{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "rug-pulls-vs-exploits",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/rug-pulls-vs-exploits/",
  "collection": "defi",
  "title": "Rug pulls and protocol exploits: different mechanisms behind a loss",
  "description": "Distinguish insider deception, misuse of contract permissions and software vulnerabilities when reading about a DeFi loss.",
  "aliases": [
    "rug pull versus smart contract exploit",
    "rug pull fraud versus contract vulnerability"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:18:00.092Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A rug pull generally describes project-linked fraud involving misuse of control over funds, including deceptive liquidity removal. An exploit abuses a technical or economic weakness. The categories can overlap, but a price crash or withdrawal failure alone does not establish either one. The useful question is what action moved value and who had the authority to perform it.",
    "claimId": "rug-pulls-vs-exploits-quick-answer",
    "sourceIds": [
      "x425-defi-doj-rug",
      "x425-defi-oz-mainnet",
      "x425-defi-oz-access"
    ]
  },
  "keyFacts": [
    {
      "label": "Authority matters",
      "value": "Administrative permissions can allow sensitive actions without a software bug.",
      "sourceIds": [
        "x425-defi-oz-access"
      ],
      "id": "authority-matters",
      "claimId": "rug-pulls-vs-exploits-fact-authority-matters"
    },
    {
      "label": "Technical failure",
      "value": "Audited contracts can still contain exploitable weaknesses.",
      "sourceIds": [
        "x425-defi-oz-mainnet"
      ],
      "id": "technical-failure",
      "claimId": "rug-pulls-vs-exploits-fact-technical-failure"
    },
    {
      "label": "Claims need checking",
      "value": "Official fraud reporting documents false assurances about locked liquidity.",
      "sourceIds": [
        "x425-defi-doj-rug"
      ],
      "id": "claims-need-checking",
      "claimId": "rug-pulls-vs-exploits-fact-claims-need-checking"
    }
  ],
  "prerequisites": [
    "documented-defi-exploits"
  ],
  "sections": [
    {
      "id": "example",
      "heading": "Different causes can produce a similar loss",
      "sourceIds": [
        "x425-defi-oz-access",
        "x425-defi-oz-mainnet",
        "x425-defi-doj-rug"
      ],
      "paragraphs": [
        "If a person with a legitimate admin key misuses a withdrawal power, the contract may have followed its written permissions. If an outsider bypasses those checks through a bug, the path is different. Both can harm users, but prevention, evidence and responsibility differ.",
        "A legitimate liquidity withdrawal or a market-price decline is not by itself proof of fraud. Intent and representations require evidence beyond the chart."
      ]
    },
    {
      "id": "evidence",
      "heading": "Reconstruct the mechanism before choosing a label",
      "sourceIds": [
        "x425-defi-oz-access",
        "x425-defi-v2-pair-code"
      ],
      "paragraphs": [
        "Identify the contracts, transaction sequence, permissions and resulting asset transfers. For a liquidity-removal claim, check which LP receipts were redeemed and where the assets went. Compare those actions with the published lock or access-control claims rather than treating a project’s own description as conclusive."
      ]
    },
    {
      "id": "response",
      "heading": "Do not pay to unlock a promised recovery",
      "sourceIds": [
        "x425-defi-fbi-liquidity-scam",
        "x425-defi-ftc-scams"
      ],
      "paragraphs": [
        "The FBI’s liquidity-mining warning describes fake dashboards and demands for extra deposits after funds become inaccessible. Preserve transaction identifiers, addresses, messages and the relevant website details. Use independently located official reporting channels; another payment to the same contact does not establish that recovery is possible."
