P07-L08 · P07 · P07-M02
Reconstruct observable changes before and after a historical liquidity event
Prerequisites: P07-L07
Learning objectives
- Reconstruct a source-reported historical event sequence without hindsight.
- Separate symptoms, mechanism and actor attribution.
- Calculate the depth consequence of a fictional proportional withdrawal.
EN source master · P07-L08 · 45 minutes estimated · needs_review
Learning objectives:
- Reconstruct a source-reported historical event sequence without hindsight.
- Separate symptoms, mechanism and actor attribution.
- Calculate the depth consequence of a fictional proportional withdrawal.
Why this matters
A collapsing price can reveal a serious economic change without revealing its cause. A creator withdrawing liquidity, a privileged account being compromised, ordinary selling into a shallow pool and a routing failure can produce superficially similar screens. This lesson teaches you to reconstruct changes and classify evidence before assigning a narrative.
“Rug pull” is a conclusion about conduct, not a unit of measurement. Learn to describe what changed, who could perform the relevant action, what the records actually establish and what remains unknown. A precise limited finding is more useful than an accusation built from a chart.
Explanation
Separate the symptom, mechanism and actor
Begin with a symptom: reserves decreased, an exchange failed, an authority changed or a holder transferred tokens. Then test a mechanism. Was liquidity withdrawn through a position, were tokens sold, was a permission exercised, or did an interface stop returning data? Finally ask about actor attribution. A transaction signer identifies an account's participation; it does not establish the human operating it or whether credentials were compromised.
Keep three columns in your notes. “Reserve decrease” belongs in the observation column if supported by a matching snapshot. “Liquidity withdrawal” requires operation-level evidence. “Creator intentionally stole funds” requires both attribution and intent evidence beyond a price chart. If the supplied source only reports an exploit, preserve that label rather than rewriting it as creator misconduct.
Token authority and pool control are separate surfaces. A revoked mint authority does not answer whether a pool position can be withdrawn. A claimed liquidity lock needs its own scope: exact position, relevant fraction, mechanism, expiry and any exceptions. Even a verified restriction on one action cannot establish that all other actions are harmless. Do not substitute a general safety score for these distinct questions.
Reconstruct state around a bounded event
Specify the network and exact asset or protocol, the time window, source and measurement coverage. Choose a before observation and an after observation that measure the same objects. Token reserves, quote reserves, liquidity positions and permissions are different variables. If one snapshot aggregates several pools while another describes one pool, their difference is not a valid single-pool change.
A sound event table contains event time, evidence locator, reported action, consequence and confidence boundary. Missing snapshots remain missing. Do not fill a before balance from a later article or a present-day dashboard. If no frozen reserve records are supplied, you can reconstruct a publisher's reported incident chronology but cannot independently calculate historical pool losses or trader execution.
A price chart alone cannot distinguish liquidity withdrawal from a sale. Removing proportional reserves can leave the reserve ratio unchanged while reducing depth. Selling into a constant-product pool changes the ratio through a different operation. To distinguish them, seek the transaction and position-level changes, not merely a descending candle.
Keep knowledge time separate from event time
Historical reporting has at least two clocks. Event time is when an action is reported to have occurred. Knowledge time is when the analyst had access to evidence about it. An article published tomorrow can describe an event today; that does not make its contents available to an analyst today.
This distinction matters when grading early warning claims. If a postmortem later attributes an event to a compromised privileged account, you cannot assume an observer knew that attribution before the report appeared. A fair reconstruction says “the later report describes this event at this time” and separately identifies what an earlier observer could have inspected. Where publication timing is known only by date, do not invent an exact release hour.
Your investigation can be useful without claiming predictive power. A mitigation timeline shows which controls reportedly changed after an incident. It does not prove that a particular alert would have prevented the incident or that future protocols with similar controls are safe.
Use the comparative historical case carefully
The historical example below is Raydium's December 2022 protocol exploit, used to compare a privileged-account compromise with a creator-withdrawal narrative. It is not presented as a memecoin creator rug pull. The official postmortem is the primary publisher's account; this lesson has not independently replayed the ledger.
