A crypto rug pull is a scam in which developers or insiders drain funds, remove liquidity, or abandon a token after attracting buyers. It often appears in new or lightly audited projects, especially on decentralised exchanges where tokens can launch quickly and with limited oversight.
This article explains how rug pulls work, the warning signs that often appear before a collapse, and the checks that can help reduce risk before buying into a project.
Key takeaways
- A rug pull happens when token creators drain liquidity or dump holdings after attracting buyers.
- Check whether liquidity is locked or burned before buying any new token.
- Review the smart contract for hidden minting, trading limits, or blacklist functions.
- Anonymous teams, copied whitepapers, and vague roadmaps often signal higher rug pull risk.
- Sudden hype, aggressive influencer promotion, and unrealistic returns often precede exit scams.
- Use blockchain explorers and token audit tools to inspect wallets, liquidity, and contract permissions.
What a crypto rug pull is and why it differs from a normal project failure
Check who controls the token’s liquidity and contract permissions before you buy. Those controls decide whether holders can exit later. A rug pull is not a normal failed launch with weak demand or poor execution. It is a setup where insiders can drain funds, block selling, mint new tokens, or remove the trading pool once buyers arrive.
That control usually sits in the smart contract or liquidity pool. On decentralised exchanges such as Uniswap, trading depends on locked liquidity staying in place. If creators can withdraw it, the token price can collapse in minutes. If the contract lets the owner change fees, blacklist wallets, or pause transfers, buyers may be able to buy but not sell.
A normal project failure loses value over time as adoption stalls, funding runs out, or the product never ships. A rug pull is different because losses come from hidden control and deliberate extraction. Contract ownership, liquidity locks, and code audits deserve more attention than marketing, follower counts, or roadmap promises.
How crypto rug pulls work across token launches, liquidity pools and smart contracts
Rug pull losses surged to $5.06B in 2021 during the DeFi boom, dropped sharply in 2022, then resurged to $94.8M in 2024 amid memecoin mania. Note: 2021 bar scaled for readability.
Losses often happen within minutes of launch, so trace who can change the token, move liquidity, and alter trading rules before any buy. That check beats hype, follower counts, or polished branding, because rug pulls usually depend on hidden control.
In token launches, the main risk sits in supply and permissions. A deployer may still mint new tokens, change transfer fees, blacklist wallets, or pause trading after buyers enter. In liquidity pools, the danger shifts to pool tokens or lock terms. If the team can withdraw liquidity at will, the market can collapse even when trading looked active an hour earlier.
Smart contracts add another layer. Proxy contracts, upgrade rights, and owner-only functions can let developers change core behaviour after launch. Renounced ownership and locked liquidity reduce risk, but they do not guarantee safety if the code still contains harmful logic. Identity checks can help, especially when a project uses What Is KYC in Crypto ?, yet KYC alone does not stop a malicious contract from draining value.
The main types of rug pulls, including liquidity theft, mint abuse and sell restrictions
| Type | Mechanism | Key Risk to Buyer | Example |
|---|---|---|---|
| Liquidity Theft (Hard Rug) | Creators withdraw the entire liquidity pool from a DEX | Token price collapses instantly; no buyers remain | BALD token (2023) — liquidity pulled, token crashed 97% |
| Honeypot / Sell Restriction | Smart contract allows buying but blocks all selling | Funds are permanently trapped; no exit possible | Squid Game Token ($SQUID) — investors could not sell |
| Hidden Mint Abuse | Deployer mints unlimited new tokens to dilute supply | Value is inflated then destroyed by sudden oversupply | PlayDapp hack — 1.79 billion tokens minted by attacker |
| Soft Rug / Gradual Exit | Insiders slowly dump holdings and abandon the project | Slow price bleed; team goes silent before full collapse | Many NFT projects; $1.2B lost to soft rugs in 2024 |
| Proxy / Upgrade Exploit | Upgradeable contracts let devs swap in malicious code post-launch | Safe-looking contract can be rewritten after investment | Kokomo Finance — legitimate code swapped for malicious version |
The biggest mistake is treating every rug pull as a simple liquidity drain. Some scams keep trading live, then use contract permissions to trap holders, inflate supply, or route value to insiders.
Liquidity theft is the clearest version. Developers pair a token with ETH, BNB or a stablecoin on a decentralised exchange, then withdraw liquidity tokens or unlock a pool they still control. Once that backing disappears, slippage spikes, the chart collapses, and sellers cannot exit near the quoted price.
Mint abuse relies on supply control. If the contract still lets the owner mint, rebalance, or exclude wallets from limits, insiders can create new tokens after buyers enter. That dilution crushes price and can give the deployer enough supply to drain the paired asset.
Sell restrictions are harder to spot because buying still works. The contract may blacklist wallets, set sell fees near 100%, pause transfers, or allow only whitelisted addresses to sell. The pool may still show liquidity, but ordinary holders stay locked in.
