TLDR:
In my five years covering crypto I’ve seen the same rug pull pattern repeat hundreds of times. A slick website, a Telegram group full of hype, a chart that goes vertical in 48 hours — and then nothing. Wallets drained, developers vanished, community in shock. The projects that scam investors almost always share the same warning signs before the collapse: mint authority left active, liquidity unlocked, one wallet holding 60% of the supply. I’ve watched it happen to experienced traders who should have known better. The difference between the people who got out and the people who lost everything usually came down to two minutes of on-chain research. This guide covers exactly what that research looks like.
Solana has become one of the most active blockchains for new token launches — and one of the most dangerous for unsuspecting investors. Research from Solidus Labs found that approximately 98.7% of tokens launched on Pump.fun and 93% of liquidity pools on Raydium have shown characteristics of pump-and-dump schemes or rug pulls. With token creation costing less than a dollar and taking minutes, scammers have turned Solana into an industrial-scale fraud machine.
The good news? Most Solana scams follow a predictable pattern, and there are free tools that let you spot them in under two minutes — if you know what to look for.
This guide covers everything you need to know: the warning signs, the tools, and a step-by-step checklist to run before putting a single dollar into any Solana token.
Before diving into detection, it helps to understand what you’re actually looking for. Solana token scams generally fall into three categories:
Rug pulls are the most common. Developers launch a token, hype it on Telegram and Twitter, attract buyers, then suddenly drain all liquidity from the trading pool. The token becomes worthless in seconds. According to research into Solana’s memecoin ecosystem, the median time from token launch to rug pull is approximately 18 hours — and the actual liquidity removal takes just 30 to 90 seconds once the developer initiates it.
Honeypots are more insidious. You can buy the token fine, but when you try to sell, the transaction fails. The developer has either used freeze authority to lock your wallet or programmed hidden sell restrictions into the token so only they can exit.
Pump-and-dump schemes involve the developer or a coordinated group buying large amounts early, artificially inflating the price to attract retail buyers, then selling everything at the peak and leaving everyone else holding worthless tokens.
Every Solana token is built on the SPL token standard, which gives token creators three key “authorities” — special permissions that control what they can do with the token after launch. These are the first thing you need to check.
Mint authority is the power to create new tokens at any time. If a developer still holds mint authority after launch, they can print unlimited tokens and dump them on the market whenever they want, instantly destroying your investment.
What to look for: Mint authority should be revoked (set to null). If it’s still active and pointing to a real wallet address, treat it as a serious red flag.
Freeze authority allows a developer to freeze individual token accounts, permanently preventing holders from transferring or selling their tokens. This is the mechanism behind honeypot scams — you buy in, the developer freezes your account, then sells their own tokens while yours are locked.
What to look for: Freeze authority should also be revoked. There are almost no legitimate reasons for a memecoin or small token project to retain freeze authority.
Update authority controls the token’s metadata — its name, symbol, logo, and description. If this isn’t revoked, a developer can change the token to impersonate a legitimate project after you’ve already bought it, then redirect victims to phishing sites.
What to look for: For any serious token, update authority should be revoked or marked as immutable.
Go to Solscan.io or Solana Explorer and paste the token’s contract address. Click on the “Authority” tab. You want to see all three authorities either revoked or set to null. Any active wallet address in these fields is a warning sign.
Even if the token authorities look clean, liquidity is the next critical check. Without locked liquidity, a developer can drain the entire trading pool in seconds.
Locked liquidity means the LP (liquidity pool) tokens have been sent to a time-lock contract and cannot be withdrawn until a specified date. This prevents the developer from pulling the rug.
Burned liquidity is even better — it means the LP tokens have been permanently destroyed and can never be withdrawn by anyone.
What to check:
You can verify liquidity status on RugCheck.xyz, Birdeye, or DexScreener by searching the token’s contract address.
A token where one or two wallets control the majority of the supply is primed for a dump. When those wallets sell, the price collapses instantly.
What to look for on Solscan or RugCheck:
Rather than checking everything manually, several free tools do the heavy lifting for you.
RugCheck.xyz is the most widely used Solana-specific tool. Paste any token contract address and it returns a risk score along with a detailed breakdown of mint authority status, freeze authority, liquidity lock status, top holders, and flagged risk factors. It’s the fastest starting point for any new token.
SolSniffer specialises in detecting suspicious patterns and provides automated scanning with risk alerts. It’s particularly good at identifying wash trading activity and unusual transaction patterns that human eyes might miss.
Birdeye is a comprehensive analytics platform that combines rug pull detection with real-time trading data. If you’re trading actively, it gives you a fuller picture of token health alongside price charts.
DexScreener doesn’t give a dedicated risk score but is invaluable for spotting unnatural trading patterns. Look at the transaction history — if you see dozens of buys of nearly identical size happening seconds apart, that’s bot activity artificially inflating volume.
TokenSpy is a Chrome extension that integrates directly with DexScreener and DexTools, showing you a risk score without needing to leave the page you’re already on.
On-chain data tells you a lot, but off-chain research closes the gaps.
Anonymous teams are not automatically a red flag — many legitimate crypto projects are built pseudonymously. But anonymous teams with no track record, no verifiable history, and no accountability are a different story.
Ask these questions:
Many Solana scams don’t rely purely on technical tricks — they manipulate psychology. These are the behavioural warning signs:
Artificial urgency: “Presale ends in 2 hours,” “only 1000 spots left,” “buy before it lists on Raydium.” Legitimate projects don’t need to manufacture FOMO.
Guaranteed returns: No investment guarantees returns. Any project promising “100x guaranteed” or “risk-free gains” is lying to you.
Paid influencer shills without disclosure: If ten Twitter accounts with large followings all post about the same new token on the same day, they were almost certainly paid. This is a pump setup.
Copied whitepapers: Some scam tokens simply copy-paste whitepapers from legitimate projects and change the name. Paste sections of the whitepaper into Google and check for plagiarism.
Weekend launches: Research into Solana rug pull timing shows developers deliberately time liquidity withdrawals for weekends when exchange support and on-chain monitoring are slower and the community is less active.
Before buying any Solana token, run through this checklist:
If a token fails more than two of these checks, the risk is not worth taking.
Recovery from a Solana rug pull is, realistically, close to impossible once liquidity has been removed. The token becomes untradable and the developer’s wallet is typically washed through multiple addresses within hours.
However, there are still steps worth taking:
The scale of fraud on Solana is a structural problem, not just bad luck. Low transaction fees make it economically viable for scammers to run hundreds of simultaneous schemes. Pump.fun’s one-click token creation has removed every technical barrier to launching a fraudulent project. And Solana’s speed — a feature for legitimate use — means a rug pull can be complete before most holders even notice something is wrong.
None of this means you should avoid Solana entirely. The ecosystem hosts genuinely innovative projects in DeFi, gaming, and payments. But it does mean you need to apply the same rigour to a $500 memecoin investment that you’d apply to any other financial decision.
The tools and checks described in this guide are free and take two minutes. Given that the alternative is losing your entire investment in under 90 seconds, two minutes is time well spent.
Disclaimer: This article is for educational purposes only and does not constitute financial or investment advice. Always do your own research before investing in any cryptocurrency.
The United States government is now the largest known state holder of Bitcoin in the…
Indiana has passed one of the most significant pieces of crypto legislation in the United…
When a bank managing $30 trillion in client assets says it's making Bitcoin "bankable," that's…
I've watched Bitcoin bounce off key support levels more times than I can count. Every…
Every day, hundreds of blockchain projects compete for the same limited attention from crypto…
PoolPays has announced the development of a decentralized liquidity pool aimed at the gaming industry…