A rug pull is one of the most preventable forms of crypto theft — if you know what to look for before you buy. Unlike a scam that targets you personally, a rug pull targets everyone who buys into a project. The red flags are almost always visible on-chain before it happens. Most victims simply didn't know where to look.
This guide covers what rug pulls look like on-chain, the 12 red flags that appear in nearly every case I've investigated, how hard and soft rugs differ, and what to do if you've already been caught in one.
Contents
What Is a Rug Pull?
A rug pull is an exit scam executed by a token's own developers or insiders. They create a new token, hype it on social media and Telegram, attract investor capital into a liquidity pool, and then either drain the pool directly or dump their own token allocation — crashing the price to near zero and taking the real assets (ETH, BNB, USDT) with them.
The name comes from the idiom "pulling the rug out" — everything looks solid until suddenly it isn't. The mechanics vary, but the outcome is almost always the same: investors are left holding tokens worth nothing, and the developers are gone.
Rug pulls accounted for over 35% of all crypto scam revenue in recent years according to on-chain analytics firms. The average victim loses between $2,000 and $15,000. Most rugs are executed within 24–72 hours of launch.
Hard Rug vs. Soft Rug
Not all rug pulls look the same. The distinction between a hard rug and a soft rug affects both how the fraud occurs and what forensic evidence survives.
| Type | How It Works | Timeframe | Forensic Footprint |
|---|---|---|---|
| Hard Rug | Developer drains liquidity pool directly via malicious contract function or admin key | Minutes to hours | Single large liquidity drain transaction; often followed by rapid cross-chain bridge activity |
| Soft Rug / Slow Rug | Team gradually dumps their own token allocation while maintaining facade of active development | Weeks to months | Pattern of insider wallet sell orders; price decline masked by continued marketing |
| Honeypot | Smart contract allows buying but disables selling for non-developer wallets | Immediate — victims can never exit | 100% of sell transactions fail on-chain; developer wallets are whitelisted exceptions |
12 Red Flags to Check Before You Buy
These are the warning signs that appear in nearly every rug pull case I've analyzed. Some are visible before launch; others become apparent in the first hours of trading. None require technical expertise — they can be verified with a block explorer and a few free tools.
On-Chain Verification Steps
You can run most of these checks in under 10 minutes using free tools. Get the token contract address before buying and verify the following:
Step 1 — Token Sniffer / Honeypot.is
Paste the contract address into tokensniffer.com or honeypot.is. These tools automatically scan for honeypot functions, high taxes, and known scam patterns. A score below 70/100 on Token Sniffer warrants serious caution.
Step 2 — Liquidity Lock Verification
Find the liquidity pool address (visible on Dexscreener or Dextools), then check unicrypt.network or team.finance to confirm whether the LP tokens are locked and for how long.
Step 3 — Holder Distribution
On Etherscan or BscScan, click the token → "Holders" tab. Note the top 10 addresses and what percentage they hold. Exclude the liquidity pool address itself. Anything over 50% in a handful of wallets is dangerous.
Step 4 — Contract Audit
Check the project's Telegram or website for an audit report. Verify the auditing firm is real and the contract address in the report matches the token you're looking at. Many scams fabricate audit documents or recycle real ones from other projects.
Step 5 — Deployer Wallet History
Find the contract deployer address on Etherscan (shown under "Contract Creator"). Trace their transaction history. A deployer who has launched and abandoned multiple tokens before this one is a strong signal of serial fraud.
What Happens On-Chain After a Rug
When a rug pull executes, the on-chain sequence is usually distinctive and rapid. Understanding this sequence is important if you're trying to document what happened:
- Liquidity drain transaction — a single large transaction removes the ETH/BNB/USDT from the liquidity pool, crashing the token price to near zero
- Bridging — funds are often moved cross-chain within minutes using bridges (Stargate, Across, LayerZero) to obscure the trail
- Mixer / privacy tool deposit — some ruggers deposit into Tornado Cash or similar within hours
- Exchange deposit — final destination is usually a centralized exchange where they convert to clean currency and withdraw
This sequence is traceable at each step. The exchange deposit is the point where identity becomes recoverable — if a KYC exchange received the funds, a subpoena can identify the account holder.
If You've Already Been Rugged
If you've already lost money to a rug pull, the window for meaningful action is short but real.
- Document everything immediately — take screenshots of the token page, your transaction history, the project's Telegram and website (use web.archive.org to preserve them), and any communications with the team
- Record all wallet addresses — the contract address, the deployer wallet, the liquidity pool address, and any wallet you were told to send funds to
- File with IC3.gov — the FBI's Internet Crime Complaint Center accepts crypto fraud reports and aggregates them for law enforcement action
- Request a forensic trace — a blockchain forensic investigator can follow the funds from the liquidity drain through bridges and mixers to their current location, identify any exchange deposits, and produce a documented evidence package for law enforcement or attorneys
After a rug pull, victim wallet addresses are often harvested and sold to secondary scammers who will contact you claiming to offer recovery services. Anyone who contacts you unsolicited about recovering your rug pull funds is running a second scam. See our guide on how to tell the difference.