Logo officiel du MASTR MASTR
Menu
Lire la publication

Hameçonnage, failles et vie privée

Compromised public X accounts used to promote crypto scams

1/2 This is my (crazy!) list of high-profile X accounts that were compromised and then used to promote memecoins, fraudulent tokens or related crypto scams.

Original sur X ↗

Original publication · 23 Jul 2026. Figures, claims and opinions reflect the original publication date.

Les publications originales sont en anglais. La navigation est disponible en sept langues.

01

Original sur X ↗

1/2
This is my (crazy!) list of high-profile X accounts that were compromised and then used to promote memecoins, fraudulent tokens or related crypto scams.

In the second post, I explain how compromises like these can happen.

The list covers roughly mid-2023 to July 2026 and focuses mainly on accounts with hundreds of thousands or even tens of millions of followers.

It is far from exhaustive.

➡️ 2024

- GCR / Gigantic Rebirth (@GCRClassic): May 26, 2024. Used to promote ORDI and Luna 2.0, reportedly connected to operations involving the $CAT memecoin team. More than 250,000 followers.

- Rich The Kid: May 2024. Used to promote $RICH, a Solana memecoin launched in the typical https://t.co/gKLwp9DDzh style.

- Caitlyn Jenner: May 2024. Used to promote $JENNER.

- Hulk Hogan: June 2024. Used to promote $HULK, also known as the Hulkamania token.

- Metallica: June 26, 2024. The band’s official account promoted $METAL on Solana using false claims involving Ticketmaster and MoonPay.

- 50 Cent: Around July 2024. His account was compromised and used to promote a scam token during the same wave of celebrity account takeovers.

- Doja Cat: July 8, 2024. Her account promoted $DOJA on Solana to 5.6 million followers. The token briefly reached a market cap of approximately $1.65 million before collapsing.

- Sydney Sweeney: July 2, 2024. Her account promoted $SWEENEY and had reportedly been involved in an earlier incident involving $MILK.

- Usher: Around September 2024. His account promoted $USHER. Investigators connected the incident to a broader series of celebrity account compromises.

- Wiz Khalifa: November 3, 2024. His account promoted $WIZ or $WIZZLE to 35.7 million followers. The token briefly reached a market cap of approximately $3.4 million.

- Drake: December 14, 2024. His account promoted $ANITA, referencing his “Anita Max Wynn” alter ego and falsely claiming a partnership with Stake. The account had approximately 39 million followers. The token generated significant trading volume before dumping.

- Multiple crypto-focused accounts: Kick, Cursor, The Arena, Brett and Alex Blania. The accounts were used to promote fraudulent memecoins, with one attacker making approximately $500,000.

➡️ 2025

- Nasdaq: January 22, 2025. Nasdaq’s official account promoted $STONKS. The token reportedly reached a market cap of approximately $123 million before crashing.

- Dean Norris: January 2025. The Breaking Bad actor’s account promoted tokens using names such as $DEAN and $SCHRADER.

- Joel Khalili / WIRED-related account: Early 2025. The compromised account was used to promote a fraudulent memecoin using WIRED branding.

- Issa Rae: Late January or early February 2025. Her account was taken over and used in a crypto scam involving malicious links. She later warned followers through Instagram.

- Nick Robinson: February 2025. The BBC journalist’s account promoted the Solana token $TODAY.

- Pumpfun: February 2025. The platform’s official account promoted a fake “official” $PUMP governance token and additional fraudulent contract addresses.

- McDonald’s-related and other accounts: generated approximately $3.5 million.

➡️ 2026

- Roaring Kitty / Keith Gill: Around May 2026. His account promoted Red Kitten Crew, or $RKC. The token briefly reached a market cap of approximately $12 million before collapsing.

- SpaceX and Starlink: July 12, 2026. Both official accounts were compromised and used to promote $SCATMAN. The attacker made approximately $135,000 from the resulting pump and dump.

- Vlad Tenev, CEO of Robinhood (@vladtenev): July 23, 2026. His account promoted $VLAD, also called “Vladhood”, as the supposed official mascot of Robinhood Chain and included a fraudulent contract address. Robinhood confirmed that the account had been compromised, and the post was removed.

The playbook is nearly always identical.

A trusted account suddenly publishes a contract address, claims that a token is official or backed by a major partnership, and directs millions of followers towards a freshly created market.

The price rises, insiders or attackers sell into the volume, and the token collapses.

A blue checkmark, a famous name and millions of followers do not make a contract address legitimate.

Any unexpected token promotion from a major account should be treated as hostile until it has been independently confirmed through multiple official channels.

Attachment to the original X post
Attachment to the original X post Ouvrir l’image en taille réelle ↗
Attachment to the original X post
Attachment to the original X post Ouvrir l’image en taille réelle ↗
Attachment to the original X post
Attachment to the original X post Ouvrir l’image en taille réelle ↗

02

Original sur X ↗

How does the X account of someone this powerful get hacked?

By now, most people have seen the news: Robinhood confirmed that CEO Vlad Tenev’s X account was compromised and used to promote a fake “official” memecoin called $VLAD.

The post was eventually removed, but the more important question remains: why are no alarm bells ringing when the CEO of a major financial platform cannot adequately protect one of his most influential public communication channels?

We have watched variations of this story for years.

Some of these compromises are unquestionably real.

Others deserve far more scrutiny than they receive.

A hack should not automatically be treated as evidence of an inside job, but neither should “I was hacked” function as a magic sentence that ends every investigation.

The exact method used against Tenev has not been publicly disclosed. In most cases, however, attackers do not need some sophisticated X zero-day.

They use painfully ordinary methods that continue to work because humans remain the weakest part of the security model.

The victim may enter credentials into a fake login page sent through a convincing security alert, partnership request or message from an already compromised account.

Attackers may reuse passwords leaked from another service, abuse an authorised third-party application, steal browser sessions through malware or social engineering, exploit weak SMS-based authentication or take control of a phone number through a SIM swap. Modern phishing kits can even capture active session cookies, meaning that simply enabling 2FA does not automatically make an account secure.

There is also an active phishing wave in which compromised accounts send apparently harmless messages asking people to “vote” for someone in a podcast or competition.

The link leads to a fake login page, the credentials are stolen, and the newly compromised account is then used to attack the next group of victims or promote crypto scams.

It is a basic chaining attack, but it scales because the message arrives from someone the victim already knows or trusts.

So what did Tenev do wrong?

At this point, nobody outside the investigation can honestly answer that. Perhaps he clicked a phishing link. Perhaps an employee, device, email account, active session or connected application was compromised.

Perhaps the account recovery process was socially engineered. Until Robinhood publishes a proper incident report, anyone claiming to know the exact cause is guessing.

Attachment to the original X post
Attachment to the original X post Ouvrir l’image en taille réelle ↗

Sources et publications originales

Preuves originales (1)
MASTR

Soutenir la recherche indépendante

Les enquêtes, les preuves originales et les guides sont en accès libre. Les dons volontaires contribuent au financement de la recherche et au maintien des outils MASTR.

Ouvrir le portefeuille