• bitcoinBitcoin (BTC) $ 63,627.00
  • ethereumEthereum (ETH) $ 1,667.93
  • tetherTether (USDT) $ 0.999554
  • bnbBNB (BNB) $ 604.85
  • usd-coinUSDC (USDC) $ 0.999871
  • xrpXRP (XRP) $ 1.14
  • solanaSolana (SOL) $ 67.07
  • tronTRON (TRX) $ 0.315226
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.086199
  • hyperliquidHyperliquid (HYPE) $ 59.25
  • usdsUSDS (USDS) $ 0.999672
  • leo-tokenLEO Token (LEO) $ 9.52
  • rainRain (RAIN) $ 0.013039
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 416.60
  • moneroMonero (XMR) $ 349.79
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.187659
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • canton-networkCanton (CC) $ 0.163403
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • cardanoCardano (ADA) $ 0.170025
  • whitebitWhiteBIT Coin (WBT) $ 51.98
  • chainlinkChainlink (LINK) $ 7.90
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • the-open-networkToncoin (TON) $ 1.69
  • ethena-usdeEthena USDe (USDE) $ 0.999554
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • daiDai (DAI) $ 0.999900
  • bitcoin-cashBitcoin Cash (BCH) $ 202.60
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 3.06
  • hedera-hashgraphHedera (HBAR) $ 0.077847
  • litecoinLitecoin (LTC) $ 43.34
  • wethWETH (WETH) $ 2,268.37
  • labLAB (LAB) $ 10.08
  • suiSui (SUI) $ 0.752321
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • usdt0USDT0 (USDT0) $ 0.998824
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • avalanche-2Avalanche (AVAX) $ 6.59
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • crypto-com-chainCronos (CRO) $ 0.059326
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • nearNEAR Protocol (NEAR) $ 2.01
  • tether-goldTether Gold (XAUT) $ 4,201.26
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • audieraAudiera (BEAT) $ 7.92
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bittensorBittensor (TAO) $ 213.78
  • pax-goldPAX Gold (PAXG) $ 4,208.24
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.058581
  • mantleMantle (MNT) $ 0.538963
  • ondo-financeOndo (ONDO) $ 0.356155
  • aster-2Aster (ASTER) $ 0.631566
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • polkadotPolkadot (DOT) $ 0.964033
  • worldcoin-wldWorldcoin (WLD) $ 0.475687
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • uniswapUniswap (UNI) $ 2.50
  • okbOKB (OKB) $ 73.78
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.996187
  • pi-networkPi Network (PI) $ 0.127072
  • usddUSDD (USDD) $ 0.999661
  • bfusdBFUSD (BFUSD) $ 0.999397
  • skySky (SKY) $ 0.056297
  • internet-computerInternet Computer (ICP) $ 2.38
  • morphoMorpho (MORPHO) $ 1.98
  • bitget-tokenBitget Token (BGB) $ 1.79
  • pepePepe (PEPE) $ 0.000003
  • ethereum-classicEthereum Classic (ETC) $ 7.17
  • cosmosCosmos Hub (ATOM) $ 2.01
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 1.00
  • aaveAave (AAVE) $ 64.42
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.96
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • quant-networkQuant (QNT) $ 66.14
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.11
  • usdtbUSDtb (USDTB) $ 0.999908
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • dexeDeXe (DEXE) $ 19.26
  • kucoin-sharesKuCoin (KCS) $ 6.69
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • render-tokenRender (RENDER) $ 1.68
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kaspaKaspa (KAS) $ 0.031038
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • stable-2​​Stable (STABLE) $ 0.035506
  • nexoNEXO (NEXO) $ 0.800598
  • wbnbWrapped BNB (WBNB) $ 759.61
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.074629
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • algorandAlgorand (ALGO) $ 0.087034
  • ethenaEthena (ENA) $ 0.078260
  • gatechain-tokenGate (GT) $ 6.56
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.688109
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • flare-networksFlare (FLR) $ 0.007921
  • venice-tokenVenice Token (VVV) $ 14.35
  • justJUST (JST) $ 0.076087
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • xdce-crowd-saleXDC Network (XDC) $ 0.030252
  • ghoGHO (GHO) $ 0.999040
  • filecoinFilecoin (FIL) $ 0.758332
  • beldexBeldex (BDX) $ 0.076400
  • midnight-3Midnight (NIGHT) $ 0.034622
  • jupiter-exchange-solanaJupiter (JUP) $ 0.167135
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.998658
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • yldsYLDS (YLDS) $ 0.999704
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • hash-2Provenance Blockchain (HASH) $ 0.010094
  • aptosAptos (APT) $ 0.645665
  • pump-funPump.fun (PUMP) $ 0.001517
  • clbtcclBTC (CLBTC) $ 76,920.00
  • arbitrumArbitrum (ARB) $ 0.084253
  • a7a5A7A5 (A7A5) $ 0.013214
  • official-trumpOfficial Trump (TRUMP) $ 2.21
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.16
  • injective-protocolInjective (INJ) $ 5.15
  • usxUSX (USX) $ 0.999455
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • true-usdTrueUSD (TUSD) $ 0.998486
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.55
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • adi-tokenADI (ADI) $ 3.73
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.32
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • kite-2Kite (KITE) $ 0.191525
  • dashDash (DASH) $ 34.58
  • euro-coinEURC (EURC) $ 1.16
  • vechainVeChain (VET) $ 0.005036
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.187456
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006728
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000074
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • hastra-primePRIME (PRIME) $ 1.04
  • apxusdapxUSD (APXUSD) $ 0.962234
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.612258
  • humanityHumanity (H) $ 0.217656
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • ethgas-2ETHGas (GWEI) $ 0.185621
  • bonkBonk (BONK) $ 0.000004
  • lighterLighter (LIT) $ 1.53
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • curve-dao-tokenCurve DAO (CRV) $ 0.239528
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • the9bitThe9bit (9BIT) $ 0.043679
  • sei-networkSei (SEI) $ 0.052479
  • aerodrome-financeAerodrome Finance (AERO) $ 0.357955
  • unibaseUnibase (UB) $ 0.134779
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • siren-2Siren (SIREN) $ 0.462580
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997988
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • blockstackStacks (STX) $ 0.180855
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kinesis-goldKinesis Gold (KAU) $ 139.54
  • sun-tokenSun Token (SUN) $ 0.016870
  • pyth-networkPyth Network (PYTH) $ 0.038480
  • celestiaCelestia (TIA) $ 0.325612
  • spx6900SPX6900 (SPX) $ 0.318556
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • skyaiSkyAI (SKYAI) $ 0.290581
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • gnosisGnosis (GNO) $ 104.17
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • ether-fiEther.fi (ETHFI) $ 0.312412
  • chilizChiliz (CHZ) $ 0.026040
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • jito-governance-tokenJito (JTO) $ 0.546891
  • apenftAINFT (NFT) $ 0.00000027
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • kinesis-silverKinesis Silver (KAG) $ 69.34
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • tezosTezos (XTZ) $ 0.235826
  • royal-dollarRoyal Dollar (RUSD) $ 1.00
  • monadMonad (MON) $ 0.021173
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • zebec-networkZebec Network (ZBCN) $ 0.002546

