Infighting Erupted on Launch Day: Robinhood Chain's Launch Platform vlad.fun Sabotaged by Its Own People

Foresight NewsXuất bản vào 2026-07-20Cập nhật gần nhất vào 2026-07-20

Tóm tắt

On July 15th, the Robinhood Chain token launchpad vlad.fun experienced internal sabotage on its launch day. Two external developers secretly hardcoded their own token into the platform's frontend, making it the only token visible to users and hiding all others. The core team detected the anomaly within two hours, fired the developers, and removed the malicious code. The developers claimed the action was for "clicks." They refunded approximately $15,000 in creator fees and test token profits, totaling about 7.8 ETH, to the team. An additional 4.16 ETH in protocol fees from the launch is held in a team multisig wallet. Built by a five-person team in 48 hours, vlad.fun's code was provided by the two external developers. Their last commit added the hardcoded line. When confronted, they initially blamed technical issues, but later attempted to delete the evidence before confessing. The platform is currently paused. A community member, Will Mexi, clarified he was not involved and was the one who discovered and reported the issue, having previously enabled branch protection which preserved the evidence. vlad.fun's design allows token deployment and direct listing on Uniswap V3/V4 in one transaction, with liquidity permanently locked to reduce rug pull risks. It features anti-whale measures and flexible fee routing. Despite this incident, the Robinhood Chain launchpad ecosystem remains active, with platforms like PONS gaining significant traction.


Author: Nicky, Foresight News


On July 15th, the Robinhood Chain token launch platform vlad.fun experienced malicious actions by internal developers on its launch day. According to official sources, two external developers involved in building the platform secretly created their own token and hardcoded it into the frontend code, causing only that token to be visible to users upon platform launch, while all other creators' tokens were completely hidden. The team discovered the anomaly within two hours, promptly dismissed the involved developers, and removed the malicious code.


The official statement emphasized that the team never approved issuing a vlad.fun platform token, and the two individuals unilaterally decided to launch one for "page views." After negotiation, the duo returned approximately $15,000 in creator fees and test token proceeds. The recovered funds, totaling about 7.8 ETH, have been deposited into the team's secure wallet. Additionally, approximately 4.16 ETH in protocol fees generated from the platform launch are held in the team's multi-signature address.


Public information shows that vlad.fun was rapidly built by a small team of 5 within 48 hours. Currently, two project-affiliated members have issued statements, but the specific identities of the two external developers have not been disclosed as of publishing. According to the incident explanation thread posted by the project's official account on July 18th, the two external developers were responsible for providing the core codebase for the launchpad. In the final code commit before the platform went live, they manually added a line of hardcoded logic to the frontend, forcing their own token to be displayed on the homepage, while other creators' tokens were completely obscured due to loading issues.


After the launch, users quickly noticed the anomaly, with the entire platform displaying only one token. Team members began reviewing the code and found the manually added hardcoded line in the commit history. When questioned by the team, the two developers initially blamed technical issues such as RPC failures, environment variable problems, and caching, but the persistent visibility of the relevant token contradicted such explanations.


According to the official account, one of the developers later requested the disabling of the branch protection feature on the code repository, claiming a need to "rollback some content." Before removing the protection, the team performed a timestamp backup of the entire repository and observed the two deleting the line containing the hardcoded logic. The official statement noted that this attempt to destroy evidence ultimately revealed their intent. Confronted with the evidence, the two developers admitted to their actions.


This incident highlights the trust risks faced by rapidly built crypto projects when involving external developers. The identities of the two involved developers have not been publicly disclosed, with the team stating they have taken advice to withhold their identities for now. vlad.fun stated that in the future, external personnel will no longer be allowed access to sensitive systems, and the team prefers developing based on open-source contracts.


The official website shows that vlad.fun is currently in a suspended operational state. The team stated they will prioritize handling matters for affected users.


Community member Will Mexi publicly clarified his role after the incident. He stated he was responsible for project application listings, frontend optimization, design, branding, and animations, and was not one of the two developers involved, nor did he participate in planning or executing the operation. According to his account, he tested a normal version of the website about 20 minutes before launch, so he did not notice the anomaly.


Will Mexi said that after the platform officially launched, he saw the token appearing illogically, immediately read the newly committed code, discovered the hardcoded line, and promptly reported it to the core team. He also mentioned that enabling branch protection earlier was due to caution regarding external code, and this setting ultimately preserved the complete commit history and evidence of intent. He simultaneously denied purchasing any platform tokens and claimed to have incurred losses due to expensive RPC, API, and server deployment costs.


