How to Spot a Rug Pull: 12 Red Flags to Check Before You Buy
A practical pre-buy checklist: 12 rug pull red flags across the contract, liquidity, holder list, and marketing, with the free tools to check each one.
In this article+
You spot a rug pull by checking the things a scammer needs in order to take your money: control over the token contract, control over the liquidity, control over most of the supply, and control over the story being told about the project. If the developers still hold any of those levers, they can pull them. Most of these checks take a few minutes with free tools like a block explorer, DEX Screener, and a token scanner.
Be clear about what that buys you. A token that passes every check below can still go to zero, and a token that fails one or two is not automatically a scam. These checks lower your odds of walking into an obvious trap. They are not proof of safety, and this article is education, not investment advice. We don't recommend buying any token.
Why these checks matter
Almost every rug pull uses one of three mechanisms: the developers drain the liquidity pool, they mint or dump a huge supply of tokens, or the contract stops ordinary holders from selling. We walk through each in detail in how rug pulls actually work. The red flags below map directly onto those mechanisms. Each one is a sign that somebody kept a lever they could use against you.
The good news is that blockchains are public. The contract code, the liquidity pool, and the holder list are all visible to anyone who knows where to look. The bad news is that scammers know this too, and the better ones design their tokens to pass automated scans. So treat every tool as one input, not a verdict.
Contract red flags
The token contract defines what the token can do and who can change it. This is where the most dangerous permissions hide.
1. Mint authority is still active (Solana) or a mint function exists (EVM)
If someone can create new tokens at will, they can print a large supply and sell it into the pool, crushing the price. On Solana, every SPL token has a mint authority. If that authority has not been revoked, the holder of that key can mint more. On Ethereum and other EVM chains, look for a mint function that the owner can call after launch.
How to check: On Solana, paste the token address into RugCheck, which reports whether mint authority is still enabled. On EVM chains, open the token on Etherscan (or BscScan, Basescan) and look at the Contract tab. Confirm the source code is verified, then look under Read Contract and Write Contract for functions like mint. Scanners such as GoPlus Token Security flag mintable tokens automatically.
2. Freeze authority is still active (Solana)
Solana tokens can also have a freeze authority, which lets its holder freeze any token account. A frozen account cannot send or sell. A developer who keeps freeze authority can let you buy and then lock you in while they exit. RugCheck shows this alongside mint authority. For most meme coins, there is no good reason for either authority to still be active.
3. Ownership is not renounced
On EVM tokens, the contract usually has an owner address with special powers: changing fees, pausing trading, excluding wallets from limits. Renouncing ownership (transferring it to a dead address) removes those powers. If the owner is still a live wallet, every owner-only function in the contract is still usable. Check the owner field under Read Contract on Etherscan, or let GoPlus or Token Sniffer report it. Note that renounced ownership only helps if there is no other back door, such as a separate privileged role or a proxy.
4. Hidden or adjustable buy and sell taxes
Many tokens charge a fee on each trade. A small, fixed, disclosed fee is common. The problem is a sell tax that is very high, or a tax the owner can raise at any time. A token can launch with a 5% sell tax and be switched to 99% once enough people have bought. Scanners report the current buy and sell tax, and GoPlus flags whether the tax is modifiable. If the tax can change, the number you see today means little.
5. Blacklist or pause functions
Some contracts let the owner add wallets to a blacklist that cannot transfer or sell, or pause all trading. Projects sometimes claim this is for stopping bots. It also lets the owner stop you from exiting. GoPlus reports blacklist, whitelist, and trading-pause capabilities. On Etherscan, look through Write Contract for functions with names like blacklist, setBots, pause, or enableTrading, keeping in mind that scammers rename functions to look harmless.
6. Proxy or upgradeable contracts
A proxy contract points to separate implementation code that can be swapped out later. That means the contract you review today may not be the contract you are holding next week. Upgradeable contracts have legitimate uses in larger protocols, but in a fresh meme coin they mostly mean the rules can change after you buy. Etherscan shows a Read as Proxy option on the Contract tab when a contract is a proxy, and GoPlus flags proxy contracts.
