TrustDex › Guides › Presale & IDO scams
How presale and IDO scams work — the playbook, stage by stage
Most fraudulent presales are not improvised. They run a script with recognizable stages, and every stage leaves a mark you can inspect before your funds ever leave your wallet.
A presale asks you to do something no open-market trade does: send money for a token that does not trade yet, priced by a promise. That structure is exactly why scammers love it — there is no chart to contradict them, no liquidity to test, and no way to sell if the story sours. What keeps repeating across fraudulent raises is the sequence. Once you can name the stages, a bad presale stops looking like an opportunity and starts looking like a checklist being executed against you.
This guide walks the funnel end to end — the hype build, the allowlist, the raise, the two ways it ends — and then turns it around: the specific on-chain facts you can verify about any presale before committing a single unit of anything.
Already been pitched a presale token?
If the token has a mint address, paste it — the scan surfaces authority flags and structure before you commit.
The funnel: hype, allowlist, raise
Stage one is atmosphere. Weeks before any raise opens, the project buys attention: paid threads from mid-size influencers, a polished landing page, a countdown, and a Telegram or Discord that seems improbably busy for a product nobody has used. The busyness is often rented — engagement farms fill the room so that when you arrive, you find a crowd already convinced. The pitch always contains scarcity ("only 400 allocations") and social proof ("backed by" logos that were never asked permission).
Stage two is the allowlist, and it is psychological machinery, not distribution logistics. Making you complete tasks — follow, retweet, invite three friends, hold a partner NFT — does two jobs at once: it spreads the marketing for free, and it converts you from a skeptic into an applicant. People who have worked to win a spot rarely audit the thing they won. By the time an allocation is "granted," the question in your head has shifted from is this real? to how much can I get?
Stage three is the raise itself. Funds go to an address the team controls — sometimes a bare wallet, sometimes a launchpad contract, sometimes a "secure escrow" that is neither secure nor escrow. Contribution caps per wallet are common, framed as fairness; their real function is to spread the raise across hundreds of small victims, none of whom individually loses enough to pursue the matter hard.
Two endings: the soft rug and the hard rug
Fraudulent presales resolve in one of two ways, and it is worth being able to tell them apart, because the soft version is far more common and far harder to call out while it is happening.
A hard rug is blunt: the raise wallet empties into a mixer or a bridge, the token never launches (or launches with no liquidity), socials vanish, done. It is over in hours and nobody involved pretends otherwise.
A soft rug keeps up appearances. The token does launch — with a fraction of the promised liquidity. The team ships just enough (a logo refresh, a "v2 roadmap") to avoid the word scam, while insiders bleed their allocations into every bounce. Announcements slow from daily to weekly to quarterly. There is never a single moment to point to; the project simply decays until the chart is flat and the team has moved on under new names. Contributors spend months in "wen utility" limbo precisely because ambiguity is the product.
| Trait | Hard rug | Soft rug |
|---|---|---|
| Speed | Hours to days | Months of slow bleed |
| Token launches? | Usually never | Yes, thinly seeded |
| Team behavior | Deletes everything, disappears | Stays visible, ships cosmetics, blames "market conditions" |
| Deniability | None | High — looks like ordinary failure |
| On-chain tell | Raise wallet drained to mixer/bridge | Insider allocations trickling to exchanges from day one |
Fake vesting dashboards and paper locks
"Team tokens locked 24 months" is the sentence that closes most presale pitches, so it is the sentence most often faked. The cheap version is a dashboard: a webpage with progress bars and unlock dates that reads from the project's own database, not from any contract. A webpage can claim anything. The slightly more expensive version is a real lock on the wrong thing — a lock covering a trivial slice of team supply while the bulk sits liquid in fresh wallets, or a lock with an owner-only early-withdraw function buried in the code, or a lock whose beneficiary quietly changed a week after the marketing screenshot was taken.