Core team member @SOLsesame also expressed support in the incident thread. He belongs to the core small team that has collaborated with Will Mexi and others for over a year and is not one of the involved external developers. His background shows he is an active builder in the Solana ecosystem, having been deeply involved in the ai16z ecosystem and its PartnersNFT and PartnersDAO projects. Recently, he collaborated with Will Mexi to build and launch the Black Bull NFT series from scratch for the ANSEM community within 24 hours.


As a token launchpad on Robinhood Chain, vlad.fun differs from traditional bonding curve launchpads. Its design goal is to complete token deployment and direct launch to Uniswap V3 or V4 in a single transaction, making tokens instantly tradable on decentralized exchanges without going through a "graduation" migration step. Liquidity pool positions are permanently locked via a locker contract and cannot be withdrawn by the team, reducing the risk of rug pulls at the mechanism level.


In terms of fairness design, the platform employs mechanisms such as a fixed supply, no presale, and no large team allocations. It also offers an optional developer priority buy feature, allowing developers to buy at launch with zero transaction fees. An anti-whale mechanism limits single wallet holdings to 2%, preventing concentrated holdings by a single address. For fee routing, the platform supports setting a 1% to 5% transaction fee, which can be instantly directed to specified recipients, including wallet addresses, social accounts, or buyback/burn proxies. Fees are locked at launch and cannot be changed. Additionally, the platform plans optional models such as staking for rewards.


Despite vlad.fun hitting pause due to the internal incident, the launchpad ecosystem on Robinhood Chain has not cooled down. According to DefiLlama data, the chain's current TVL is approximately $258 million, with 24-hour fees around $118,000 and revenue about $106,000. Uniswap's 24-hour fee expenditure on the chain reached $1.95 million. The ecosystem has already gathered multiple launchpads, each forming a differentiated competitive landscape: the latecomer PONS holds the leading launchpad position with intensive development and continuous updates. Its platform token has a market cap of about $12 million, with a gain of over 4200% in the past 7 days. Furthermore, the Butterfly platform focuses on stock-like meme tokens but has yet to produce a hit. Native Uniswap innovative mechanism tokens, such as RWA dividend-sharing tokens like index, which received official attention, once surged to a market cap of $30 million on July 17th.

Tiền kỹ thuật số thịnh hành

Câu hỏi Liên quan

QWhat was the primary technical action taken by the two external developers that led to the incident on vlad.fun?

AThey secretly added a line of hardcoded script to the platform's front-end code, which forced only their own token to be displayed on the homepage, while hiding all other creators' tokens.

QAccording to the article, what was the main reason given by the developers for their actions, and what key evidence contradicted this reason?

AThey claimed it was for 'page views.' However, the key contradictory evidence was that when questioned, they initially tried to blame technical issues like RPC failures or cache problems, but the fact that their token remained consistently visible made these excuses implausible.

QHow did the core team discover and prove the malicious intent of the external developers?

AAfter users reported seeing only one token, the team reviewed the code commit history and found the manually added hardcoded line. The developers then tried to delete this code and asked to disable branch protection on the repository, which the team had already backed up. Their attempt to destroy evidence confirmed their malicious intent.

QWhat are two key design features of the vlad.fun platform aimed at reducing scam risks compared to traditional launchpads?

A1. Tokens are launched directly to Uniswap V3/V4 in a single transaction, making them instantly tradable without a migration step. 2. The liquidity pool is permanently locked via a locker contract, preventing the team from withdrawing it and reducing 'rug pull' risks.

QWhat is the current status of the vlad.fun platform following the incident, and what does the article suggest about the broader launchpad ecosystem on Robinhood Chain?

AThe vlad.fun platform is currently paused. The article suggests that despite this incident, the launchpad ecosystem on Robinhood Chain remains active, with platforms like PONS gaining significant traction and others exploring different niches.