      ]
    }
  ],
  "faq": [
    {
      "question": "Can a project with locked liquidity still cause losses?",
      "answer": "Yes. The lock may be partial or misrepresented, and other token or administrative powers can create separate risks.",
      "sourceIds": [
        "x425-defi-doj-rug",
        "x425-defi-oz-access",
        "x425-defi-uncx-lock"
      ]
    }
  ],
  "claims": [
    {
      "id": "rug-pulls-vs-exploits-quick-answer",
      "articleSlug": "rug-pulls-vs-exploits",
      "statement": "A rug pull generally describes project-linked fraud involving misuse of control over funds, including deceptive liquidity removal. An exploit abuses a technical or economic weakness. The categories can overlap, but a price crash or withdrawal failure alone does not establish either one. The useful question is what action moved value and who had the authority to perform it.",
      "sourceIds": [
        "source-14600b470ef1f569",
        "source-51752d973dc3abdc",
        "source-56dd3f4220f6fea2"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-14600b470ef1f569",
          "locator": "Evidence at trial; representations about locked liquidity"
        },
        {
          "sourceId": "source-51752d973dc3abdc",
          "locator": "Auditing and security; Admin accounts; Upgrades admin"
        },
        {
          "sourceId": "source-56dd3f4220f6fea2",
          "locator": "Ownership; roles; delayed access"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Independently reopened DOJ May21,2025 jury-verdict report through web.run after direct HTTP returned challenge; locked-liquidity misrepresentations supported. Checked FBI false-dashboard/additional-payment warning and OZ authority versus bugs; no unsupported fraud allegation about another project."
        ]
      }
    },
    {
      "id": "rug-pulls-vs-exploits-fact-authority-matters",
      "articleSlug": "rug-pulls-vs-exploits",
      "statement": "Authority matters: Administrative permissions can allow sensitive actions without a software bug.",
      "sourceIds": [
        "source-56dd3f4220f6fea2"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-56dd3f4220f6fea2",
          "locator": "Ownership; roles; delayed access"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Independently reopened DOJ May21,2025 jury-verdict report through web.run after direct HTTP returned challenge; locked-liquidity misrepresentations supported. Checked FBI false-dashboard/additional-payment warning and OZ authority versus bugs; no unsupported fraud allegation about another project."
        ]
      }
    },
    {
      "id": "rug-pulls-vs-exploits-fact-technical-failure",
      "articleSlug": "rug-pulls-vs-exploits",
      "statement": "Technical failure: Audited contracts can still contain exploitable weaknesses.",
      "sourceIds": [
        "source-51752d973dc3abdc"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-51752d973dc3abdc",
          "locator": "Auditing and security; Admin accounts; Upgrades admin"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Independently reopened DOJ May21,2025 jury-verdict report through web.run after direct HTTP returned challenge; locked-liquidity misrepresentations supported. Checked FBI false-dashboard/additional-payment warning and OZ authority versus bugs; no unsupported fraud allegation about another project."
        ]
      }
    },
    {
      "id": "rug-pulls-vs-exploits-fact-claims-need-checking",
      "articleSlug": "rug-pulls-vs-exploits",
      "statement": "Claims need checking: Official fraud reporting documents false assurances about locked liquidity.",
      "sourceIds": [
        "source-14600b470ef1f569"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-14600b470ef1f569",
          "locator": "Evidence at trial; representations about locked liquidity"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Independently reopened DOJ May21,2025 jury-verdict report through web.run after direct HTTP returned challenge; locked-liquidity misrepresentations supported. Checked FBI false-dashboard/additional-payment warning and OZ authority versus bugs; no unsupported fraud allegation about another project."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-defi-doj-rug",
      "label": "Chief Executive Officer of Digital Asset Company Found Guilty in Multi-Million Dollar Crypto-Fraud Scheme",
      "publisher": "US Department of Justice",