7. You can buy but you cannot sell (honeypot)
A honeypot is a token that lets anyone buy but only lets approved wallets sell. The chart looks healthy because only buys go through. Honeypot.is simulates a buy and a sell on Ethereum, BNB Chain, and Base and reports whether the sell would succeed and what tax it would pay. Token Sniffer and GoPlus also test for honeypot behavior. As honeypot.is itself warns, a clean result is a snapshot: a token that is sellable now can be changed later if the owner kept the power to do it.
Liquidity red flags
Liquidity is the pool of paired assets (usually ETH, SOL, or a stablecoin) that lets people trade the token. Whoever controls the liquidity-pool (LP) tokens can withdraw that pool.
8. Liquidity is not locked or burned
When developers add liquidity, they receive LP tokens that represent their share of the pool. If they still hold those LP tokens, they can pull the liquidity whenever they want, which is the classic rug pull. Two things reduce that risk: burning the LP tokens (sending them to an address nobody controls) or locking them in a time-lock contract. RugCheck reports how much of the LP is locked or burned for Solana tokens. On EVM chains, Token Sniffer and GoPlus report LP holders and whether they are lockers or dead addresses. DEX Screener shows the pool and links to its explorer page so you can look at the LP holders yourself.
9. Short lock duration, or liquidity that is tiny next to market cap
A lock is only as good as its expiry date. Liquidity locked for a few days or weeks protects you for a few days or weeks. Check when the lock ends, and treat an expiry that lines up with a hyped event or a roadmap date as a warning, not a comfort.
Also compare liquidity to market cap on DEX Screener, which shows both on every pair page. If a token claims a large market cap but has very little liquidity behind it, the price can move enormously on modest selling, and the market cap figure is largely theoretical. You would not be able to sell a meaningful position anywhere near the quoted price.
Holder and distribution red flags
Even with locked liquidity and a clean contract, a token can be rugged by whoever owns most of it. If a handful of wallets can dump into the pool, the lock does not help you much.
10. A few wallets hold most of the supply
Open the Holders tab on Etherscan or Solscan and look at the top 10 to 20 addresses. Ignore the liquidity pool address and known burn or lock addresses, then add up the rest. If the deployer wallet or a small group of wallets controls a large share, they can sell into you at any time. RugCheck lists top holders for Solana tokens, and Token Sniffer and GoPlus report holder concentration on EVM chains. Also click into the deployer address and see what else it has launched. A wallet that has deployed a long string of tokens that all died is telling you something.
11. Bundled or sniper wallets at launch
A common trick is to buy a big chunk of supply in the very first block or the first few seconds of trading, spread across many fresh wallets, so the holder list looks distributed even though one person controls it. Signs include many wallets that were funded from the same source shortly before launch, bought in the same block, and hold similar amounts. You can see this by sorting early trades on DEX Screener or the explorer and clicking through a few of the earliest buyer wallets to see where their funds came from. It takes some patience, but a cluster of wallets all funded by one address is hard to explain innocently.
Team and marketing red flags
Contract and liquidity checks tell you what the developers *can* do. The team and marketing tell you something about what they *plan* to do.
12. Pressure, paid hype, and claims you cannot verify
This last red flag is really a cluster. Any one of these alone is common in crypto. Several together should make you stop.
- Anonymous team plus urgency. Anonymous founders are normal in crypto, but pairing them with countdown timers, "last chance" messages, and pressure to buy before a listing is a pattern built to stop you from checking anything.
- Paid influencer shills. A wave of accounts posting the same token at the same time, often without disclosing payment, is marketing, not independent interest. Search the influencers' past calls and see how those tokens ended up.
- Fake or meaningless audits. An "audit" badge proves nothing on its own. Find the report on the auditor's own website, confirm it names this exact contract address, and read what it actually found. Some audits list serious issues that were never fixed.
- Copied whitepapers and websites. Paste a few distinctive sentences from the whitepaper into a search engine. Scam projects often reuse text and roadmaps from other tokens with the name swapped.
- Deleted questions and banned critics. If people asking about liquidity, taxes, or the dev wallet get muted or removed from the Telegram or Discord, the team is managing appearances instead of answering.
If you are already in a project that looks like this, it is worth quietly saving screenshots of the channel, pinned messages, and website now. Teams that rug usually delete everything within hours. Our guide to preserving evidence covers exactly what to capture.
