kommunitas logo
BlogLaunchpad

How to Spot Rug Risks on Launchpads

How to Spot Rug Risks on Launchpads

How to Spot Rug Risks on Launchpads

Launchpad April 15, 2026

By Priyo Harjiyono

Investing in early-stage crypto projects via launchpads offers high-growth potential, but it is also the primary hunting ground for rug pulls. Most guides stop at "check if liquidity is locked." That is not enough. Below are the 12 specific rug risks that actually appear in post-launch analysis of token sales across EVM chains, grouped by where they hide, plus the exact tool to check each one.

This framework is informed by observed rug patterns where recurring exploit structures — liquidity asymmetry, proxy contract abuse, and sell restriction logic — have been consistently identified. Use it to audit project security like a professional analyst.

Liquidity and Tokenomics Red Flags

1. Liquidity-to-Market Cap Ratio Below 5%

High liquidity relative to market cap makes a hard rug (draining the pool) more difficult. If a project has $1M in market cap but only $20k in liquidity, even a small sell-off by the team can crash the price to zero. A ratio under 5% is where cascading slippage collapses become common in low-cap launchpad listings.

Check with: Dexscreener — watch for sudden TVL drops or suspicious sell blocks.

2. Vesting Schedule That Unlocks Before Milestones

Check if the team's vesting schedule aligns with the project roadmap. If team tokens unlock significantly before major product milestones ship, the incentive to exit scam increases sharply. Symmetry between unlock dates and delivery dates is the signal you want.

Check with: The project's own tokenomics documentation, cross-referenced against on-chain unlock schedules.

3. Unverified "Burned" Liquidity

If a project claims to have burned liquidity, verify the dead address (for example 0x000...dead) directly on a blockchain explorer. A marketing graphic claiming a burn is not proof of a burn.

Check with: Etherscan or Solscan — verify the lock and holder counts manually.

4. Wallet Clusters Disguised as Organic Holders

In multiple rug cases observed on EVM chains, 20–40% of token supply was spread across dozens of seemingly independent wallets — later revealed through clustering analysis to be controlled by a single entity.

Check with: Bubble Maps — look for clusters of wallets linked to one deployer.

Smart Contract Risks a "Passed" Audit Can Miss

5. HoneyPot Contracts (You Can Buy, But Never Sell)

Some contracts allow purchases but block sales entirely. The chart looks healthy because nobody can sell. This is invisible on price charts alone.

Check with: Token Sniffer or Honeypot.is — simulate a sell transaction before you buy.

6. Upgradeable Proxy Contracts

Be wary of upgradeable or proxy contracts. These let developers change the contract logic after you have invested, potentially adding a withdraw-all function later. A clean audit today does not bind the code that runs tomorrow.

Check with: Contract ownership and upgrade permissions on-chain. Note that a "low risk" score from an automated scanner does not account for proxy upgradeability.

7. Mutable Buy/Sell Tax

Check whether the buy/sell tax can be changed after launch. A common scam sets a reasonable 5% tax initially, then raises it to 99% once enough liquidity is trapped — turning every exit into a total loss.

Check with: The contract's tax function and owner permissions on a block explorer.

8. Masterchef Contract Warnings

Staking and farming contracts carry their own attack surface, particularly around migrator functions that can move deposited funds.

Check with: RugDoc.io — specifically their high-risk ratings on masterchef contracts.

Team and Institutional Trust Signals

9. No Launchpad-Level Protection Mechanism

Some launchpads mitigate risk through structured protections such as refund guarantees or post-listing price support. Kommunitas, for example, operates frameworks where certain projects qualify for partial or full refunds if post-listing performance fails to meet predefined thresholds. Treat these as risk mitigation layers, not guarantees of success — but their absence entirely is itself a signal. Compare how different platforms handle this in our breakdown of what makes a crypto launchpad trustworthy.