- Check whether ownership is renounced or moved to a time-locked contract.
- Review verified contract functions on Etherscan or the relevant chain explorer before buying.
- Confirm that liquidity is locked through a recognised locker, not held in the deployer wallet.
These patterns point to a wider question many new buyers ask: is crypto safe? what you own often depends less on branding than on who can still change the rules after launch.
Warning signs to check before buying a low-cap token or joining a new crypto project
Assume a new low-cap token is unsafe until the contract, liquidity and team controls prove otherwise.
Check the contract on Etherscan, BscScan or the relevant block explorer before buying. Review whether ownership is renounced, whether minting or blacklisting remains possible, and whether trading can be paused or fees changed. Then inspect the liquidity pool on Uniswap, PancakeSwap or the project’s stated exchange to see if liquidity is locked, for how long, and who holds the lock.
Read the token distribution next. A few wallets holding a large share, heavy insider allocations, or transfers between linked wallets raise dump risk. If the project claims an audit, open the report and check whether it is recent, complete and issued by a known firm, not just quoted in marketing copy.
The most common mistake is relying on social buzz, price momentum or a polished website. Anonymous teams are not always fraudulent, but hidden permissions, unlocked liquidity and concentrated supply are stronger warning signs than community hype.

How to research a token’s contract, liquidity and team before investing
Losses become less likely when a token’s contract permissions, liquidity lock and team identity hold up under scrutiny. Check the contract on Etherscan, BscScan or the chain’s main explorer, then review the verified code and recent owner actions. Verified code does not make a project safe, but unverified code blocks review and raises risk.
Check whether the owner can mint tokens, change fees, pause transfers, blacklist wallets or alter router settings after launch. If ownership is renounced, confirm those functions are disabled rather than moved to another privileged wallet. Security dashboards such as Token Sniffer can flag common risks, but they do not replace manual checks.
Inspect liquidity on the relevant decentralised exchange and confirm whether LP tokens are locked, burned or still held by insiders. A lock only helps if the amount is meaningful and the unlock date is visible. Finish with the team: named founders, linked profiles, past projects and public communication lower uncertainty, while anonymous teams with copied bios, fresh social accounts and no verifiable history deserve caution.
What to do if a rug pull happens and how to reduce the risk in future trades
Act fast on containment: stop interacting with the token, revoke approvals, and save transaction hashes. A rug pull rarely becomes recoverable on-chain, so the first goal is to prevent extra loss from unlimited approvals, fake recovery offers, or follow-up phishing.
Revoke permissions through a trusted approval checker such as Revoke.cash, then review wallet activity on Etherscan or the relevant chain explorer. If funds moved through a centralised exchange, report the wallet addresses and transaction IDs there at once. You can also file a report with Action Fraud in the UK, though recovery is often limited after assets are swapped or bridged.
For future trades, cut exposure before you buy. Keep positions small, avoid fresh launches with opaque teams, and treat unlocked liquidity or upgradeable contracts as a hard stop unless the risk is clear. If you provide liquidity, learn what impermanent loss is, since pool losses do not always come from fraud.
Use a separate wallet for speculative tokens and keep long-term holdings isolated. That limits damage if a contract turns hostile after purchase.
Frequently Asked Questions
What is a crypto rug pull and how does it differ from other crypto scams?
A crypto rug pull is a scam where developers attract buyers, then drain liquidity or abandon the project after taking investors’ funds. It differs from hacks and phishing because the fraud usually comes from the project’s own creators. Rug pulls often involve sudden token crashes, blocked selling, or vanished teams and websites.
How do crypto rug pulls usually work in decentralised finance and token launches?
The key point is that rug pulls exploit control, not just hype. In DeFi and token launches, developers attract buyers, build liquidity, then remove funds or use hidden contract functions to block selling, mint extra tokens, or drain the pool. Prices collapse once holders cannot exit.
Which warning signs can help identify a potential rug pull before investing?
Check the token’s liquidity lock, contract ownership, and wallet concentration before investing. Rug pulls often leave clear traces: unlocked liquidity, anonymous developers, sudden hype, no independent audit, and a few wallets holding most of the supply. Read the smart contract for minting, blacklist, or trading restriction functions.
Can a crypto rug pull happen on established exchanges, or is it mostly linked to new tokens?
If an exchange fully vets listings and controls liquidity, a classic rug pull is less likely. Most rug pulls involve new or thinly traded tokens, especially on decentralised exchanges where creators can remove liquidity or dump large holdings. Established exchanges reduce that risk, but they do not remove the chance of fraud or price manipulation.
What steps can investors take to reduce the risk of losing money to a crypto rug pull?
Most rug pulls share early warning signs: anonymous teams, unaudited contracts, locked selling, or liquidity the creators can remove at any time. Check those points before buying. Stick to established exchanges, read token contract permissions, and avoid projects promising guaranteed returns or sudden hype-driven gains.
