NewsCryptoCrypto trader Frogman loses $4 million in Solana wallet drain on TOKEN2049's opening morning

Crypto trader Frogman loses $4 million in Solana wallet drain on TOKEN2049's opening morning

Author: Cryptopolitan·

Key Takeaways

  • •Attackers drained about $4 million from two of Frogman's Solana wallets at 4:14.m. Singapore time on Tuesday, with onchain data showing the tokens sold in four equal lots across nine minutes.
  • •The stolen holdings covered nine tokens, led by 1.43 million BP worth roughly $1.77 million, followed by 13.96 million MARSCOIN valued around $1.55 million and about 3.7 million CASHCAT worth approximately $515,000.
  • •Frogman stated he has found no evidence of a breach on his phone or email, and how the attacker obtained access to his wallets is still unanswered.
  • •The attacker converted the tokens into ETH, BNB and SOL and moved them through Privacy Cash and Chainflip, services that hinder tracing, while the self-custodied nature of the wallets leaves no operator able to freeze the funds.
  • •Third-quarter crypto losses reached $1.2 billion, a 53% rise from the second quarter, and incidents targeting private holders in Europe climbed to 39 in the first half of 2026 from 14 across all of 2025.
Crypto trader Frogman loses $4 million in Solana wallet drain on TOKEN2049's opening morning

Crypto trader Frogman has lost roughly $4 million after attackers drained tokens from his Solana wallet and sold them in four equal lots within a span of nine minutes, according to onchain data. The trader said he has found no evidence of a breach on his phone or email.

The drain hit at 4:14 a.m. as TOKEN2049 opened in Singapore

The tokens left the wallet at 4:14 a.m. Singapore time, or 20:14 UTC on Tuesday, just as TOKEN2049 opened that morning. Frogman was in Singapore for the conference, which runs October 7 and 8 at the Marina Bay Sands. The event sold out and drew 25,000 attendees from 160 countries.

“Was drained for $4m+ USD this morning at 4:30am while I was asleep,” Frogman wrote in a post on X at 1:21 p.m. local time. He said he was “not sure how it happened yet” and noted that he had met “a lot of new people” in Singapore.

His 4:30 a.m. estimate is 16 minutes off the onchain timestamp. He thanked “the teams and individuals who are helping with the investigation” and said he would share more information when he could. How the attacker obtained access remains the central unanswered question in the case.

Two of his wallets were hit, with combined losses of about $4 million. Onchain analyst EmberCN, also known as Yu Jin, flagged the transactions roughly five hours before Frogman confirmed the theft.

BP made up $1.77 million of the haul

The stolen holdings spanned nine tokens. The largest position was 1.43 million BP worth approximately $1.77 million, followed by 13.96 million MARSCOIN worth about $1.55 million. The third largest holding, roughly 3.7 million CASHCAT, was valued at about $515,000. Six smaller positions made up the remainder.

The attacker converted the tokens into ETH, BNB and SOL. The funds then passed through Privacy Cash and Chainflip, two services that make money harder to trace from wallet to wallet. For a self-custodied wallet there is no backstop at that stage: blockchain transfers cannot be reversed, and no operator sits in a position to freeze the attacker’s addresses once the funds arrive.

September’s hacks followed a similar pattern, as Cryptopolitan reported. Stolen funds were moved within hours and mixed over days through DEX swaps, the Tornado Cash mixer, and no-KYC exchanges. Some proceeds from September were also swapped into Monero and shielded Zcash.

The biggest losses came from compromised wallet keys, which gave hackers access to Bitget’s hot wallets. September was the worst month of 2026 so far, with hackers stealing $766.49 million. Bitget’s hack alone accounted for $387.5 million. The Liquid Network exploit reaped $320 million, although about $285 million was returned. That kind of partial clawback is a feature of exchange incidents: with an operator in control of the compromised system, funds can sometimes be recovered — an option that does not exist for a personal wallet like Frogman’s, where the drain is effectively final once the tokens move.

Losses for the third quarter reached $1.2 billion, a 53% increase from the second quarter. Incidents rose 12.8% quarter-on-quarter to 247, with more than 11% of them involving phishing.

In Europe, private crypto holders also faced increased targeting, with 39 incidents in the first half of 2026 compared with 14 for all of 2025. Frogman’s case sits on that individual side of the ledger — not an exchange breach, but a direct drain of a personal wallet, the type of attack where recovery depends on tracing funds through services like Privacy Cash and Chainflip.