Nội dung Liên quan

a16z: Từ Công ty đến DAO, DUNA có thể trở thành hình thức tổ chức tiếp theo

Từ các đoàn thương nhân gia đình như Marco Polo đến các công ty cổ phần như Đông Ấn Hà Lan, lịch sử kinh doanh là lịch sử của sự hợp tác. Mỗi bước nhảy vọt tổ chức đều giải quyết vấn đề phối hợp của thời đại mình. Công ty, với tư cách pháp nhân và trách nhiệm hữu hạn, là đột phá vĩ đại cho thời kỳ công nghiệp. Ngày nay, công nghệ blockchain và các giao thức internet cho phép hợp tác phi tập trung mà không cần quản lý tập trung, dẫn đến sự ra đời của các Tổ chức Tự trị Phi tập trung (DAO). Tuy nhiên, DAO đối mặt với thách thức pháp lý: thiếu sự công nhận pháp lý khiến thành viên chịu trách nhiệm vô hạn, và sự mơ hồ trong quy định chứng khoán (như bài kiểm tra Howey của SEC) đã kìm hãm sự phát triển. DUNA (Hiệp hội phi lợi nhuận phi tập trung không hợp nhất) xuất hiện như một giải pháp. Được công nhận ở một số bang Mỹ, DUNA cung cấp cho một nhóm người tư cách pháp nhân và trách nhiệm hữu hạn, cho phép họ quản trị thông qua cơ chế dựa trên blockchain mà không cần bộ máy quản lý tập trung truyền thống. Nó lấp đầy khoảng trống pháp lý cho các mạng lưới phi tập trung, cho phép họ ký hợp đồng, nắm giữ tài sản một cách hợp pháp. Giống như công ty đã cách mạng hóa hợp tác trong quá khứ, DUNA có thể đại diện cho hình thức tổ chức tiếp theo cho kỷ nguyên internet.

marsbit4 phút trước

a16z: Từ Công ty đến DAO, DUNA có thể trở thành hình thức tổ chức tiếp theo

marsbit4 phút trước

Báo cáo giữa năm 2026 về RWA trên chuỗi: Vốn hóa thị trường cổ phiếu được token hóa tăng gấp đôi trong một năm, nhưng 90% quyền lợi chỉ là vỏ bọc

Báo cáo giữa năm 2026 về RWA trên chuỗi chỉ ra rằng vốn hóa thị trường cổ phiếu được mã hóa đã tăng gấp đôi trong một năm lên 18,9 tỷ USD. Tuy nhiên, tăng trưởng này chủ yếu đến từ một vài sản phẩm và nền tảng, với sự tập trung cao: ba nền tảng hàng đầu (Ondo, xStocks, Securitize) chiếm 85,1% tổng giá trị phân phối. Thị trường tồn tại một mâu thuẫn cơ bản: các sản phẩm có tính thanh khoản cao (thường là sản phẩm đóng gói "offshore") lại thiếu quyền sở hữu pháp lý thực tế, trong khi các sản phẩm có nền tảng pháp lý vững chắc (từ cơ sở hạ tầng Mỹ được quản lý) thì khả năng phân phối và thanh khoản còn hạn chế. Chưa có sản phẩm nào kết hợp hoàn hảo cả quyền sở hữu tiêu chuẩn, phân phối ví rộng rãi, tính thanh khoản thể chế và cơ chế phát hiện giá độc lập trên chuỗi. Sự gia tăng giá trị được báo cáo chủ yếu phản ánh biến động giá thị trường và điều chỉnh phân loại, không chỉ đơn thuần là dòng tiền đầu tư mới. Cần hiểu thận trọng các số liệu tổng thể về RWA. Báo cáo kết luận thị trường này tốt nhất nên được xem như một hệ thống "Lớp 2.5" bị phân mảnh, nơi cơ sở pháp lý và tính thanh khoản thường đánh đổi lẫn nhau.

marsbit54 phút trước

Báo cáo giữa năm 2026 về RWA trên chuỗi: Vốn hóa thị trường cổ phiếu được token hóa tăng gấp đôi trong một năm, nhưng 90% quyền lợi chỉ là vỏ bọc

marsbit54 phút trước

Cảnh báo, người dùng Bitcoin! Vụ tấn công hôm nay có thể lớn hơn bạn nghĩ. Đây là những gì bạn cần làm

