A token went from $2M market cap to zero in twelve minutes.
The order book didn't lie. Someone bought the top. Then it vanished.
The trigger wasn't a smart contract exploit. No flash loan attack. No oracle manipulation. Just a hijacked account on X (formerly Twitter) — SpaceX's official handle — shilling a ticker called SCATMAN.
Crude. Effective. Predictable.
Context: The Playbook Is Public
This wasn't a one-off. It's a pattern. The attacker compromised SpaceX and Starlink accounts, posted a single tweet claiming a partnership with the space company, and linked to a freshly minted token on a decentralized exchange. Within seconds, the token's market cap hit $2 million. Then the attacker sold every last token — 10 trillion of them — into the liquidity pool, collecting $135,000.
By the time the tweet was deleted, the token was dead. Retail traders who bought the top held bags of dust.
Lookonchain tracked the wallet. GeckoTerminal recorded the chart. The data is public. The script is repeatable.
This is not a hack. It's a systematic extraction of attention value, monetized through the worst asset class in crypto: the low-liquidity meme coin.
Scroll. Pepe. WinRAR. Roaring Kitty. The same pattern has hit multiple high-profile accounts over the past year. Each time, the victim is a verified account. Each time, the token is launched moments before the tweet. Each time, retail jumps in first, then gets dumped on.
The median profit per event: somewhere between $50K and $200K. For the attacker, it's a low-risk operation. For the buyer, it's a guaranteed loss.
Core: The Order Flow Mechanics of a Social Media Rug Pull
Let's break down the execution. The attacker used a standard ERC-20 token with 18 decimals, total supply of 10 trillion. No freeze functions. No blacklist. No liquidity lock. Pure, unfiltered supply.
The token was deployed on a DEX — likely Uniswap V2 or a fork — with a small initial liquidity pool. According to the on-chain data, the attacker provided liquidity in a single-sided manner, then used the other side of the pool to sell into the buy pressure generated by the tweet.
Key metric: the attacker sold 100% of the supply within a single block or a few blocks. That's not a gradual exit. That's a market order for the entire float. The slippage was extreme — the price went from near-zero to $0.00000002 per token at peak market cap, then crashed to $0.000000001 within two blocks.
In options terms, this is a gamma squeeze in reverse. The buying pressure from retail acted as the catalyst for a massive delta imbalance. The attacker held all the gamma — the directional exposure — and exercised it the moment liquidity was available.
The withdrawal was not subtle. The wallet dumped into the pool, draining the base currency (likely ETH or a stablecoin). The final balance: $135,000 in proceeds.
Code is law, but math is the judge. The math here is simple: total supply sold, minus fees, equals net profit. No alpha. No edge. Just timing and a weaponized attention vector.
What I find revealing is the efficiency. The attacker didn't waste time building a narrative. They didn't post multiple tweets. They didn't schedule a reveal. One post. One pool. One dump. The entire lifecycle of this token was shorter than my lunch break.
Contrarian: The Real Victim Is Trust, Not the Token
The conventional takeaway is: "Don't buy meme coins from hijacked accounts." True, but insufficient.
The deeper point is that the $135,000 stolen is a tiny fraction of the systemic damage done. Every time a verified account gets hijacked to shill a scam token, the value of a blue check mark on X decreases. The platform's authentication system — which was supposed to signal legitimacy — becomes a liability. Social media platforms are now the largest attack surface in crypto, and their security models are not designed for real-time financial extraction.
Volatility is price. Trust is alpha. But trust cannot be quantified on a balance sheet. Spread the damage across 10 such events, and you corrode the informational foundation of the entire market. Retail traders become paranoid of any new token from any account, even legitimate ones. The signal-to-noise ratio plummets.
Second contrarian point: This attack model is a feature, not a bug, of the current meme coin ecosystem. Meme coins derive their entire value from narrative velocity. The fastest way to generate velocity is to borrow (steal) a trusted voice. The ecosystem incentivizes this extraction. Every project that launches with a fake influencer endorsement is a soft version of the same playbook.
Third: The attacker's identity is almost certainly safe. $135,000 is below the threshold for serious FBI or SEC attention, especially when the trail leads to an anonymous wallet and a burner phone. The compliance burden falls on the victims. KYC is theater, as always. Buying a few wallet holdings bypasses it — compliance costs are passed entirely to honest users.
Takeaway: Predicting the Next Hijack
You cannot prevent this pattern. You can only position yourself to avoid being the exit liquidity.
Watch for three signals: 1. A verified account that normally doesn't post about crypto suddenly shilling a token. 2. The token contract is less than 5 minutes old at the time of the post. 3. The liquidity pool has extremely low depth — typical for a fresh deploy.
If all three align, the probability of a rug pull exceeds 95%. Do not trade. Do not FOMO. Let the attacker collect their $135K and move on.
The only winning move is to not play.
Gamma exposure is the hidden cliff. Next time, it might be a different account — maybe a celebrity, maybe a protocol, maybe your own exchange. The script is already written.
Question is: will you be the one reading it, or the one buying the top?