logo svg
logo

August 2, 2026

Updated: August 2, 2026

Rug Pull Statistics 2026: Crypto Scam Losses and DeFi Risk

A source-aware analysis of rug pull losses, token collapse data, Solana findings, reporting caveats, and defensive controls for crypto and Web3 teams.

Mohammed Khalil

Mohammed Khalil

Featured Image

Rug pull statistics vary sharply because researchers count different behaviors, ecosystems, thresholds, and forms of loss.

Executive Answer: No global rug-pull total is reliable. Chainalysis attributed more than $2.8 billion in stolen funds to rug pulls in 2021, with one centralized exchange accounting for nearly 90% of that value. A 2026 Solana preprint identified 76,469 candidate rug-pull tokens among 100,063 tokens issued on three decentralized exchanges in early 2025, estimating at least $151 million in directly traceable losses. Separately, Solidus Labs found that 98.6% of more than seven million Pump.fun tokens it studied had fallen below $1,000 in liquidity but that threshold shows collapse, not proven criminal fraud.

The figures answer different questions. Chainalysis measured investor funds it classified as stolen in rug pulls, not subsequent token-price decline, and its 2021 result was unusually concentrated in Thodex. The firm’s 2021 scam analysis is therefore evidence for that year and method, not a reusable global average.

Solidus Labs examined platform-specific token and pool behavior. Its 2025 Solana report used liquidity and withdrawal thresholds that identify collapse or suspicious behavior; they do not establish criminal intent for every token or pool.

The Solana study is a 2026 academic preprint, not a peer-reviewed census of all blockchains. Its 76,469 labels are detection candidates from a defined six-month, three-DEX dataset, while its loss estimate follows a conservative on-chain cash-out method.

For broader context, DeepStrike’s crypto crime report covers categories that extend well beyond rug pulls. That wider context should not be merged into a rug-pull total.

Rug Pull Statistics at a Glance

How to read these statistics: treat each row as a scoped finding; compare figures only when the measured object, time window, denominator, valuation, and classification method match.

StatisticValuePeriodMeasured objectEcosystem / geographyDefinition or thresholdSourceWhat it does not prove
Rug-pull funds classified as stolenMore than $2.8 billion; 37% of the source’s 2021 crypto-scam revenue2021Investor funds taken in incidents Chainalysis classified as rug pullsGlobal on-chain analytics coverageSource methodology counted stolen investor funds, excluding later token-value declineChainalysis (2021) — https://www.chainalysis.com/blog/2021-crypto-scam-revenues/A typical annual loss: Thodex represented nearly 90% of the value
Pump.fun token liquidity outcomeMore than 7 million tokens studied; 97,000 retained more than $1,000 liquidity; 98.6% fell below that thresholdJanuary 2024–March 2025Tokens with at least five tradesPump.fun on SolanaRemaining liquidity below $1,000; tokens upgraded to Raydium excluded from that measureSolidus Labs (2025) — https://www.soliduslabs.com/reports/solana-rug-pulls-pump-dumps-crypto-complianceThat every low-liquidity token was an intentional or legally proven rug pull
Raydium pool behaviorApproximately 93% of 388,000 pools examined showed the report’s soft-rug characteristicsReport published May 2025; underlying observation window not disclosedRaydium V4 automated-market-maker poolsRaydium on SolanaDeposit/withdrawal and LP mint/burn analysis; a 90% liquidity-withdrawal sweep threshold used for distribution statisticsSolidus Labs (2025) — https://www.soliduslabs.com/reports/solana-rug-pulls-pump-dumps-crypto-complianceA cross-chain rug-pull rate or adjudicated fraud count
Candidate rug-pull tokens76,469 candidates among 100,063 newly issued tokensJanuary 1–June 30, 2025Newly issued tokens on Orca, Raydium, and MeteoraThree Solana DEXsBehavior-guided detection pipeline covering pump-and-dump, liquidity withdrawal, and freeze-authority abuseSolana preprint v2 (2026) — https://arxiv.org/html/2603.24625v2A final legal finding for every candidate or a rate for all Solana tokens
Directly traceable loss in the candidate datasetAt least $151,089,437.80 across 7,322 profitable addressesJanuary 1–June 30, 2025Quantifiable assets cashed out by addresses associated with detected candidatesThree Solana DEXsConservative tracking of verifiable SOL and USDT/USDC cash-outsSolana preprint v2 (2026) — https://arxiv.org/html/2603.24625v2Total victim harm, unrealized token-value decline, or a global loss estimate
Not rug-pull-specific: cryptocurrency-nexus complaints181,565 complaints and $11.366 billion in reported losses2025Complaints with a cryptocurrency nexusUnited States reporting to FBI IC3Victim-reported complaint classificationFBI IC3 2025 Annual Report, pp. 51–52 — https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdfThe number of confirmed crimes, unique victims, or losses caused specifically by rug pulls

Direct sources for the table:

The table deliberately keeps dollars, token counts, pool counts, percentages, and complaint data separate. Adding them would create a number with no defensible meaning.

