Cointime

Download App
iOS & Android

How to Detect and Avoid Rug Pulls

Validated Project

In this post, we’ll explain “rug pulls,” a common type of crypto scam targeting primarily retail investors.

A “rug pull,” derived from the expression “pulling the rug out” — suddenly taking away support, — is a type of crypto scam in which a project’s team pumps its token before disappearing with the funds received from retail investors.

According to a report from the blockchain risk monitoring firm Solidus Labs, 117,629 rug pulls occurred in 2022, a 41% increase over the previous year, a sign that this type of scam is on the rise and has the potential to thrive.

Meanwhile, not all kinds of rug pulls are technically illegal. Still, those that are classified as hard rug pulls can be pursued under the law.

Hard rug pulls: liquidity theft and scam tokens

Liquidity theft involves creating a liquidity pool within a scam project and luring users to add pairs of tokens to it by promising a triple-digit APY. A project of that kind also typically releases a new token that is heavily promoted. Thus, hoping for substantial passive income from the project, users add their tokens to the pool and receive LP tokens in exchange. Eventually, the team responsible for maintaining the pool withdraws the tokens and exits, abandoning investors with worthless LP tokens and no way to get their funds back.

Technical manipulation with a smart contract algorithm is another type of a hard rug pull, enabling stealing from investors in various ways. For example, the “approve” part of the code needed for the smart contract to spend a token within a transaction can be modified in a way that allows users only to buy the token. In this scheme, those who invested in the scam token of a hyped project on its rise are left with nothing after the developers disappear — the price of the token drops, and the holders cannot resell it. Also, worthless tokens can contain a 99% buy or sell fee, as well as other surprises.

Soft rug pulls: token dumping

A pump-and-dump scheme relies on artificially inflating a project’s value and dumping the team’s assets when the price is at its peak, instantly devaluing the tokens of tricked investors.

To facilitate a scheme of this kind, the team can hold on to a disproportionately large number of tokens since the project’s launch. How significantly the token price falls, depends on how many tokens the team throws onto the market at once. Technically, these actions are not illegal, but they are certainly unethical. Sometimes, when promoting a project, developers may even promise donations to charity, eventually failing to do that and simply cashing in on people buying up the token of a project that no one ever intended to develop.

Some rug pull schemes can mislead even risk experts. For example, when the price of the Flare project fell by more than 95%, opinions split on whether it was a rug pull or an exploit, the latter version promoted by the project’s team. Meanwhile, the fact that about $17 mln Flare tokens were received by addresses associated with the project’s developers was an argument in favor of a scam.

Day of Defeat also claimed to be hacked, with its value decreasing by more than 96%. All project assets worth over $1.35 mln were withdrawn to external wallets. Once the funds disappeared, the project claimed that third parties had compromised it.

Basically, these schemes follow more or less the same scenario, involving a project pumping up its price and then swapping its tokens for liquid assets and transferring them to external wallets. Usually, the project’s social media accounts and websites also end up being removed.

This is exactly what the DeFi project DRAC Network did in mid-2022, dropping the price of the TEDDY token by 99,4% and transferring $10,000 in BNB and $2 mln in BUSD to Binance. Quantitative trading company MGNR went the same way, draining a total of $52 mln in USDC to Coinbase and Genesis Trading, then deleting all of its tweets.

Sometimes, rug pulls combine multiple types of scam, as was the case with one of the most notable fraudulent projects in scam history, SQUID. The developers, who have not yet been identified, attracted many investors by offering a game based on the popular South Korean TV series Squid Game but not officially affiliated with it. Their SQUID token contained hidden modifications that blocked its resale. Therefore, none of the holders could get rid of their tokens after the development team withdrew all the liquidity from the project, which was worth about $3.3 mln.

How to detect a rug pull

Lack of audit: You should only join liquidity pools of projects that have been audited by a trustworthy security firm, no matter how quick and large returns the project promises.

Disproportionate distribution: The white paper, as one of the essential documents of any project, contains its token distribution program. If a large number of tokens is held by the project team, it’s a potential red flag. Block explorers like Etherscan allow users to check which wallets hold specific tokens. Block explorers also show the total supply and the number of transfers. If the number of wallets holding the tokens is small while the token’s value is skyrocketing, there is obviously some price manipulation happening. Ideally, there shouldn’t be more than 20% of the total new token amount in the top 10 wallets.

Absence of liquidity lock: If liquidity is locked in a project, no one can withdraw it instantly. When providing tokens to a pool, temporary locking implies a period that can vary and reach five years, but its complete absence is also a red flag.

Using only reputable platforms can be a security guarantee for those who don’t want to dig into block explorers or white papers of new projects. The same applies to tokens. A hidden code function is unlikely to be visible to a non-expert user. Therefore, at the very least, it is worth it to make sure that you are dealing with tokens having transactions behind them. There is also an option of trading with some small token amount in a test mode or using online rug pull-detecting tools to analyze tokens and platform code.

https://blog.1inch.io/avoiding-rug-pulls-a051f092e214

Comments

All Comments

Recommended for you

  • Bitcoin native application platform Arch developer completes $7 million seed round of financing, led by Multicoin Capital

    Bitcoin native application platform Arch developer Arch Labs announced the completion of a $7 million seed round of financing, led by Multicoin Capital, with participation from Portal Ventures, OKX Ventures, Big Brain Holdings, CMS Holdings and Tangent.

