Security & Scams

How to spot a rug pull before aping in (red flags checklist)

Every degen has a story. The token that mooned 50x in your watchlist while you were sleeping. The contract that hit your buy and immediately blacklisted your wallet. The founder who tweeted "GM family" twelve minutes before draining the LP.

IgnizIgniz Research
4 min read
Cover image for the article "How to spot a rug pull before aping in (red flags checklist)"

Every degen has a story. The token that mooned 50x in your watchlist while you were sleeping. The contract that hit your buy and immediately blacklisted your wallet. The founder who tweeted "GM family" twelve minutes before draining the LP.

You can't avoid all of them. You can avoid most of them.

This is the actual checklist seasoned wallets run before they touch a new launch. Not the "do your own research" platitude. The specific things you look at, where you look at them, and what the answers should be.

The contract tells the truth

The smart contract is the only honest thing about a new project. Read it, or pay something to read it for you.

Things that should make you close the tab:

A live mint function. A token where the deployer can still print more supply is a token where you own nothing. Run the contract address through a honeypot scanner like honeypot.is, tokensniffer, or gopluslabs before you send a dollar.

Blacklist or pause functions. If the team can block your wallet from selling, they will, the moment you become inconvenient.

Modifiable tax. A contract that lets the owner crank the sell tax to 99 percent is a delayed execution order on your bag.

Renounced ownership that isn't really renounced. Check the contract on the relevant explorer. "Ownership: 0x000...000" is what you want to see. Ownership transferred to another wallet the team controls is theater.

Proxy contracts that can be upgraded silently. Upgradable logic on a meme token is a backdoor wearing a suit.

The chart tells a different truth

Open a holders tab. Open Bubblemaps, Arkham, or Nansen. Look at the wallet distribution like you're looking at a crime scene.

A handful of wallets holding 40 percent of supply that all got funded by the same source three blocks before launch is not a community. It's a coordinated dump in slow motion. The bubble map shows you the spider web. If you see one, leave.

Check the liquidity. Locked LP is the floor under your trade. Without it, the deployer can pull the entire pool in one transaction and walk away with your stablecoins. Verify any lock claims on Unicrypt, Team Finance, or PinkSale. Check the duration. A six-hour lock is not a lock.

Look at the early buyers. Sniper bots and dev wallets accumulating in the first few blocks, then a slow distribution to "the community," is a rug being staged.

Trace the funding. Wallets funded fresh from Tornado Cash or a centralized exchange minutes before deploying a token, then linked across two or three previous failed projects, will do this again.

Vibes are data

The team can be anonymous. The team can be doxxed. What matters is whether the signal makes sense.

Reverse image search the profile photos. A founder using a stock image or a stolen LinkedIn headshot is a founder who plans to disappear. Twitter accounts created in the same week, Telegram channels with 40,000 members but message activity from the same fifteen handles, replies that all read like ChatGPT wrote them with the temperature too low.

Watch for engagement that doesn't match reach. A "viral" project with 80,000 followers and 4 likes per tweet bought everything you're seeing.

The domain is worth thirty seconds. Whois lookups are free. A protocol claiming six months of build on a domain registered two weeks ago is lying about one of those things.

The pitch is the giveaway

Read what they promise. Ask whether the math works.

Fixed yield of 400 percent APY with no clear source means the yield is coming from new deposits. That's not yield, that's a queue. Roadmaps written in pure buzzword soup, AI plus RWA plus ZK plus modular plus restaking plus intents, with no working primitive underneath, are pitch decks for exit liquidity, not products.

Audits matter, but only real ones. A glossy "audited by" badge linking to a one-page PDF from a firm with a Fiverr-grade website is not an audit. Check Certik, Hacken, Trail of Bits, OpenZeppelin, PeckShield. Read the actual findings. Did the team fix the high-severity issues, or did they ship anyway and edit the readme?

Behavior in the late innings

Some flags only show up once you're holding.

Critics quietly banned from the Telegram. Comments disabled on every post. The team going silent for three days after a price drop. Sudden DM blasts from accounts that followed you yesterday. "Last chance, final pump" messaging when the chart is bleeding.

Watch the dev wallet on chain. DeBank and Arkham let you put any address on a watchlist. If the wallet holding 15 percent of supply starts moving tokens to a centralized exchange, that's the only signal you need. You don't wait for the announcement. The announcement is the wallet movement.

The one-minute version

Before you click buy, run this loop:

Pull up the contract. Renounced ownership, no mint, no blacklist, no modifiable tax, no upgradable proxy.

Pull up the holder map. No single wallet over 5 percent, no cluster of related wallets, sniper concentration below 10 percent.

Verify liquidity is locked and check the duration.

Audit the socials for age, organic engagement, and reverse-image-searchable photos.

Read the audit. If there isn't one, the audit is you.

The part nobody puts in the checklist

You can do everything above and still get rugged. The space evolves. New attack vectors ship every week. Soft rugs where the team slowly abandons the project after pulling marketing wallets are harder to spot than hard rugs that pull liquidity in one block.

Size accordingly. The position you can afford to lose is the only position that survives a rug emotionally. Everything else costs sleep.

Conviction is cheap. Verification is expensive. The wallets that survive multiple cycles are the ones that pay for the second one before they need it.

Cover image for the article "Recognizing Common Crypto Scams and Phishing Attacks"
Security & Scams

Recognizing Common Crypto Scams and Phishing Attacks

There is a comforting story people tell themselves about getting scammed. It goes: the victims were careless, or greedy, or technically clueless, and I am none of those things, so this will not happen to me. That story is the single most dangerous thing in your wallet.…

Igniz

Stay up to date with Igniz and the future of trading.