was created at 14:14 UTC on Monday, approximately 46 minutes before the unauthorized message appeared on Tenev's verified profile at 15:00 UTC. The timing suggests the attacker prepared the infrastructure in advance, waiting for the opportune moment to broadcast the contract address to the executive's 200,000-plus followers.
The hacked post, which remained visible for roughly 30 minutes before removal, directed users to a Uniswap V2 pair containing the newly minted token paired against Wrapped Ether. Within minutes, automated snipers and retail buyers drove the pool's volume past $1.2 million, generating substantial swap fees for the liquidity provider , the deployer's wallet.
Unlike typical rug pulls where creators drain the pool entirely, the Vladhood deployer has left the liquidity intact while systematically claiming the 0.3% protocol fee accruing on each trade. Data from Etherscan shows the address has collected over 3.8 ETH in fees since deployment, with the amount growing steadily as speculative trading continues. The liquidity itself , roughly 45 ETH and 1.2 billion Vladhood tokens , remains locked in the pair contract.
Security researchers note this "fee farming" approach represents a lower-risk variation on the celebrity impersonation scam. By avoiding a full liquidity pull, the attacker reduces the likelihood of immediate onchain detection tools flagging the exit, while still monetizing the hype cycle. The strategy also complicates potential legal recovery efforts, since the pool remains functional and token holders can theoretically still sell.