Go to app

The Exploit Mechanism

Published 7/13/2026, 6:33:52 AM

On July 13, 2026, hackers compromised the official @SpaceXAI and @Starlink X (formerly Twitter) accounts to orchestrate a "rug pull" exploit involving a fake memecoin named SCATMAN. By leveraging the high trust of these verified accounts to promote the token, the attackers inflated its market capitalization to $2 million before dumping their supply for a total profit of approximately $125,000 (73.7 ETH) [Source: https://x.com/CryptoPatel/status/2076539368018239924, https://x.com/cryptoamanclub/status/2076520039763923365].

The Exploit Mechanism

The attackers utilized a social engineering and "pump and dump" strategy:

  1. Account Hijacking: The official SpaceX and Starlink accounts were breached and used to repost and promote SCATMAN, a token parodying OpenAI CEO Sam Altman [Source: https://beincrypto.com/spacex-starlink-scatman-rug-pull-hack/].
  2. Pre-minting: Before the promotion began, the attacker minted 10 trillion SCATMAN tokens [Source: https://x.com/cryptothedoggy/status/2076533342430970130].
  3. The Pump: Perceived endorsement from Elon Musk-linked accounts caused the token's market cap to surge to $2 million within an hour [Source: https://x.com/cryptoamanclub/status/2076520039763923365].
  4. The Dump: Once the price peaked, the hackers liquidated their holdings across two primary wallets, causing the token price to crash by over 98% [Source: https://x.com/CryptoPatel/status/2076539368018239924].

Financial Breakdown of Hacker Profits

The hackers consolidated their gains into Ethereum (ETH) across two main transactions:

Wallet / ActionTokens SoldCurrency ReceivedUSD Value (Approx.)
Wallet 110 Trillion SCATMAN59 ETH$108,000
Wallet 259.28 Million SCATMAN14.7 ETH$27,000
Total Profit—73.7 ETH$125,000

[Source: https://x.com/cryptothedoggy/status/2076533342430970130, https://x.com/CryptoPatel/status/2076539368018239924]

Technical Details and Risks

While the social engineering aspect is well-documented, technical verification of the smart contract remains incomplete. The token was reportedly launched on the Robinhood Chain, though this has not been independently confirmed [Note: not independently confirmed].

The primary hacker wallet addresses identified in the exploit are:

  • 0xfee50d4ce48f2d05f520ce04c875647e4870a8ba
  • 0xdd9f6d3e16ebda7f35cb694ceadb50af3eebba89

[Source: https://x.com/CryptoPatel/status/2076539368018239924]

The SCATMAN token (contract: 0x6feefb56bf77c4348dae5aba3225a2143361cccc) is considered highly dangerous, as the liquidity was pulled immediately following the dump, leaving most retail investors with near-total losses.