Skip to content

Invest1 publisherNot yet confirmed elsewhere3 min readPublished

Attacker sells Frogman's $4 million of drained Solana tokens in nine minutes

Crypto trader Frogman lost about $4 million when his Solana wallets were drained at 4:14 a.m. as TOKEN2049 opened in Singapore. The attacker finished selling within nine minutes, hours before anyone noticed, and the route to his keys is still unknown.

The Investor · Invest desk

How we use AISend a correction

What happened

  • According to Frogman, he has not turned up any sign that his phone or email was breached.
  • The attacker swapped the tokens into ETH, BNB and SOL, then moved the money through Privacy Cash and Chainflip.
  • Onchain analyst EmberCN flagged the transactions about five hours before Frogman confirmed the theft on X.
  • Crypto hack losses reached $1.2 billion in the third quarter, up 53% from the second, according to Cryptopolitan.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • constraint Protection for a position this size has to work before a key is used, because this attacker finished selling about nine minutes in, while the owner slept.
  • decision Large holders weighing whether conference travel needs its own security plan cannot settle it from this case yet, since nothing has turned up on Frogman's phone or email.
  • exposure Individuals with large positions are drawing more attackers in their own right: Europe logged about 2.8 times 2025's full-year count of private-holder incidents in six months.

The sales went through in four equal lots, and they were done by about 4:23 a.m. Singapore time [1][20]. EmberCN's flag came roughly four hours after the drain [22]. Frogman's own post came about nine hours after it [21]. "Was drained for $4m+ USD this morning at 4:30am while I was asleep," Frogman wrote on X [6]. His estimate was 16 minutes off the onchain timestamp [8].

The $4 million is what the positions were worth before the sale [3], and two tokens carried most of it. BP and MARSCOIN together come to $3.32 million, about 83% of the total [23]. CASHCAT was third at about $515,000 [11]. That leaves roughly $165,000 across the six smaller holdings, if the total is $4 million [24]. Unloading two concentrated positions inside nine minutes means taking whatever bids exist at four in the morning. So the attacker's proceeds and Frogman's loss are probably different numbers, and Cryptopolitan reported only the loss.

The laundering matched what Cryptopolitan described for September, when stolen funds were moved within hours and mixed within days through DEX swaps, the Tornado Cash mixer and no-KYC exchanges [13]. I think clearing nine tokens in four equal lots inside nine minutes points to a prepared script [1][3].

How the attacker got in is still open. Frogman said he was "not sure how it happened yet" and that he had met "a lot of new people" in Singapore [7]. This can resolve three ways. The compromise could sit on a device or account he has not checked yet. His keys could have been exposed before he travelled, in which case the conference timing is coincidence. Or someone at TOKEN2049, a sold-out event with 25,000 attendees from 160 countries [5], could have been the way in. The evidence so far fits all three. In September the largest losses came from compromised wallet keys [14], and more than 11% of the third quarter's 247 incidents, so more than 27, were phishing [17][27].

By size, Frogman's loss is a fairly ordinary incident. The quarter's 247 incidents averaged about $4.9 million each [25]. Bitget's $387.5 million hack pulls that mean up, and on its own it was about 32% of the quarter's losses [15][26].

In my view, timing is the part large holders can act on now. The owner was asleep and the first public flag was about four hours away [22]. An alarm would mostly have meant hearing the bad news sooner. Whether the conference itself matters depends on the investigation. Frogman thanked "the teams and individuals who are helping with the investigation" and said he would share more when he could [19]. If it traces the access to someone or something in Singapore, holders who travel to these events have a specific risk to plan for. If it finds the keys were exposed weeks earlier, TOKEN2049 was only where he happened to be.

What to watch

  • Frogman's promised account of how his keys were reached, and whether it traces to someone or something in Singapore or to an earlier exposure.
  • Whether any of the proceeds routed through Privacy Cash and Chainflip are traced to an exchange or frozen.
  • Reports of similar drains from other TOKEN2049 attendees; a second case would make a conference-linked route more likely than coincidence.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories