August 2, 2026
Updated: August 2, 2026
A source-aware analysis of rug pull losses, token collapse data, Solana findings, reporting caveats, and defensive controls for crypto and Web3 teams.
Mohammed Khalil

Rug pull statistics vary sharply because researchers count different behaviors, ecosystems, thresholds, and forms of loss.
Executive Answer: No global rug-pull total is reliable. Chainalysis attributed more than $2.8 billion in stolen funds to rug pulls in 2021, with one centralized exchange accounting for nearly 90% of that value. A 2026 Solana preprint identified 76,469 candidate rug-pull tokens among 100,063 tokens issued on three decentralized exchanges in early 2025, estimating at least $151 million in directly traceable losses. Separately, Solidus Labs found that 98.6% of more than seven million Pump.fun tokens it studied had fallen below $1,000 in liquidity but that threshold shows collapse, not proven criminal fraud.
The figures answer different questions. Chainalysis measured investor funds it classified as stolen in rug pulls, not subsequent token-price decline, and its 2021 result was unusually concentrated in Thodex. The firm’s 2021 scam analysis is therefore evidence for that year and method, not a reusable global average.
Solidus Labs examined platform-specific token and pool behavior. Its 2025 Solana report used liquidity and withdrawal thresholds that identify collapse or suspicious behavior; they do not establish criminal intent for every token or pool.
The Solana study is a 2026 academic preprint, not a peer-reviewed census of all blockchains. Its 76,469 labels are detection candidates from a defined six-month, three-DEX dataset, while its loss estimate follows a conservative on-chain cash-out method.
For broader context, DeepStrike’s crypto crime report covers categories that extend well beyond rug pulls. That wider context should not be merged into a rug-pull total.
How to read these statistics: treat each row as a scoped finding; compare figures only when the measured object, time window, denominator, valuation, and classification method match.
| Statistic | Value | Period | Measured object | Ecosystem / geography | Definition or threshold | Source | What it does not prove |
|---|---|---|---|---|---|---|---|
| Rug-pull funds classified as stolen | More than $2.8 billion; 37% of the source’s 2021 crypto-scam revenue | 2021 | Investor funds taken in incidents Chainalysis classified as rug pulls | Global on-chain analytics coverage | Source methodology counted stolen investor funds, excluding later token-value decline | Chainalysis (2021) — https://www.chainalysis.com/blog/2021-crypto-scam-revenues/ | A typical annual loss: Thodex represented nearly 90% of the value |
| Pump.fun token liquidity outcome | More than 7 million tokens studied; 97,000 retained more than $1,000 liquidity; 98.6% fell below that threshold | January 2024–March 2025 | Tokens with at least five trades | Pump.fun on Solana | Remaining liquidity below $1,000; tokens upgraded to Raydium excluded from that measure | Solidus Labs (2025) — https://www.soliduslabs.com/reports/solana-rug-pulls-pump-dumps-crypto-compliance | That every low-liquidity token was an intentional or legally proven rug pull |
| Raydium pool behavior | Approximately 93% of 388,000 pools examined showed the report’s soft-rug characteristics | Report published May 2025; underlying observation window not disclosed | Raydium V4 automated-market-maker pools | Raydium on Solana | Deposit/withdrawal and LP mint/burn analysis; a 90% liquidity-withdrawal sweep threshold used for distribution statistics | Solidus Labs (2025) — https://www.soliduslabs.com/reports/solana-rug-pulls-pump-dumps-crypto-compliance | A cross-chain rug-pull rate or adjudicated fraud count |
| Candidate rug-pull tokens | 76,469 candidates among 100,063 newly issued tokens | January 1–June 30, 2025 | Newly issued tokens on Orca, Raydium, and Meteora | Three Solana DEXs | Behavior-guided detection pipeline covering pump-and-dump, liquidity withdrawal, and freeze-authority abuse | Solana preprint v2 (2026) — https://arxiv.org/html/2603.24625v2 | A final legal finding for every candidate or a rate for all Solana tokens |
| Directly traceable loss in the candidate dataset | At least $151,089,437.80 across 7,322 profitable addresses | January 1–June 30, 2025 | Quantifiable assets cashed out by addresses associated with detected candidates | Three Solana DEXs | Conservative tracking of verifiable SOL and USDT/USDC cash-outs | Solana preprint v2 (2026) — https://arxiv.org/html/2603.24625v2 | Total victim harm, unrealized token-value decline, or a global loss estimate |
| Not rug-pull-specific: cryptocurrency-nexus complaints | 181,565 complaints and $11.366 billion in reported losses | 2025 | Complaints with a cryptocurrency nexus | United States reporting to FBI IC3 | Victim-reported complaint classification | FBI IC3 2025 Annual Report, pp. 51–52 — https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf | The number of confirmed crimes, unique victims, or losses caused specifically by rug pulls |
Direct sources for the table:
The table deliberately keeps dollars, token counts, pool counts, percentages, and complaint data separate. Adding them would create a number with no defensible meaning.

