• bitcoinBitcoin (BTC) $ 76,871.00
  • ethereumEthereum (ETH) $ 2,287.27
  • tetherTether (USDT) $ 0.999860
  • xrpXRP (XRP) $ 1.39
  • bnbBNB (BNB) $ 624.26
  • usd-coinUSDC (USDC) $ 0.999794
  • solanaSolana (SOL) $ 84.00
  • tronTRON (TRX) $ 0.323471
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.099549
  • whitebitWhiteBIT Coin (WBT) $ 54.34
  • usdsUSDS (USDS) $ 0.999763
  • hyperliquidHyperliquid (HYPE) $ 40.55
  • leo-tokenLEO Token (LEO) $ 10.37
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.247047
  • bitcoin-cashBitcoin Cash (BCH) $ 446.46
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 379.05
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • chainlinkChainlink (LINK) $ 9.25
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • canton-networkCanton (CC) $ 0.149566
  • zcashZcash (ZEC) $ 337.42
  • stellarStellar (XLM) $ 0.164643
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • memecoreMemeCore (M) $ 3.54
  • usd1-wlfiUSD1 (USD1) $ 0.999879
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999621
  • litecoinLitecoin (LTC) $ 55.23
  • avalanche-2Avalanche (AVAX) $ 9.18
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • hedera-hashgraphHedera (HBAR) $ 0.089188
  • ethena-usdeEthena USDe (USDE) $ 0.999091
  • suiSui (SUI) $ 0.926297
  • wethWETH (WETH) $ 2,268.37
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • rainRain (RAIN) $ 0.007341
  • paypal-usdPayPal USD (PYUSD) $ 0.999935
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.31
  • crypto-com-chainCronos (CRO) $ 0.069361
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,624.27
  • global-dollarGlobal Dollar (USDG) $ 0.999828
  • bittensorBittensor (TAO) $ 249.08
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.073233
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pax-goldPAX Gold (PAXG) $ 4,622.21
  • mantleMantle (MNT) $ 0.632825
  • skySky (SKY) $ 0.088934
  • polkadotPolkadot (DOT) $ 1.22
  • uniswapUniswap (UNI) $ 3.22
  • pi-networkPi Network (PI) $ 0.188558
  • falcon-financeFalcon USD (USDF) $ 0.997521
  • okbOKB (OKB) $ 83.73
  • nearNEAR Protocol (NEAR) $ 1.35
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • aster-2Aster (ASTER) $ 0.635641
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • ripple-usdRipple USD (RLUSD) $ 0.999913
  • aaveAave (AAVE) $ 97.68
  • usddUSDD (USDD) $ 1.00
  • bitget-tokenBitget Token (BGB) $ 1.96
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • internet-computerInternet Computer (ICP) $ 2.41
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bfusdBFUSD (BFUSD) $ 0.999290
  • ethereum-classicEthereum Classic (ETC) $ 8.39
  • ondo-financeOndo (ONDO) $ 0.261887
  • kucoin-sharesKuCoin (KCS) $ 8.42
  • gatechain-tokenGate (GT) $ 7.26
  • morphoMorpho (MORPHO) $ 1.92
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.06
  • pump-funPump.fun (PUMP) $ 0.001767
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • united-stablesUnited Stables (U) $ 0.999754
  • algorandAlgorand (ALGO) $ 0.114441
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • quant-networkQuant (QNT) $ 69.45
  • cosmosCosmos Hub (ATOM) $ 1.98
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.091766
  • blockchain-capitalBlockchain Capital (BCAP) $ 105.75
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • ethenaEthena (ENA) $ 0.105370
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • render-tokenRender (RENDER) $ 1.76
  • kaspaKaspa (KAS) $ 0.032962
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • nexoNEXO (NEXO) $ 0.885899
  • worldcoin-wldWorldcoin (WLD) $ 0.250534
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.036108
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • aptosAptos (APT) $ 0.959413
  • arbitrumArbitrum (ARB) $ 0.124792
  • hash-2Provenance Blockchain (HASH) $ 0.012443
  • filecoinFilecoin (FIL) $ 0.920454
  • justJUST (JST) $ 0.081976
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.191132
  • dexeDeXe (DEXE) $ 14.64
  • flare-networksFlare (FLR) $ 0.007679
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.010090
  • beldexBeldex (BDX) $ 0.079869
  • vechainVeChain (VET) $ 0.007187
  • xdce-crowd-saleXDC Network (XDC) $ 0.030618
  • ousgOUSG (OUSG) $ 115.06
  • usdtbUSDtb (USDTB) $ 1.00
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • ghoGHO (GHO) $ 0.999174
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • official-trumpOfficial Trump (TRUMP) $ 2.48
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • midnight-3Midnight (NIGHT) $ 0.033857
  • usual-usdUsual USD (USD0) $ 0.998046
  • bonkBonk (BONK) $ 0.000006
  • clbtcclBTC (CLBTC) $ 76,920.00
  • yldsYLDS (YLDS) $ 0.999876
  • siren-2Siren (SIREN) $ 0.720768
  • chilizChiliz (CHZ) $ 0.049504
  • true-usdTrueUSD (TUSD) $ 0.999852
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.50
  • a7a5A7A5 (A7A5) $ 0.012402
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • edgexedgeX (EDGE) $ 1.35
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.202215
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.688543
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 35.14
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • manadiaManadia (UMXM) $ 2.12
  • euro-coinEURC (EURC) $ 1.17
  • aerodrome-financeAerodrome Finance (AERO) $ 0.465577
  • tezosTezos (XTZ) $ 0.392231
  • adi-tokenADI (ADI) $ 4.01
  • blockstackStacks (STX) $ 0.224291
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998223
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • venice-tokenVenice Token (VVV) $ 8.87
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • sei-networkSei (SEI) $ 0.059508
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000069
  • cocaCOCA (COCA) $ 1.30
  • usxUSX (USX) $ 0.999420
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.362935
  • zebec-networkZebec Network (ZBCN) $ 0.003679
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • injective-protocolInjective (INJ) $ 3.59
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • kinesis-goldKinesis Gold (KAU) $ 149.30
  • layerzeroLayerZero (ZRO) $ 1.41
  • ether-fiEther.fi (ETHFI) $ 0.426185
  • sun-tokenSun Token (SUN) $ 0.018226
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • monadMonad (MON) $ 0.029271
  • spx6900SPX6900 (SPX) $ 0.370412
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • curve-dao-tokenCurve DAO (CRV) $ 0.227481
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • lido-daoLido DAO (LDO) $ 0.393897
  • decredDecred (DCR) $ 19.06
  • gnosisGnosis (GNO) $ 123.76
  • hastra-primePRIME (PRIME) $ 1.03
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • celestiaCelestia (TIA) $ 0.355039
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • bittorrentBitTorrent (BTT) $ 0.00000032
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apenftAINFT (NFT) $ 0.00000031
  • flokiFLOKI (FLOKI) $ 0.000032
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bitcoin-svBitcoin SV (BSV) $ 15.43
  • conflux-tokenConflux (CFX) $ 0.059235
  • olympusOlympus (OHM) $ 19.26
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • doublezeroDoubleZero (2Z) $ 0.085517
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • jasmycoinJasmyCoin (JASMY) $ 0.005948
  • syrupMaple Finance (SYRUP) $ 0.246637
  • usdaiUSDai (USDAI) $ 0.999740
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • crvusdcrvUSD (CRVUSD) $ 1.00

