The State of Solana Rugs, 2026: What 18,884 Flagged Tokens Reveal
Between February 15 and September 3, 2026, DeFade's scanner flagged 18,884 Solana tokens as elevated rug risk. 3,234 of them have since been confirmed dead — collapsed from their peak and never recovered. That is a large enough sample to say something concrete about how Solana rugs actually work in 2026, and the data contradicts most of the folk wisdom traders still use to stay safe.
Every number in this report comes from that dataset. The methodology — including its biases, which are real — is at the bottom. The numbers you should remember:
Finding 1: The safety checklist is dead
Every beginner guide to avoiding rugs teaches the same three checks: mint authority revoked, freeze authority revoked, liquidity locked or burned. Across all 18,884 flagged tokens, 99.7% had mint authority revoked and 99.7% had freeze authority revoked. Narrow it to the 3,234 confirmed rugs and it gets worse: 99.9% had revoked mint authority, and 72.9% had fully locked liquidity. Only 2.2% of confirmed rugs had the "classic" unlocked LP that the checklist is designed to catch.
This is not because the checks are wrong — it is because launchpads now do them automatically, for scammer and honest developer alike. When 99.9% of rugs pass a check, the check carries no information. The rug moved somewhere the checklist does not look: into who holds the supply and how they got it. We covered the mechanics of this failure mode in why tokens with perfect safety scores still rug; this is the dataset behind that argument.
Finding 2: Rugging is an industry, not an accident
The single most damning number in the dataset is about the people, not the tokens. Among flagged tokens where the deployer's history could be resolved:
- The median deployer had 3 previous token launches behind them.
- 45.1% came from deployers with 5 or more prior launches.
- 30.6% came from deployers with 20 or more. That is one in three flagged tokens launched by someone doing it at industrial scale — 1,390 flagged tokens traced to deployers with roughly a hundred prior launches each.
The supporting cast agrees: 58.5% of flagged tokens were launched from a creator wallet less than a week old — a disposable identity, funded fresh for this launch, exactly as described in our guide to dev wallet analysis. And 16.7% carried paid DEX listing enhancements: the operation has a marketing budget. These are not devs whose projects failed. They are production lines.
Finding 3: The bundle is the standard playbook
53.1% of flagged tokens showed bundled-wallet buying — coordinated wallets acquiring supply at or around launch, funded from a common source, exactly the pattern described in our bundle sniping explainer. Among confirmed rugs the figure is 40.2%. Meanwhile classic top-holder concentration warnings ("top 20 wallets hold 40%+") appeared on 38.7%.
Read those two numbers together and the strategy is obvious: operators have learned that one wallet holding 30% of supply gets caught by every scanner, so the position is split across dozens of bundled wallets instead. The visible holder chart looks healthy; the funding graph says one owner. Detection has to follow the money, not the snapshot — this is the entire case for funding-origin tracing over holder-list eyeballing.
Finding 4: It is over fast — but not too fast to check
The median flagged token was small and young: $21.6k market cap, $14.9k liquidity, 20 holders at flag time, and 45.7% were flagged within their first hour of existence. For the 2,983 confirmed rugs with clean timing data:
| From first flag to confirmed collapse | Share of rugs |
|---|---|
| Within 6 hours | 17.6% |
| Within 24 hours | 41.2% |
| Median | 30.8 hours |
| Slowest quartile | 140+ hours (5.8+ days) |
Two things follow. First, the window is real: the median rug took more than a day to die after being flagged, which is plenty of time for a scan to save you. Second, the slow tail matters — a quarter of rugs took nearly six days or longer, long after early hype watchers moved on. The delayed sweep is a real pattern, not paranoia.
The 653 confirmed rugs with recorded price peaks topped out at a combined $302 million in peak market value (median peak: $85k). Market cap is paper value, not realized losses — but it is a measure of how much belief these operations manufactured before pulling the floor.
Finding 5: The scores called it — in both directions
A risk score is only worth quoting if it works on tokens whose outcome is now known. Among the 1,143 confirmed rugs that had a recorded first scan, the median first-scan score was 95 out of 100 (on DeFade's scale, higher = more dangerous). 85.7% scored 55+ on their very first scan — before the rug, often within the token's first hour — and 68.9% scored 75+.
Calibration cuts both ways, so here is the other direction. DeFade separately tracks scanned tokens that went on to pump 5x or more: 88 of them in this period (median 8.7x, best 8,400x+). Their median lowest pre-pump score was 13 out of 100 — the winners really did score clean before winning. A scanner that flags everything is as useless as one that flags nothing; the gap between 95 and 13 is the tool doing its job.
What this means if you trade memecoins
- Stop treating revoked authorities and locked LP as safety. They are launchpad defaults. 99.9% of confirmed rugs had them.
- Check the deployer before the token. One in three flagged tokens came from a 20+ launch serial operator. The deployer's history is the strongest single signal in the dataset.
- Assume the holder chart is staged. Majority-of-rugs levels of bundled buying mean the tidy distribution you see is often manufactured. What matters is who funded the buyers.
- You have time for one deep scan — usually not much more. Median collapse came 30.8 hours after first flag; 1 in 6 died within 6 hours.
The Data Comes From Real Scans
Every number above was produced by DeFade scans — bundle detection, funding-origin tracing, deployer history, live dev tracking. Your first scan each day runs the full Pro analysis, free.
Scan a Token Now →Methodology, including the biases
Sample: every token scanned on DeFade between 2026-02-15 and 2026-09-03 that scored 40+ on the 0–100 rug probability scale enters the flagged database; this report covers the 18,884 Solana entries (EVM chains are tracked too but the sample is still small). Percentages are shares of flagged tokens, not of all Solana launches — this is a scanned-and-suspicious sample, biased toward tokens traders were already unsure about, and it says nothing about the base rate of rugging across all launches.
"Confirmed rug" means automated death detection: sustained collapse from peak with no recovery, stamped independently of the score. Signal percentages (bundles, serial deployers, concentration) are floors, not exact rates — each token records only its top-listed signals, so a signal crowded out by five louder ones goes uncounted here. Deployer-history figures cover the 18,861 tokens where creator history resolved. First-scan score analysis covers the 1,143 confirmed rugs with a recorded first score; time-to-rug covers the 2,983 with clean timestamps. Numbers are point-in-time as of September 3, 2026 and will drift as the database grows.
Want to cite this report? Link this page; the numbers, dates and sample sizes above are the canonical version. For questions about the dataset, reach us via the FAQ page.
Further reading
Why Tokens With Perfect Safety Scores Still Rug — the mechanism behind Finding 1, in detail.
The Best Solana Rug Checkers in 2026 — which tools catch which of these patterns.
How to Spot a Solana Rug Pull: 10 Red Flags — the practical checklist, updated for what this data shows.