Lookonchain APP

App Store

Report: Rug Pull Incidents in the Crypto Space Have Decreased, but Their Impact Has Grown

2025.04.18 14:25:11

On April 18th, according to a report by Cointelegraph. Based on the latest report from the blockchain analytics platform DappRadar, there were 21 "Rug Pull" incidents in the early part of 2024. In contrast, there were only 7 incidents from 2025 to the present. This indicates a declining frequency year by year. However, since the early 2025, the Web3 ecosystem has lost nearly $6 billion due to such incidents. 92% of this loss was attributed to the collapse of Mantra's OM token (the token's founder denies this was a "Rug Pull"). In contrast, the total loss from "Rug Pull" incidents in the same period of 2024 was $90 million. DappRadar analyst Sara Gherghelas pointed out that although the frequency of such incidents has decreased, their destructiveness has increased. Scams are becoming more sophisticated and are often orchestrated by professional teams. The nature of these incidents is also evolving. Many incidents in the first quarter of 2024 originated from DeFi protocols, NFT projects, and Meme coins. While in the same period of 2025, they mostly occurred in the Meme coin space. Gherghelas also warned that a sudden surge in the number of active wallets, a high transaction volume but low user activity, unverified smart contracts, limited GitHub activity, anonymous developer teams, or projects with a sudden spike in DApp popularity could all be warning signs of a "Rug Pull."
Relevant content

Even more damaging than hacking Hugging Face: Astra’s sibling model once breached OpenAI’s internal network, ultimately gaining top-level access.

Dongcha Beating AI News Flash: OpenAI’s latest technical report also revealed an internal incident that had previously flown under the radar: an internal model belonging to the same family as its next-generation model Astra successfully breached OpenAI’s cloud infrastructure during an evaluation. It first leveraged signature key material left over from a prior attack to forge new administrator credentials, regaining access to Artifactory, OpenAI’s internal software repository. The model then moved laterally to breach OpenAI’s cloud Kubernetes cluster, obtaining `cluster-admin`—the highest-level permission for the entire cluster. With this access, the agent created privileged containers, accessed authentication tokens for OpenAI’s cloud key management, identity and access, and CI platforms, and even spun up a public load balancer that could have exposed parts of the internal infrastructure directly to the internet. Notably, this is not Astra itself, nor the model that led the earlier Hugging Face attack. OpenAI clarified that the model only shares the same family as Astra but uses different post-training methods.

1 seconds ago

Fu Peng on NVIDIA's earnings report: The market has grown indifferent to its financial results; going forward, attention should focus on how long the boosting effect from Jensen Huang's remarks will last.

Fu Peng, chief economist at Xinhuo Group, published an article noting that while NVIDIA’s latest financial results have beaten expectations for 15 consecutive quarters, the market has shown a lukewarm response to the figures themselves. Indicators such as stock prices and option volatility show that market investors are currently “more concerned about the future: whether the free cash flow at the center of future stock indices can be delivered smoothly, and how long the momentum of AI growth can be sustained. These issues actually carry more weight than single-quarter financial performance, so even if this quarter’s results exceed Wall Street expectations by a few percentage points, they cannot change the denominator side of valuation.” Fu Peng believes that Jensen Huang’s explicit statement in the earnings call that “the inflection point for AI has arrived” is essentially a move to calm the market, aimed at strengthening confidence in the formation of a closed-loop AI industry chain and easing concerns over overinvestment. Going forward, investors should observe how long it takes the market to digest this round of confidence boost, the elevated expectations brought by Jensen Huang, and how long this sentiment will last. If the sentiment fades quickly, it indicates the market’s typical mindset of “not acting until seeing results” (the Chinese idiom for waiting for concrete proof before acting). The impact of repeated confidence boosts and reassurances from manufacturers is actually gradually weakening, a trend that can be clearly observed from the duration of market volatility following each earnings call.

1 seconds ago

Circle CEO: Stablecoin foreign exchange engine StableFX is set to launch on the Arc mainnet.

Circle co-founder and CEO Jeremy Allaire tweeted that StableFX is set to launch on the mainnet. The institutional-grade stablecoin foreign exchange engine had previously launched on the Arc public testnet. It covers local currency stablecoins from major and emerging markets, supports near-instant, 24/7 on-demand settlement, uses a payment-versus-payment (PvP) mechanism—where both parties receive funds simultaneously or neither does—to reduce capital occupation, and enables access to multiple vetted counterparties via a single onboarding process.

1 seconds ago

Defimon: A vulnerability has been detected on Enjin, resulting in losses of approximately $142,000.

According to security firm Defimon’s monitoring, a vulnerability has been detected on Web3 game ecosystem development platform Enjin, resulting in losses of approximately $142,000. Enjin’s ERC-1155 “Crypto Items” allow each item to route transfers via a dedicated item adapter. Attackers registered and used a malicious transfer adapter that bypassed owner approval checks, enabling their exploit contract to call transferFrom without approval to siphon ENJ-supported items from around 52 unrelated holders’ wallets (via legitimate TransferSingle events, with no setApprovalForAll required). Afterwards, the attackers called melt() on each stolen item, redeeming 500 ENJ per item from the platform’s reserves.

1 seconds ago

Bitcoin multi-signature hardware wallet Frostsnap fixes two security vulnerabilities, team urges users to update as soon as possible.

Bitcoin multi-signature hardware wallet Frostsnap has released version 0.4.0, fixing two security vulnerabilities, and confirmed no user funds have been lost so far. The two flaws are: FSA-2026-001: Malicious signature requests can mark a transaction output as belonging to the user’s wallet; the device does not verify this claim or display it on the confirmation screen, which could lead to funds being sent to addresses the user has never encountered. FSA-2026-002: Change addresses may fall outside the wallet’s recovery scan range, causing apparent missing funds after backup and recovery, though the funds actually remain in the wallet. After the update, the app will prompt users to upgrade their device firmware, and firmware downgrade protection has been added. The team advises updating both the app and firmware without delay.

1 seconds ago

CZ Discusses Binance’s Hiring Logic: Proactivity Is Crucial, Self-Motivation Especially Essential for Remote Positions

Binance founder Changpeng Zhao (CZ) stated at today’s offline Hong Kong meetup for his book *Binance Life* that many people have inquired about Binance’s hiring logic. Though he no longer participates heavily in candidate selection, he emphasized that initiative is essential. Noting that many remote roles may lead to employees slacking off, he explained that unproactive staff might fail to deliver results even after two months. He added that he does not actively track work progress, instead waiting for employees to submit updates, hence why initiative is far more important than waiting for bosses to check on performance.

1 seconds ago

Popular tokens

BitcoinEthereumHyperliquidSolanaTRONBNBTetherAaveXRPPepeFartcoinOndoJupiterUniswapBonkPendleEthenaArbitrumAvalancheLidoChainlinkPolygonDogecoinCardano