Imagine discovering a promising new token with thousands of holders, rising prices, and an active community. Everything appears legitimate until the liquidity suddenly disappears. That is how a rug pull begins.
Rather than simply siphoning off your money, developers first manufacture trust through locked liquidity and renounced contracts. Later on, they create a buzz around their token via active social media platforms and coordinated hype.
The stronger the community grows, the easier it becomes to attract fresh capital and deepen investor confidence. The entire process often unfolds within 48-72 hours, from hype-creation to exit.
Hard rug pulls drain liquidity in one move through developer wallet dumps or pool withdrawals, while soft rugs quietly erode value through insider selling, token unlocks, or abandoned roadmaps.
Eventually, the developer withdraws the proceeds, and the TVL begins to collapse, revealing what the hype concealed all along. As a result, this leaves the token on-chain but with little practical market value or investor confidence.
The patterns behind most rug pulls
Not every token is as decentralized as it first appears. A project can attract thousands of holders and still leave most of the control in a few developer wallets. That is where the real risk begins.
Historical rug pull cases reveal that warning signs rarely emerge in isolation. Instead, multiple indicators tend to appear together long before liquidity is removed.
The smart contract then determines whether that risk becomes reality. Hidden mint functions, retained ownership, upgradeable contracts, or sell restrictions can quietly give developers more control than investors expect.
On-chain data consistently associates high wallet concentration, where the top 5 to 10 holders control more than 30% of supply, with increased manipulation risk. Furthermore, that exposure grows when developer allocations lack meaningful vesting or liquidity locks expire quickly after the launch of the project.
Contract architecture adds another layer of concern. Unverified source code, active mint functions, upgradeable proxies, and adjustable sell restrictions allow developers to retain control after deployment.
Market behavior often reinforces these structural risks. This happens through rapid price appreciation supported by influencer-driven promotion. This is in addition to low organic volume and decreasing holder growth rates that occur prior to large developer wallet transfers and declining liquidity pools.
For instance, cases such as SQUID and LIBRA followed similar trajectories despite different narratives. Collectively, these patterns suggest rug pulls are better identified through converging on-chain, contract, and behavioral signals rather than any single metric alone.
That being said, not all projects follow that trajectory. The use of transparent vesting, verified code, and third-party audit processes makes manipulation extremely difficult. Ultimately, decentralization is determined by how much control developers are willing to relinquish.
The exploits that trap investors
That control often reveals itself through the type of exploit developers choose. Honeypots remain the most common, accounting for 98,442 scam tokens. These contracts let investors buy normally but prevent or heavily restrict selling, effectively trapping funds once enough liquidity enters.


Hidden mint functions follow with 60,985 cases, allowing developers to inflate the supply after launch and dilute existing holders. Fake ownership renunciations appear in another 48,974 tokens, reinforcing how control can remain hidden despite claims of decentralization.
That said, the growing variety of exploits suggests scammers are adapting faster, making smart contract scrutiny as important as price action before investing.
Final Summary