Chú ý: Người dùng Bitcoin có thể đối mặt với lỗ hổng bảo mật nghiêm trọng. Công ty Coinkite, nhà sản xuất ví phần cứng Coldcard, đã cảnh báo về một lỗi trong quá trình tạo "seed phrase" (cụm từ khôi phục) trên một số thiết bị Coldcard Mk3 (chạy firmware từ phiên bản 4.0.1 đến 5.0.3). Tất cả địa chỉ Bitcoin được tạo từ seed phrase trên các thiết bị này đều có nguy cơ bị xâm phạm. Cảnh báo được đưa ra sau khi một cuộc tấn công quy mô lớn đã làm rỗng 1.196 ví Bitcoin đơn ký, đánh cắp tổng cộng 1.082,65 BTC (tương đương khoảng 70,2 triệu USD vào thời điểm đó) chỉ trong vòng 41 phút vào ngày 30/7. Các giao dịch có đặc điểm giống nhau, cho thấy khả năng cao được thực hiện bởi một công cụ tự động quét các khóa riêng tư đã bị rò rỉ. Coinkite khuyến cáo người dùng Coldcard Mk3 đã tạo seed phrase trên thiết bị cần hành động ngay lập tức: 1. Không coi seed phrase cũ là an toàn. 2. Tạo một seed phrase mới trên một thiết bị phần cứng đáng tin cậy và hiện đại. 3. Chuyển toàn bộ số tiền sang địa chỉ mới được tạo từ seed phrase mới này. Lưu ý quan trọng: Chỉ nâng cấp thiết bị là không đủ; tuyệt đối không sử dụng lại seed phrase cũ trên bất kỳ ví mới nào.

cryptonews.ru2 giờ trước

Cảnh báo, người dùng Bitcoin! Vụ tấn công hôm nay có thể lớn hơn bạn nghĩ. Đây là những gì bạn cần làm

cryptonews.ru2 giờ trước

Bitcoin trong tháng Tám: Các chuyên gia kỳ vọng thử nghiệm phạm vi, không phải đảo chiều nhanh chóng

Tháng 8 sẽ là thời điểm thử nghiệm các mức giá then chốt đối với Bitcoin hơn là một bước ngoặt tăng mạnh, theo đánh giá của nhiều chuyên gia. Dù phục hồi vào tháng 7, thị trường vẫn chưa sẵn sàng cho một đà tăng bền vững và nguy cơ giảm xuống dưới 60.000 USD vẫn tồn tại. Các nhà phân tích chỉ ra áp lực từ môi trường vĩ mô như lãi suất cao, lạm phát dai dẳng và đồng USD mạnh, khiến dòng vốn chảy vào tài sản rủi ro như tiền mã hóa bị hạn chế. Dòng tiền ròng ra khỏi các ETF Bitcoin trong nửa đầu năm cũng phản ánh tâm lý thận trọng này. Về mặt kỹ thuật, Bitcoin được dự báo sẽ tiếp tục dao động trong phạm vi, với ba kịch bản chính cho tháng 8: dao động chính trong khoảng 58.000-68.000 USD (xác suất 50%), giảm về 50.000-55.000 USD (30%), hoặc tăng lên 71.000-75.000 USD (20%). Mức hỗ trợ then chốt là quanh 60.000-61.000 USD. Các chuyên gia khuyến nghị nhà đầu tư có thể tích lũy dần ở các mức giá hiện tại cho dài hạn, nhưng cần thận trọng trước khả năng biến động ngắn hạn và ưu tiên các đồng coin mạnh thay vì meme coin. Sự bứt phá mạnh mẽ hơn có thể chỉ xuất hiện vào quý IV/2025.

cryptonews.ru3 giờ trước

Bitcoin trong tháng Tám: Các chuyên gia kỳ vọng thử nghiệm phạm vi, không phải đảo chiều nhanh chóng