Trading behavior that should worry you
Finally, watch how the token actually trades. None of these patterns proves a rug on its own, but they fit how rugs tend to look in the hours before one.
- Only green candles. A chart with almost no sells can mean a honeypot. Check whether any wallet other than the developers has sold successfully.
- Huge volume from few wallets. Wash trading between related wallets inflates volume to attract buyers. On DEX Screener, look at the number of unique buyers and sellers, not just the volume figure.
- Liquidity changes. A sudden drop in pool liquidity, or LP tokens moving out of a lock or to a new address, is often the first on-chain sign of a pull.
- Dev wallet selling in pieces. Steady sales from the deployer or top holders while the team talks up the roadmap is a classic slow rug.
A 10-minute pre-buy checklist
Here is the order we would run these checks in, using only free tools:
- Get the contract address from an official source and confirm it matches the pair on DEX Screener. Copycat tokens with the same name are common.
- On DEX Screener, note liquidity, market cap, pair age, and the ratio of buys to sells.
- Run a scanner: RugCheck for Solana; Token Sniffer, GoPlus, and honeypot.is for EVM chains.
- Confirm mint and freeze authority (Solana) or ownership, mint, blacklist, pause, and proxy status (EVM).
- Confirm the LP is burned or locked, and check when any lock expires.
- Open the Holders tab on the block explorer, exclude pool and burn addresses, and see how much the top wallets and the deployer control.
- Click into the deployer wallet and the earliest buyers to look for past launches and shared funding sources.
- Check the team's claims: audit reports on the auditor's own site, whitepaper text, and how the community channel handles hard questions.
If anything in that list comes back wrong, the simplest decision is to walk away. There is always another token, and none of them is worth ignoring a clear warning sign.
If it already happened
Plenty of people who lose money to a rug pull did check some of these things. Scammers study the same checklists and design around them. If you have already been rugged, the useful next steps are about evidence and timing: save your transaction hashes, capture whatever the team has not deleted yet, and report the loss. Our guide on what to do after a rug pull walks through it step by step.
Recoup is not a law firm, and recovery is never guaranteed. What we do is gather victims of the same project into one case, so the cost of tracing funds and pursuing the people behind a token is shared instead of carried by one person alone.
Frequently asked questions
Is there a rug pull checker that tells you if a token is safe?
+
No tool can tell you a token is safe. Scanners like Token Sniffer, GoPlus, honeypot.is, and RugCheck check for known risks such as active mint authority, unlocked liquidity, high or adjustable taxes, and sell restrictions. A clean result means no obvious trap was detected at the time of the scan. It does not rule out a custom back door, a team dumping its tokens, or a change made after you buy.
How can I tell if a token is a honeypot?
+
A honeypot lets you buy but blocks or heavily taxes your sell. Tools like honeypot.is simulate a buy and a sell and report whether the sell succeeds and what tax applies. You can also check the token's trade history for successful sells from ordinary wallets. Be aware that an owner who kept control of the contract can turn a sellable token into a honeypot later.
Does locked liquidity mean a token can't be rugged?
+
No. Locked liquidity stops the developers from withdrawing the pool until the lock expires, which removes one common rug method. They can still dump a large token supply into the pool, mint more if mint authority is active, raise taxes, or block sells if the contract allows it. Always check the lock's expiry date and the holder list alongside the lock itself.
What do mint authority and freeze authority mean on Solana?
+
Mint authority is the key that can create new tokens. Freeze authority is the key that can freeze any holder's token account so it cannot send or sell. If either is still active, whoever holds that key can inflate the supply or trap holders. For a typical meme coin, both should be revoked. RugCheck shows the status of both for any Solana token address.
Is an anonymous team always a sign of a scam?
+
Not always. Many legitimate crypto projects have pseudonymous developers. Anonymity matters most when it is combined with other red flags, like unlocked liquidity, concentrated holdings, pressure to buy fast, or claims that cannot be verified. An anonymous team also makes recovery much harder if something goes wrong, because there is no known person to hold accountable without on-chain tracing.
Lost money to a rug pull?
Put your case on record with other affected claimants.
Recoup documents your loss and evidence and organizes victims of the same project into one case. We are not a law firm, and recovery is never guaranteed.