← News & Guides
SECURITY/SEP 25, 2026·15 MIN READ

Crypto rug pulls: how liquidity drains and insider exits work

Rug pulls use liquidity drains, insider token dumps, or malicious contracts to extract value. Learn the warning signs before buying a new crypto token.

Crypto rug pulls: how liquidity drains and insider exits work

A new token launches. Social media fills with price charts, influencer posts, and promises about the roadmap. Buyers arrive, liquidity grows, and the chart moves higher.

Then the insiders cash out.

Sometimes they remove the trading pool. Sometimes they dump a concentrated token allocation into buyers. In more technical schemes, the contract prevents holders from selling or gives its owner hidden control over supply and transfers.

These incidents are usually grouped under one term: rug pull.

Key takeaways

  • A rug pull happens when insiders use their control over a project to extract value from buyers or users.

  • Common methods include removing liquidity, selling large token allocations, draining a treasury, and abusing contract permissions.

  • An audit, liquidity lock, or public team can reduce uncertainty, but none guarantees safety.

  • Token distribution and contract control often reveal more than a polished website or active community.

What is a rug pull?

A rug pull is a crypto exit scam in which a project's creators or insiders take funds, dump their holdings, or abuse privileged control at the expense of other participants.

The team may disappear afterward, but disappearance isn't required. Some projects remain online while insiders quietly extract liquidity, sell vested tokens through related wallets, or change contract settings against holders.

The term is often associated with tokens launched on decentralized exchanges because creating a token and opening an automated market maker pool requires little infrastructure. Rug pulls can also involve NFT collections, yield products, bridges, launchpads, and projects with centrally controlled treasuries.

Not every failed project is a rug pull. Poor execution, a security exploit, or an unsustainable business model can also destroy a token's value. The difference is intent and insider conduct, which may not be obvious from the price chart alone.

How rug pulls work

Liquidity withdrawal

A new token needs a trading pair before users can buy and sell it on a DEX. The team may pair its token with ETH, SOL, USDC, or another liquid asset and deposit both sides into a pool.

In return, the liquidity provider receives LP tokens or another form of ownership record. Whoever controls that position may be able to withdraw the pool's assets.

A liquidity rug commonly follows this sequence:

  1. The team launches a token and creates a liquidity pool.

  2. Promotion and early buying push up the quoted price.

  3. Traders add valuable assets to the pool as they buy the new token.

  4. The team uses its LP position to remove most of the liquidity.

  5. Holders are left with tokens that have little or no executable market.

The chart may show a price, but there may not be enough liquidity to sell at anything close to it.

Insider token dump

Not every rug requires liquidity to be removed.

If the team, deployer, or connected wallets control a large share of the supply, they can sell those tokens into public demand. The pool still exists, but its valuable side is drained as insiders exchange their tokens for ETH, SOL, or stablecoins.

This can resemble an ordinary market selloff. On-chain analysis may be needed to trace funding relationships, token transfers, and coordinated wallets.

A disclosed token allocation isn’t automatically suspicious. The problem is concentrated supply combined with weak vesting, hidden wallets, or misleading claims about circulation.

Malicious contract controls

A token contract may give its owner powers that ordinary buyers don’t have.

Potentially dangerous functions include the ability to:

  • Mint additional supply

  • Change transfer taxes

  • Block specific wallets from selling

  • Pause transfers

  • Restrict transaction sizes

  • Exempt insiders from limits

  • Replace contract logic through a proxy upgrade

  • Redirect fees or treasury funds

A honeypot contract allows purchases but blocks or heavily penalizes sales. Some contracts apply a near-total sell tax rather than rejecting the transaction outright.

A malicious contract can’t normally take unrelated assets from a wallet without authorization. The common route is to trick a user into signing an approval or transaction that grants the contract permission to move specific tokens.

Published or “verified” source code isn’t proof of safety. Verification usually means the displayed code matches deployed bytecode. It doesn’t mean the logic is harmless.

Treasury drain and project abandonment

Some teams raise funds through token sales, NFT mints, or protocol deposits, then transfer the treasury to wallets they control.

The project may shut down immediately. In slower exits, development stops, support channels become inactive, and insiders continue selling while claiming that work is ongoing.

This type of rug may use perfectly ordinary contracts. The risk comes from centralized custody, weak governance, and false claims rather than hidden code.

Rug pull versus pump-and-dump

The two can overlap, but they aren’t identical.

A pump-and-dump relies on promotion and coordinated selling. Promoters create demand, insiders sell into it, and the price collapses.

A rug pull usually involves additional project-level control. The insiders may own the liquidity, manage the treasury, control contract permissions, or hold enough supply to determine whether other users can exit.

A token can be both. A team may pump the price through marketing, dump its allocation, and then remove the remaining liquidity.