Why Rug Pull Statistics Disagree

Five-step checklist for evaluating rug-pull statistics: definition, dataset, denominator, valuation, and confirmation.

Source note: DeepStrike analysis based on the source-method review cited in this article.

“Rug pull” is a practical label, not a universal measurement standard. One source may count stolen crypto traced to an operator. Another may flag a token whose liquidity disappeared. A third may detect a price-and-wallet pattern. An agency report may count victim complaints under a broader category without identifying rug pulls at all.

Use the DeepStrike Rug-Pull Evidence Matrix before repeating a headline number:

  1. Definition: What exact behavior counts withdrawal restrictions, liquidity removal, insider selling, abandonment, or a centralized exit?
  2. Dataset: Which chain, platform, pool, token set, addresses, or complaints were observed, and during what period?
  3. Denominator: Out of how many eligible tokens, pools, projects, or reports, and with what inclusion threshold?
  4. Valuation: Does “loss” mean assets transferred, proceeds cashed out, victim-reported loss, liquidity removed, token-price decline, or market-cap change?
  5. Confirmation: Is the event a detection candidate, an analytics classification, an allegation, a disputed case, or a court/enforcement finding?

Two additional biases matter. Activity bias makes a busy token-launch platform produce more observed cases even if its risk rate is unknown. Observation bias makes a well-monitored chain look worse than a chain with weaker labels or less accessible data. Neither justifies ranking one blockchain as the “worst” without comparable denominators and detection coverage.

A low-liquidity token is not automatically evidence of fraud. Projects can fail, lose users, or be abandoned without an intentional scheme. Conversely, a detection rule can miss slower, coordinated, or off-chain abuse. The Solana preprint itself reported a very low observed false-positive rate in one random audit but also found missed slower cases in a separate non-rug sample. That combination argues for cautious labels, not certainty.

Valuation creates another fault line. A perpetrator’s realized withdrawal is measurable on-chain but may omit indirect harm. A token’s market-cap decline can be much larger, yet it is not cash available to withdraw and is highly sensitive to price and liquidity. Victim-reported loss is valuable U.S. context, but complaints are not equivalent to verified transactions or court findings.

Why Published Estimates Differ

Source / datasetDefinitionChain / platformTime windowDenominator / thresholdLoss or value basisConfirmation statusComparable with
Chainalysis 2021 scam analysisIncidents classified as rug pulls under the firm’s crypto-scam analyticsMulti-chain/global analytics coverage2021Covered services and addresses; full denominator not disclosed on the pageInvestor funds classified as stolen; later token-value decline excludedAnalytics-classifiedSame Chainalysis series and definition only; not directly comparable with token-collapse counts
Solidus Labs Pump.fun studyTokens falling below a remaining-liquidity threshold in a platform studyPump.fun on SolanaJanuary 2024–March 2025More than 7 million tokens with at least five trades; $1,000 liquidity threshold; Raydium upgrades excludedRemaining liquidity, not a victim-loss totalMethod-classified collapse/pump-and-dump behaviorOther studies using the same platform, inclusion rule, exclusion, date window, and threshold
Solidus Labs Raydium studyPools showing the report’s soft-rug characteristicsRaydium V4 on SolanaReport published May 2025; underlying observation window not disclosed388,000 pools; distribution statistics use a 90% liquidity-withdrawal thresholdLiquidity sweep amounts; median about $2,832 and maximum $1.9 million under the stated thresholdMethod-classified behaviorSame pool model and threshold only; not directly comparable with token counts or complaints
2026 Solana preprintBehavior-guided candidates: pump-and-dump, liquidity withdrawal, or freeze-authority abuseOrca, Raydium, and Meteora on SolanaJanuary 1–June 30, 2025100,063 newly issued tokens; model developed from a manually verified benchmarkDirect, verifiable SOL and USDT/USDC cashed out by associated profitable addressesPreprint; detection candidates, with sampled validationThe same pipeline applied to a comparable token population; not a global or adjudicated total
FBI IC3 2025 Annual ReportCryptocurrency-nexus complaints and reported losses; no rug-pull categoryU.S. complaints2025Reports submitted to IC3; not disclosed as a unique-victim censusVictim-reported lossesComplaint data; not rug-pull-specificIC3 figures using the same complaint categories; not directly comparable with on-chain detection

Direct sources for the comparison table:

Each source uses a different measured object and method.