A vesting claim is only as good as the contract address behind it. If the project cannot point you to a specific lock contract on a specific explorer, holding specific token amounts, the schedule exists only in a PNG. Verify the lock, the amount, the beneficiary, and whether the lock's terms can be modified — in that order.
Team-allocation dumping: the launch is the exit
Even when a presale token genuinely lists, the tokenomics table often hides the exit. Watch for large "ecosystem," "marketing," and "advisor" buckets with no cliff — these are team supply wearing a costume, liquid at launch while your presale tranche vests. The pattern on chain is unmistakable in hindsight: within minutes of the pool opening, wallets funded from the deployer begin selling into presale buyers' own excitement. The people who paid earliest, at the "best" price, become the liquidity that lets insiders realize the raise a second time.
Refund theater and the aftermath
When a raise collapses publicly, the playbook has a final act: the refund announcement. A form appears asking contributors to submit wallet addresses — occasionally seed phrases, which no refund ever requires — and a partial repayment goes out to a handful of loud community members whose screenshots then quiet everyone else. The remaining funds never move back. Sometimes the "refund" is a new token, replacing money you sent with a promise you cannot sell, and restarting the entire cycle under a fresh ticker. Treat any post-collapse process that requires you to sign a transaction or reveal secrets as a second attack on the same victims.
Verifying a presale on-chain before you send anything
Everything above is avoidable with checks you can do in minutes, because presales make claims that live on public ledgers. Before contributing, confirm five things yourself rather than accepting the pitch deck's word: (1) the raise address — is it a contract with published, verified source or a plain wallet someone can empty? (2) the token contract, if deployed — do authority flags or owner functions allow minting, trading pauses, or blocklists after launch? (3) the locks — real contracts, correct amounts, immutable terms, sensible cliffs? (4) the deployer's history — walk its funding backwards; serial ruggers reuse infrastructure wallets even when they burn front wallets. (5) the liquidity plan — what fraction of the raise is contractually committed to the pool, and what enforces that commitment beyond a Medium post?
Where the token already has a mint or contract address, run it through a scanner first — structural problems like an active mint authority or a pausable transfer function are dealbreakers regardless of how good the fundraise story is. A presale whose answers to these five questions are vague, hostile, or "trust us" has answered a sixth question you didn't ask.
Scan the token behind the raise
Structure beats story — check authorities and risk flags before the presale closes, not after.
Presale questions, answered
Are all crypto presales scams?
No — presales are a legitimate fundraising format that scammers happen to exploit heavily because buyers cannot test liquidity or exit before launch. The honest ones survive scrutiny: verifiable raise contracts, real vesting locks, and a deployer history you can trace. The fraudulent ones rely on you skipping exactly those checks.
How can I tell if a vesting schedule is real?
Ask for the lock contract's address and read it on a block explorer. Confirm the tokens are actually inside it, the beneficiary matches the team's stated wallets, the unlock dates match the pitch, and the contract has no owner function that permits early withdrawal or beneficiary changes. A dashboard screenshot proves nothing on its own.
What is a soft rug in a presale context?
A soft rug is a slow-motion abandonment: the token launches with minimal liquidity, insiders sell their allocations into every rally, and the team ships cosmetic updates while effort winds down. There is no single theft event to report, which is precisely why teams prefer it — it reads as failure rather than fraud.
Does a doxxed team make a presale safe?
It lowers one risk and leaves the rest untouched. A public identity makes total disappearance costlier, but plenty of soft rugs run under real names — mismanagement, quiet insider selling, and abandoned roadmaps need no anonymity. Verify the on-chain claims with the same rigor you would apply to an anonymous team.
Where does the money go after a presale rug?
In hard rugs, raise wallets typically route funds through mixers, cross-chain bridges, or batches of fresh wallets before reaching exchanges, which is why recovery is rare. In soft rugs the extraction is slower — allocations sold into the open market over months — and even harder to characterize as theft after the fact.