  • Tokenization platform AgriDex completes $5 million Pre-Seed round of financing

    AgriDex, a tokenization platform on the Solana blockchain, announced the completion of a $5 million Pre-Seed round of financing, led by Endeavor Ventures, with participation from African Crops Limited, Oldenburg Vineyards, and former Goldman Sachs and Citadel executive, Hank Oberoi. It is reported that AgriDex is expected to launch its platform and token, AGRI, in the third quarter of this year. According to its white paper, AgriDex has reserved 5% of the total token supply, or 50 million tokens out of 1 billion tokens, for airdrops.

  • Multidimensional gas pricing

    In Ethereum, resources were up until recently limited, and priced, using a single resource called "gas". Gas is a measure of the amount of "computational effort" needed to process a given transaction or block. Gas merges together multiple types of "effort", most notably:

  • UXUY Completes $7 Million Pre-A Round of Financing, with Investments from Binance Labs, Bitcoin Magazine, and Other Institutions

    UXUY, the next-generation decentralized multi-chain trading platform incubated by Binance Labs, announced the completion of a $7 million Pre-A round of financing. Since its establishment, its total financing amount has exceeded $10 million. UXUY is an important builder of the Bitcoin ecosystem, and more than 100,000 traders use Bitcoin Lightning Network services through UXUY. UXUY's current round of financing has received investment from well-known institutions in Asia, North America, and Europe, such as Binance Labs, UTXO Management (Bitcoin Magazine), JDI Ventures, Bixin Ventures, SWC Global, Matrix Partners, CMS Holdings, Dewhales Capital, Comma3 Ventures, Satoshi Labs, YBB Capital, GBV Capital, Web3Vision, Pentos Ventures, NGC Ventures, Alti5, Metalpha, and GSR. The funds raised by UXUY in this round will be used for the construction of the Bitcoin ecosystem infrastructure, and will be committed to promoting the efficient and low-cost trading of Lightning Network Taproot Assets, Ordinals BRC-20, Runes, and other assets. Jordan, co-founder of UXUY, said: "We are pleased to be strategic partners with all investors! This year, we have successfully built a bridge between the Bitcoin Lightning Network and the multi-chain ecosystem. UXUY will continue to promote the use cases and popularization of the Lightning Network in trading scenarios, and make more contributions to the Bitcoin ecosystem." According to RootData, a Web3 asset data platform, UXUY is a next-generation decentralized multi-chain trading platform based on MPC wallets. UXUY actively participates in the construction of the Bitcoin Layer2 ecosystem, fully integrates into the Bitcoin Lightning Network and Taproot ecosystem, provides Lightning Address DID services to users, and becomes an important bridge connecting the Bitcoin and Ethereum ecosystems. As a decentralized multi-chain trading platform, UXUY provides immediate cross-chain trading services for Coin, Token, and Inscription among public chains through the establishment of uPool.

  • Why the Future of Ethereum is Smart (Accounts)

    In the dynamic landscape of Ethereum, the traditional concept of digital ownership through externally owned accounts (EOAs) is revealing its limitations. As Ethereum's ecosystem grows, incorporating more complex applications and expanding through layer-2 scaling solutions, it becomes evident that our foundational tools for ownership and interaction need an overhaul.

  • Taiwan's administrative agency passed four new anti-fraud laws to bring cryptocurrency traders under control

    It was announced that Taiwan's administrative management agency has passed the "New Anti-Fraud Law" to regulate cryptocurrency traders. In the future, businesses or individuals providing virtual asset services or third-party payment services must complete anti-money laundering measures and register their services or log in. Failure to do so may result in a maximum of 2 years in prison or a fine of up to NT$5 million. Businesses or individuals outside of Taiwan providing virtual asset or third-party payment services must register their companies or branches according to company law and complete anti-money laundering measures and service registration or login. Otherwise, they are not allowed to provide virtual asset services or third-party payment services in Taiwan. Qiu Shuzhen, the deputy chairman of Taiwan's financial regulatory agency, stated that there are currently around 60 to 70 cryptocurrency traders in the market, of which 25 have passed the anti-money laundering review by the financial regulatory agency. In the future, all traders will be required to declare and undergo review, and a cryptocurrency traders' association will be established for legal, administrative, and association management. Accounting professionals will also be enlisted to assist with internal control.

  • Speculatory Divergence

    There has been a growing divergence in performance between Bitcoin and Ethereum during the 2023-23 cycle thus far. This has manifested as weaker price performance for ETH, and can be explained by an overall weaker capital rotation trend, especially relative to past cycles and ATH breaks.

  • EigenLayer TVL falls back to $14.794 billion

    According to DefiLlama data, the total value locked (TVL) in Ethereum's re-staking protocol EigenLayer has fallen below $15 billion, currently at $14.794 billion.

  • The EU is considering including cryptocurrencies in the 12 trillion euro investment market, and its impact may far exceed that of US ETFs

    The European Securities and Markets Authority (ESMA) is consulting with the investment product advisory industry and experts on whether cryptocurrency assets should be included. This move could open up a broader market for cryptocurrencies, far exceeding the market size of spot Bitcoin ETFs. The plan aims to expand the scope of UCITS (EU Transferable Securities Collective Investment Scheme), with the UCITS market reaching as high as €12 trillion. If successful, this would be a key step in mainstreaming cryptocurrency assets in Europe.

  • The Usage & Evolution of Decentralized Exchanges (DEX’s)

    Checking in on pool liquidity, trading volumes and adoption across Ethereum DEX's