The Exploit Mechanism
Published 7/13/2026, 6:33:52 AM
On July 13, 2026, hackers compromised the official @SpaceXAI and @Starlink X (formerly Twitter) accounts to orchestrate a "rug pull" exploit involving a fake memecoin named SCATMAN. By leveraging the high trust of these verified accounts to promote the token, the attackers inflated its market capitalization to $2 million before dumping their supply for a total profit of approximately $125,000 (73.7 ETH) [Source: https://x.com/CryptoPatel/status/2076539368018239924, https://x.com/cryptoamanclub/status/2076520039763923365].
The Exploit Mechanism
The attackers utilized a social engineering and "pump and dump" strategy:
- Account Hijacking: The official SpaceX and Starlink accounts were breached and used to repost and promote SCATMAN, a token parodying OpenAI CEO Sam Altman [Source: https://beincrypto.com/spacex-starlink-scatman-rug-pull-hack/].
- Pre-minting: Before the promotion began, the attacker minted 10 trillion SCATMAN tokens [Source: https://x.com/cryptothedoggy/status/2076533342430970130].
- The Pump: Perceived endorsement from Elon Musk-linked accounts caused the token's market cap to surge to $2 million within an hour [Source: https://x.com/cryptoamanclub/status/2076520039763923365].
- The Dump: Once the price peaked, the hackers liquidated their holdings across two primary wallets, causing the token price to crash by over 98% [Source: https://x.com/CryptoPatel/status/2076539368018239924].
Financial Breakdown of Hacker Profits
The hackers consolidated their gains into Ethereum (ETH) across two main transactions:
| Wallet / Action | Tokens Sold | Currency Received | USD Value (Approx.) |
|---|---|---|---|
| Wallet 1 | 10 Trillion SCATMAN | 59 ETH | $108,000 |
| Wallet 2 | 59.28 Million SCATMAN | 14.7 ETH | $27,000 |
| Total Profit | — | 73.7 ETH | $125,000 |
[Source: https://x.com/cryptothedoggy/status/2076533342430970130, https://x.com/CryptoPatel/status/2076539368018239924]
Technical Details and Risks
While the social engineering aspect is well-documented, technical verification of the smart contract remains incomplete. The token was reportedly launched on the Robinhood Chain, though this has not been independently confirmed [Note: not independently confirmed].
The primary hacker wallet addresses identified in the exploit are:
0xfee50d4ce48f2d05f520ce04c875647e4870a8ba0xdd9f6d3e16ebda7f35cb694ceadb50af3eebba89
[Source: https://x.com/CryptoPatel/status/2076539368018239924]
The SCATMAN token (contract: 0x6feefb56bf77c4348dae5aba3225a2143361cccc) is considered highly dangerous, as the liquidity was pulled immediately following the dump, leaving most retail investors with near-total losses.