Ripple CTO Flags Sophisticated Robinhood Email Scam

In spite of looking authentic, Robinhood’s prompts to review recent login activity might be rogue.

Robin Hood with a digital face made out of crypto logos staring at the camera in a digital dark green forest.

Ripple’s Chief Technology Officer (CTO) is warning his audience on X about a new, sophisticated scam that’s specifically targeting Robinhood’s customers. In a shared screenshot, Ripple’s David ‘JoelKatz’ Schwartz has drawn the public’s eye to a recent Robinhood login notification, which appears to be fake.

Crucial Robinhood Customer Alert: Emails Infected?

“Any emails you get that appear to be from Robinhood (and may actually be from their email system) are phishing attempts.”, – stated the veteran developer. Some users on Crypto Twitter have advised to look for the blue check mark to identify legit correspondence, but the issue seems to go deeper than that.

▸ Live tracker
Follow every XRP institutional move in real time
Bank pilots, ETF flows, ODL volume & more — all in one place.
Open XRP Live Hub →

The emails appear to be seemingly legitimate. The messages appear to be genuine to most recipients, as the fraudulent emails successfully pass through the SPF, DKIM, and DMARC checkpoints. The screenshot also hints at made-up ‘recent login’ details, attempting to lure in the unsuspecting Robinhood customer.

Ripple CTO Deciphers Robinhood’s Email Incident

It shows the claimed login device, location details & more. Moreover, Ripple’s CTO David Schwartz claims the hackers were able to infect Robinhood’s automated email system from within. Labelling the Robinhood email ‘quite sneaky’, JoelKatz. This is known as the ‘dot trick’, where multiple variations of the same address is wrongfully perceived as legitimate.

The hackers probably assigned a malicious HTML code to a device, allowing the HTML payload to render within Robinhood’s email system. This creates multiple authenticated email messages with malicious intent, deceiving the crypto exchange’s customers into thinking they’re pressing on an official Robinhood link.

Despite rising sharply in 2026, phishing scams are nothing new. A similar attack was deployed on MetaMask’s users at the beginning of the year – stealing seed phrases all around the place. With centralized platforms, the retrieval of stolen access is considerably easier, while DeFi dwellers have multiple security layers that serve as stronger preventative measures.

Check out DailyCoin’s hottest crypto scoops today:
Deepfake Call Tricks Cardano Dev, Exposes New Weak Spot
CLARITY Act Hits A Big Delay As Lobbying Fight Escalates

People Also Ask:

What exactly is the Robinhood email scam David Schwartz warned about?

Scammers are sending highly realistic phishing emails that appear to come directly from Robinhood’s own email system (like noreply@robinhood.com). These messages pass authentication checks and look completely legitimate, often claiming unusual account activity and urging you to click “Review Activity Now.”

Did Robinhood comment on the ongoing scam?

Yes — Robinhood has acknowledged fraudulent emails sent from their domain and advised users to ignore them and secure their accounts.

How can I protect my Robinhood account moving forward?

Enable two-factor authentication (2FA), use a strong unique password, avoid clicking links in emails, and always access your account directly rather than through email links. Consider app-based 2FA over SMS.

DailyCoin's Vibe Check: Which way are you leaning towards after reading this article?
Market Sentiment
100% Bearish

This article is for information purposes only and should not be considered trading or investment advice. Nothing herein shall be construed as financial, legal, or tax advice. Trading forex, cryptocurrencies, and CFDs pose a considerable risk of loss.

Author
Tadas Klimasevskis

Tadas Klimaševskis is a DailyCoin Journalist, covering memecoins & latest developments. Tadas has moderate holdings in SHIB, HBAR, LTC, MATIC and a selection of low-cap meme currencies.

Read more

Subscribe here