There is therefore no defensible annual rug-pull chart across these sources. A chart that places their totals on one timeline would hide changes in object, chain, threshold, and loss basis. A source-comparison table is the more accurate answer.

What Counts as a Rug Pull?

A practical working definition is an insider- or operator-driven scheme in which people controlling a crypto project, token, liquidity pool, or custodial platform misuse that control and leave other participants unable to realize the represented value. The boundary is not fixed. Chainalysis has explicitly noted that the definition is not set in stone, and technical studies often classify behavior rather than intent.

Rug pulls also differ from many incidents in DeepStrike’s DeFi hacks and exploits statistics. A hack normally centers on unauthorized exploitation by an external or unauthorized actor; a rug pull generally centers on deceptive or abusive use of insider, deployer, owner, or operator control. A case can involve both, and attribution may remain disputed.

TypeDefensive descriptionObservable on-chain/off-chain signalsWhat the signal cannot establishDefensive control
Hard-coded honeypot or withdrawal restrictionToken or contract logic permits buying or depositing but restricts ordinary selling, transferring, or withdrawingReverting sell paths; privileged allow/deny lists; mutable transfer rules; extreme or changeable fees; proxy or owner controlsWho intended harm, whether the behavior is temporary, or whether a regulator/court would classify it as fraudIndependent code and authority review; buy/sell simulation in a safe environment; monitoring of upgrades and privileged changes
Liquidity sweepA controller removes most available liquidity, preventing holders from exiting at expected pricesConcentrated LP ownership; unlocked or revocable liquidity; rapid LP-token movement; sudden reserve reductionWhether removal was disclosed, authorized, required by an emergency, or criminalVerify lock/burn claims and ownership; monitor reserves and LP-token movements; require multisig/timelock controls where applicable
Developer dump / pump-and-dump overlapInsiders or coordinated wallets build demand, then sell concentrated holdings into buyersConcentrated supply; linked wallets; promotional bursts; transfers before large sales; wash-like volumeWallet identity, coordination, false representations, or legal intent by itselfAnalyze allocations and related wallets; define vesting and disclosure controls; monitor concentration and abnormal transfers
Abandonment or soft rugOperators stop development, support, or promised delivery while value deterioratesDormant repositories; missed milestones; disappearing communications; treasury movement; revoked accessWhether the project failed in good faith, suffered operational disruption, or was designed to deceiveVerify governance, treasury controls, release evidence, key-person risk, and incident communications before exposure
Centralized exit scamA custodial operator blocks withdrawals or misappropriates assets while controlling user balancesWithdrawal delays; opaque reserves; inconsistent statements; asset transfers to related wallets; access restrictionsInsolvency, operational failure, or criminal responsibility without fuller evidenceMinimize custodial exposure; verify governance and controls; maintain withdrawal monitoring and incident escalation paths
Matrix matching five rug-pull patterns with warning signals and defensive controls, noting that signals are not proof and controls reduce—not eliminate—risk.

Source note: DeepStrike defensive synthesis based on Chainalysis classification notes, Solidus Labs’ disclosed on-chain methods, and a CFTC Commissioner’s August 5, 2025 statement describing hard-coded rug-pull patterns. The Commissioner’s statement is not a Commission rule or endorsement.

Pump-and-dump behavior overlaps when insiders create or amplify demand and exit into it. Some studies treat that pattern as a rug-pull subtype; others classify it separately. A careful report names the source’s category instead of silently converting every pump-and-dump candidate into a proven rug pull.

Rug Pull Losses and Trends Over Time

The most defensible historical headline remains Chainalysis’ 2021 estimate: more than $2.8 billion in stolen funds, or 37% of the firm’s crypto-scam revenue for that year. It should not be interpreted as a normal annual baseline. Thodex, a centralized exchange, accounted for nearly 90% of the amount, so one analytics-classified incident dominated the series.

Chainalysis later clarified the measurement distinction in its 2022 Crypto Crime Report introduction: its rug-pull loss estimate captured investor funds taken by the operators, not the value erased as the associated tokens declined. That rule makes the figure more concrete, but it also means other sources using market-cap decline or victim reports are measuring something else.

