A rug pull is a scam where the people behind a token or NFT project extract the invested money and abandon the project, leaving holders with assets that are unsellable or nearly worthless. The two common mechanisms are pulling liquidity from the trading pool and quietly minting or dumping hidden supply. Warning signs exist before both.
L4 News publishes information, not investment advice, and nothing here is a reason to buy or avoid any specific asset. Crypto assets can lose most or all of their value quickly, by fraud or without it — this guide is about recognizing the fraud-shaped version.
How does a rug pull work mechanically?
Most new tokens launch on decentralized exchanges, paired against ETH or a stablecoin in a liquidity pool the team controls. Buyers pay in; the pool grows. In a liquidity pull, the team withdraws its pool share at once — the price collapses because the buyer side just vanished. Mint scams work the same way, with freshly created tokens.
Think of the pool as the shop's cash register — the analogy breaks down immediately: a real register has an owner who can be sued, while a liquidity pool obeys whoever holds its withdrawal keys, and 'withdraw your own liquidity' is a routine, legitimate-looking transaction until the moment it isn't. Nothing about the pull requires a hack or a broken promise in code; it requires only that the team held the keys.
The mint variant adds one trick. The contract includes, or later gains through an administrative key, the ability to create new tokens at will. Supply appears, gets sold into the market, and the price absorbs it badly. To the chain, everything is ordinary: the tokens are real, the sales are real, and the exit is legal-shaped enough to be hard to prosecute.
What warning signs appear before the pull?
The loudest are structural: an anonymous team, no third-party audit, unlocked liquidity, and a supply concentrated in a few wallets. Add behavioral tells — guaranteed-return promises, aggressive countdowns, and pressure to buy before a 'listing.' None is proof alone; together they describe a project built so that disappearing is cheap.
Each sign is checkable, none requires special tooling, and each answers a specific question.
| Sign | How to check | What it doesn't prove |
|---|---|---|
| Anonymous team | Project's own channels; verifiable history | Named founders can still run; anonymity removes recourse, not certainty |
| No audit | Look for a dated report from a known firm | An audit reviews code, not intent or team conduct |
| Unlocked liquidity | Locker tools and explorers show lock status and duration | A lock expiring in a month protects almost nothing |
| Concentrated supply | Block explorer's holders page, top wallets | Large holders may be contracts or vesting — read the labels |
| Guaranteed returns | Nothing to check — treat the promise itself as the finding | Nothing; guaranteed returns in crypto are a claim with no honest version |
Read as a set, these describe an asymmetry: a legitimate project can survive every check, while a rigged one needs to fail several quietly. Your job is not to convict; it is to notice how many questions the structure refuses.
What did famous rug pulls look like?
Two dated cases cover both main mechanisms. In November 2021, a token themed on the Squid Game series climbed vertiginously over its first week — and its trading contract contained anti-selling mechanics that prevented most holders from selling. When the price peaked, the developers' wallets cashed out and the team disappeared, and the chart went to effectively zero, as reported at the time. Buyers had bought an asset they could never exit at the top by design.
In March 2022, the U.S. Department of Justice charged the creators of the Frosties NFT collection in what prosecutors described as an early 'rug pull' prosecution: the collection sold out, and the team allegedly abandoned the project and took the proceeds — roughly a million dollars, per the charges at the time. The case is a reminder that reversibility exists mostly in courts, and only sometimes.
The shared anatomy: hype assembled faster than accountability, exit liquidity provided by excited buyers, and a moment where the team's advantages — keys, mint rights, selling permissions — turned out to be the product.
Does an audit mean a project won't rug?
No. An audit reviews specific code at a specific time and states what was checked — it doesn't cover the team's intent, future administrative keys, or a liquidity pull, which can be a legitimate-looking transaction. A real audit still helps; a fake 'audited' badge on a website helps only the scammer.
Audit scope is the detail worth reading. Reports state which contracts were reviewed, what was out of scope, and which findings were fixed. An audit of the token contract says nothing about who holds the liquidity, and a clean report on old code says nothing about what an upgrade key can change later. Scammers exploit exactly this gap: technically reviewed code, structurally rigged project.
What can you do once a rug happens?
Very little, which is the honest answer, and why the entire weight of this guide sits before the pull. On-chain sales into a pool are final; the tokens left in your wallet have no buyer, and the project's channels go quiet or delete. That finality is the mechanism working as designed — it just isn't working for you.
What remains is reporting and hygiene. In the United States, the FBI's Internet Crime Complaint Center at ic3.gov accepts crypto-fraud complaints, and the Frosties case above shows prosecutions do happen — slowly, occasionally, and mostly after many victims report. Preserve your transaction hashes and the project's pages before they vanish.
The prevention reading is short: verify team accountability or accept its absence knowingly, check where the liquidity and supply actually sit, and treat urgency as information about the seller rather than the deal.
For more context, read What is address poisoning?.
For more context, read airdrop scam.
For more context, read How to spot a crypto drainer before it takes your wallet.




