0x217db190217d…217db193

ConfirmedSecurity477 vB178 sat/vB2 min decode

Crypto Trader Frogman Loses Over $4 Million in Wallet Hack During TOKEN2049

Trader Frogman confirmed losing roughly $4 million across two wallets during TOKEN2049, with stolen tokens converted to ETH, BNB and SOL via Chainflip and Privacy Cash.

Outputs

  1. Trader Frogman lost approximately $4 million across two wallets, confirmed October 7, 2026

  2. Analyst EmberCN (Yu Jin) flagged suspicious transactions five hours before public confirmation

  3. Losses included 1.43M BP tokens (~$1.77M) and 13.96M MarsCoin (~$1.55M)

  4. Stolen funds were converted into ETH, BNB and SOL via Chainflip and Privacy Cash

  5. Breach occurred while the trader attended TOKEN2049 in Singapore

Crypto trader Frogman confirmed on October 7, 2026 that attackers drained two of his wallets for approximately $4 million in digital assets while he attended the TOKEN2049 conference in Singapore.

On-chain analysts detected the breach before the victim did. EmberCN, an analyst also known as Yu Jin, flagged suspicious transactions roughly five hours before Frogman publicly confirmed the compromise on X, where he posts as @frogmanhaha. By that point, the attacker had already begun moving, selling and converting the stolen holdings, primarily into Ethereum (ETH), Binance Coin (BNB) and Solana (SOL).

How did the attacker launder the funds?

The stolen assets passed through privacy-focused services including Privacy Cash and Chainflip, according to on-chain tracking. These tools obscure the link between the originating wallet and the destination address, complicating recovery efforts and forensic attribution.

The conversion chain itself — niche tokens into liquid majors into privacy rails — followed a pattern consistent with prior high-value wallet compromises, where attackers prioritize converting illiquid holdings into assets that can be moved and cashed out quickly across multiple chains.

What was in the stolen portfolio?

The drained wallets held nine tokens. Three positions accounted for the bulk of the losses:

  • 1.43 million BP tokens, valued at approximately $1.77 million
  • 13.96 million MarsCoin, worth around $1.55 million
  • Roughly 3.7 million Cash Cat tokens, estimated at $510,000 to $515,000

The remaining six tokens made up the rest of the loss, with individual values below the top three positions.

The concentration of the portfolio in low-liquidity tokens matters operationally: positions of this size in thin markets are difficult to unwind without severe slippage, which may explain why the attacker prioritized rapid conversion into ETH, BNB and SOL rather than attempting direct disposal.

What has Frogman said?

Frogman said he does not know how the breach occurred. He thanked the people assisting with the investigation and said he would share further updates as they become available.

No immediate market impact was reported from the theft. Approximately $4 million is significant for a single trader but small relative to the liquidity depth of ETH, BNB and SOL, limiting any observable price effect.

Why does the timing matter?

Two operational takeaways stand out for traders and security teams. First, on-chain monitoring detected the exploit roughly five hours before the victim's public confirmation — a window during which assets were already being converted. Second, the breach occurred during TOKEN2049, a period when many industry participants travel and may be slower to respond to security alerts.

For victims of comparable incidents, the practical response playbook remains unchanged: contact exchanges and laundering-service counterparts such as Chainflip immediately, engage forensic trackers like EmberCN early, and file reports with relevant law enforcement before the privacy-layer hop completes. Recovery odds decline sharply once funds clear cross-chain swaps and mixers.

via Crypto Briefing (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles