What Is a Rug Pull in Crypto? The Complete 2026 Guide

Last updated: April 2026 | Estimated reading time: 27 minutes

What Is a Rug Pull in Crypto?

What is a rug pull in crypto? A rug pull is a scam where developers create a cryptocurrency token or project, attract investors, and then deliberately drain the funds — leaving buyers with worthless tokens and no recourse. The term comes from the phrase “pulling the rug out from under someone.” In crypto, it describes the moment developers vanish with investor money, usually within hours or days of a project’s launch.

Understanding what a rug pull is in crypto matters more than ever in 2026. Rug pull losses peaked at approximately $5.06 billion in 2021 and have resurged significantly, with Chainalysis tracking $94.8 million in confirmed rug pull losses in 2024. Additionally, rug pulls account for approximately 35% of all crypto scam losses, with over $2.8 billion lost across all chains in 2025 alone.

The scale of the problem has shifted too. Solidus Labs reported that between January 2024 and March 2025, over 7 million tokens were deployed on Pump.fun with at least five trades. Only 97,000 maintained liquidity above $1,000 — meaning 98.6% collapsed into worthless pump-and-dump schemes. Additionally, over 62% of meme coins launched in 2025 were flagged as potential rug pulls within 30 days of creation.

Furthermore, on Raydium, a Solana-based DEX, 93% of liquidity pools showed signs of rug pulls and pump-and-dumps, with a median rug pull value of $2,832 according to Solidus Labs. These figures point to a fundamental shift — away from high-value, one-off scams toward industrialised, high-volume, low-value token fraud deployed at machine scale.

What makes a rug pull uniquely dangerous compared to other crypto risks is its source. The attacker in a rug pull is an insider — not an outsider. Hacks exploit code vulnerabilities from outside a project. Rug pulls exploit trust from inside. The people you trusted to build the project are the people stealing from you.

Before investing in any new token or DeFi project, run it through the Cryptosmap Trust Engine — a free six-layer on-chain safety check that flags rug pull signatures, honeypot contracts, and unverified code in under 60 seconds.


The Three Types of Rug Pull in Crypto

Not every rug pull works the same way. There are three primary types, each with a different mechanism, a different detection approach, and a different risk profile. Knowing what type of rug pull you are looking at determines which tools you use to check for it.

Type 1 — Liquidity Theft (Hard Rug Pull)

A liquidity theft rug pull is the most sudden and total form of the scam. Here is how it works.

When a token is launched on a decentralised exchange (DEX) like Uniswap, PancakeSwap, or Raydium, a liquidity pool is created. This pool holds two assets — typically the new token paired with ETH, BNB, or SOL. The pool is what allows buyers and sellers to trade. Without it, the token cannot be exchanged for anything.

In a liquidity theft rug pull, developers remove all assets from this pool in a single transaction. The removal happens on-chain and takes seconds. The moment it completes, the token price drops to zero. Every investor’s balance becomes worthless simultaneously.

The Squid Game Token collapse exemplifies this type perfectly. In November 2021, developers drained $3.38 million from the liquidity pool and disappeared, leaving the token worthless. The website and social media accounts vanished overnight — making it the textbook example of a liquidity theft rug pull.

The key detection tool for this type is liquidity lock verification. If the developer holds the liquidity pool tokens without locking them in a time-locked contract, they can remove all liquidity instantly. Check for locks on Etherscan (ERC-20 tokens) or RugCheck (Solana tokens) before buying any token.

Type 2 — Sell Restriction (Honeypot Scam)

A honeypot is a rug pull variant where the smart contract allows investors to buy the token freely but blocks or heavily taxes selling. The token’s price appears to rise — sometimes dramatically — because only buying is possible. Investors watch their paper gains grow, attempt to sell, and discover they cannot.

The Squid Game Token’s smart contract locked over 40,000 wallet holders out due to blocked sell functionality coded directly into the contract. Investors could watch their balances increase in real time. However, none of them could exit, because the exit had been removed at the code level before the token even launched.