Recent platform studies supply useful prevalence and mechanism evidence, but they do not extend the same annual series. Solidus measures token and pool outcomes under disclosed thresholds. The Solana preprint detects candidates and separately estimates certain cash-outs. FBI IC3 measures submitted complaints under broader categories. Treating those as successive yearly observations would produce a false trend.

The correct conclusion is narrower: rug-pull risk remains observable across centralized and decentralized structures, while the reported scale depends heavily on where researchers look and what they count. Broader cybercrime statistics can help frame the surrounding fraud environment, but they cannot fill missing rug-pull years.

Ecosystem and Platform Findings

Pump.fun tokens

Solidus Labs studied more than seven million Pump.fun tokens created between January 2024 and March 2025 that had at least five trades. Only 97,000 maintained more than $1,000 in liquidity; the report described 98.6% as having collapsed below that threshold. It excluded tokens upgraded to Raydium from this specific remaining-liquidity measure.

That is a striking platform outcome, not a 98.6% criminal-fraud rate. The threshold says what happened to liquidity under the study’s rule. It does not prove why each token failed, whether every buyer suffered a realizable loss, or whether an identifiable operator committed fraud.

Raydium pools

The same Solidus report examined 388,000 Raydium V4 automated-market-maker pools and reported that approximately 93% showed its soft-rug characteristics. Its method analyzed deposits, withdrawals, LP-token minting, and burning. For sweeps using a 90% liquidity-withdrawal threshold, 25% of detected amounts were below $732, the median was about $2,832, and the maximum was $1.9 million.

The report’s summary contains a malformed affected-pool count alongside the rounded percentage, so this article does not reconstruct the missing digit or publish a derived count. The percentage is retained as reported and qualified. This is the safer approach whenever a source’s display is internally inconsistent.

Three Solana decentralized exchanges

The 2026 preprint began with 68 community-reported incidents and built a manually verified benchmark of 117 confirmed rug-pull tokens. Its behavior-guided pipeline then evaluated 100,063 newly issued tokens on Orca, Raydium, and Meteora during the first half of 2025, labeling 76,469 candidates: 60,402 pump-and-dump candidates, 15,606 liquidity-withdrawal candidates, and 461 freeze-authority-abuse candidates.

In a random audit of 382 labeled samples, the authors observed a 0.26% false-positive rate and reported a 95% upper bound of 1.45%. A separate check of 100 non-rug samples found nine slower cases the system had missed. Those tests support the pipeline’s usefulness within the study, but they also demonstrate why “candidate” must remain in the public label.

For loss, the paper tracked verifiable amounts cashed out by 7,322 profitable addresses in SOL and the stablecoins USDT and USDC. It estimated at least $151,089,437.80 in direct loss. The method is conservative about on-chain realization, yet it does not capture every holder’s unrealized decline, every off-chain transfer, or activity beyond the selected DEXs and dates.

These datasets cannot determine which blockchain has the most rug pulls. Cross-chain ranking would require the same observation period, asset-inclusion rule, behavior classifier, denominator, price source, and validation procedure on every chain. No source used here provides that comparison.

Four separate cards comparing a 2021 analytics estimate, two Solana datasets, and broader 2025 FBI complaint context.

Source note: Source-reported figures from Chainalysis (2021), Solidus Labs (2025), the Solana preprint v2 (2026), and FBI IC3 (2025). The figures are not added, normalized, or converted into a cross-source rate.

The Largest Reported Rug Pulls and Why Rankings Are Fragile

A definitive “largest rug pulls” ranking is not supportable from a single consistent, current primary dataset. The table below instead shows selected high-authority cases and preserves the classification and impact basis. It is not a global leaderboard.

