Cointime

Download App
iOS & Android

How to Detect and Avoid Rug Pulls

Validated Project

In this post, we’ll explain “rug pulls,” a common type of crypto scam targeting primarily retail investors.

A “rug pull,” derived from the expression “pulling the rug out” — suddenly taking away support, — is a type of crypto scam in which a project’s team pumps its token before disappearing with the funds received from retail investors.

According to a report from the blockchain risk monitoring firm Solidus Labs, 117,629 rug pulls occurred in 2022, a 41% increase over the previous year, a sign that this type of scam is on the rise and has the potential to thrive.

Meanwhile, not all kinds of rug pulls are technically illegal. Still, those that are classified as hard rug pulls can be pursued under the law.

Hard rug pulls: liquidity theft and scam tokens

Liquidity theft involves creating a liquidity pool within a scam project and luring users to add pairs of tokens to it by promising a triple-digit APY. A project of that kind also typically releases a new token that is heavily promoted. Thus, hoping for substantial passive income from the project, users add their tokens to the pool and receive LP tokens in exchange. Eventually, the team responsible for maintaining the pool withdraws the tokens and exits, abandoning investors with worthless LP tokens and no way to get their funds back.

Technical manipulation with a smart contract algorithm is another type of a hard rug pull, enabling stealing from investors in various ways. For example, the “approve” part of the code needed for the smart contract to spend a token within a transaction can be modified in a way that allows users only to buy the token. In this scheme, those who invested in the scam token of a hyped project on its rise are left with nothing after the developers disappear — the price of the token drops, and the holders cannot resell it. Also, worthless tokens can contain a 99% buy or sell fee, as well as other surprises.

Soft rug pulls: token dumping

A pump-and-dump scheme relies on artificially inflating a project’s value and dumping the team’s assets when the price is at its peak, instantly devaluing the tokens of tricked investors.

To facilitate a scheme of this kind, the team can hold on to a disproportionately large number of tokens since the project’s launch. How significantly the token price falls, depends on how many tokens the team throws onto the market at once. Technically, these actions are not illegal, but they are certainly unethical. Sometimes, when promoting a project, developers may even promise donations to charity, eventually failing to do that and simply cashing in on people buying up the token of a project that no one ever intended to develop.

Some rug pull schemes can mislead even risk experts. For example, when the price of the Flare project fell by more than 95%, opinions split on whether it was a rug pull or an exploit, the latter version promoted by the project’s team. Meanwhile, the fact that about $17 mln Flare tokens were received by addresses associated with the project’s developers was an argument in favor of a scam.

Day of Defeat also claimed to be hacked, with its value decreasing by more than 96%. All project assets worth over $1.35 mln were withdrawn to external wallets. Once the funds disappeared, the project claimed that third parties had compromised it.

Basically, these schemes follow more or less the same scenario, involving a project pumping up its price and then swapping its tokens for liquid assets and transferring them to external wallets. Usually, the project’s social media accounts and websites also end up being removed.

This is exactly what the DeFi project DRAC Network did in mid-2022, dropping the price of the TEDDY token by 99,4% and transferring $10,000 in BNB and $2 mln in BUSD to Binance. Quantitative trading company MGNR went the same way, draining a total of $52 mln in USDC to Coinbase and Genesis Trading, then deleting all of its tweets.

Sometimes, rug pulls combine multiple types of scam, as was the case with one of the most notable fraudulent projects in scam history, SQUID. The developers, who have not yet been identified, attracted many investors by offering a game based on the popular South Korean TV series Squid Game but not officially affiliated with it. Their SQUID token contained hidden modifications that blocked its resale. Therefore, none of the holders could get rid of their tokens after the development team withdrew all the liquidity from the project, which was worth about $3.3 mln.

How to detect a rug pull

Lack of audit: You should only join liquidity pools of projects that have been audited by a trustworthy security firm, no matter how quick and large returns the project promises.

Disproportionate distribution: The white paper, as one of the essential documents of any project, contains its token distribution program. If a large number of tokens is held by the project team, it’s a potential red flag. Block explorers like Etherscan allow users to check which wallets hold specific tokens. Block explorers also show the total supply and the number of transfers. If the number of wallets holding the tokens is small while the token’s value is skyrocketing, there is obviously some price manipulation happening. Ideally, there shouldn’t be more than 20% of the total new token amount in the top 10 wallets.

Absence of liquidity lock: If liquidity is locked in a project, no one can withdraw it instantly. When providing tokens to a pool, temporary locking implies a period that can vary and reach five years, but its complete absence is also a red flag.

Using only reputable platforms can be a security guarantee for those who don’t want to dig into block explorers or white papers of new projects. The same applies to tokens. A hidden code function is unlikely to be visible to a non-expert user. Therefore, at the very least, it is worth it to make sure that you are dealing with tokens having transactions behind them. There is also an option of trading with some small token amount in a test mode or using online rug pull-detecting tools to analyze tokens and platform code.

https://blog.1inch.io/avoiding-rug-pulls-a051f092e214

Comments

All Comments

Recommended for you

  • Crypto trading ecosystem LazyBear completes strategic financing of 4 million USDT

    The cryptocurrency trading ecosystem LazyBear announced the completion of a strategic financing of 4 million USDT, with participation from Gogeko Labs, DWF Labs, Shadow Labs, Salad Labs, Bees Network, REI Network, IBIT, Crypto Bullish, SYNBO Protocol, Bazaars, Sypool, Bitcoin Gbox, GemX Crypto, Wikibit, and others. It is reported that LazyBear is a cryptocurrency trading ecosystem for retail traders, committed to providing users with an industry-leading, low-fee, inclusive, and enjoyable trading experience.