A first-party report can establish what its publisher stated. Independent confirmation of each statement requires matching transactions, archived state and reproducible decoding. Preserve this distinction in the evidence panel. It is acceptable to cite an official report while stating that its proposed initial intrusion explanation was not established.
Historical comparisons should transfer a method, not a verdict. Ask which privilege was implicated, which remediation reportedly removed or relocated it, and which evidence would be needed to establish losses and control independently. Then apply the same questions to a memecoin case only after obtaining that case's own records.
Model depth without pretending to measure the incident
For the separate fictional model, use a zero-fee two-reserve constant-product pool with base reserve X and quote reserve Y. A quote input q returns Xq/(Y+q) base units. The marginal quote price is Y/X. This is the same restricted model introduced in P07-L03 [S-PRICING]; it is not a reconstruction of Raydium's exploited pools.
A proportional withdrawal changes X and Y by the same factor. The ratio can remain unchanged while a fixed order becomes large relative to remaining reserves. This illustrates why a stable displayed price is insufficient evidence of stable executable depth. Fees, concentrated liquidity, other routes, transfer restrictions and intervening trades require different calculations.
Do not conflate model conclusions with observed facts. The model shows a possible mechanical consequence under declared assumptions. The historical report supplies a chronology. Neither supplies a measured return, an investment recommendation or an identification of a memecoin perpetrator.
Key terms
- Symptom: a visible change that may have several causes.
- Mechanism: the operation connecting a state change to its result.
- Attribution: a supported link from an action to an actor.
- Event time: the reported time of an action.
- Knowledge time: when evidence became available to an observer.
- Postmortem: retrospective incident account with its own evidentiary limits.
- Depth: available reserves relevant to a specified order and route.
Historical example
HISTORICAL SOURCE RECORD — HIST-P07-08. Frozen editorial summary of Raydium's official postmortem [S-INCIDENT], published December 17, 2022 and inspected September 30, 2026. All times below are publisher-reported UTC event times. No transaction replay, reserve snapshot or independent human attribution is supplied.
| Record | Reported event time UTC | Publisher's reported event | Boundary |
|---|---|---|---|
| H1 | 2022-12-16 10:12 | Incident began; compromised pool-owner/admin account implicated | Initial intrusion vector not established |
| H2 | 2022-12-16 14:16 | Hot patch revoked compromised authority and moved authority to a new hardware account | Source-reported mitigation, not proof of recovery |
| H3 | 2022-12-17 10:27 | AMM V4 upgrade removed administrative parameters | Does not measure historical reserves |
| H4 | 2022-12-17 approximately 15:00 | Remaining administrative functions moved to Squads multisig | Approximate time must remain approximate |
The article reports an exploit involving privileged functions and fee accounting. It discusses a possible intrusion explanation without establishing the exact initial vector. This is a protocol exploit comparison, not a documented creator rug-pull classification.
ILLUSTRATIVE MODEL — FIX-P07-08. Fictional base and quote units; no Raydium historical reserves.
| State | Base reserve X | Quote reserve Y | Marginal quote price Y/X |
|---|---|---|---|
| Before proportional withdrawal | 100,000 | 100 | 0.001 |
| After 90% proportional withdrawal | 10,000 | 10 | 0.001 |
Assume zero fees, unrestricted transfers, no other routes and no intervening trades. Apply a hypothetical quote input of 1 unit separately to each starting state.
What the evidence proves
OBSERVED SOURCE STATEMENT: H1–H4 are inspectable statements in the cited publisher report. Their event times are source-reported, not independently verified here.
INFERRED: In FIX-P07-08, proportional removal preserves the marginal ratio but increases the average execution premium for the specified input. This follows from the supplied model, not the incident.
What the evidence does not prove
UNKNOWN: Actual historical pool reserve snapshots, each transaction's independently decoded effects, exact initial intrusion vector and what a particular observer knew before publication.