      "url": "https://www.justice.gov/usao-edny/pr/chief-executive-officer-digital-asset-company-found-guilty-multi-million-dollar-crypto",
      "locator": "Evidence at trial; representations about locked liquidity",
      "note": "Dated public prosecution report used for terminology and evidence distinctions, not a legal assessment of other projects.",
      "version": "Report published 2025-05-21; retrieved 2026-10-02; hash recorded",
      "checkedAt": "2026-10-02T19:11:55.721Z",
      "contentSha256": "c08ee41a5b913e73a58ff32c01b15a34b4c12f50b1bf409e000d8c7ad5f537a6",
      "recordId": "source-14600b470ef1f569"
    },
    {
      "id": "x425-defi-oz-mainnet",
      "label": "Preparing for mainnet",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet",
      "locator": "Auditing and security; Admin accounts; Upgrades admin",
      "note": "Audits are scoped security work, not a guarantee.",
      "version": "Primary page retrieved 2026-10-02; hash recorded",
      "checkedAt": "2026-10-02T19:10:47.728Z",
      "contentSha256": "fcc42714a13cadcdc2be1db3c72e63f47865f426b94a3baebb02459111d08a27",
      "recordId": "source-51752d973dc3abdc"
    },
    {
      "id": "x425-defi-oz-access",
      "label": "Access Control",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/access-control",
      "locator": "Ownership; roles; delayed access",
      "note": "Privileges beyond a locked LP position.",
      "version": "Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded",
      "checkedAt": "2026-10-02T18:53:23.338Z",
      "contentSha256": "64d4904044619055e92ed628892df0be1db2aec6a37ccd1c14384b4348211c80",
      "recordId": "source-56dd3f4220f6fea2"
    },
    {
      "id": "x425-defi-v2-pair-code",
      "label": "Uniswap v2 Pair implementation",
      "publisher": "Uniswap",
      "url": "https://raw.githubusercontent.com/Uniswap/v2-core/v1.0.1/contracts/UniswapV2Pair.sol",
      "locator": "mint; burn; swap; _mintFee",
      "note": "LP redemption authority and reserve accounting.",
      "version": "Uniswap v2-core v1.0.1",
      "checkedAt": "2026-10-02T18:53:23.210Z",
      "contentSha256": "43a5421b31415868367b62bfa161ca10bcee03778873faad905f5a3e2cce9cbd",
      "recordId": "source-5651ae58cdcb25c2"
    },
    {
      "id": "x425-defi-fbi-liquidity-scam",
      "label": "Scammers Target and Exploit Owners of Cryptocurrencies in Liquidity Mining Scam",
      "publisher": "FBI IC3",
      "url": "https://www.ic3.gov/PSA/2022/PSA220721",
      "locator": "Tactics; Actions to Protect Yourself",
      "note": "Dated 2022 public-service notice; no adoption of dated loss totals.",
      "version": "Primary page retrieved 2026-10-02; hash recorded",
      "checkedAt": "2026-10-02T19:10:49.579Z",
      "contentSha256": "101f13e47f06a52f0441de1a207528b4d871a26eadb6ae26129e2ccb24862d9d",
      "recordId": "source-7893e281eacfe9e3"
    },
    {
      "id": "x425-defi-ftc-scams",
      "label": "What To Know About Cryptocurrency and Scams",
      "publisher": "Federal Trade Commission",
      "url": "https://consumer.ftc.gov/articles/what-know-about-cryptocurrency-and-scams",
      "locator": "Investment scams; cryptocurrency payments",
      "note": "General scam signals; does not establish intent in a particular protocol loss.",
      "version": "Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded",
      "checkedAt": "2026-10-02T18:53:24.083Z",
      "contentSha256": "f032b702d3bfff0ded760dbbdbd74e900f66cd902188c3d401e9a1461c10671e",
      "recordId": "source-319cd8df21980df0"
    },
    {
      "id": "x425-defi-uncx-lock",
      "label": "UNCX Network introduction",
      "publisher": "UNCX Network",
      "url": "https://docs.uncx.network/",
      "locator": "Liquidity Lockers",
      "note": "Locker provider explanation; not an endorsement or adoption of safety guarantees.",
      "version": "Documentation retrieved 2026-10-02; hash recorded",
      "checkedAt": "2026-10-02T19:10:58.873Z",
      "contentSha256": "7542c6ceed1296fe8ac3d54ba64d101d017f3ead6e535b95051565ee656dd9c2",
      "recordId": "source-2601cf7bc26edfa6"
    }
  ],
  "related": {
    "articles": [
      "liquidity-locks-burned-lp",
      "bug-bounties-vs-audits",
      "protocol-upgrades-and-admin-powers",
      "defi-cover-claims"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Rug pulls and protocol exploits: different mechanisms behind a loss.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/rug-pulls-vs-exploits/"
}
