Cointime

Download App
iOS & Android

How to Detect and Avoid Rug Pulls

Validated Project

In this post, we’ll explain “rug pulls,” a common type of crypto scam targeting primarily retail investors.

A “rug pull,” derived from the expression “pulling the rug out” — suddenly taking away support, — is a type of crypto scam in which a project’s team pumps its token before disappearing with the funds received from retail investors.

According to a report from the blockchain risk monitoring firm Solidus Labs, 117,629 rug pulls occurred in 2022, a 41% increase over the previous year, a sign that this type of scam is on the rise and has the potential to thrive.

Meanwhile, not all kinds of rug pulls are technically illegal. Still, those that are classified as hard rug pulls can be pursued under the law.

Hard rug pulls: liquidity theft and scam tokens

Liquidity theft involves creating a liquidity pool within a scam project and luring users to add pairs of tokens to it by promising a triple-digit APY. A project of that kind also typically releases a new token that is heavily promoted. Thus, hoping for substantial passive income from the project, users add their tokens to the pool and receive LP tokens in exchange. Eventually, the team responsible for maintaining the pool withdraws the tokens and exits, abandoning investors with worthless LP tokens and no way to get their funds back.

Technical manipulation with a smart contract algorithm is another type of a hard rug pull, enabling stealing from investors in various ways. For example, the “approve” part of the code needed for the smart contract to spend a token within a transaction can be modified in a way that allows users only to buy the token. In this scheme, those who invested in the scam token of a hyped project on its rise are left with nothing after the developers disappear — the price of the token drops, and the holders cannot resell it. Also, worthless tokens can contain a 99% buy or sell fee, as well as other surprises.

Soft rug pulls: token dumping

A pump-and-dump scheme relies on artificially inflating a project’s value and dumping the team’s assets when the price is at its peak, instantly devaluing the tokens of tricked investors.

To facilitate a scheme of this kind, the team can hold on to a disproportionately large number of tokens since the project’s launch. How significantly the token price falls, depends on how many tokens the team throws onto the market at once. Technically, these actions are not illegal, but they are certainly unethical. Sometimes, when promoting a project, developers may even promise donations to charity, eventually failing to do that and simply cashing in on people buying up the token of a project that no one ever intended to develop.

Some rug pull schemes can mislead even risk experts. For example, when the price of the Flare project fell by more than 95%, opinions split on whether it was a rug pull or an exploit, the latter version promoted by the project’s team. Meanwhile, the fact that about $17 mln Flare tokens were received by addresses associated with the project’s developers was an argument in favor of a scam.

Day of Defeat also claimed to be hacked, with its value decreasing by more than 96%. All project assets worth over $1.35 mln were withdrawn to external wallets. Once the funds disappeared, the project claimed that third parties had compromised it.

Basically, these schemes follow more or less the same scenario, involving a project pumping up its price and then swapping its tokens for liquid assets and transferring them to external wallets. Usually, the project’s social media accounts and websites also end up being removed.

This is exactly what the DeFi project DRAC Network did in mid-2022, dropping the price of the TEDDY token by 99,4% and transferring $10,000 in BNB and $2 mln in BUSD to Binance. Quantitative trading company MGNR went the same way, draining a total of $52 mln in USDC to Coinbase and Genesis Trading, then deleting all of its tweets.

Sometimes, rug pulls combine multiple types of scam, as was the case with one of the most notable fraudulent projects in scam history, SQUID. The developers, who have not yet been identified, attracted many investors by offering a game based on the popular South Korean TV series Squid Game but not officially affiliated with it. Their SQUID token contained hidden modifications that blocked its resale. Therefore, none of the holders could get rid of their tokens after the development team withdrew all the liquidity from the project, which was worth about $3.3 mln.

How to detect a rug pull

Lack of audit: You should only join liquidity pools of projects that have been audited by a trustworthy security firm, no matter how quick and large returns the project promises.

Disproportionate distribution: The white paper, as one of the essential documents of any project, contains its token distribution program. If a large number of tokens is held by the project team, it’s a potential red flag. Block explorers like Etherscan allow users to check which wallets hold specific tokens. Block explorers also show the total supply and the number of transfers. If the number of wallets holding the tokens is small while the token’s value is skyrocketing, there is obviously some price manipulation happening. Ideally, there shouldn’t be more than 20% of the total new token amount in the top 10 wallets.

Absence of liquidity lock: If liquidity is locked in a project, no one can withdraw it instantly. When providing tokens to a pool, temporary locking implies a period that can vary and reach five years, but its complete absence is also a red flag.

