Rug Pulls: A Field Guide to the Exit That Was Always in the Code

A rug pull isn't a hack — the murder weapon was published in the verified contract before anyone bought. Peel the onion: five whys, the SQUID code, and the boring four-check diligence that kills the whole category.

Most people call it a hack. The contract says otherwise — and that’s the part worth understanding

Most people think a rug pull is a hack. Some clever exploit, some broken code, someone finding a flaw.

Wrong. A rug pull is the only scam I know where the murder weapon is published, in advance, in public, in code the victims could have read before clicking “buy.” No vulnerability is exploited. No key is stolen. The contract executes exactly as written — it’s just that nobody read what was written. Once you see that distinction, the whole phenomenon stops being mysterious and starts being something much more uncomfortable: a discipline failure with a countdown timer attached.

Let me peel this apart layer by layer, because the surface explanation is the one that teaches you nothing.

Rug Pulls: A Field Guide to the Exit That Was Always in the Code
jurvetson, CC BY 2.0, via Flickr/Openverse

Peeling the onion

The surface: “we got hacked.” When SQUID collapsed from $2,861 to $0.0007 in five minutes on November 1, 2021, the developers’ farewell message blamed stress and an alleged hacking attempt. Note how the story is shaped: something was done to us. That framing survives because it flatters the victims. It’s also false — on-chain forensics from TRM Labs later tied the same developers to at least two other rug pulls, a combined scheme worth roughly $19.3 million. Serial operators don’t get hacked three times in a row. They run a business model.

One layer down: no exploit happened at all. Go read the contract. I mean that literally — the sell restriction was in the verified source code from day one, dressed up as an “anti-dump mechanism”:

function transfer(address to, uint256 amount) public {
    if (msg.sender != owner && sellingLocked(msg.sender)) {
        revert("Selling locked");   // everyone can buy
    }                              // almost no one can sell
    _transfer(to, amount);
}

Buying was permissionless. Selling was not. That’s not a backdoor — that’s the front door, bolted from the inside, with a sign on it. Some 43,000 buyers walked past the sign because the chart was pointing at the moon.

Deeper still: this wasn’t even a contract problem. The other two weapons in the rug arsenal don’t require any code tricks at all. An unlocked liquidity pool — where the developers hold the keys and can withdraw everything in one transaction — is a configuration choice, visible on the DEX. And the concentration dump doesn’t even need a drain: a handful of insider wallets holding most of the supply, selling into the crowd, is technically just selling your own tokens. Which leads to the uncomfortable bottom of the onion:

At the core, a rug pull is a voluntary transfer of money from people who won’t do ten minutes of reading to people who count on exactly that.

Rug Pulls: A Field Guide to the Exit That Was Always in the Code
chascow, CC BY 2.0, via Flickr/Openverse

Five whys, honestly asked

I find the 5-Whys exercise clarifying here, because each answer moves the blame somewhere the comfortable version of the story never goes:

  • Why did 43,000 people lose money on SQUID? Because they bought a token they could not sell.
  • Why couldn’t they sell? Because the contract restricted selling, in public code, from the moment it deployed.
  • Why didn’t the restriction stop the buying? Because nobody reads contracts, and a 75,000% weekly green candle is more persuasive than a revert("Selling locked") ever will be.
  • Why is the candle more persuasive? Because the chart manufactures urgency and the code requires patience — and the entire marketing architecture of these tokens is engineered so that urgency arrives before patience can.
  • Why does this keep working, years later, with every warning label imaginable? Because the exploit isn’t in the contract. The exploit is that verification is boring, and it always will be.

That last answer is the one I’d tattoo somewhere visible. The industry responded to SQUID with warning labels — CoinMarketCap flags, exchange blacklists, Binance investigations. The rugs adapted faster than the labels. ZKasino didn’t need a sell-lock in 2024; it just changed the withdrawal terms after users bridged in $33 million. AnubisDAO didn’t even have a contract worth reading — $60 million gone in 20 hours, no whitepaper, anonymous team. You cannot label your way out of a discipline problem.

$3.38M — what the SQUID developers walked away with — from a token whose only trick was a “no selling” rule written in plain sight

So what do you actually do

Fine — I’ve spent this whole article demolishing the “hack” framing. Demolishing without constructing is cheap criticism, so here is the ten-minute version of the diligence I run on any new token, in the order I run it. Not because it’s clever, but because it’s boring, which is the point:

  • Test the exit before you believe the entry. Buy the smallest tradeable amount, then sell it. If the sell reverts, you’ve found the trap for the price of a coffee. This single step kills the entire honeypot category.
  • Check the liquidity lock. Is the pool locked or burned, by whom, until when? An unlocked pool means the floor is a promise from an anonymous stranger.
  • Count the whales. Pull the holder list, exclude exchanges, and add up the top ten wallets. If they can jointly decide your Tuesday, they eventually will.
  • Read the verified contract — or find someone who did. You’re looking for owner-controlled sell logic, mint functions, blacklist switches. Twenty minutes with a block explorer, or a search for an audit from a firm that staked its name.
Rug Pulls: A Field Guide to the Exit That Was Always in the Code
James Inskipp, Public domain, via Wikimedia Commons

None of this is sophisticated. That’s what makes the failure rate so damning: every confirmed rug I’ve examined failed at least three of these four checks before the pump started. The information was available, free, on-chain, in real time. The scam didn’t beat the system. It beat the attention span.

So the next time a rug makes the news and someone tells you about “another crypto hack,” push back on the word. A hack is when someone defeats your defenses. A rug pull is when you never raised any. If you cannot sell a token, you don’t own a token — you own a receipt for one. And the receipt was yours to check, the whole time.

(The End)

Blockchain

Why DAOs Exist: When "Code Is Law" Meets a Lawyer

2026-10-9 10:16:37

Blockchain

Tokenomics in Four Steps: The Spreadsheet Behind Every Token You Hold

2026-10-9 20:54:42

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search