INSUFFICIENT EVIDENCE: The historical records do not establish a memecoin creator rug pull, an earlier predictive warning or safety after remediation. A fictional reserve calculation cannot establish real incident losses.
Common mistakes
Assigning the “rug pull” label from a falling chart; treating compromised credentials as proof of creator intent; confusing publication date with event time; calculating historical reserves from fictional inputs; and interpreting an unchanged reserve ratio as unchanged depth.
Practical exercise
Inputs are H1–H4 and FIX-P07-08. Work offline without connecting a wallet.
- Write the four reported events in chronological order and preserve approximate timing.
- Assess the claim “At 11:00 UTC on December 16, the analyst already knew the official postmortem's attribution.” Use only supplied records.
- Calculate base output and average quote price for q=1 in both fictional states. Compare each average price with its initial marginal price.
- Write a bounded three-sentence incident finding and list the additional records required to test a liquidity-withdrawal claim independently.
Show worked correction
Worked correction and expected reasoning
The order is H1, H2, H3, H4. H4 stays approximate. The article's publication date is December 17; the fixture does not supply an earlier availability record. Therefore the earlier knowledge claim is unsupported. This does not prove that nobody had earlier evidence; it means this dataset cannot establish that they did.
Before withdrawal, output = 100,000×1/101 = 990.0990 base units. Average quote price = 1/990.0990 = 0.00101, a 1% premium over 0.001. After withdrawal, output = 10,000×1/11 = 909.0909 units. Average quote price = 0.0011, a 10% premium. The initial marginal ratios are equal, but the same input receives fewer base units after reserves shrink. These percentages describe average execution premiums in this model, not historical losses or final marginal-price changes.
A defensible finding: “Raydium's December 17 postmortem reports a December 16 privileged-account exploit and subsequent authority changes. The initial intrusion vector and independent historical reserve reconstruction remain unverified in this lesson. This source does not establish a memecoin creator rug pull.” Request matching signatures, decoded operations, frozen before/after reserves and position/authority records to test a withdrawal mechanism. Human attribution requires additional evidence.
Score out of ten: chronology and precision (two), knowledge-time boundary (two), both model calculations with assumptions (four), bounded finding and evidence requests (two). Unsupported actor attribution or invented historical balances receive no evidentiary credit.
Checklist
- Identify the object, mechanism and attribution claim separately.
- Record source, event time and knowledge-time limits.
- Compare matching before/after state.
- Preserve unknown causes and alternative explanations.
- Keep illustrative mathematics separate from historical measurement.
- Report the narrow supported conclusion without a financial call.
Summary
Reconstructing an incident means preserving the chain from source to event to state change. A postmortem can teach that method without proving a creator rug pull. Historical outcomes cannot supply evidence to an earlier observer retroactively.
Summary
A label cannot replace a mechanism. Stable marginal price can coexist with reduced depth. Publisher attribution, independent verification and human intent remain distinct claims.
Visual specifications
Build H1–H4 UTC timeline using the publisher's report; separate event-time lane from publication-date lane, label H4 approximate and attribution source-reported. Add a separate explicitly illustrative inset for FIX-P07-08 with equal marginal ratios and q=1 outputs. Never plot fictional reserves as historical incident measurements.
Visual delivery rules: dark navy/black, cyan/electric-blue/violet accents, units and uncertainty explicitly labelled. Use deterministic charts or SVG, not fabricated screenshots. At 390 px stack annotations and provide the data table as a text alternative; verify 768 px and desktop later. In Arabic localize labels and layout with native RTL, while isolating addresses/hashes LTR and retaining the actual direction of transfers and chronology. Use only the supplied official ZECOIN logo if branding is added. No visual asset or mobile/RTL rendering is claimed ready.
Tools
Use RADAR only when the exact network, asset and needed fields are supported and their provenance is visible. This is a read-only educational inspection, not a trade or a token launch. Use the supplied offline dataset if access or data is unavailable; missing information remains unknown. A future Open in ZECOIN action needs validated runtime routing and source coverage. No executable asset CTA is supplied for illustrative identifiers. Academy participation and commercial status never change Radar observations.