Read this before you click on any Robinhood email

0 0


Robinhood customers received some particularly convincing phishing emails this weekend. The messages, which appeared to come directly from the company, featured authenticated headers, were correctly signed, included a genuine sender’s address, were sent from an authentic email server, and weren’t caught by spam filters.

Worse, the email from [email protected] even earned Gmail’s automatic route into the same conversation threads as legitimate, prior security alerts from Robinhood.

The only fraudulent things about the email were obscure technical irregularities and its contents, a phishing call-to-action seeking login information.

By Sunday night, hackers used Robinhood’s own notification pipeline to render their assault.

Analysis of the exploit went viral on social media soon after.

Robinhood phishing emails were ‘kinda beautiful’

Security researcher Abdel Sabbah posted an analysis of the event, calling it “kinda beautiful” with a sinister connotation. Unfortunately, he was right.

To craft the attack, the hacker first utilized a Gmail “dot trick,” a well-known Google feature whereby Gmail routes [email protected], [email protected], and [email protected] to the same inbox.

Gmail, unlike the rest of the internet, ignores dots in the part of the address before the @ symbol, so all of those variants deliver to the same inbox.

Because Robinhood, unlike Gmail, doesn’t normalize the dotted variants, an attacker used a “dot” modified version of Robinhood’s legitimate customer emails.

Next, the attacker set the device name on the new account to a block of raw HTML. When Robinhood’s “unrecognized activity” email is generated, the template inserts that device name without sanitizing it, rendering the nefarious HTML.

The result, in Sabbah’s words, is what appeared to be “a real email from [email protected], DKIM pass, SPF pass, DMARC pass, with a phishing CTA.”

That CTA or “call to action,” of course, is a fake security alert email with a hyperlink to an attacker-controlled webpage that harvests login credentials and two-factor authentication codes.

The ultimate goal, like almost all phishing campaigns, was to steal customer’s money — in this case, from their Robinhood account.

These AI chatbots are happy to help you run a crypto scam

Think before you click on any email

Many crypto influencers warned people about the convincing emails.

Ripple’s David Schwartz amplified the warning. “Any emails you get that appear to be from Robinhood (and may actually be from their email system) are phishing attempts,” he posted. Quoting Sabbah’s thread, Schwartz added, “It’s quite sneaky.”

Stay safe out there, everyone 🥺

— Laura Shin (@laurashin) April 27, 2026

In April 2025, Ethereum Name Service Lead Developer Nick Johnson documented an almost identical exploit involving emails that appeared to send from Google itself.

Attackers used a similar series of tricks to use Google’s own infrastructure to deliver DKIM-signed phishing emails from [email protected].

The lesson then is the lesson now: beware of clicking any link in any email, no matter how authentic it appears.

Traditional anti-phishing advice tells users to check the sender domain and look for authentication failures. None of that helped here. The domain appeared real. The signatures appeared real. Only the intent was criminal.

Robinhood’s own scam guidance tells customers to verify the sender’s email domain and lists @robinhood.com as the authentic example.

Protos reached out to Robinhood for comment but didn’t receive a reply prior to publication time. In Nasdaq trading today, the common stock of Robinhood opened flat for trading relative to Friday’s closing print.



Source link

Leave A Reply

Your email address will not be published.