Source note: DeepStrike analysis based on the source-method review cited in this article.
“Rug pull” is a practical label, not a universal measurement standard. One source may count stolen crypto traced to an operator. Another may flag a token whose liquidity disappeared. A third may detect a price-and-wallet pattern. An agency report may count victim complaints under a broader category without identifying rug pulls at all.
Use the DeepStrike Rug-Pull Evidence Matrix before repeating a headline number:
Two additional biases matter. Activity bias makes a busy token-launch platform produce more observed cases even if its risk rate is unknown. Observation bias makes a well-monitored chain look worse than a chain with weaker labels or less accessible data. Neither justifies ranking one blockchain as the “worst” without comparable denominators and detection coverage.
A low-liquidity token is not automatically evidence of fraud. Projects can fail, lose users, or be abandoned without an intentional scheme. Conversely, a detection rule can miss slower, coordinated, or off-chain abuse. The Solana preprint itself reported a very low observed false-positive rate in one random audit but also found missed slower cases in a separate non-rug sample. That combination argues for cautious labels, not certainty.
Valuation creates another fault line. A perpetrator’s realized withdrawal is measurable on-chain but may omit indirect harm. A token’s market-cap decline can be much larger, yet it is not cash available to withdraw and is highly sensitive to price and liquidity. Victim-reported loss is valuable U.S. context, but complaints are not equivalent to verified transactions or court findings.
| Source / dataset | Definition | Chain / platform | Time window | Denominator / threshold | Loss or value basis | Confirmation status | Comparable with |
|---|---|---|---|---|---|---|---|
| Chainalysis 2021 scam analysis | Incidents classified as rug pulls under the firm’s crypto-scam analytics | Multi-chain/global analytics coverage | 2021 | Covered services and addresses; full denominator not disclosed on the page | Investor funds classified as stolen; later token-value decline excluded | Analytics-classified | Same Chainalysis series and definition only; not directly comparable with token-collapse counts |
| Solidus Labs Pump.fun study | Tokens falling below a remaining-liquidity threshold in a platform study | Pump.fun on Solana | January 2024–March 2025 | More than 7 million tokens with at least five trades; $1,000 liquidity threshold; Raydium upgrades excluded | Remaining liquidity, not a victim-loss total | Method-classified collapse/pump-and-dump behavior | Other studies using the same platform, inclusion rule, exclusion, date window, and threshold |
| Solidus Labs Raydium study | Pools showing the report’s soft-rug characteristics | Raydium V4 on Solana | Report published May 2025; underlying observation window not disclosed | 388,000 pools; distribution statistics use a 90% liquidity-withdrawal threshold | Liquidity sweep amounts; median about $2,832 and maximum $1.9 million under the stated threshold | Method-classified behavior | Same pool model and threshold only; not directly comparable with token counts or complaints |
| 2026 Solana preprint | Behavior-guided candidates: pump-and-dump, liquidity withdrawal, or freeze-authority abuse | Orca, Raydium, and Meteora on Solana | January 1–June 30, 2025 | 100,063 newly issued tokens; model developed from a manually verified benchmark | Direct, verifiable SOL and USDT/USDC cashed out by associated profitable addresses | Preprint; detection candidates, with sampled validation | The same pipeline applied to a comparable token population; not a global or adjudicated total |
| FBI IC3 2025 Annual Report | Cryptocurrency-nexus complaints and reported losses; no rug-pull category | U.S. complaints | 2025 | Reports submitted to IC3; not disclosed as a unique-victim census | Victim-reported losses | Complaint data; not rug-pull-specific | IC3 figures using the same complaint categories; not directly comparable with on-chain detection |
Direct sources for the comparison table:
Each source uses a different measured object and method.
There is therefore no defensible annual rug-pull chart across these sources. A chart that places their totals on one timeline would hide changes in object, chain, threshold, and loss basis. A source-comparison table is the more accurate answer.
A practical working definition is an insider- or operator-driven scheme in which people controlling a crypto project, token, liquidity pool, or custodial platform misuse that control and leave other participants unable to realize the represented value. The boundary is not fixed. Chainalysis has explicitly noted that the definition is not set in stone, and technical studies often classify behavior rather than intent.
Rug pulls also differ from many incidents in DeepStrike’s DeFi hacks and exploits statistics. A hack normally centers on unauthorized exploitation by an external or unauthorized actor; a rug pull generally centers on deceptive or abusive use of insider, deployer, owner, or operator control. A case can involve both, and attribution may remain disputed.
| Type | Defensive description | Observable on-chain/off-chain signals | What the signal cannot establish | Defensive control |
|---|---|---|---|---|
| Hard-coded honeypot or withdrawal restriction | Token or contract logic permits buying or depositing but restricts ordinary selling, transferring, or withdrawing | Reverting sell paths; privileged allow/deny lists; mutable transfer rules; extreme or changeable fees; proxy or owner controls | Who intended harm, whether the behavior is temporary, or whether a regulator/court would classify it as fraud | Independent code and authority review; buy/sell simulation in a safe environment; monitoring of upgrades and privileged changes |
| Liquidity sweep | A controller removes most available liquidity, preventing holders from exiting at expected prices | Concentrated LP ownership; unlocked or revocable liquidity; rapid LP-token movement; sudden reserve reduction | Whether removal was disclosed, authorized, required by an emergency, or criminal | Verify lock/burn claims and ownership; monitor reserves and LP-token movements; require multisig/timelock controls where applicable |
| Developer dump / pump-and-dump overlap | Insiders or coordinated wallets build demand, then sell concentrated holdings into buyers | Concentrated supply; linked wallets; promotional bursts; transfers before large sales; wash-like volume | Wallet identity, coordination, false representations, or legal intent by itself | Analyze allocations and related wallets; define vesting and disclosure controls; monitor concentration and abnormal transfers |
| Abandonment or soft rug | Operators stop development, support, or promised delivery while value deteriorates | Dormant repositories; missed milestones; disappearing communications; treasury movement; revoked access | Whether the project failed in good faith, suffered operational disruption, or was designed to deceive | Verify governance, treasury controls, release evidence, key-person risk, and incident communications before exposure |
| Centralized exit scam | A custodial operator blocks withdrawals or misappropriates assets while controlling user balances | Withdrawal delays; opaque reserves; inconsistent statements; asset transfers to related wallets; access restrictions | Insolvency, operational failure, or criminal responsibility without fuller evidence | Minimize custodial exposure; verify governance and controls; maintain withdrawal monitoring and incident escalation paths |

Source note: DeepStrike defensive synthesis based on Chainalysis classification notes, Solidus Labs’ disclosed on-chain methods, and a CFTC Commissioner’s August 5, 2025 statement describing hard-coded rug-pull patterns. The Commissioner’s statement is not a Commission rule or endorsement.
Pump-and-dump behavior overlaps when insiders create or amplify demand and exit into it. Some studies treat that pattern as a rug-pull subtype; others classify it separately. A careful report names the source’s category instead of silently converting every pump-and-dump candidate into a proven rug pull.
The most defensible historical headline remains Chainalysis’ 2021 estimate: more than $2.8 billion in stolen funds, or 37% of the firm’s crypto-scam revenue for that year. It should not be interpreted as a normal annual baseline. Thodex, a centralized exchange, accounted for nearly 90% of the amount, so one analytics-classified incident dominated the series.
Chainalysis later clarified the measurement distinction in its 2022 Crypto Crime Report introduction: its rug-pull loss estimate captured investor funds taken by the operators, not the value erased as the associated tokens declined. That rule makes the figure more concrete, but it also means other sources using market-cap decline or victim reports are measuring something else.
Recent platform studies supply useful prevalence and mechanism evidence, but they do not extend the same annual series. Solidus measures token and pool outcomes under disclosed thresholds. The Solana preprint detects candidates and separately estimates certain cash-outs. FBI IC3 measures submitted complaints under broader categories. Treating those as successive yearly observations would produce a false trend.
The correct conclusion is narrower: rug-pull risk remains observable across centralized and decentralized structures, while the reported scale depends heavily on where researchers look and what they count. Broader cybercrime statistics can help frame the surrounding fraud environment, but they cannot fill missing rug-pull years.
Solidus Labs studied more than seven million Pump.fun tokens created between January 2024 and March 2025 that had at least five trades. Only 97,000 maintained more than $1,000 in liquidity; the report described 98.6% as having collapsed below that threshold. It excluded tokens upgraded to Raydium from this specific remaining-liquidity measure.
That is a striking platform outcome, not a 98.6% criminal-fraud rate. The threshold says what happened to liquidity under the study’s rule. It does not prove why each token failed, whether every buyer suffered a realizable loss, or whether an identifiable operator committed fraud.
The same Solidus report examined 388,000 Raydium V4 automated-market-maker pools and reported that approximately 93% showed its soft-rug characteristics. Its method analyzed deposits, withdrawals, LP-token minting, and burning. For sweeps using a 90% liquidity-withdrawal threshold, 25% of detected amounts were below $732, the median was about $2,832, and the maximum was $1.9 million.
The report’s summary contains a malformed affected-pool count alongside the rounded percentage, so this article does not reconstruct the missing digit or publish a derived count. The percentage is retained as reported and qualified. This is the safer approach whenever a source’s display is internally inconsistent.
The 2026 preprint began with 68 community-reported incidents and built a manually verified benchmark of 117 confirmed rug-pull tokens. Its behavior-guided pipeline then evaluated 100,063 newly issued tokens on Orca, Raydium, and Meteora during the first half of 2025, labeling 76,469 candidates: 60,402 pump-and-dump candidates, 15,606 liquidity-withdrawal candidates, and 461 freeze-authority-abuse candidates.
In a random audit of 382 labeled samples, the authors observed a 0.26% false-positive rate and reported a 95% upper bound of 1.45%. A separate check of 100 non-rug samples found nine slower cases the system had missed. Those tests support the pipeline’s usefulness within the study, but they also demonstrate why “candidate” must remain in the public label.
For loss, the paper tracked verifiable amounts cashed out by 7,322 profitable addresses in SOL and the stablecoins USDT and USDC. It estimated at least $151,089,437.80 in direct loss. The method is conservative about on-chain realization, yet it does not capture every holder’s unrealized decline, every off-chain transfer, or activity beyond the selected DEXs and dates.
These datasets cannot determine which blockchain has the most rug pulls. Cross-chain ranking would require the same observation period, asset-inclusion rule, behavior classifier, denominator, price source, and validation procedure on every chain. No source used here provides that comparison.

Source note: Source-reported figures from Chainalysis (2021), Solidus Labs (2025), the Solana preprint v2 (2026), and FBI IC3 (2025). The figures are not added, normalized, or converted into a cross-source rate.