Using only reputable platforms can be a security guarantee for those who don’t want to dig into block explorers or white papers of new projects. The same applies to tokens. A hidden code function is unlikely to be visible to a non-expert user. Therefore, at the very least, it is worth it to make sure that you are dealing with tokens having transactions behind them. There is also an option of trading with some small token amount in a test mode or using online rug pull-detecting tools to analyze tokens and platform code.

https://blog.1inch.io/avoiding-rug-pulls-a051f092e214

Comments

All Comments

Recommended for you

  • CZ: Welcomes More DEX Competition, Does Not Oppose Hyperliquid

    On September 26, Binance founder CZ stated during the podcast "WhenShiftHappens" that he does not oppose Hyperliquid and welcomes more centralized and decentralized trading platforms to participate in innovation, as the industry is far from saturated. He estimates that the proportion of the population holding some form of cryptocurrency is about 5% to 15%, but based on personal wealth allocation, the penetration rate of crypto assets may be less than 1%, indicating that the industry is still in its early stages. CZ mentioned that some members of the Hyperliquid community have attempted to build their community by criticizing centralized trading platforms and Binance, but he views this as normal competition and does not oppose the project. Previously, Trump mentioned Hyperliquid, which is very positive for the industry. Assets like HYPE, BNB, and Bitcoin could all benefit from the overall growth of the industry. CZ also pointed out that first movers do not necessarily become the long-term biggest winners. Google, Facebook, and Binance were not the first products in their respective fields, and later entrants can often optimize further based on the groundwork laid by pioneers. Although he holds a significant amount of Binance shares and BNB, the centralized trading platform is just part of his asset allocation; rather than expanding a single platform, he hopes to promote the growth of the entire crypto industry.

  • Bitget CEO Confirms $387.5 Million Hacker Attack but Plans IPO Within Three Years

    On September 26, Crypto Briefing reported that Bitget CEO Gracy Chen stated that despite the platform being hacked on September 24 at 18:31 UTC, resulting in a loss of $387.5 million, the company still plans to go public within three years. The stolen assets included approximately 103 million XRP (about $157 million) as well as ETH and USDT, while the cold wallet was unaffected and no private keys were leaked. Chen noted that the characteristics of the attack were similar to previous actions by North Korean hacker groups, based on IP and transaction pattern analysis. Law enforcement has been notified, and on-chain tracking has been initiated, with Mandiant and SlowMist assisting in the investigation. Withdrawals remain suspended. Bitget's user protection fund exceeds $464 million, which can fully cover the losses with approximately $76 million remaining. Chen mentioned that in 2026, the AI and aerospace sectors would attract investors' attention, making the IPO environment challenging.

  • Bitget CEO Calls on THORChain: Refuse Service to Attackers' Addresses

    On September 26, Bitget CEO Gracy Chen posted on the X platform stating that the addresses of the attackers from Bitget have been publicly listed and are being actively tracked. The platform formally requests the cross-chain protocol THORChain to refuse service to these addresses. She emphasized that decentralization is a design principle and should not serve as a shield for facilitating known stolen funds, stating, 'The entire industry is watching.' Previously, blockchain security firm MistTrack pointed out that following the Bitget security incident, funds related to the Bitget attackers were again observed being transferred to THORChain for asset exchange and cross-chain transfer, publicly questioning the protocol's responsibility for facilitating large cross-chain exchanges when it is aware that the funds come from a publicly identified major hacking incident.

  • U.S. Spot Solana ETF Sees Record Daily Net Inflow of $80 Million

    According to Crypto Briefing, on September 25, the U.S. spot Solana ETF recorded a daily net inflow of approximately $80 million to $87 million, more than doubling the previous daily record of $33.5 million set in August. For the week, inflows reached $181 million, bringing the total net inflow to over $1.6 billion, with total assets under management ranging between $1.8 billion and $1.96 billion. Among these, Bitwise's staking-supported BSOL attracted about $55.7 million in a single day, accounting for roughly two-thirds of the total for that day; since its inception on October 28, 2025, BSOL has cumulatively represented about 80% of inflows in this category (approximately $1.22 billion). Grayscale's GSOL saw a daily increase of about $18.5 million, ranking second, while Fidelity's FSOL and Morgan Stanley's MSOL contributed less. During the inflow period, the price of SOL was around $120. Analysts suggest that the ability to support staking and yield generation is a core advantage that distinguishes these funds from Bitcoin ETFs.

  • Hyperliquid Assistance Fund Repurchases and Destroys Over 47.5 Million HYPE Worth $4.366 Billion

    According to monitoring, the Hyperliquid assistance fund has repurchased and destroyed over 47.5058 million HYPE, with a total purchase cost of approximately $1.321 billion, currently valued at around $4.366 billion.