Honeypots are detectable before you invest. Running a token’s contract address through Honeypot is simulates a sell transaction without risking real funds. Specifically, if the simulation shows the sell will fail or the sell tax exceeds 10%, walk away. This check takes 30 seconds and would have prevented every honeypot loss ever recorded.

Type 3 — Developer Token Dump (Soft Rug Pull)

A soft rug pull does not require malicious smart contract code. Instead, developers or early insiders simply sell their large token allocation on the open market — either gradually or all at once — crashing the price as they exit.

Soft rug pulls operate through behavioural patterns rather than coded exploitation. In these schemes, developers or insiders gradually withdraw from projects by cashing out tokens, halting development, or ghosting community communications. These scams are subtler and often masquerade as legitimate project failures rather than outright fraud.

The Hawk Tuah Token demonstrates modern meme-based soft rug pulls. Following the viral meme, the project collapsed within days. Token pumping on social media preceded insider dumps that drained liquidity — weaponising meme culture for an exit scam.

Detecting a soft rug pull requires checking token distribution. Specifically, look at the top holders list on the relevant block explorer. If early wallets — particularly developer or team wallets funded at token creation — hold a large, unlocked percentage of the supply, they can crash the price the moment they decide to sell.


How a Rug Pull Works — Step by Step

Understanding what a rug pull is in crypto becomes clearer when you follow the process from creation to collapse. Here is the standard playbook, step by step.

Stage 1 — Token Creation (Days 1–3)

The scammer deploys a smart contract for a new token on a low-cost blockchain — most commonly Solana, BNB Chain, or Base. The majority of rug pulls happen on Solana and BSC, where deployment costs are lowest — sometimes under $10 to launch an entire token. The smart contract may include hidden functions: sell restrictions, hidden mint capabilities that allow unlimited new token creation, or ownership controls that were never genuinely transferred away from the developer.

Stage 2 — Hype Generation (Days 3–14)

The developers create social media presence — a Twitter/X account, a Telegram group, a Discord server — and begin generating artificial excitement. Social media drove 80% of rug pull traffic in 2025, with Telegram and Discord dominating promotion. In many cases, they pay influencers — who may or may not disclose the payment — to post about the token. They post roadmaps with ambitious promises, affiliate with real projects to borrow credibility, and manufacture social proof through bot-inflated follower counts.

Stage 3 — Liquidity Addition and Initial Price Action

The developers add liquidity to the DEX pool — creating the trading pair that allows public buying. They may seed the pool with a small amount, knowing retail buyers will add much more. As word spreads and buyers enter, the token price rises. This rising price creates its own momentum — more buyers see the chart going up and enter, pushing it higher still. The paper gains look compelling.

Stage 4 — The Exit

The timing of the exit varies by rug pull type. In a hard rug pull, developers remove all liquidity in a single transaction the moment they decide the pool is large enough — sometimes within hours of launch, sometimes after several weeks of building momentum. In a soft rug pull, insiders sell their allocation over days as the price rises, then disappear. In a honeypot, buyers accumulate tokens they cannot sell while the developer watches the pool grow, then drains it at their leisure.

Stage 5 — The Disappearance

Within minutes of the exit, the project’s website goes offline, the Discord server is deleted, the Telegram group is archived or deleted, and the Twitter/X account either goes dark or is abandoned. Stolen funds are typically transferred immediately to a crypto mixer like Tornado Cash — an anonymising service — to break the on-chain trail. Victims are left with tokens worth zero and no way to contact the team.

Therefore, the single most important moment in the rug pull timeline is Stage 1 — because every detection tool discussed in Section 6 of this guide operates on data that exists at token creation. The smart contract is written, the liquidity lock (or lack of one) is set, and the token distribution is established before a single retail buyer enters. Consequently, all of these signals are visible to you before you spend a dollar.


The Biggest Rug Pulls in Crypto History

Real case studies bring the abstract mechanics of a rug pull into sharp relief. Additionally, each of these cases teaches a specific lesson about what to look for.

