Crypto trader Frogman has confirmed that roughly $4 million of digital assets were stolen from wallets linked to him, after on-chain investigators detected nine tokens being transferred, sold and converted into ETH, BNB and SOL before the proceeds were dispersed across multiple networks.
The largest losses included approximately 1.43 million BP tokens valued at about $1.77 million, 13.96 million MarsCoin worth roughly $1.55 million and 3.7 million Cash Cat valued at around $510,000 at the time of the transfers.
Those three positions alone account for about $3.83 million of the reported loss. Six additional tokens made up the remainder.
On-chain analyst EmberCN was among the first to flag the activity early October 7. Frogman subsequently confirmed that his assets had been stolen and said he did not yet know how the compromise occurred. He said he was in Singapore and that teams and individuals were assisting with the investigation.
No verified attack vector has yet been disclosed.
Two Frogman-Linked Wallets Were Reportedly Drained
The earliest reports described a wallet associated with Frogman as compromised, but subsequent tracking indicates that two addresses linked to the trader were affected.
Lookonchain’s analysis of the theft identified the roughly $4 million loss and listed BP, MarsCoin and Cash Cat as the three largest stolen holdings.
The attacker did not simply transfer the original tokens to another address and leave them untouched.
Instead, the assets were sold and consolidated into more liquid cryptocurrencies including ETH, BNB and SOL. The resulting funds were then dispersed using Privacy Cash and Chainflip.
That conversion pattern is significant because illiquid or recognizable tokens can be relatively easy for investigators to follow. Moving into highly liquid native assets and then shifting value across networks can make recovery and attribution substantially harder.
Chainflip itself is a cross-chain swap protocol rather than a privacy mixer. Its use in a suspicious transaction does not imply involvement by the protocol or its operators. For an attacker, however, cross-chain infrastructure can provide a way to move value from one blockchain to another without relying on a centralized exchange account that may be easier to freeze.
The Theft Appears to Have Started Around Midnight in Cairo
The chronology places the apparent compromise during the opening hours of October 7.
One of the first widely indexed reports carrying EmberCN’s findings appeared around 02:33 UTC, or approximately 05:33 in Cairo. The on-chain assessment at that point said the transfers had occurred about five hours earlier.
That would place the initial suspicious activity at approximately 21:30 UTC on October 6, or around 00:30 Cairo time on October 7.
The timing remains approximate because the “five hours ago” description was itself rounded. Exact blockchain transaction timestamps provide the more useful forensic record, while the publication time establishes when outside observers began identifying the transfers as suspicious.
The distinction matters in wallet investigations. A public alert can arrive hours after the first malicious signature, seed compromise or unauthorized transaction, especially when there is no centralized operator monitoring a personal wallet in real time.
Frogman’s Confirmation Changes the Story From Suspicion to Theft
The initial on-chain reporting was necessarily cautious.
A large wallet moving assets, selling tokens and bridging across chains can look suspicious without necessarily representing a hack. Crypto holders routinely rebalance portfolios, rotate assets or use cross-chain protocols themselves.
Frogman’s subsequent acknowledgement removes much of that ambiguity.
He confirmed that the assets were stolen while saying the mechanism remained unknown. That separates two questions that should not be conflated: whether the transfers were unauthorized and how the attacker obtained control.
The first is now supported by the wallet owner’s own statement. The second remains unresolved.
There has been no verified disclosure showing whether Frogman’s seed phrase or private key was exposed, whether he signed a malicious transaction, whether compromised software or a browser extension was involved, or whether another wallet-management failure enabled access.
Until forensic evidence identifies the cause, describing the event as a phishing attack, malware incident or private-key leak would go beyond the available evidence.
The Token Mix May Have Made Immediate Liquidation More Important
The composition of the stolen portfolio likely influenced the attacker’s next steps.
BP and MarsCoin represented close to $3.3 million of the reported value. Cash Cat contributed another roughly $510,000.
Smaller or less liquid tokens can expose an attacker to several risks if left untouched. Issuers or communities may identify the stolen wallet, exchanges may flag the assets, and market prices can collapse once traders notice a compromised holder is likely to sell.
Converting them quickly into ETH, BNB and SOL gives the attacker deeper liquidity and assets that can move through considerably broader infrastructure.
There is a cost to that strategy. Selling millions of dollars of smaller tokens can itself generate slippage and leave a highly visible trail.