cryptonews.ru3 giờ trước

Ví cứng Coldcard bị hack: Tin tặc rút 594 Bitcoin trong 25 phút

Ví phần cứng Coldcard bị xâm phạm: Lỗi phần mềm nghiêm trọng dẫn đến mất 594 BTC Ví phần cứng Coldcard của Coinkite, vốn được coi là phương pháp lưu trữ tiền điện tử an toàn nhất, đã bị xâm phạm nghiêm trọng vào ngày 30/7/2026. Tin tặc đã rút 594,5 Bitcoin (khoảng 40 triệu USD) từ hàng trăm địa chỉ chỉ trong 25 phút. Nguyên nhân chính là một lỗi phần mềm tồn tại suốt 5 năm mà không bị phát hiện. Một lỗi đánh máy trong mã nguồn từ tháng 3/2021 đã vô hiệu hóa chức năng tạo số ngẫu nhiên thực sự từ chip chuyên dụng của thiết bị. Thay vào đó, ví tạo ra seed phrase (cụm từ khôi phục) dựa trên dữ liệu có thể dự đoán được như số sê-ri CPU và thời gian hệ thống. Điều này làm giảm nghiêm trọng độ an toàn mật mã, khiến không gian tìm kiếm khóa bị thu hẹp đáng kể (xuống còn khoảng 40-bit hoặc 72-bit thay vì 128-bit theo yêu cầu). Tin tặc không cần truy cập vật lý vào thiết bị. Họ đã tận dụng thông số của bộ tạo số kém an toàn này để tạo ra hàng triệu seed phrase có thể có, sau đó kiểm tra chống với sổ cái công khai blockchain để tìm địa chỉ có số dư và ký các giao dịch chuyển tiền. Coinkite thừa nhận lỗi và xác nhận tất cả các thiết bị chạy firmware bị ảnh hưởng đều dễ bị tấn công. Công ty đã phát hành các bản cập nhật firmware an toàn mới. Tuy nhiên, việc cập nhật đơn thuần không bảo vệ seed phrase đã được tạo ra trước đó. Chủ sở hữu cần: 1. Cập nhật firmware lên phiên bản an toàn. 2. Tạo một seed phrase mới HOÀN TOÀN trên thiết bị đã được cập nhật. 3. Chuyển toàn bộ số tiền sang các địa chỉ mới được tạo từ seed phrase mới này. Sự việc này nhấn mạnh rằng ngay cả phần cứng chuyên dụng cũng cần được kiểm tra và đánh giá mã nguồn độc lập một cách liên tục, đặc biệt là các chức năng mật mã cốt lõi.

cryptonews.ru3 giờ trước

Ví cứng Coldcard bị hack: Tin tặc rút 594 Bitcoin trong 25 phút

cryptonews.ru3 giờ trước

Giao dịch

Giao ngay

Bài viết Nổi bật

Làm thế nào để Mua PEOPLE

Chào mừng bạn đến với HTX.com! Chúng tôi đã làm cho mua ConstitutionDAO (PEOPLE) trở nên đơn giản và thuận tiện. Làm theo hướng dẫn từng bước của chúng tôi để bắt đầu hành trình tiền kỹ thuật số của bạn.Bước 1: Tạo Tài khoản HTX của BạnSử dụng email hoặc số điện thoại của bạn để đăng ký tài khoản miễn phí trên HTX. Trải nghiệm hành trình đăng ký không rắc rối và mở khóa tất cả tính năng. Nhận Tài khoản của tôiBước 2: Truy cập Mua Crypto và Chọn Phương thức Thanh toán của BạnThẻ Tín dụng/Ghi nợ: Sử dụng Visa hoặc Mastercard của bạn để mua ConstitutionDAO (PEOPLE) ngay lập tức.Số dư: Sử dụng tiền từ số dư tài khoản HTX của bạn để giao dịch liền mạch.Bên thứ ba: Chúng tôi đã thêm những phương thức thanh toán phổ biến như Google Pay và Apple Pay để nâng cao sự tiện lợi.P2P: Giao dịch trực tiếp với người dùng khác trên HTX.Thị trường mua bán phi tập trung (OTC): Chúng tôi cung cấp những dịch vụ được thiết kế riêng và tỷ giá hối đoái cạnh tranh cho nhà giao dịch.Bước 3: Lưu trữ ConstitutionDAO (PEOPLE) của BạnSau khi mua ConstitutionDAO (PEOPLE), lưu trữ trong tài khoản HTX của bạn. Ngoài ra, bạn có thể gửi đi nơi khác qua chuyển khoản blockchain hoặc sử dụng để giao dịch những tiền kỹ thuật số khác.Bước 4: Giao dịch ConstitutionDAO (PEOPLE)Giao dịch ConstitutionDAO (PEOPLE) dễ dàng trên thị trường giao ngay của HTX. Chỉ cần truy cập vào tài khoản của bạn, chọn cặp giao dịch, thực hiện giao dịch và theo dõi trong thời gian thực. Chúng tôi cung cấp trải nghiệm thân thiện với người dùng cho cả người mới bắt đầu và người giao dịch dày dạn kinh nghiệm.

Tổng lượt xem 812Xuất bản vào 2024.12.12Cập nhật vào 2026.06.02

Làm thế nào để Mua PEOPLE

Thảo luận

Chào mừng đến với Cộng đồng HTX. Tại đây, bạn có thể được thông báo về những phát triển nền tảng mới nhất và có quyền truy cập vào thông tin chuyên sâu về thị trường. Ý kiến ​​của người dùng về giá của PEOPLE (PEOPLE) được trình bày dưới đây.

活动图片