  • Tether Invests $200M in Majority Stake of Brain-Computer Interface Company Blackrock Neurotech

    Tether's venture capital division, Tether Evo, has invested $200 million to acquire a majority stake in Blackrock Neurotech, a company that develops medical devices powered by brain signals to aid those impacted by paralysis and neurological disorders. The investment will fund the roll-out and commercialization of the devices and research and development purposes. Tether, the issuer of stablecoin USDT, has recently established four divisions to expand beyond stablecoin issuance and believes in nurturing emerging technologies with transformative capabilities. Paolo Ardoino, CEO of Tether, stated that Blackrock Neurotech's brain-computer-interfaces have the potential to open new realms of communication, rehabilitation, and cognitive enhancement.

  • Turnkey Raises $15M Series A Funding to Expand Wallet Infrastructure for Crypto Developers

    New York-based Turnkey has secured $15m in Series A funding led by Lightspeed Faction and Galaxy Ventures, with participation from Sequoia, Coinbase Ventures, Alchemy, Figment Capital, and Mirana Ventures. The company, founded by the team behind Coinbase Custody, offers a wallet infrastructure that enables developers to build anything that involves a wallet or cryptographic transaction. Turnkey plans to use the funds to expand operations and development efforts, and has already integrated with companies including Alchemy, Dynamic, Goldfinch, Halliday, Thunder Terminal, and Kinto. The product suite offers embedded and smart wallet services, biometric passkey logins, and seamless onboarding experiences for users.

  • Thai regulator to crack down on deceptive cryptocurrency ads

    Cryptocurrency advertisements that contain false, exaggerated, distorted, concealed, or misleading information violate Thai regulations. Regulatory agencies in major cryptocurrency markets have also taken similar measures to minimize investment losses in cryptocurrencies. For example, the UK Financial Conduct Authority (FCA) issued 450 illegal cryptocurrency advertising alerts in 2023 alone. In addition, in November 2023, the Spanish National Securities Market Commission, the main securities market regulatory agency, condemned fraudulent cryptocurrency asset promotion activities on X and reiterated the company's obligation to comply with local laws. The Thai Securities and Exchange Commission reminded cryptocurrency exchanges to include appropriate warnings about investment risks and to avoid attracting new users through special promotions. He warned that violating the above guidelines would result in "legal punishment".

  • Volume 180: Digital Asset Fund Flows Weekly Report

    US$435 outflows continue as incumbent ETF issuers continue to see withdrawals

  • Russia to impose cryptocurrency restrictions, exempting miners and central bank projects

    Russia will implement cryptocurrency restrictions, exempting miners and central bank projects. Starting from September 1st, Russia will impose strict restrictions on the circulation of cryptocurrencies such as Bitcoin, only allowing the issuance of digital financial assets within its jurisdiction. Anatoly Aksakov, Chairman of the Financial Market Committee of the State Duma, led this initiative. This is part of a wider government effort to control the cryptocurrency ecosystem in the face of escalating geopolitical tensions. Aksakov stated that the upcoming legislation aims to restrict non-Russian cryptocurrency transactions to strengthen the dominance of the ruble. Meanwhile, recent reports indicate that Russian entities have used cryptocurrencies, particularly Tether's USDT, to purchase key components for military technology.

  • Ethereum stablecoin transaction volume exceeds $1 trillion so far in April, setting a new record

    On April 29th, The Block data shows that as of April 28th, the trading volume of stablecoins on the Ethereum blockchain reached a record high of $1.08 trillion in April, with DAI trading volume ranking first at $578.07 billion, followed by USDC at $268.15 billion in second place, and USDT at $198.62 billion in third place.

  • Shenyu: Up to one billion users' cloud input methods may have leaked input content. Please take immediate measures to reduce the risk.

    On April 29th, Cobo co-founder and CEO Shen Yu wrote on X platform that the cloud input method used by up to one billion users may have leaked input content. If you have entered mnemonic words or other sensitive information through any of the following cloud input methods, please take immediate measures to reduce the risk.

  • EU member states prepare to enforce landmark crypto law, MiCA

    The European Union is set to enforce MiCA, a crypto law that mandates national regulators to license and supervise service providers. While the regulation is EU-wide, countries can implement slightly different technical standards that crypto firms must adhere to. MiCA's specialized rules for stablecoin issuers will take effect in a few months, followed by licensing and other requirements for crypto firms broadly in December. Each jurisdiction must transpose the EU regulation into local law, select which of their regulators will oversee crypto, and prepare to authorize token issuers and other service providers. Regulators are facing challenges in implementing the new legislation, particularly in terms of licensing requirements, and each country's crypto industry has its own concerns about implementation and proposed laws.

  • The total open interest of BTC contracts on the entire network dropped to $29.83 billion

    According to Coinglass data, the total open position of BTC futures contracts on the entire network is 478,180 BTC, equivalent to 29.83 billion US dollars.