That means the nominal $4 million value of the wallet immediately before the theft does not necessarily equal the amount ultimately realized by the attacker.
Actual proceeds depend on execution prices, liquidity, slippage, fees and how much value remained after the cross-chain movements.
Cross-Chain Movement Can Compress the Recovery Window
For victims, the first hours after a wallet drain are often critical.
Assets sent directly to a centralized exchange can sometimes be frozen if investigators identify the destination quickly and the exchange cooperates. Tokens remaining on their original chain can also be easier to track because investigators are following a single transaction graph.
Cross-chain movement complicates that process.
Once stolen funds are swapped into several native assets and distributed across different blockchains, investigators have to reconstruct multiple trails, identify bridge or swap interactions and determine where each resulting asset went next.
A similar issue appears repeatedly after protocol exploits. Dave Finances recently covered how Payy halted payments after a $1.83 million USDC bridge exploit, where tracing and containment became central immediately after funds moved.
The Frogman incident differs because there is currently no evidence that a protocol itself failed. The affected asset appears to have been wallet control rather than smart-contract infrastructure.
Personal-Wallet Theft Has Different Recovery Economics From Protocol Hacks
That distinction may ultimately matter more than the headline amount.
When a protocol vulnerability causes a loss, there may be an identifiable project treasury, development team, governance process or insurance mechanism capable of coordinating a response.
There may also be an opportunity to patch the vulnerability before additional funds leave.
Dave Finances recently examined this dynamic in the HelioBond vault vulnerability, where the central question was whether a software flaw could be exploited and how the protocol should mitigate it.
A private-wallet compromise is different.
If an attacker gains control of the actual signing authority, the blockchain generally has no mechanism for distinguishing the attacker from the legitimate owner. A valid cryptographic signature is treated as authorization regardless of who physically generated it.
Recovery therefore depends heavily on tracing, counterparties voluntarily freezing funds, token issuers intervening where technically possible, or law-enforcement action.
The Attack Vector Is Now the Most Important Unanswered Question
The most valuable next disclosure would not be another estimate of the stolen balance. The approximately $4 million loss is already reasonably well established.
The key question is how two wallets associated with the same trader came under unauthorized control.
If both wallets shared the same seed phrase or signing device, a single credential compromise could explain the theft.
If they were genuinely independent wallets with different keys, investigators would need to examine other common points such as the same computer, wallet extension, hardware environment, malicious approval flow or operational process.
The answer would materially change the security lesson for other traders.
A leaked seed phrase points toward key-storage failure. A malicious signature points toward transaction-verification weaknesses. Compromised software would raise broader questions about who else may have been exposed.
The crypto industry has repeatedly seen incidents where identifying the root cause becomes more important than the initial loss figure. Dave Finances’ coverage of a Relay API leak affecting 5,600 users showed how determining the precise technical exposure can define who remains at risk after an incident becomes public.
The Biggest Risk for High-Value Traders Is Concentrated Signing Authority
Frogman’s loss also illustrates a structural weakness of self-custody for high-value active traders.
A wallet can eliminate custodial exchange risk while simultaneously concentrating responsibility for millions of dollars into one signing environment.
That trade-off becomes particularly difficult for active traders, who cannot always keep assets in deep cold storage. They may need frequent access to decentralized exchanges, bridges, token launches and other applications, creating more opportunities for malicious approvals or compromised interfaces.
The security model therefore needs to change as wallet value rises.
Separating long-term holdings from active trading capital, limiting the amount exposed through frequently used wallets and isolating signing devices can reduce the amount available to a single compromise. Multi-signature structures can provide another layer where the trading workflow permits them.
None of those measures establish what happened to Frogman. They illustrate why the eventual forensic explanation matters.
The $4 Million Figure May Be the Beginning, Not the End, of the Investigation
For now, the clearest facts are straightforward.
Two wallets linked to Frogman lost approximately $4 million across nine tokens. The largest positions were roughly $1.77 million of BP, $1.55 million of MarsCoin and just over $500,000 of Cash Cat. The assets were converted principally into ETH, BNB and SOL, with subsequent movement involving Privacy Cash and Chainflip.
Frogman has confirmed the theft but has not identified the attack vector.
That leaves investigators with two priorities: tracing where the converted assets ultimately settle and determining how the attacker obtained signing authority in the first place.
The first may determine whether any money can be recovered.
The second will determine whether this was an isolated failure in one trader’s security setup or evidence of a threat that could still affect other wallets.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

