DeFi Scams: Rug Pulls, Drainers & Major Hacks
Understand DeFi-specific scams — rug pulls like Frosties and Squid Game, wallet drainers, and the largest crypto heists in history including the February 2025 Bybit hack.
13 min · beginner · part of Crypto Scams & How to Stay Safe
What you'll learn
- Anatomy of a Rug Pull
- Frosties and Squid Game: NFT and Token Rug Pulls
- Wallet Drainers: A 494 Million Dollar Industry
- Major Hacks: From The DAO to Bybit 2025
- A DeFi Self-Defense Checklist
Key terms
- Rug pull
- A scam where a project team drains the liquidity backing their token and disappears. The Squid Game token reached 28,610,000 percent gains before its rug pull on November 1, 2021 drained approximately 3.38 million dollars.
- Locked liquidity
- A protection where the team commits liquidity-pool tokens to a time-locked smart contract, preventing withdrawal for a fixed period. Absence of a credible lock is a strong negative signal.
- Wallet drainer
- Malicious smart contracts and front-ends that trick users into signing transactions that sweep their wallets. The 2024 drainer ecosystem stole approximately 494 million dollars from over 300,000 wallets.
- Inferno Drainer
- The dominant drainer-as-a-service kit in 2023-2024, controlling roughly 40-45 percent of drainer market share at its peak.
- Address poisoning
- An attack where the attacker sends a tiny transaction from a vanity address mimicking a victim's frequent counterparty. A May 2024 incident lost 1,155 wBTC (about 68 million dollars), most of which was eventually recovered.
- Token approval
- A signed permission granting a smart contract the right to move specific tokens from your wallet. Audit and revoke unused approvals regularly via revoke.cash or Etherscan.
- The DAO hack (2016)
- A reentrancy exploit that drained approximately 3.6 million ETH from a smart-contract fund in June 2016, leading to the Ethereum / Ethereum Classic chain split.
- Ronin Bridge hack
- The March 2022 drain of approximately 624 million dollars from the Axie Infinity sidechain, attributed by OFAC to North Korea's Lazarus Group. Five of nine validators were compromised.
- Ledger Connect Kit incident
- A December 14, 2023 supply-chain attack where a phished ex-employee enabled malicious code to be pushed to NPM. About 600,000 dollars was stolen in five hours; Ledger reimbursed affected users.
- Bybit February 2025 hack
- The largest crypto heist on record. On February 21, 2025 approximately 400,000 ETH (about 1.5 billion dollars) was drained; the FBI attributed the attack to Lazarus Group on February 26, 2025.
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