  • Fidelity Executive: Bitcoin Power Law Model Indicates New Bull Market Cycle, Target Price of $300,000 by 2029

    On September 26, Jurrien Timmer, Global Macro Director at Fidelity Investments, stated on social media that the mathematical calculations of Bitcoin's 'power law' continue to indicate that a new cyclical bull market is forming after holding the $60,000 level, with a target price of $300,000 by 2029. Timmer also included a chart illustrating Bitcoin's power law valuation as evidence. It should be noted that the power law model is a long-term trend fitting tool, and its extrapolated prices are not deterministic predictions; actual trends are still influenced by liquidity, regulation, and changes in market structure.

  • Foreign Ministry Spokesperson Answers Questions on Artificial Intelligence

    On September 26, a reporter asked: We noticed that during the introduction of the results of this visit, the U.S. side used 'superintelligence' instead of 'artificial intelligence.' What is China's comment on this? The spokesperson responded: During the meeting between the Chinese and U.S. heads of state, in-depth discussions were held on the issue of artificial intelligence. Regarding the terminology of artificial intelligence, China values the U.S. position and respects their phrasing. The technology of artificial intelligence is continuously evolving, and all parties can strengthen communication, engage in in-depth discussions, and seek consensus based on the latest developments.

  • Iranian President: We No Longer Trust Negotiations with the U.S.

    On September 26, Al Jazeera reported that Iranian President Ebrahim Raisi stated that Iran "no longer trusts negotiations with Washington" because the U.S. has repeatedly launched attacks and imposed sanctions after each round of talks. Qatar and Pakistan are currently mediating between Iran and the U.S., relaying Tehran's messages to Washington. Raisi also mentioned that negotiations should be based on the memorandum of understanding previously signed by the two countries, adding that the Americans must clarify their position regarding this memorandum. Furthermore, he attributed the closure of the Strait of Hormuz to the U.S., stating, "It is the U.S. that has blocked our path." When Iran's path is obstructed, closing the Strait of Hormuz is a natural response. The crisis in the Strait of Hormuz can be resolved through negotiations rather than the use of force. If negotiations lead to a resolution of disputes, the waterway "will remain open for trade."

  • Bitget CEO Reveals $80,000 Loss from Impersonation Scam Linked to Lazarus Group

    On September 26, Crypto Briefing reported that Bitget CEO Gracy Chen disclosed a loss of approximately $80,000 from her personal wallet due to a social engineering attack disguised as a journalist interview. The attack involved hackers stealing the X account of a well-known crypto media outlet and impersonating a journalist to contact her under the guise of scheduling an interview. Chen stated that her personal losses are not covered by Bitget's user protection fund, which only covers users and not the CEO's personal wallet. Previously, Bitget's cold and hot wallets were hacked, resulting in an estimated loss of about $387.5 million (revised from an initial estimate of $351.6 million). The attackers did not utilize private keys but instead forged transaction data to redirect funds; the user protection fund has a scale of over $464 million. Chen attributed both incidents to the North Korean Lazarus Group, noting that the modus operandi and operational characteristics are consistent with the group's past actions, and mentioned that her personal wallet had previously been targeted, with tactics related to those used against other exchanges.

  • Bitget Confirms Being Deceived into 'Self-Approving' $388 Million Transfer, Losses Revised

    On September 26, Unchained reported that Bitget stated attackers transferred approximately $387.5 million from its exchange on Thursday, revising the initially estimated loss of $351.6 million after accounting for transfers on the Zcash and TRON chains. The attackers did not require private keys: CEO Gracy Chen mentioned that the attackers compromised key backend systems of its wallet infrastructure, forged transaction data, and triggered the authorization process, which was signed by Bitget's own system. The related vulnerability has been identified and fixed, and the withdrawal status, which has been suspended since Thursday, will be announced before midnight Eastern Time. Mandiant and SlowMist are assisting with the investigation. Chen noted that based on IP behavior patterns and on-chain signatures, this attack is consistent with methods used by North Korean-linked hacker organizations and resembles the previous $1.5 billion theft case from Bybit. Nansen tracking shows that 40,000 ETH were evenly distributed to four new addresses; as of Friday, 6:34 PM Eastern Time, eight attacker addresses held a total of approximately 68,300 ETH (about $18.4 million), with no further transactions initiated. Bitget stated that some of the funds have been frozen and is offering a 5% bounty on the recovered amounts to those who facilitate the freezing; the $464 million protection fund fully covers the losses.