Squid Game Token — $3.38 Million (November 2021)

The Squid Game Token (SQUID) launched on October 26, 2021, riding the hype of Netflix’s Squid Game series. Promising a play-to-earn game, it falsely claimed ties to the show. The token surged from $0.01 to $2,861, attracting 43,000+ investors. However, investors could buy SQUID but were unable to sell it — a honeypot restriction embedded in the smart contract from day one.

A few users began investigating and discovered the project’s founders were absent from all major platforms like LinkedIn. Those who tweeted about their concerns were blocked, while the Telegram and Discord groups were suddenly shut down. Further review of the whitepaper revealed several outlandish claims that were impossible to verify.

On November 1, developers drained $3.38 million and abandoned the project. The lesson: a honeypot check on Honeypot.is before purchase would have identified the sell restriction within 30 seconds. No buyer needed to lose anything.

AnubisDAO — $60 Million (October 2021)

In October 2021, AnubisDAO executed one of the fastest rug pulls in crypto history. The project raised approximately $60 million worth of Ethereum in just 20 hours before the developers drained the funds. What made this case particularly shocking was the speed — most rug pulls build momentum over weeks, but AnubisDAO collapsed within a single day of launch.

The project had no website, no whitepaper, and no verified team. Nevertheless, it attracted $60 million purely through social media hype and the credibility borrowed from legitimate projects in its ecosystem. The lesson: the size of an investment round is not evidence of legitimacy.

Frosties NFT — $1.1 Million (January 2022)

Launched on January 7, 2022, Frosties was an ice-cream-themed collection of 8,888 NFTs that built a sizable Discord community and promised collectors merchandise, raffles, and a longevity fund. Once the collection sold out, the project’s website and Discord disappeared, and the funds were transferred to various wallets.

Notably, this case became the first NFT rug pull prosecution in US history. On March 24, 2022, prosecutors from the Southern District of New York arrested and charged founders Ethan Nguyen and Andre Llacuna with conspiracy to commit fraud and conspiracy to commit money laundering. The case established that rug pull developers can face criminal prosecution — a precedent that has shaped subsequent enforcement actions.

Evolved Apes — $2.7 Million (September 2021)

Evolved Apes’ creator, operating anonymously as Evil Ape, managed to steal 798 ETH ($2.7 million) from investors just one week after the collection’s launch. The project had promised a fighting game akin to Axie Infinity. However, the game was never built. Evil Ape’s Twitter account and the project website vanished simultaneously. The NFTs remain in circulation on OpenSea — worthless digital art with no utility.

The lesson from Evolved Apes is specific: an anonymous team combined with ambitious, unverifiable utility promises is a documented rug pull precursor. Additionally, the fact that the NFTs remained technically on-chain while having zero value demonstrates that blockchain permanence does not equal investor protection.

ZKasino — $33 Million (April 2024)

ZKasino was a crypto gambling platform that ran a bridge-to-earn campaign, promising that users could deposit ETH — over 10,500 in total, worth about $33 million from around 10,000 investors — earn ZKAS token rewards, and withdraw their original ETH within 30 days of mainnet launch.

The ETH was never returned. Instead, developers converted the deposited funds to ZKAS tokens at an arbitrary rate and refused withdrawals. Furthermore, critics including Vitalik Buterin pointed out that the project’s claimed use of zero-knowledge proofs was mostly marketing hype — technical language used to manufacture credibility for a non-technical audience.

MetaYield Farm — $290 Million (February 2025)

In February 2025, MetaYield Farm executed the largest rug pull of the year, stealing $290 million before vanishing. The project operated as a DeFi yield farming protocol promising high annual returns. It attracted significant capital from both retail and institutional participants before the developers executed a complete liquidity drain. As of April 2026, none of the stolen funds have been recovered.


