MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Scam Alerts / Crypto Trader Frogman Loses $4M in Wallet Drain Hours Before TOKEN2049
Scam Alerts

Crypto Trader Frogman Loses $4M in Wallet Drain Hours Before TOKEN2049

By MABOnChain Desk · Published · Updated · 4 min read

Editorial digital-art illustration of a giant glowing smartphone wallet cracking open at night, streams of luminous crypto tokens pouring into a digital river flowing through privacy-mixer gears and a cross-chain bridge, Singapore Marina Bay skyline glowing behind and a shadowy hooded silhouette watching the drain

Published October 7, 2026, 23:45 UTC. Based on on-chain analysis by EmberCN and Lookonchain, Frogman's public confirmation, and reporting by The Crypto Times.

Two of crypto trader Frogman's wallets were drained for more than $4 million while he slept in a Singapore hotel room, hours before TOKEN2049 opened its doors in the city on October 7, 2026. The attacker pulled nine tokens out of the wallets, converted them into major cryptocurrencies, and routed the proceeds through privacy and cross-chain services, according to on-chain analysts who spotted the theft before Frogman himself confirmed it.

The drain happened at about 4:30 a.m. Singapore time on October 7, which is roughly 20:30 UTC on October 6, a few hours before the conference began, according to The Crypto Times. Frogman, who posts on X as @frogmanhaha, said in a post at 05:21 UTC on October 7 that he had been drained of more than $4 million at 4:30 a.m. while asleep. He said he was in Singapore, had met many new people during his visit, and would share more details once his investigation allowed, The Crypto Times reported.

The 4:30 a.m. drain

The theft was flagged on-chain before the victim spoke publicly. EmberCN, the on-chain analyst also known as Yu Jin, posted at 01:59 UTC on October 7 that Frogman's wallets appeared to have been hit about five hours earlier. EmberCN estimated the loss at about $4 million across nine assets and said the tokens were sold for Ether, BNB and SOL, then dispersed through Privacy Cash and Chainflip, according to The Crypto Times and TradingView's aggregation of the report.

Lookonchain corroborated the incident in a post at 06:24 UTC on October 7, reporting that two of Frogman's wallets had been hacked for about $4 million. In a follow-up note published later the same morning, Lookonchain restated the theft as covering nine tokens and linked the Ethereum address 0x14A..794 to the incident.

The $3.8 million trio

Three obscure tokens accounted for nearly the entire loss. Lookonchain listed the three largest holdings taken: 1.43 million BP, worth about $1.77 million; 13.96 million MarsCoin, worth about $1.55 million; and 3.7 million Cash Cat, worth about $510,000. Together the three tokens represent roughly $3.8 million of the reported loss, with six smaller positions making up the remainder, according to the two on-chain reports.

The attacker did not hold the stolen tokens. According to both EmberCN and Lookonchain, the proceeds were swapped for ETH, BNB and SOL, converting the scattered portfolio into the three most liquid cryptocurrencies before moving them.

Privacy Cash and Chainflip: the laundering route

The money then crossed privacy infrastructure. EmberCN reported that the proceeds were dispersed through Privacy Cash, a privacy protocol used to obscure transaction trails, and Chainflip, a cross-chain swap protocol that moves assets between different blockchains, according to TradingView's aggregation, which cited ChainCatcher's account of the flow. Lookonchain separately reported that the attacker laundered the funds.

The route matters because it is becoming the standard exit for multi-chain thefts. Privacy Cash mixes the trail on one chain while Chainflip carries the value across chains, forcing investigators to track both hops at once.

Seed phrase or device: the leading theory

The attacker is not known to have used any contract exploit. Because the losses spanned multiple blockchains rather than a single token approval, analysts suggested the attacker compromised the trader's seed phrase or his device, The Crypto Times reported. Frogman himself said he did not yet know how the attacker gained access.

The theft underscores a pattern that keeps repeating at major crypto conferences: traders travel with valuable hot wallets, meet dozens of new people, and connect devices to unfamiliar networks. TOKEN2049 Singapore ran on October 7 and 8, 2026, and drew thousands of investors, developers and market participants to the city, according to The Bit Gazette. This incident is a reminder that in-person exposure may be the weakest link in a trader's setup.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading

Regulation

Jury Finds Uranium Finance Hacker Guilty in $55 Million DeFi Theft

October 7, 2026 · 4 min read

A Manhattan federal jury convicted Maryland cybersecurity consultant Jonathan Spalletta of stealing nearly $55 million from the Uranium Finance exchange in April 2021, Bloomberg reported. He faces up to 20 years on the money-laundering count, with sentencing set for February 16, 2027.