Read this before you click on any Robinhood email

0 0


Robinhood customers received some particularly convincing phishing emails this weekend. The messages, which appeared to come directly from the company, featured authenticated headers, were correctly signed, included a genuine sender’s address, were sent from an authentic email server, and weren’t caught by spam filters.

Worse, the email from [email protected] even earned Gmail’s automatic route into the same conversation threads as legitimate, prior security alerts from Robinhood.

The only fraudulent things about the email were obscure technical irregularities and its contents, a phishing call-to-action seeking login information.

By Sunday night, hackers used Robinhood’s own notification pipeline to render their assault.

Analysis of the exploit went viral on social media soon after.

Robinhood phishing emails were ‘kinda beautiful’

Security researcher Abdel Sabbah posted an analysis of the event, calling it “kinda beautiful” with a sinister connotation. Unfortunately, he was right.

To craft the attack, the hacker first utilized a Gmail “dot trick,” a well-known Google feature whereby Gmail routes [email protected], [email protected], and [email protected] to the same inbox.

Gmail, unlike the rest of the internet, ignores dots in the part of the address before the @ symbol, so all of those variants deliver to the same inbox.

Because Robinhood, unlike Gmail, doesn’t normalize the dotted variants, an attacker used a “dot” modified version of Robinhood’s legitimate customer emails.

Next, the attacker set the device name on the new account to a block of raw HTML. When Robinhood’s “unrecognized activity” email is generated, the template inserts that device name without sanitizing it, rendering the nefarious HTML.

The result, in Sabbah’s words, is what appeared to be “a real email from [email protected], DKIM pass, SPF pass, DMARC pass, with a phishing CTA.”

That CTA or “call to action,” of course, is a fake security alert email with a hyperlink to an attacker-controlled webpage that harvests login credentials and two-factor authentication codes.

The ultimate goal, like almost all phishing campaigns, was to steal customer’s money — in this case, from their Robinhood account.

These AI chatbots are happy to help you run a crypto scam

Think before you click on any email

Many crypto influencers warned people about the convincing emails.

Ripple’s David Schwartz amplified the warning. “Any emails you get that appear to be from Robinhood (and may actually be from their email system) are phishing attempts,” he posted. Quoting Sabbah’s thread, Schwartz added, “It’s quite sneaky.”

Stay safe out there, everyone 🥺

— Laura Shin (@laurashin) April 27, 2026

In April 2025, Ethereum Name Service Lead Developer Nick Johnson documented an almost identical exploit involving emails that appeared to send from Google itself.

Attackers used a similar series of tricks to use Google’s own infrastructure to deliver DKIM-signed phishing emails from [email protected].

The lesson then is the lesson now: beware of clicking any link in any email, no matter how authentic it appears.

Traditional anti-phishing advice tells users to check the sender domain and look for authentication failures. None of that helped here. The domain appeared real. The signatures appeared real. Only the intent was criminal.

Robinhood’s own scam guidance tells customers to verify the sender’s email domain and lists @robinhood.com as the authentic example.

Protos reached out to Robinhood for comment but didn’t receive a reply prior to publication time. In Nasdaq trading today, the common stock of Robinhood opened flat for trading relative to Friday’s closing print.



Source link

Leave A Reply

Your email address will not be published.