Warning signs to check

One warning sign rarely proves fraud. Several appearing together should change how much risk you are willing to take.

Concentrated token ownership

Check how much supply is held by the deployer, team wallets, treasury, and largest holders.

A block explorer can show the largest addresses, but the list needs interpretation. Exchange wallets, liquidity pools, bridges, and burn addresses may appear as large holders without representing insider ownership.

The reverse problem also exists: one insider can split tokens across many wallets. A holder chart may look decentralized even when control is concentrated.

Removable or short-term liquidity

Find out who owns the LP position and whether it is locked, burned, or controlled by a multisig.

If liquidity is locked, check the amount, unlock date, locker contract, and beneficiary. A small locked position doesn’t protect a much larger unlocked pool. A short lock may only postpone the withdrawal.

Liquidity locks help with one specific risk. They don’t stop insider dumping, malicious minting, tax changes, or treasury theft.

Privileged contract roles

Look for owner, admin, operator, minter, pauser, blacklist, and upgrade roles.

“Ownership renounced” can be misleading if another privileged role remains active or the contract is upgradeable through a separate proxy administrator. Check the deployed architecture rather than relying on a badge or social media claim.

Missing or weak vesting

Team and investor allocations should have clear unlock terms.

Check whether vesting happens on-chain and whether the schedule can be changed. A document promising a multiyear lock means little if the tokens are already liquid in a team-controlled wallet.

Large upcoming unlocks aren’t proof of a rug. They do create potential sell pressure that buyers should understand before entering.

Unaudited or recently changed code

An independent audit may catch vulnerabilities and dangerous permissions, but the report must match the deployed contract.

Check the contract address, code version, audit date, scope, unresolved findings, and whether the project changed its code afterward. An old audit of one component doesn’t cover a new token, proxy upgrade, bridge, or staking contract.

An audit is evidence, not insurance.

Unrealistic claims

Guaranteed returns, fixed high yields, and vague descriptions of revenue deserve scrutiny.

Claims about investors, partnerships, audits, and exchange listings should be confirmed through the other party's official channels. A logo on a project website proves nothing.

Heavy promotion can also hide weak fundamentals. Paid influencer coverage is marketing, even when it is presented as independent analysis.

Buying works, but selling doesn’t

Before making a meaningful purchase, check whether other users are successfully selling the same token.

Contract simulation and token scanners may identify honeypot behavior, high taxes, or transfer restrictions. They can miss logic that activates later, changes through an upgrade, or treats selected wallets differently.

A successful small sale is useful evidence. It isn’t a permanent guarantee that future sales will work.

How to investigate a token before buying

Start with the exact contract address. Token names and tickers are easy to copy, so never rely on branding alone.

Then review:

  1. Contract permissions: Who can mint, pause, blacklist, change fees, or upgrade the code?

  2. Supply distribution: How much belongs to connected or newly funded wallets?

  3. Liquidity ownership: Who controls the LP position, and when can it be withdrawn?

  4. Vesting: Are team and investor unlocks enforced on-chain?

  5. Trading activity: Is volume spread across real users, or concentrated among a small group of wallets?

  6. Audit coverage: Does the report cover the deployed address and current code?

  7. Treasury control: Can one person move project funds, or is approval shared through a multisig?

Read the whitepaper if one exists, but verify its claims against deployed contracts and on-chain activity. Documentation describes what the team says the system does. The contract shows what it can do.

Reducing the damage if your analysis is wrong

No checklist can prove that a new token is safe. Insider relationships may be hidden, governance can change, and apparently harmless contracts can interact with riskier external components.

Position size still matters.

Avoid committing money you can’t afford to lose to an unproven token. Revoke approvals you no longer need, and avoid signing transactions you don’t understand. For unfamiliar contracts, use a separate wallet with limited funds rather than your primary holdings.

Be careful with urgency. A countdown, presale cap, or rapidly rising chart is designed to shorten the time available for scrutiny. Missing a trade is cheaper than discovering that the exit was never available.

Are rug pulls illegal?

Fraud, theft, market manipulation, and deceptive fundraising can violate criminal or civil law in many jurisdictions. Whether a specific rug pull is illegal depends on the facts, local law, and how the project was marketed and operated.

Enforcement is difficult when teams are pseudonymous, wallets cross several networks, and participants live in different countries. Technical decentralization doesn’t automatically remove legal responsibility, but it can make the responsible parties harder to identify.

For buyers, legal recourse is uncertain and usually slow. The useful questions come before the purchase: who controls the supply, who controls the liquidity, and what can the contract owner change?

If those answers aren’t available, the uncertainty is part of the trade.

#Security#Scams#DeFi#Tokens#Rugpulls