10. Dead or Forked GitHub Activity

For technical projects, check the repository. Is code updated regularly, or frozen since launch? Is it a unique codebase, or a 1:1 fork of a popular project with the names swapped?

Check with: The project's public GitHub commit history.

11. Unverified Advisor Social Proof

Scammers routinely list well-known advisors without permission. The fix takes five minutes: contact the advisor directly on X or LinkedIn and ask whether they are actually involved.

Behavioral Red Flags: The Psychology of a Rug

12. Artificial Urgency, Echo Chambers, and Marketing-Heavy Spend

Scammers rely on FOMO to bypass logical defenses. Three patterns to watch:

  • Artificial urgency: countdowns that never actually end, or "limited spots" that mysteriously reopen.
  • The echo chamber test: in the project's Telegram, ask a hard technical question about tokenomics or any risk above. If you are banned or labelled a FUDder instead of receiving a technical answer, leave.
  • Marketing-to-tech ratio: if 90% of energy goes to shilling and influencer partnerships and 10% to development, it is likely a pump-and-dump.

Professional Tool Checklist for Due Diligence

ToolPurposeWhat to Look For
DexscreenerLiquidity monitoringSudden drops in TVL or suspicious sell blocks
Bubble MapsWallet analysisClusters of wallets linked to a single deployer
RugDoc.ioAudit reviewsHigh-risk ratings on masterchef contracts
Token SnifferContract integrityHoneypot simulation; note that low-risk scores ignore proxy upgradeability
Solscan / EtherscanManual verificationLiquidity locks and holder counts, verified directly

Frequently Asked Questions

What is the fastest way to check if a launchpad project is a rug?

Start with the liquidity-to-market cap ratio on Dexscreener. If liquidity sits below roughly 5% of market cap, the project can collapse from a single sizeable exit regardless of how good the rest looks. It takes under a minute and eliminates the highest-risk listings immediately.

Does a passed smart contract audit mean a project is safe?

No. An audit confirms the code was reviewed at a point in time; it does not prevent upgradeable proxy contracts from changing that code later, and automated scanners frequently miss honeypot logic and mutable tax functions. Always cross-check contract ownership and upgrade permissions on-chain.

What is a honeypot token?

A honeypot is a contract that lets you buy but blocks you from selling. The price chart looks strong precisely because no one is able to exit. Simulate a sell using Token Sniffer or Honeypot.is before committing funds.

How can I tell if token holders are really independent wallets?

Use a wallet clustering tool such as Bubble Maps. In multiple observed rug cases, 20–40% of supply appeared spread across dozens of separate wallets that clustering later traced back to a single deployer.

Do launchpad refund policies actually protect investors?

They reduce risk rather than remove it. Some launchpads, including Kommunitas, run frameworks where qualifying projects offer partial or full refunds if post-listing performance misses defined thresholds. Treat this as one mitigation layer among several — never as a guarantee of returns.

What is the single biggest behavioral red flag?

Being banned for asking a technical question. A legitimate team answers scrutiny about tokenomics or contract permissions. A project that removes critics instead of addressing them is protecting a narrative, not a product.

Key Takeaway: The Trust-But-Verify Rule

Assume every project is a risk until data proves otherwise. If a project has unlocked liquidity, an anonymous team with no verifiable history, and an aggressive no-questions-asked community, no amount of hype justifies the risk.

Before joining any sale, check whether the launchpad itself has a guaranteed refund policy — platforms that stand behind their vetting tend to publish it openly. You can review the Kommunitas refund and buyer protection policy as a reference point for what that looks like in practice.

For a wider view of which platforms operate with transparent vetting in the first place, see our roundup of top crypto launchpads.

This content is provided for educational and informational purposes. Investing in cryptocurrency and Initial KOMmunity Offerings (IKOs) involves substantial risk. Always Do Your Own Research (DYOR) and consider consulting a professional financial advisor before making any investment decision.

Share This Article

This link will open in a new window