Project / incidentYearClassification sourceStatusReported impactImpact basisCurrent caveat
Thodex2021Chainalysis (2021)Analytics-classified rug pull; centralized exchangeMore than $2 billion and nearly 90% of Chainalysis’ 2021 rug-pull valueInvestor funds classified as stolen under the firm’s methodNot a court-determined loss figure in this source; later legal records and estimates may use different bases
AnubisDAO2021Chainalysis (2021)Analytics-classified; perpetrator attribution disputedMore than $58 millionCrypto removed from the project’s liquidity pool after roughly 20 hoursThe source said the pattern pointed to a standard rug pull but did not establish who was responsible
SafeMoon2025 conviction; 2026 sentenceU.S. Department of Justice (2026)CEO convicted of securities-fraud, wire-fraud, and money-laundering conspiracy; sentenced to 100 months$7.5 million forfeiture; restitution was still to be determined at sentencingCourt-ordered forfeiture, not a complete victim-loss or token-market-cap measureDOJ described false liquidity-access claims and misappropriation but did not present this as a ranked generic rug-pull loss

Case sources:

These cases illustrate why ranking requires more than a dollar sign. A centralized exchange exit, a liquidity-pool withdrawal, and fraud involving liquidity representations can all appear in “rug pull” discussions, yet their legal findings, datasets, and impact measures differ.

U.S. Reporting and Legal Context

The FBI IC3 2025 Annual Report recorded 181,565 cryptocurrency-nexus complaints and $11.366 billion in reported losses. IC3 does not publish “rug pull” as a separate category in that report, so the figure is not a rug-pull count or loss total. Complaints also should not be read as court-confirmed incidents or necessarily unique victims. The article omits the report’s investment-fraud loss subfigure because the summary and detailed table publish different amounts.

U.S. legal exposure depends on the facts: representations to buyers, control over liquidity or assets, conduct, instrument characteristics, state and federal law, and jurisdiction. The SEC Division of Corporation Finance’s meme-coin staff statement expressed a staff view that transactions in the described meme coins generally did not involve securities. The document also says it is not a rule, regulation, guidance, or Commission statement, has no legal force, does not cover disguised securities, and does not prevent other agencies from pursuing fraud.

The SafeMoon prosecution demonstrates the danger of categorical claims that a liquidity-related scheme is “legal.” A federal jury convicted its CEO in May 2025, and a court imposed a 100-month sentence on February 10, 2026 for conspiracies involving false claims about locked liquidity and the misappropriation of millions. The result is case-specific; it does not convert every failed token or liquidity event into the same offense.

Investigation can combine on-chain records with platform, exchange, identity, infrastructure, and legal process. DeepStrike’s overview of how law enforcement tracks online criminals provides broader context, but victims should report through official channels rather than attempting their own attribution.

This is general information, not legal or financial advice.

Warning Signals and Defensive Controls

No indicator proves a rug pull on its own. The goal is to identify concentrated control, unverifiable claims, and pathways through which insiders could change rules, withdraw value, or obstruct exits.

Contract and token controls

Review minting rights, transfer restrictions, pause and blacklist powers, fee controls, ownership transfer, proxy upgrades, and any method that changes who can buy, sell, or withdraw. Test expected user paths in a safe environment. Record which authorities exist now and how they can change later.

An independent review can reduce technical uncertainty, but its scope matters. DeepStrike’s smart contract auditor roadmap is useful educational context; it does not mean an audit can prove honest intent, validate marketing claims, or guarantee future governance behavior.

Liquidity and market structure

Verify who owns LP tokens, whether a claimed lock is real and irrevocable for the stated period, whether liquidity is deep enough for plausible exits, and whether concentrated wallets can overwhelm the market. Monitor reserve changes, LP-token transfers, linked-wallet activity, and abrupt changes in fees or trading rules.

Deployer and team behavior

Map supply concentration, deployer and treasury relationships, vesting, privileged wallets, recent transfers, and discrepancies between public claims and on-chain control. Identity verification can raise accountability, but a known identity is not a substitute for enforceable controls.

Governance and operations

Assess multisig thresholds, timelocks, key storage, administrator access, release approvals, monitoring, and incident response. In Web3 and fintech systems, ordinary operational weaknesses can compound token risk; DeepStrike’s fintech breach statistics covers the broader environment without treating every breach as a rug pull.

Token controls are only one attack surface. A dApp frontend, API, cloud account, administrative portal, identity system, or software-delivery pipeline can redirect users or expose privileged operations. A scoped web application penetration test can examine those conventional application surfaces, but it is not a substitute for token-economics review, smart-contract assurance, or legal due diligence.

Communications and evidence

Treat guaranteed returns, manufactured urgency, unverifiable partnerships, anonymous or inconsistent operators, copied documentation, audit-logo misuse, and vague liquidity-lock claims as reasons for deeper verification. Confirm what an audit covered, when it was performed, which code version it reviewed, and what remained out of scope.

