Frogman Reports $4M Loss as Wallets Drain Across Three Chains

Semi-realistic scene of unauthorized signing draining $4M memecoins across EVM and Solana wallets.

Crypto trader Frogman reported losing more than $4 million in a wallet drain while attending TOKEN2049 in Singapore, with an on-chain reconstruction tracing assets across Solana, Base and BNB Chain. The three wallets examined by Trenchbook were emptied within a 69-second window, pointing to coordinated control across multiple networks rather than an isolated token or protocol failure. Frogman has not publicly identified the affected wallet addresses or explained how access was obtained.

According to Trenchbook’s investigation, the addresses were initially attributed to Frogman by on-chain researcher EmberCN. Frogman separately confirmed publicly that he had lost more than $4 million while asleep on October 7, but said he did not yet know how it happened. The wallet attribution therefore comes from third-party on-chain analysis, while the loss itself has been acknowledged by the trader.

Three Chains Were Emptied Within 69 Seconds

The sequence began at 4:14:54 a.m. Singapore time, when the Solana wallet sent approximately 1.43 million BP, 7,860 USDC and additional tokens to a newly active address. Fifteen seconds later, the EVM wallet began moving BLUE CHIP and Basecat on Base, before transferring roughly 13.96 million MarsCoin and 91.6 tokenized SpaceX units on BNB Chain. The initial movements across all three networks were completed between 4:14:54 and 4:16:03 a.m.

Trenchbook found that the transfers were authorized by the affected wallets themselves rather than being pulled through an identified token allowance. A separate address also supplied gas to the EVM wallet shortly before the Base transfers and later funded the receiving address on Ethereum. That pattern is consistent with unauthorized control of the signing layer, but it does not establish whether the underlying cause was stolen keys, compromised account access, malware, a device breach or another mechanism.

The cross-chain timing makes the security boundary particularly important. An exploit confined to a specific smart contract or token approval would ordinarily operate within the permissions available to that contract on the relevant network. Here, coordinated transfers occurred from accounts spanning unrelated chains. The evidence therefore points away from a vulnerability in BP, MarsCoin or another individual token and toward a shared wallet or signing-control problem. No forensic post-mortem has yet identified that shared point of failure.

That distinction separates the incident from conventional contract exploits such as the Truebit legacy-contract vulnerability, where the vulnerable component could be identified directly. It is closer at the security-boundary level to incidents where trusted wallet infrastructure becomes compromised, including the Trust Wallet malicious browser-extension update. Valid blockchain transactions do not by themselves establish that the legitimate owner intended to authorize them.

Privacy Cash Trail Extends to 32 New Wallets

After receiving the stolen Solana assets, the destination wallet sold the 1.43 million BP for approximately 13,053.6 SOL and liquidated the remaining holdings. It subsequently deposited 13,240.97 SOL, worth roughly $1.6 million at the time, into Privacy Cash through 10 transactions. The deposits occurred between 4:36 and 5:00 p.m. ET on October 6, less than an hour after the initial drain.

Trenchbook later reconstructed activity on the other side of the privacy pool. It identified 36 withdrawals totaling approximately 13,240 SOL into 32 addresses whose first transaction was the Privacy Cash withdrawal. The amounts and timing closely tracked the preceding deposits, with some withdrawals occurring less than a minute afterward. The correlation allows the public trail to continue further than initially thought, although it cannot cryptographically prove that the same actor controlled both sides of each privacy transaction.

The case arrives alongside other incidents showing that wallet security can fail above the smart-contract layer. SlowMist recently traced a Fomo phishing campaign that stole authenticated browser-session credentials, while previous fake video-call attacks targeted wallet approvals and access credentials. Those attacks demonstrate possible security boundaries, but none currently provides evidence explaining how Frogman’s wallets were compromised.

No recovery, freeze or return of Frogman’s reported losses has been publicly confirmed. The strongest conclusion remains deliberately narrow: someone appears to have obtained sufficient authority to move assets from wallets spanning Solana and EVM networks almost simultaneously, but how that authority was acquired remains unresolved. Until Frogman or investigators publish additional forensic evidence, attributing the incident to phishing, malware, seed exposure, physical access or any specific application would go beyond what the on-chain record establishes.

Find Us on Socials

Join Our
Newsletter

Subscribe to get latest crypto news!

Latest News

You may also like

The Chain Observer
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.