TrustDexGuides › After a rug

Rugged? What to do in the first hour — a practical checklist

The minutes after a token collapses are when panic does its worst damage — and when a few unglamorous steps protect whatever the scam didn't take.

Educational guide · reviewed August 2026 · not financial advice

You bought a token; now the chart is vertical in the wrong direction, or your sell button produces nothing but errors, and the project's chat is either euphoric with denial or already gone. What you do next matters more than it feels like it does — not because the lost money is coming back (it almost certainly isn't), but because rug victims routinely lose more in the following hour: to lingering approvals, to panicked interactions with hostile contracts, and to the predators who specialize in people in exactly your position, in exactly this hour.

Work this list in order. It is deliberately short, deliberately boring, and designed to be executable while angry.

First, confirm what you're dealing with

Paste the token's address — the scan shows authority abuse and structural traps in seconds, no guessing from the chart.

Step 1 — Diagnose: which failure actually happened?

"Rug" covers three distinct events, and your next moves differ by which one hit you. Check the pool and the token's recent transactions before doing anything else — the answer is usually visible within a minute.

What happenedWhat you'll seeWhat it means for you
Liquidity pulledPool drained in one or a few withdrawals; price effectively zero; sells technically work but return dustPosition unrecoverable; focus on containment & evidence
Sells blocked / honeypotBuys go through, sells revert or face absurd taxes; other wallets show the same patternYou hold a token you cannot exit; stop paying gas to retry
Insider dumpHuge sells from deployer-linked wallets; pool intact but price collapsedExit may still be possible for pennies; token often lingers as a zombie

Diagnosis matters for one practical reason: after an insider dump you can still choose to exit a remnant position, while after a liquidity pull there is nothing to exit into, and with a honeypot every retry just burns more gas. Knowing which situation you're in stops you from fighting the wrong battle.

Step 2 — Stop the bleeding: approvals and isolation

Ask the ugly question first: what did you sign to get into this? If you only swapped through a reputable DEX, your exposure is likely limited to the position itself. But if you interacted with the project's own site — a "claim," a staking page, a migration, anything — you may have granted approvals that reach assets the rug never touched. Open a trusted revocation tool, review every approval your wallet has granted recently, and revoke anything connected to the project or that you can't identify. If you typed your seed phrase anywhere along the way, skip revoking: that wallet is gone. Create a fresh wallet with a new seed and move everything of value to it immediately, most valuable assets first.

Sign nothing new for the rest of the hour. No "emergency migration," no "compensation claim," no token the team suddenly airdrops as an apology. Post-rug prompts to interact are how a bad hour becomes a catastrophic one — the people who just took your money are the ones most eager to get you signing again.

Step 3 — Capture evidence while it still exists

Scam infrastructure is demolished fast — sites go dark, chats purge, accounts rename — but you have a window, and on-chain data never closes it entirely. Save now: the token's contract or mint address; your buy transaction hashes and the hashes of the rug event itself (the liquidity withdrawal, the blocked sells, the insider dumps); the deployer's address; screenshots of the website, the Telegram or Discord, pinned announcements, and any DMs with promoters; and the usernames or handles of everyone who marketed it to you. Archive pages to a web-archiving service where possible rather than relying on screenshots alone. You're building the packet that any future report — to a platform, an exchange, or law enforcement — will ask for, and it's a ten-minute job today versus impossible next week.

Step 4 — Recovery odds and where reporting actually helps

Honesty first: direct recovery of rugged funds is rare enough that you should plan your finances as if the money is gone. Transactions don't reverse, the tokens you hold have no market, and the proceeds are usually laundered through mixers or bridges within hours. The realistic value of reporting isn't your refund — it's cutting off the operator and protecting the next buyer. Report the deployer and drain addresses to major explorers and wallet-security databases so they get flagged; report to any centralized exchange the funds flow toward, since deposits to a KYC'd account are the one chokepoint where freezes genuinely happen; file with your jurisdiction's cybercrime portal, which occasionally matters when cases aggregate; and post a factual warning — addresses and hashes, no speculation — where the token's buyers gather. On the tax side, many jurisdictions let realized losses offset gains in some form; the rules differ enough that this is purely a keep-your-records-and-ask-a-professional item, but it is one more reason the evidence packet earns its ten minutes.

Step 5 — Survive round two: recovery scams hunt victims

Within hours of any visible rug, replies and DMs arrive: a "blockchain recovery agent" with testimonials, an "ethical hacker" who traced your funds, a fake exchange-support account, even someone impersonating law enforcement. They found you because you posted about the loss — victim lists are actively farmed from complaint threads. Every one of these follows the same shape: confidence about recovery (which nobody can promise), then an upfront fee, or a request for your seed phrase "to trace the wallet," or a smart-contract interaction that will drain what's left. There is no service that reverses on-chain theft for a fee. Anyone certain they can is running the second act of the scam you just survived — and victims desperate to be made whole are precisely why the second act exists.

Step 6 — Turn it into armor

Once the hour is over and the checklist is done, take the lesson without the shame: rugs work on experienced traders because they're engineered to, not because their victims are stupid. Fold the incident into your process — scan structure before buying, size positions like the worst case is real, keep a separate wallet for experimental trades so approvals and losses stay contained, and treat unaudited project sites as hostile by default. The trade you lost is sunk; the process upgrade is the only dividend this experience pays, so collect it.

Scan it before the next one

Most rugs advertise themselves in advance — authorities, concentration, unlocked liquidity. Check the next token first.

Post-rug questions, answered

Is there any realistic chance of getting my money back after a rug?

Very rarely, and never through anyone who contacts you offering it. The plausible paths are narrow: an exchange freezing funds that land in a KYC'd account, or law enforcement action in unusually large cases. Plan as though the funds are gone, report through official channels anyway, and treat every unsolicited recovery offer as a scam.

Should I sell or burn the rugged tokens still in my wallet?

After a liquidity pull there's nothing to sell into, and interacting further with a malicious contract can waste gas or trigger new prompts — hiding the token in your wallet is enough. If the pool survived (an insider dump), exiting the remnant is a personal choice; just weigh the dust value against the fee first.

How do I check and revoke token approvals after a scam?

Use a well-known revocation tool or your wallet's built-in approvals view, connect the affected wallet, and review everything it has authorized. Revoke entries tied to the scam project and anything you don't recognize; each revocation is a small on-chain transaction. If your seed phrase was ever exposed, revoking isn't enough — migrate to a brand-new wallet.

Who should I actually report a rug pull to?

Flag the scam addresses on major block explorers and wallet-security lists, notify any exchange the stolen funds move toward, file a report with your national cybercrime portal, and warn the token's community with plain facts — the contract address and transaction hashes. None of these promise recovery; all of them make the operator's next round harder.

How do recovery scams recognize and target rug victims?

They monitor complaint threads, comment sections, and scam-token holder lists, then reach out with unsolicited confidence: guaranteed fund tracing, upfront fees, or requests for your seed phrase to 'verify ownership.' Legitimate investigators never DM victims first, never guarantee outcomes, and never need your keys.

TrustDex is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a TrustDex product