"Hacked" or Habits? Examining the Matt Furie Account Pattern

Matt Furie created Pepe the Frog, the meme behind one of the most valuable memecoins ever. He has also been "hacked" more times in a single year than most accounts will be in a lifetime.

Share

The man who made the meme, and missed the coin

Furie created Pepe the Frog in 2005, long before crypto existed. When the NFT boom arrived years later, Pepe made the trip into Web3. A Pepe NFT linked to him sold for 150 ETH, worth about $537,000 at the time. A buyer later alleged the value collapsed and sued Furie, Chain/Saw and PegzDAO, a case dismissed with prejudice. Meanwhile, the official PEPE memecoin reached billion-dollar valuations with no involvement from the frog's creator.

That gap between where the money went and who created the culture sits at the center of the current controversy. Scammers continued using Furie's name and characters to launch tokens, and in June 2025 the Replicandy NFT project, connected to Furie, was exploited: the attacker minted 6,000 NFTs for $2 each before the floor crashed 97% in an hour. ZachXBT connected projects tied to Furie, Chain/Saw and Favrr to roughly $1 million in losses, with the attack allegedly linked to North Korean IT workers.

A year, and a pattern, that reads as more than coincidence

The events that drive this article cluster in a tight window in 2026. In a single week, Furie's account promoted four bundled tokens: $BOYZ, $MEGUSTA, $DORK and $MUFFIN. The posts were later deleted, and Furie claimed he had been hacked. Users quickly noted the same wallets tended to top the profit-and-loss tables on each promoted token.

The account then went private, a move Bubblemaps flagged with the sort of dry understatement the situation invites.

Community analysts cataloged the pattern across the year. One breakdown of the $BOYZ saga concluded Jason, involved with the Arena on the Robinhood chain, appeared to be socially engineered into shilling the token, while Furie's account showed signs of either a persistent hack or insider involvement. The analyst put the odds at roughly 50-50, and noted that if the account really had been compromised this many times, the absence of legal action or tightened security after months and multiple compromised posts was difficult to explain.

Three hacks in a month, and a question of password hygiene

The skepticism crystallized around a simple post: Matt Furie has been "hacked" three times this month. Is he part of the scams, or does he genuinely have a weak password?

The replies were merciless. Jokes about the password being "12345" and "password" mixed with more substantive accusations: that Furie was "farming" the incidents, that paid arrangements on the order of tens of thousands of dollars exist for accounts that post a contract address, leave it up for a couple of hours, then claim a hack, and that the account was never meaningfully recovered in the first place. One recurring theme was that a third compromise, by this point, demands a public postmortem.

The other side of the ledger

Not everything cuts against Furie. The June 2025 Replicandy exploit and the North Korean-linked losses were, by most accounts, genuine attacks with real victims. And there is a reasonable reading of the location mismatches and inactivity across his platforms as consistent with an attacker who has held control for a long time, rather than with a willing participant. Skeptics concede the evidence supports both a persistent hack and routine complicity.

But the burden of proof has shifted. After five or more incidents inside a pattern that does not resemble ordinary phishing, the community is no longer asking whether Matt Furie's account was hacked. It is asking whether the word "hacked" has become a convenient endpoint for a series of intentional-looking promotions.

How Bubblemaps approaches it

Bubblemaps does not adjudicate motives; it tracks on-chain behavior. The bundling patterns associated with the promoted tokens, the profit concentration in recurring wallets, and the timing of deletions all sit within view of on-chain analysis, even when the intent behind them does not.

An investigation into whether Matt Furie was actually hacked is now live on Intel Desk, where holders can vote with $BMT to push the case forward.

The question the pattern leaves behind

Pepe the Frog outlived every one of these incidents, which is part of why the situation feels strange. The creator of the most famous meme in internet history does not need to shill bundled tokens to be relevant, and if the incidents are staged, they are the rare kind of grift that damages the reputation it is meant to enrich. The doubt is not going away on its own. The answer, as with most things on-chain, will likely settle where the evidence and the wallets point.