A definitive “largest rug pulls” ranking is not supportable from a single consistent, current primary dataset. The table below instead shows selected high-authority cases and preserves the classification and impact basis. It is not a global leaderboard.
| Project / incident | Year | Classification source | Status | Reported impact | Impact basis | Current caveat |
|---|---|---|---|---|---|---|
| Thodex | 2021 | Chainalysis (2021) | Analytics-classified rug pull; centralized exchange | More than $2 billion and nearly 90% of Chainalysis’ 2021 rug-pull value | Investor funds classified as stolen under the firm’s method | Not a court-determined loss figure in this source; later legal records and estimates may use different bases |
| AnubisDAO | 2021 | Chainalysis (2021) | Analytics-classified; perpetrator attribution disputed | More than $58 million | Crypto removed from the project’s liquidity pool after roughly 20 hours | The source said the pattern pointed to a standard rug pull but did not establish who was responsible |
| SafeMoon | 2025 conviction; 2026 sentence | U.S. Department of Justice (2026) | CEO convicted of securities-fraud, wire-fraud, and money-laundering conspiracy; sentenced to 100 months | $7.5 million forfeiture; restitution was still to be determined at sentencing | Court-ordered forfeiture, not a complete victim-loss or token-market-cap measure | DOJ described false liquidity-access claims and misappropriation but did not present this as a ranked generic rug-pull loss |
Case sources:
These cases illustrate why ranking requires more than a dollar sign. A centralized exchange exit, a liquidity-pool withdrawal, and fraud involving liquidity representations can all appear in “rug pull” discussions, yet their legal findings, datasets, and impact measures differ.
The FBI IC3 2025 Annual Report recorded 181,565 cryptocurrency-nexus complaints and $11.366 billion in reported losses. IC3 does not publish “rug pull” as a separate category in that report, so the figure is not a rug-pull count or loss total. Complaints also should not be read as court-confirmed incidents or necessarily unique victims. The article omits the report’s investment-fraud loss subfigure because the summary and detailed table publish different amounts.
U.S. legal exposure depends on the facts: representations to buyers, control over liquidity or assets, conduct, instrument characteristics, state and federal law, and jurisdiction. The SEC Division of Corporation Finance’s meme-coin staff statement expressed a staff view that transactions in the described meme coins generally did not involve securities. The document also says it is not a rule, regulation, guidance, or Commission statement, has no legal force, does not cover disguised securities, and does not prevent other agencies from pursuing fraud.
The SafeMoon prosecution demonstrates the danger of categorical claims that a liquidity-related scheme is “legal.” A federal jury convicted its CEO in May 2025, and a court imposed a 100-month sentence on February 10, 2026 for conspiracies involving false claims about locked liquidity and the misappropriation of millions. The result is case-specific; it does not convert every failed token or liquidity event into the same offense.
Investigation can combine on-chain records with platform, exchange, identity, infrastructure, and legal process. DeepStrike’s overview of how law enforcement tracks online criminals provides broader context, but victims should report through official channels rather than attempting their own attribution.
This is general information, not legal or financial advice.
No indicator proves a rug pull on its own. The goal is to identify concentrated control, unverifiable claims, and pathways through which insiders could change rules, withdraw value, or obstruct exits.
Review minting rights, transfer restrictions, pause and blacklist powers, fee controls, ownership transfer, proxy upgrades, and any method that changes who can buy, sell, or withdraw. Test expected user paths in a safe environment. Record which authorities exist now and how they can change later.
An independent review can reduce technical uncertainty, but its scope matters. DeepStrike’s smart contract auditor roadmap is useful educational context; it does not mean an audit can prove honest intent, validate marketing claims, or guarantee future governance behavior.
Verify who owns LP tokens, whether a claimed lock is real and irrevocable for the stated period, whether liquidity is deep enough for plausible exits, and whether concentrated wallets can overwhelm the market. Monitor reserve changes, LP-token transfers, linked-wallet activity, and abrupt changes in fees or trading rules.
Map supply concentration, deployer and treasury relationships, vesting, privileged wallets, recent transfers, and discrepancies between public claims and on-chain control. Identity verification can raise accountability, but a known identity is not a substitute for enforceable controls.
