GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Robinhood CEO Discloses Attacker Compromised His X Account by Social Engineering X Customer Support to Bypass 2FA

Robinhood CEO Vlad Tenev stated that his X account was compromised last week. Attackers deceived X customer support through social engineering tactics, bypassing security measures such as two-factor authentication and login alerts, and posted false content related to meme coins. Subsequently, the X security team assisted in swiftly removing the relevant posts and restored account access on the same day.

Robinhood CEO's X Account Hacked, Fake Meme Coin Information Deleted

According to The Block, Robinhood CEO Vlad Tenev's X account was hacked at approximately 17:24 UTC on July 23. Hackers posted claiming to launch "Vladhood ($VLAD)" as the "official mascot of Robinhood Chain," and attached a contract address. The Robinhood Chain blockchain explorer has labeled the token as a "potential scam," and the token has generated approximately 1,868 transactions since deployment. Robinhood officially confirmed later that the account was compromised, the relevant posts have been deleted, and the company is working with the X platform to restore account access.

Robinhood CEO Vlad Tenev's X account was hacked

Odaily Planet Daily reported that Onchain Lens stated on the X platform that Robinhood CEO Vlad Tenev's X account was hacked.

Pons responds to front-end authorization vulnerability: Launchpad trading page lacks Multicall3 functionality, only $0.66 worth of NOXA affected

Robinhood Chain launchpad Pons has officially responded to earlier reports about a token authorization vulnerability in its front end, stating that the Pons launchpad trading page does not have any Multicall3 functionality. The Multicall3 feature mentioned in the tweet originated from the previous Debank Chain old version bridge and was released before the Pons launchpad, thus it does not affect launchpad users. It is currently confirmed that only 0.60 NOXA tokens, valued at approximately $0.66, are affected.As a security precaution, Pons recommends that users who previously used the old version bridge revoke token authorizations via revoke.cash. The team is currently working with audit firms to investigate potential risks and has stated that Pons' front-end services will be restored after confirming the absence of any actual vulnerabilities.

Token Pocket Chief Business Officer: Robinhood Founder's Seed Phrase Leaked During Live Stream, Address Now Frozen

Michael, Chief Business Officer of Token Pocket, stated on platform X that Robinhood founder's seed phrase was leaked during a live stream. After gaining control of the address, the hacker used it and associated addresses to heavily purchase the Meme token $1, prompting thousands of investors to follow suit. In a short time, the token's market cap quickly surged from approximately $500,000 to $14 million.Subsequently, the price of the $1 token dropped sharply, with two-hour trading volume reaching around $20 million. After the address was frozen, the hacker quickly moved to the BNB Chain, using the address and its associated addresses to issue a new token. They created trading activity through tactics like wash trading, ultimately dumping the tokens for profit.Currently, Robinhood's RPC has frozen the address, and the node does not allow transactions originating from this address to be packaged, making transfers, purchases, or sales impossible.

Robinhood Phishing Attack Exploits Gmail’s “Dot Alias” Feature to Forge Official Emails and Lure Users into Logging In

According to Cointelegraph, Robinhood users have recently fallen victim to a phishing attack. Attackers exploited Gmail’s feature of ignoring periods (“.”) in email usernames, along with a vulnerability in Robinhood’s account creation process, to register accounts with email addresses highly similar to those of their targets. This enabled them to trick Robinhood’s official email server into delivering spoofed alert emails containing phishing links directly to victims’ inboxes. Cybersecurity researcher Alex Eckelberry noted that these emails pass SPF, DKIM, and DMARC authentication checks and thus appear to originate from Robinhood’s official domain. Robinhood stated that this incident does not involve any breach of its systems or customer accounts, and user funds and personal information remain unaffected. However, the company urges users to delete such emails and avoid clicking any suspicious links.