Rug Pull Red Flags — 15 Warning Signs to Check Before You Invest

Knowing what a rug pull is in crypto is the foundation. Additionally, knowing how to spot one before it happens is the protection. Every red flag below is derived from documented rug pull cases — not theoretical risk. Each one appeared in at least one of the case studies above.

Red Flag 1 — Unlocked liquidity This is the single most critical check. If the developer holds the liquidity pool tokens without locking them in a time-locked contract, they can remove all liquidity instantly. Verify locks on Etherscan, RugCheck, or DEXTools before buying. Developers should lock liquidity for a set period using a time-lock contract to prevent draining funds. Anything under 90 days is a warning. No lock at all is an exit.

Red Flag 2 — Anonymous or unverifiable team Legitimate crypto projects typically have publicly identified teams with verifiable experience. Anonymous teams face no accountability if the project collapses or turns out to be fraudulent. Always research team members on LinkedIn, Twitter, and GitHub to confirm their track records. Anonymity alone is not automatically a red flag — Bitcoin’s Satoshi Nakamoto was anonymous. However, anonymity combined with any other item on this list significantly elevates the risk.

Red Flag 3 — No independent security audit Every legitimate DeFi project commissions a security audit from a reputable firm — CertiK, Hacken, Trail of Bits, or OpenZeppelin. Specifically, verify any audit on the auditing firm’s own website, not the project’s homepage. Check the audit date, scope, and whether the team addressed flagged issues. A badge on a homepage is not a verified audit.

Red Flag 4 — Unverified smart contract Go to the relevant blockchain explorer — Etherscan for ERC-20 tokens, Solscan for Solana, BscScan for BNB Chain — and confirm the contract is verified. Unverified contracts mean the code has not been published for independent review. Therefore, nobody outside the developer team knows what the contract actually does.

Red Flag 5 — Concentrated token distribution Check the top holders on the block explorer. If fewer than ten wallets hold more than 30% of the circulating supply (excluding known exchange addresses), the price can be crashed instantly by coordinated selling from those wallets. Additionally, check whether multiple top holders were funded from the same source transaction — a documented rug pull setup technique.

Red Flag 6 — No sell transactions on the chart On DEXTools or DexScreener, a price chart showing only green (buy) candles with no red (sell) candles is a classic honeypot signature. Legitimate trading always produces mixed activity. Consequently, a token with exclusively bullish candle patterns over multiple hours has no genuine two-sided market.

Red Flag 7 — Hidden mint function in the contract A hidden mint function allows the developer to create unlimited new tokens after launch, diluting existing holders to zero. This is detectable through GoPlus Security API or TokenSniffer — both of which flag hidden mint capabilities as a high-risk finding. Furthermore, it cannot be spotted by looking at the chart or the website.

Red Flag 8 — Ownership not genuinely renounced Many projects claim to have renounced contract ownership — meaning no one can change the contract after deployment. However, some use proxy contracts or multisig arrangements that preserve effective control while appearing to renounce it. Verify renouncement on the blockchain explorer and check whether any proxy ownership patterns remain.

Red Flag 9 — Social media community with no critical discussion Legitimate projects have communities where users ask hard questions, raise concerns, and debate the tokenomics. Additionally, they moderate without censoring. A Telegram or Discord where only positive sentiment is visible, where critical questions are deleted, and where all comments sound identical suggests either heavy moderation or bot-populated channels.

Red Flag 10 — Whitepaper is vague, plagiarised, or absent Paste a key paragraph from the whitepaper into Google. If it appears in another project’s documents, stop immediately. Moreover, a whitepaper that cannot clearly explain the technology, tokenomics, use case, and vesting schedule in specific terms is either deliberately evasive or incompetently written — neither of which belongs in your portfolio.

Red Flag 11 — Promises of guaranteed or unusually high returns No legitimate investment guarantees returns. Additionally, returns that are specific — “12% weekly,” “5% daily” — and unaccompanied by a clear, technically credible explanation of how they are generated do not exist as described.

