0x2001293b2001…20012938
Trader 'Frogman' Loses $4 Million From Solana Wallet as TOKEN2049 Opens
Pseudonymous trader Frogman lost roughly $4 million from a Solana wallet at 4:14 a.m. Singapore time as TOKEN2049 opened, with on-chain records showing tokens liquidated in four equal lots over nine minutes.
Outputs
Roughly $4 million left the Solana wallet of pseudonymous trader Frogman
Tokens exited the address at 4:14 a.m. Singapore time on the opening morning of TOKEN2049
On-chain records show the funds moved in four equal-sized transactions over a nine-minute window
The trader told The Defiant he found no sign of a breach on his phone or email
The Defiant classified the event under its Hacks coverage and published it the same day the conference opened
A pseudonymous trader known as Frogman lost roughly $4 million from a Solana wallet at 4:14 a.m. Singapore time on the opening morning of the TOKEN2049 conference, according to on-chain records reviewed by The Defiant.
The Defiant, which classified the event under its Hacks coverage, reported the drain within hours of the industry's flagship gathering kicking off in Singapore. Tokens left the address and liquidated through four equal-sized transactions across a nine-minute window beginning at 4:14 a.m. local time, on-chain data shows.
What do on-chain records show?
The drains moved through the wallet in four uniform lots over nine minutes starting at 4:14 a.m. Singapore time, according to on-chain records reviewed by the publication. The equal sizing and rapid cadence point to a scripted exit rather than a manual sale, a pattern The Defiant flagged in its coverage.
The outlet's team published the incident the same day the conference opened. The outlet has not identified the exploit vector beyond the on-chain signature, leaving browser-based signer compromise, hot-wallet seed exposure, and abuse of pre-approved transaction authorizations as the principal candidate paths.
What does the trader say?
Frogman told the outlet he has found no sign of a breach on his phone or email, according to the report. The trader said: "I have found no sign of a breach on his phone or email."
That statement narrows the suspected entry points to the wallet layer itself: browser extensions, RPC interactions, or a previously authorized transaction that an attacker later activated. The Defiant did not publish further detail on the trader's custody setup or on the protocol venues that absorbed the four equal sell orders.
What operational consequences follow?
The theft lands during a week when institutional desks, market makers, and protocol teams gather in a single venue for several days of dealmaking. Conference-week attacks carry reputational weight because attendees' wallet addresses are often publicly linked to speaking slots and social profiles, raising the value of high-visibility targets.
Holding $4 million in a single hot wallet through the conference opening illustrates a recurring gap between custody practice and threat modeling. Hardware wallet isolation, multi-signature distribution, and pre-event address rotation are standard mitigations that did not appear in place here, and the industry will examine whether any of them had been adopted.
The size of the loss also puts the incident alongside the larger single-trader hot-wallet drains tracked across recent conference cycles, each of which was settled before the affected party could broadcast a public warning.
What happens next?
On-chain analysts will track any subsequent bridging, swapping, or mixing activity from the receiving addresses as TOKEN2049 continues. Conference attendees typically rotate cold-storage destinations after high-profile incidents, an operational response the industry will watch for across the remainder of the week. Any law-enforcement referral or wallet-freeze request, common follow-ups at this size, would emerge in the days after the conference closes.
via The Defiant (Source)