ع Scan a token with Orixa
Scam Prevention

Honeypot vs. Rug Pull: What's the Difference?

Honeypot vs rug pull, explained: a honeypot blocks the exit from the start; a rug pull lets you trade then removes the value later. How mechanism, timing, and detection differ — and how they overlap.

"Honeypot" and "rug pull" are the two terms new-token buyers hear most, and they are often used as if they mean the same thing. They don't. Both end with you losing money, but the mechanism, the timing, and the way you detect them are different — and knowing which one you are looking at changes what you check.

The one-line difference

  • A honeypot is a property of the contract: you can buy, but you cannot sell. The exit is blocked from the start.
  • A rug pull is an event: you can trade normally for a while, and then the value is removed — usually by draining liquidity or dumping a hidden supply.

Put simply: a honeypot never lets you out; a rug pull lets you in and out until the moment it doesn't.

Timing and mechanism

A honeypot traps you immediately. The sell restriction is baked into the transfer logic — a reverting sell, a near-100% sell tax, disabled trading, or a blacklist that catches your address after you buy. You often discover it the first time you try to exit. See What Is a Honeypot Crypto Token.

A rug pull unfolds later. The market works, buyers accumulate, the pool fills with real assets — and then whoever controls the liquidity or a large reserve pulls it. The token is technically "sellable" the whole time; the failure is that eventually there is nothing left to sell into. See What Is a Rug Pull.

How you detect each

Because the mechanisms differ, the checks differ:

Honeypot Rug pull
Core question Can I sell at all? Can the value be removed later?
Best single test Live sell simulation Liquidity lock + owner powers + concentration
When it hits Immediately, on first sell Later, when liquidity/supply is pulled
Primary evidence Sell path / tax behavior LP lock status, mint/withdraw permissions, holder distribution

A honeypot is caught by simulating the exit. A rug is caught by checking who is able to take the value — whether liquidity is locked or burned, whether an owner can mint or withdraw, and whether supply is dangerously concentrated. The step-by-step exit test is in How to Check If a Token Is a Honeypot.

They can overlap

Plenty of tokens carry both risks at once. A contract can block sells (honeypot) and keep liquidity removable and supply concentrated (rug-ready). In Orixa's public flagged-tokens report, many entries stack a honeypot flag alongside thin liquidity, near-total concentration, and removable LP — which is why a single label is rarely the whole story, and why looking at the combined evidence (and treating each flag as evidence to verify, not a proven verdict) matters more than picking one word.

How Orixa treats both

Orixa does not force a token into one bucket. Its scan reports an independent sell-simulation result (the honeypot question) and liquidity, owner-permission, and holder-concentration signals (the rug question), then summarizes them as a Risk Score, a Rug Probability, and a Confidence value. The point is to show which risks are present and how well the evidence supports each — not to reduce a token to a single scary word. More on that in What Is Orixa.

Remember that any high-risk classification reflects the evidence available at scan time and is not, on its own, proof of intent to defraud.

The practical takeaway

If you are about to buy: run a sell simulation to rule out a honeypot, and separately check liquidity lock, owner powers, and concentration to gauge rug exposure. Different questions, different tools, both worth two minutes before you commit funds.


Scan a contract in Orixa to see the sell-simulation result and the liquidity/owner/holder signals side by side — then verify the critical findings independently. Orixa is decision support, not financial advice.

Turn this research into a practical check

Enter a contract address and review the available risk evidence.

Scan a token with Orixa