Red Flag 12 — Aggressive urgency and FOMO marketing “Last chance,” “only 48 hours left,” “whitelist closes tonight” — scammers manufacture urgency specifically to prevent you from researching carefully. Legitimate projects do not expire in 24 hours. Therefore, any pressure to invest immediately is a reason to pause, not to hurry.

Red Flag 13 — The token launched on Pump.fun with no roadmap Over 7 million tokens were deployed on Pump.fun between January 2024 and March 2025 — 98.6% of which collapsed into worthless pump-and-dump schemes. Pump.fun itself is a legitimate launch platform, but the base rate of fraud among tokens launched there without any additional documentation, roadmap, or verified team is extremely high.

Red Flag 14 — Multiple top holders funded from the same wallet This is detectable using Bubblemaps — a free visual cluster analysis tool that shows whether multiple top holder wallets share a common funding source. Specifically, if multiple wallets in the top 20 holders were all funded from a single transaction, they are almost certainly controlled by the same person.

Red Flag 15 — Project uses another brand’s IP without permission The Squid Game Token used Netflix’s branding without any affiliation. This type of unauthorised brand association is a documented rug pull tactic used to create false credibility rapidly. Moreover, it is illegal — which means the developer already has no concern for legal compliance before stealing investor funds.


How to Check Any Token for Rug Pull Risk in 6 Steps

This is the exact verification framework Cryptosmap applies to every token review. Use it before investing in any new or unfamiliar token. Every step uses free tools accessible to anyone.

Step 1 — Run the Contract Through Honeypot.is

Go to Honeypot.is and paste the token’s contract address. Select the correct blockchain. The tool will simulate a buy and sell transaction without using real funds and return one of three results: not a honeypot, a honeypot, or a warning. If the result is anything other than “not a honeypot,” stop immediately.

This step costs 30 seconds and catches every sell-restriction rug pull before you spend a dollar.

Step 2 — Check Liquidity Lock Status

For ERC-20 tokens, go to Etherscan and search the contract address. Navigate to the token tracker and look for liquidity lock events. Additionally, use Team Finance or Unicrypt to verify active locks. For Solana tokens, use RugCheck.xyz. For BNB Chain tokens, use PancakeSwap’s liquidity section alongside BSCheck.

A lock of under 30 days is a warning. No lock at all means the developer can drain the pool at any moment. Therefore, do not invest in any token where liquidity is not locked for at least 90 days.

Step 3 — Analyse Token Distribution on Bubblemaps

Go to Bubblemaps, select the correct blockchain, and paste the contract address. The tool generates a visual cluster map of wallet relationships. Specifically, look for clusters of wallets that share a common funding source — these indicate coordinated holdings likely controlled by the same team.

Additionally, check the top holders list on the relevant block explorer. No single non-exchange wallet should hold more than 5% of the total supply. Furthermore, the combined developer and team allocation should be subject to a documented vesting schedule.

Step 4 — Read the Audit on the Auditor’s Own Website

Search for the project name on CertiK.com, Hacken.io, or any other reputable auditing firm’s website. Specifically, do not rely on the project’s own homepage badge — badges can be fabricated or refer to outdated audits. When you find the audit, check: the date (anything over 12 months old needs a fresh review), the scope (did it cover the specific contract version deployed?), and the findings (were critical or high-severity issues found and subsequently fixed?).

Step 5 — Run the GoPlus Security API Check

Go to GoPlus Security and run a token security check on the contract address. The API returns a comprehensive report covering: hidden mint functions, transfer restrictions, blacklist capabilities, sell tax percentage, ownership status, and whether the contract is a known proxy. Any finding marked high-risk is a reason to stop and investigate before investing.

Step 6 — Use the Cryptosmap Trust Engine

Run the complete contract address through the Cryptosmap Trust Engine. It aggregates all of the above checks — honeypot detection, liquidity lock verification, contract risk analysis, and community-verified threat intelligence — into a single risk score in under 60 seconds. Additionally, it cross-references against our live database of flagged projects updated in real time from our Scam & Rug Pull Alerts page.


