What Makes a Token High-Risk? The Flags Behind the Data
Ranking the evidence behind 5,707 high-risk decisions: removable liquidity appears on 97.7% of them, while outright honeypots are just 4.3%. Risk is structural.
When Orixa marks a token very-high-risk, which evidence is actually behind that verdict? People assume the answer is exotic — a hidden honeypot, a mint backdoor. The data says something plainer and more useful: the single most common reason a token is high-risk is that its liquidity can simply be removed. This report breaks down the flags behind 5,707 high-risk decisions, in order of how often they appear.
The flags, ranked
Among the 5,707 tokens flagged very-high-risk in Orixa's ledger to August 2026, the evidence sorts like this. (Not every check resolves for every token, so each rate is measured over the tokens where that flag was actually evaluated.)
| Risk flag | How often it appears |
|---|---|
| Liquidity not locked / removable | 97.7% |
| Unverified source code | 33.3% |
| Mintable supply | 13.9% |
| Proxy / upgradeable | 8.1% |
| Blacklist-capable | 5.4% |
| Honeypot-flagged (sell fails) | 4.3% |
| Unsafe ownership | 0.6% |
On average, a high-risk token trips close to 20 individual checks — risk is rarely one thing; it is a stack.
Liquidity structure is the story
Nearly every high-risk token — 97.7% — has liquidity that is not credibly locked or burned, meaning it can leave. This is not a coincidence; it is the mechanism behind the most common way tokens go to zero. A pool whose LP can be pulled is a pool that can be rugged, which is exactly the arc reconstructed in Anatomy of a Rug Pull, On-Chain. If you check one thing before buying, check this one.
The second tier — unverified code (33%) and mintable supply (14%) — are the classic "can't inspect it" and "can dilute you" problems. They are common enough to expect and serious enough to investigate, but they are not the headline.
Honeypots are real, but rare
The finding that most surprises people: an outright honeypot flag appears on only 4.3% of high-risk tokens, and unsafe ownership on well under 1%. The dramatic traps are the minority. Far more often, a token is dangerous for a mundane, structural reason — removable liquidity, unverifiable code — than for a cinematic one. (The honeypot minority is detailed in the Honeypot Report.)
This matters for how you screen. Waiting to be caught by a clever trap is the wrong mental model; most losses come from ordinary, checkable weaknesses that were visible before purchase.
What to check, in priority order
The data points to a simple, ranked checklist that mirrors how often each problem actually occurs:
- Can the liquidity be removed? By far the most common failure. Confirm a credible lock or burn — and remember a lock is not automatic safety.
- Is the source verified? Unverified code hides what the contract can do.
- Can supply be minted? An open mint dilutes holders.
- Is it a proxy, blacklist-capable, or a honeypot? Less common, but each is a hard stop when present.
Risk is a combination, not a single alarm. A token that fails several of these at once is the profile behind most very-high-risk verdicts — and the live flagged-tokens report shows that profile on real entries.
Figures are from Orixa's scan ledger as of August 2026; rates are measured over tokens where each flag resolved, and change as tokens are scanned and re-scanned. Run a contract through Orixa to see which of these flags it trips. Orixa is decision support, not a guarantee of safety.
Enter a contract address and review the available risk evidence.
Orixa provides risk-analysis tools, not financial advice or a safety guarantee. Always verify evidence independently before interacting with a token.