DeFi Scams: Rug Pulls, Drainers & Major Hacks
Understand DeFi-specific scams — rug pulls like Frosties and Squid Game, wallet drainers, and the largest crypto heists in history including the February 2025 Bybit hack.
13 min · beginner · part of Crypto Scams & How to Stay Safe
Anatomy of a Rug Pull
A rug pull is a scam in which the team behind a crypto project drains the funds backing the project — typically liquidity in a decentralized exchange pool — and disappears. The name comes from the phrase "pulling the rug out from under someone." The blueprint is consistent across hundreds of cases.
Step one is launch. The team deploys an ERC-20 token, lists it on Uniswap or another decentralized exchange, and seeds a liquidity pool with their own ETH or stablecoins paired against the new token. Step two is hype. Promotion runs through Twitter, Discord, Telegram, paid influencer posts, and sometimes faked partnerships or audit logos. Step three is inflow. Buyers send ETH into the pool to obtain the new token, and the team is now sitting on a pool that contains real ETH and the worthless tokens the team created from nothing. Step four is the pull. The team withdraws the ETH side of the pool, sells whatever team allocation they hold into what remains of the bid stack, and walks away. Buyers are left holding tokens with no liquidity to sell against.
The economic mechanics matter. On most decentralized exchanges, anyone can list any token. There is no listing committee, no approval process, and no due diligence. The exchange smart contract simply matches whoever wants to buy with the liquidity pool. If the team controls the liquidity, they control the exit.
Two protections reduce this risk. The first is locked liquidity, where the team commits the pool tokens to a time-locked smart contract that prevents withdrawal for a defined period (often six months to several years). The second is renounced ownership, where the team gives up the ability to mint new tokens or change critical parameters in the smart contract. Neither protection is absolute — locks expire, and renounced ownership can hide other rug-pull mechanics — but their absence is a strong negative signal.
Also in this lesson
- Frosties and Squid Game: NFT and Token Rug Pulls
- Wallet Drainers: A 494 Million Dollar Industry
- Major Hacks: From The DAO to Bybit 2025
- A DeFi Self-Defense Checklist
Key terms
- Rug pull
- A scam where a project team drains the liquidity backing their token and disappears. The Squid Game token reached 28,610,000 percent gains before its rug pull on November 1, 2021 drained approximately 3.38 million dollars.
- Locked liquidity
- A protection where the team commits liquidity-pool tokens to a time-locked smart contract, preventing withdrawal for a fixed period. Absence of a credible lock is a strong negative signal.
- Wallet drainer
- Malicious smart contracts and front-ends that trick users into signing transactions that sweep their wallets. The 2024 drainer ecosystem stole approximately 494 million dollars from over 300,000 wallets.
- Inferno Drainer
- The dominant drainer-as-a-service kit in 2023-2024, controlling roughly 40-45 percent of drainer market share at its peak.
- Address poisoning
- An attack where the attacker sends a tiny transaction from a vanity address mimicking a victim's frequent counterparty. A May 2024 incident lost 1,155 wBTC (about 68 million dollars), most of which was eventually recovered.
- Token approval
- A signed permission granting a smart contract the right to move specific tokens from your wallet. Audit and revoke unused approvals regularly via revoke.cash or Etherscan.
- The DAO hack (2016)
- A reentrancy exploit that drained approximately 3.6 million ETH from a smart-contract fund in June 2016, leading to the Ethereum / Ethereum Classic chain split.
- Ronin Bridge hack
- The March 2022 drain of approximately 624 million dollars from the Axie Infinity sidechain, attributed by OFAC to North Korea's Lazarus Group. Five of nine validators were compromised.
- Ledger Connect Kit incident
- A December 14, 2023 supply-chain attack where a phished ex-employee enabled malicious code to be pushed to NPM. About 600,000 dollars was stolen in five hours; Ledger reimbursed affected users.
- Bybit February 2025 hack
- The largest crypto heist on record. On February 21, 2025 approximately 400,000 ETH (about 1.5 billion dollars) was drained; the FBI attributed the attack to Lazarus Group on February 26, 2025.
Continue this lesson — 4 more sections in the CryptoBipto app.
Open lessonEducational only — not financial advice.