Rug Pulls vs Other Crypto Scams — Key Differences

Understanding what a rug pull is in crypto also means knowing how it differs from related scam types. The distinctions matter because they determine which detection tools apply.

Rug pull vs hack: A rug pull is an inside job. The attacker is the developer. A hack exploits code vulnerabilities from outside a project. Consequently, a rug pull does not require a security flaw — it requires only the opportunity to disappear. Furthermore, hacks can happen to legitimate projects with verified teams and audited code. Rug pulls, by definition, require developer intent to defraud.

Rug pull vs pump and dump: A pump and dump can involve a legitimate token whose price is artificially inflated by coordinated buying and then crashed by coordinated selling. However, it does not necessarily involve the token’s developers. A rug pull is always executed by insiders who built the project specifically to steal. Additionally, pump and dumps often use existing tokens, whereas rug pulls typically involve newly created ones.

Rug pull vs pig butchering: A pig butchering scam builds a personal relationship with a victim before directing them to a fake investment platform. Conversely, a rug pull is an impersonal, market-wide event — all investors in the token are victims simultaneously. Furthermore, pig butchering involves a fake platform; a rug pull involves a real token on a real DEX whose mechanics are malicious.

Rug pull vs Ponzi scheme: A Ponzi scheme pays early investors using later investors’ money, maintaining the illusion of returns for longer. A rug pull ends abruptly in a single event. Therefore, a Ponzi typically lasts longer and collapses differently — through fund depletion rather than a deliberate single-moment exit.


The Legal Picture — Are Rug Pulls Illegal?

The legal status of rug pulls exists in complex territory where decentralised technology meets evolving regulatory frameworks. While some rug pulls constitute clear fraud, others operate in ambiguous spaces between unethical behaviour and prosecutable crime.

In the United States, the DOJ has demonstrated an increasing willingness to prosecute rug pull developers. The DOJ’s April 2025 memo names fake digital asset development projects such as rug pulls as a prosecution priority. Specifically, this means federal resources are now actively directed toward identifying and charging rug pull developers — not just investigating them.

The Frosties case established an important precedent. Founders Ethan Nguyen and Andre Llacuna were charged with conspiracy to commit wire fraud and money laundering — one of the first prosecutions for an NFT rug pull — and face up to 20 years in prison if convicted. This case demonstrated that anonymous online personas do not prevent prosecution — investigators traced the founders despite their online-only presence.

However, most rug pulls remain unprosecuted for practical reasons. Enforcement depends on fraud type — tokens qualifying as securities may violate securities laws, while misappropriated assets may trigger property or wire fraud statutes. However, many rug pulls appear as project failures unless investigators can prove intent, deception, or malicious design.

Furthermore, jurisdictional complexity is a significant barrier. Chainalysis reported that 40% of funds stolen in 2024 rug pulls were moved through Tornado Cash or similar mixers — making fund tracing significantly harder. Additionally, developers operating across multiple countries can exploit jurisdictional gaps in enforcement.

The practical implication for investors is stark: recovery of funds after a rug pull is extremely rare. Therefore, legal recourse is not a viable protection strategy. Prevention — through the six-step verification framework we covered earlier — is your only meaningful defence. cryptosmap


Frequently Asked Questions

Q: What is a rug pull in crypto in simple terms?

A rug pull is a crypto scam where developers create a token or project, attract investors, and then steal the funds — leaving buyers with worthless tokens. The term describes the moment the project “pulls the rug out” from under investors. It is always an inside job: the people who created the project are the people stealing from it.

Q: How does a crypto rug pull work?

Developers create a token, generate social media hype, add liquidity to a DEX, and attract retail buyers. Once enough funds have entered the liquidity pool, developers either remove all liquidity in a single transaction (hard rug pull), sell their large token allocation on the open market (soft rug pull), or exploit a sell restriction coded into the smart contract (honeypot). All three types end the same way — investors hold worthless tokens and developers disappear with the funds.