What To Do After a Suspected Rug Pull

  1. Stop sending funds. Do not interact with new links or contracts shared by supposed support accounts.
  2. Avoid recovery scams. Do not pay unsolicited services that guarantee recovery or ask for seed phrases, private keys, or additional “release” payments.
  3. Preserve evidence. Save transaction hashes, wallet and contract addresses, exact URLs, timestamps and time zones, screenshots, messages, token identifiers, exchange records, and the device/account context.
  4. Contact the relevant platform or exchange promptly. Provide precise identifiers and ask that records be preserved. A recipient platform may have its own fraud workflow; it cannot promise recovery.
  5. Report through official U.S. channels. The FTC’s cryptocurrency-scam guidance points consumers to ReportFraud.ftc.gov, FBI IC3, the SEC, the CFTC, and the exchange or payment provider as applicable.
  6. Get qualified advice for material losses. Counsel, tax professionals, financial advisers, or incident-response specialists can help assess obligations and next steps within their actual scope.

Do not publish personal accusations from wallet patterns alone. Preserve the distinction between an observable transaction, an analytics classification, an allegation, and an adjudicated finding.

Frequently Asked Questions

How common are crypto rug pulls?

There is no reliable global rate. Solidus Labs found extremely high rates of low-liquidity or soft-rug-like outcomes in defined Pump.fun and Raydium datasets.

A Solana preprint labeled 76,469 candidates among 100,063 tokens issued on three DEXs in six months. Both results describe selected platforms, rules, and dates not all tokens or proven fraud worldwide.

How much money is lost to rug pulls each year?

No current source in this review supplies a consistent annual global series. Chainalysis attributed more than $2.8 billion in stolen funds to rug pulls in 2021, but Thodex accounted for nearly 90% of that amount. Later platform studies use different objects and loss methods, so joining them into a year-by-year chart would mislead.

What is the difference between a rug pull, honeypot, exit scam, and pump-and-dump?

A rug pull is the broadest practical label for insider or operator abuse that leaves participants unable to realize represented value. A honeypot uses restrictions that obstruct selling or withdrawing. An exit scam usually describes an operator disappearing with controlled assets, often in a custodial setting. A pump-and-dump centers on creating demand and then selling concentrated holdings. Sources may classify overlapping behavior differently.

Which blockchain has the most rug pulls?

The available evidence does not support a fair ranking. Solana is prominent in recent research because token-launch and DEX activity can be studied at scale, but a larger detected count can reflect more activity, better data, or a broader classifier. A valid comparison would apply the same dates, denominator, thresholds, and validation procedure across chains.

Are rug pulls illegal in the United States?

There is no categorical answer for every token failure. Fraud, false statements, misappropriation, market conduct, money laundering, and securities or commodities laws may apply depending on the facts and jurisdiction. The SEC staff’s meme-coin statement is nonbinding and says fraudulent conduct may still face action under other federal or state law.

A failed project is not automatically criminal, while the SafeMoon conviction and sentence show that false liquidity claims and misappropriation can lead to criminal liability on case-specific facts. Seek qualified counsel for a specific case.

Can a smart-contract audit prevent a rug pull?

No. A good audit may identify dangerous code paths, privileged functions, and control weaknesses in the reviewed version. It cannot prove operator intent, guarantee that governance will act honestly, validate off-chain representations, prevent misuse of legitimate privileges, or remove frontend, API, cloud, key-management, and custody risk.

What should a victim do after a suspected rug pull?

Stop further transfers, avoid unsolicited recovery offers, preserve transaction and communications evidence, notify the relevant platform or exchange, and use the official routes in the FTC’s cryptocurrency-scam guidance, including FBI IC3 where applicable. For material losses, consider qualified legal, tax, financial, and incident-response advice. Never share a seed phrase or private key with a supposed investigator or recovery service.

Conclusion

A rug-pull number is useful only when its definition, dataset, denominator, valuation, and confirmation status are visible. Chainalysis’ 2021 stolen-funds estimate, Solidus Labs’ platform thresholds, the Solana preprint’s candidate detection, and FBI complaint context each illuminate a different part of the problem. None can stand in for the others.

For organizations, the practical response is layered assurance: review token and governance controls, then test the surrounding applications and operations that users and administrators rely on. DeepStrike’s verified penetration testing services cover conventional security assessment; the precise scope should be agreed before testing.

U.S. Web3 and fintech teams can ask DeepStrike to scope an assessment of dApp frontends, APIs, cloud systems, administrative interfaces, identity controls, and software-delivery pipelines. This scope does not include asset recovery, legal advice, investment due diligence, or an implied smart-contract-audit service.

About the Author

Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us