Assess multisig thresholds, timelocks, key storage, administrator access, release approvals, monitoring, and incident response. In Web3 and fintech systems, ordinary operational weaknesses can compound token risk; DeepStrike’s fintech breach statistics covers the broader environment without treating every breach as a rug pull.
Token controls are only one attack surface. A dApp frontend, API, cloud account, administrative portal, identity system, or software-delivery pipeline can redirect users or expose privileged operations. A scoped web application penetration test can examine those conventional application surfaces, but it is not a substitute for token-economics review, smart-contract assurance, or legal due diligence.
Treat guaranteed returns, manufactured urgency, unverifiable partnerships, anonymous or inconsistent operators, copied documentation, audit-logo misuse, and vague liquidity-lock claims as reasons for deeper verification. Confirm what an audit covered, when it was performed, which code version it reviewed, and what remained out of scope.
Do not publish personal accusations from wallet patterns alone. Preserve the distinction between an observable transaction, an analytics classification, an allegation, and an adjudicated finding.
There is no reliable global rate. Solidus Labs found extremely high rates of low-liquidity or soft-rug-like outcomes in defined Pump.fun and Raydium datasets.
A Solana preprint labeled 76,469 candidates among 100,063 tokens issued on three DEXs in six months. Both results describe selected platforms, rules, and dates not all tokens or proven fraud worldwide.
No current source in this review supplies a consistent annual global series. Chainalysis attributed more than $2.8 billion in stolen funds to rug pulls in 2021, but Thodex accounted for nearly 90% of that amount. Later platform studies use different objects and loss methods, so joining them into a year-by-year chart would mislead.
A rug pull is the broadest practical label for insider or operator abuse that leaves participants unable to realize represented value. A honeypot uses restrictions that obstruct selling or withdrawing. An exit scam usually describes an operator disappearing with controlled assets, often in a custodial setting. A pump-and-dump centers on creating demand and then selling concentrated holdings. Sources may classify overlapping behavior differently.
The available evidence does not support a fair ranking. Solana is prominent in recent research because token-launch and DEX activity can be studied at scale, but a larger detected count can reflect more activity, better data, or a broader classifier. A valid comparison would apply the same dates, denominator, thresholds, and validation procedure across chains.
There is no categorical answer for every token failure. Fraud, false statements, misappropriation, market conduct, money laundering, and securities or commodities laws may apply depending on the facts and jurisdiction. The SEC staff’s meme-coin statement is nonbinding and says fraudulent conduct may still face action under other federal or state law.
A failed project is not automatically criminal, while the SafeMoon conviction and sentence show that false liquidity claims and misappropriation can lead to criminal liability on case-specific facts. Seek qualified counsel for a specific case.
No. A good audit may identify dangerous code paths, privileged functions, and control weaknesses in the reviewed version. It cannot prove operator intent, guarantee that governance will act honestly, validate off-chain representations, prevent misuse of legitimate privileges, or remove frontend, API, cloud, key-management, and custody risk.
Stop further transfers, avoid unsolicited recovery offers, preserve transaction and communications evidence, notify the relevant platform or exchange, and use the official routes in the FTC’s cryptocurrency-scam guidance, including FBI IC3 where applicable. For material losses, consider qualified legal, tax, financial, and incident-response advice. Never share a seed phrase or private key with a supposed investigator or recovery service.
A rug-pull number is useful only when its definition, dataset, denominator, valuation, and confirmation status are visible. Chainalysis’ 2021 stolen-funds estimate, Solidus Labs’ platform thresholds, the Solana preprint’s candidate detection, and FBI complaint context each illuminate a different part of the problem. None can stand in for the others.
For organizations, the practical response is layered assurance: review token and governance controls, then test the surrounding applications and operations that users and administrators rely on. DeepStrike’s verified penetration testing services cover conventional security assessment; the precise scope should be agreed before testing.
U.S. Web3 and fintech teams can ask DeepStrike to scope an assessment of dApp frontends, APIs, cloud systems, administrative interfaces, identity controls, and software-delivery pipelines. This scope does not include asset recovery, legal advice, investment due diligence, or an implied smart-contract-audit service.
Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us