Q: Can you get your money back after a rug pull?

In most cases, no — blockchain transactions are irreversible. However, report the incident to the FBI IC3 at ic3.gov and your national financial regulator. Additionally, document every transaction and wallet address involved. Some on-chain analytics firms have traced rug pull funds and assisted law enforcement. However, statistically, the recovery rate for rug pull losses is extremely low. cryptosmap

Q: What is the difference between a rug pull and a honeypot?

A honeypot is a specific type of rug pull where the smart contract allows buying but blocks selling through malicious code. In a standard rug pull, you can sell — but developers drain the liquidity first, crashing the price. In a honeypot, you cannot sell at all — the contract prevents it. Consequently, you should run every new token through Honeypot.is before buying to detect sell restrictions.

Q: How do I check if a token is a rug pull?

Run the contract address through these four free tools: Honeypot.is (sell restriction check), GoPlus Security API (contract risk analysis), Bubblemaps (wallet cluster analysis), and Etherscan or RugCheck (liquidity lock verification). Additionally, use the Cryptosmap Trust Engine for a consolidated six-layer risk assessment in under 60 seconds.

Q: What blockchains are most used for rug pulls?

Binance Smart Chain hosted approximately 71% of all rug pull scams in 2024 due to lower fees and ease of deployment. Additionally, Solana has become a primary rug pull chain in 2025 through Pump.fun, where extremely low deployment costs allow thousands of fraudulent tokens to be launched daily.

Q: Is a rug pull illegal?

Generally, yes — where intent to defraud can be proven. The DOJ’s April 2025 memo names rug pulls as a prosecution priority. However, prosecution requires proving deliberate fraud rather than a project failure, making many rug pulls practically difficult to prosecute despite being ethically clear-cut. Therefore, prevention through on-chain verification is far more reliable than legal recourse after the fact. cryptosmap

Q: What was the biggest rug pull ever?

The 2021 peak of rug pull losses was $5.06 billion, over 200 times higher than the year before, overwhelmingly driven by the Thodex exchange collapse in Turkey where approximately $2 billion in user funds disappeared. In 2025, MetaYield Farm executed the largest single rug pull of the year, stealing $290 million before vanishing.

Q: How do I report a rug pull?

Report to the FBI IC3 at ic3.gov, the FTC at reportfraud.ftc.gov, your national financial regulator, and the platform where you discovered the project. Additionally, submit the token address and project details to the Cryptosmap Scam & Rug Pull Alerts page — we publish community-verified reports in real time to warn other investors before they invest.

Q: What is Pump.fun and why is it associated with rug pulls?

Pump.fun is a legitimate Solana-based token launch platform that allows anyone to create and list a token for minimal cost. The platform itself is not a scam. However, of the over 7 million tokens deployed on Pump.fun between January 2024 and March 2025, only 97,000 maintained liquidity above $1,000 — meaning 98.6% collapsed. The extremely low barriers to token creation have made it the preferred launch platform for rug pull developers operating at industrial scale. cryptosmap


Further Reading on Cryptosmap

  • Cryptosmap Trust Engine — run any token contract through our six-layer on-chain rug pull detection check, free, in under 60 seconds
  • Scam & Rug Pull Alerts — live database of flagged tokens, active rug pull schemes, and community-verified scam reports updated in real time
  • Is Bybit Safe? 2026 Security Review — for anyone evaluating where to trade safely after understanding the risks of unverified tokens
  • Educational Guides — how to read a smart contract audit, how to set up a hardware wallet, how to evaluate any exchange before depositing

Disclaimer

This article is for educational and informational purposes only. It does not constitute financial, investment, or legal advice. Cryptocurrency investments are highly volatile and carry significant risk of capital loss. Never invest more than you can afford to lose. All statistics are sourced from publicly available reports by Chainalysis, Solidus Labs, the US Department of Justice, and other named primary sources. Published April 2026. cryptosmap.com

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top