Every monthly recap we publish is dominated by exploits — a bridge boundary, a leaked cloud key, a firmware build flag. Those are the incidents with post-mortems, forensic timelines, and named attackers.

They are not the most common way people lose money in crypto.

The most common way is buying a token that was never intended to work. No exploit, no vulnerability, no CVE. The contract does exactly what it was written to do, the liquidity leaves, and there is no incident report because nothing malfunctioned.

That category has no good headline, which is roughly why it keeps working.


What the On-Chain Data Actually Shows

Loss estimates for rug pulls circulate widely and most of them are unusable — they aggregate incompatible definitions, or they recycle a Chainalysis figure from 2021 in which a single Turkish exchange collapse (Thodex) accounted for nearly 90% of the total.

The more useful evidence comes from detection research that scans issuance directly rather than tallying reported incidents.

Applied to Solana over a six-month window, one such pipeline examined 100,063 newly issued tokens and flagged 76,469 as rug-pull candidates:

PatternCandidates
Pump-and-dump60,402
Liquidity withdrawal15,606
Freeze-authority abuse461
Total flagged76,469 of 100,063

The directly traceable cash-outs across three decentralised exchanges came to just over $151 million, spread across 7,322 profitable addresses. The pipeline reported a 0.26% false-positive rate in validation.

Two other numbers frame the launchpad economy around it. Of the 7 million-plus tokens issued on Pump.fun between January 2024 and March 2025, 98.6% ended below $1,000 in remaining liquidity. On Raydium, roughly 93% of 388,000 pools showed soft-rug characteristics, with a median loss around $2,832.

That median is the important number, and it is the reason this category stays invisible.

The Soft Rug Is the Business Model

The dramatic version of a rug pull — anonymous team, locked liquidity that turns out not to be locked, a single transaction that drains the pool — is the version everyone screens for. It is also the minority case.

The dominant pattern is the soft rug: no single criminal transaction, just a coordinated exit. Insiders who received supply at issuance sell into retail demand they manufactured, liquidity thins, the team goes quiet, and the token decays to zero over days or weeks. There is rarely a specific moment you can point to and call theft.

This matters for three reasons:

It is hard to prosecute. A drained liquidity pool is a discrete act. A founder selling their own allocation into a rally is, absent provable misrepresentation, often just a bad look.

It is hard to measure. Losses at a $2,832 median almost never get reported. There is no exchange to sue, no protocol to announce a reimbursement plan, and the victim frequently concludes they simply made a bad trade — which, from the outside, is indistinguishable from what happened.

It scales without limit. Issuance is effectively free. A campaign that nets a few thousand dollars per token is a viable business when you can run hundreds in parallel, and the infrastructure to do so is now a consumer product.

The industrialisation is the story. Chainalysis flagged 74,037 tokens launched in 2024 as linked to suspected pump-and-dump activity — around 3.6% of all tokens issued that year. That was before this cycle’s launchpad tooling made the whole pipeline point-and-click.

Enforcement Is Landing — Several Years Late

The prosecution side has improved, and 2026 has produced real outcomes. The lag is the problem.

SafeMoon. The CEO was sentenced on 10 February 2026 to 100 months for wire fraud and money-laundering conspiracy, with a $7.5 million forfeiture. SafeMoon’s peak was in 2021. The sentence landed roughly five years after the harm.

The Scam Center Strike Force. Launched in November 2025 and aimed at Southeast Asian fraud compounds, it has returned more than $800 million and restrained over $700 million in crypto. On 21 July 2026, the DOJ filed five civil forfeiture complaints seeking more than $25 million tied to international fraud networks targeting US and Canadian residents — the largest case involving romance scams against more than 200 victims, with launderers operating from Southeast Asia and IPs resolving to China, Malaysia, and Cambodia.

Those are meaningful recoveries against organised, high-value fraud with identifiable infrastructure — the same operational category we covered in the AI-assisted pig butchering reckoning and the 276-arrest global crackdown.

But note what enforcement can reach. It reaches compounds, laundering networks, and named executives of projects that raised at scale. It does not reach 76,000 flagged token launches with a $2,832 median loss. There is no investigative model in which that volume is prosecutable, and there probably never will be.

The high-frequency end of crypto fraud is structurally outside enforcement’s reach. Whatever is going to reduce it will have to happen at the point of issuance and the point of purchase, not in a courtroom.

Screening That Actually Corresponds to the Data

Most published rug-pull checklists screen for the hard rug — anonymous teams, unaudited contracts, unlocked liquidity. Useful, but tuned to the wrong failure mode. Screens that map to what detection research actually finds:

  • Holder concentration at issuance, not now. The relevant question is who received supply in the first blocks. Present-day distribution has already been laundered through trading. Pull the earliest transfers.
  • Freeze and mint authority. On Solana, unrevoked freeze authority means the issuer can stop you selling. It appeared in only 461 flagged cases, but it is a total loss when it appears, and it takes seconds to check.
  • Liquidity depth against your own position size. A pool that cannot absorb your exit at an acceptable price is a rug whether or not anyone intends it as one. Size to the pool, not to the chart.
  • Locked ≠ locked. Read the lock contract’s unlock timestamp and check who holds the admin key. A short lock is a countdown, not a safeguard.
  • Insider wallet clustering. Funding several “independent” early holders from one source wallet is the single most reliable tell, and block explorers make it visible without specialist tooling.
  • Assume the launchpad is not a filter. A 98.6% failure rate on Pump.fun tokens means listing venue carries close to zero signal. It is issuance infrastructure, not diligence.

None of this makes speculating on new tokens safe. It moves you out of the fattest part of the distribution, which is a different and more achievable goal.


The Framing Problem

Crypto security discourse is organised around exploits because exploits are legible: a root cause, a fix, a lesson. The rug pull economy has none of that, so it gets treated as a retail-behaviour issue rather than a security issue.

That framing is wrong. When three-quarters of new issuance on a major chain carries rug characteristics, the failure is not that users were careless. It is that the issuance layer has no cost, no accountability, and no friction — and every other layer has been built on the assumption that someone downstream is checking.

Nobody is checking. That is the design.

Sources: Rug Pull Statistics 2026 — DeepStrike · Detecting rug pulls in decentralized exchanges — ScienceDirect · Chainalysis: Southeast Asian scam centers · DOJ $25M forfeiture filings · Memecoin Statistics 2026 — Coinlaw