Sources & claim boundaries
- Raydium Detailed Post-Mortem and Next Steps — Issuer-reported Dec 2022 incident and mitigation timeline; not independent attribution or a memecoin rug-pull finding. Checked 2026-09-30.
- Uniswap v2 Pricing — Two-reserve constant-product pool pricing; not a model for every launch or pool. Checked 2026-09-30.
- Solana Set Authority — Specific authority roles and removal of a selected authority. Checked 2026-09-30.
The tables and exercise fixtures are original educational material unless explicitly designated HISTORICAL. Fictional identifiers are deliberately invalid as blockchain addresses. Documentation supports mechanism definitions, not the invented exercise values. Source inspection is editorial research, not a live-chain measurement. Sources may change; re-review before publication.
Next lesson
P07 is complete. Review your event chronology, liquidity model and evidence boundaries, then return to the Academy dashboard. Separate labs retain their listed prerequisites.
Visual specifications
P07-L08-V01
What changed when, and which facts were reported retrospectively?
Raydium publisher-reported exploit/mitigation chronology; comparative case, not a memecoin rug-pull finding. Reserve inset is illustrative.
Build H1–H4 UTC timeline using the publisher's report; separate event-time lane from publication-date lane, label H4 approximate and attribution source-reported. Add a separate explicitly illustrative inset for FIX-P07-08 with equal marginal ratios and q=1 outputs. Never plot fictional reserves as historical incident measurements.
Four reported historical events occur December 16–17, 2022; postmortem publication is December 17. Separate fictional pools share marginal ratio but differ in depth.
390px: stacked annotations and text table; 768px and desktop acceptance pending
RTL labels/layout; identifiers LTR; preserve factual axis, chronology and edge direction.
HIST-P07-08
P07-L08-V02
Which claims are observed, inferred, unknown or insufficiently supported?
Evidence classification for this lesson; no investment verdict.
Four labelled rows; show claim, evidence pointer, boundary and next verification step.
Text table of four evidence states and the limits of each conclusion.
390px: stacked annotations and text table; 768px and desktop acceptance pending
RTL labels/layout; identifiers LTR; preserve factual axis, chronology and edge direction.
HIST-P07-08
Sources & claim boundaries
S-INCIDENT · official_incident_report
Raydium Detailed Post-Mortem and Next Steps
- Supported claim
- Issuer-reported Dec 2022 incident and mitigation timeline; not independent attribution or a memecoin rug-pull finding.
- Verification boundary
- Primary publisher page read; historical ledger transactions not independently replayed.
- Checked at
- 2026-09-30
https://raydium.medium.com/detailed-post-mortem-and-next-steps-d6d6dd461c3e
S-PRICING · official_documentation
Uniswap v2 Pricing
- Supported claim
- Two-reserve constant-product pool pricing; not a model for every launch or pool.
- Verification boundary
- Primary publisher page read; historical ledger transactions not independently replayed.
- Checked at
- 2026-09-30
https://developers.uniswap.org/docs/protocols/v2/concepts/pricing
S-AUTHORITY · official_documentation
Solana Set Authority
- Supported claim
- Specific authority roles and removal of a selected authority.
- Verification boundary
- Primary publisher page read; historical ledger transactions not independently replayed.
- Checked at
- 2026-09-30
https://solana.com/docs/tokens/basics/set-authority
Dataset provenance
id: HIST-P07-08
dataStatus: HISTORICAL
observedAt: 2022-12-16T10:12:00Z
historicalCoverage: 2022-12-16/2022-12-17
capturedAt: 2026-09-30
sourceId: S-INCIDENT
publishedAt: 2022-12-17
observationBasis: First publisher-reported event time; other source-reported times frozen in H1–H4; not independently replayed ledger measurements.
scope: Official report chronology only; no historical reserve dataset or creator-rug-pull attribution.
id: FIX-P07-08
dataStatus: ILLUSTRATIVE
observedAt: null
scope: Original zero-fee constant-product reserve model; separate from historical protocol incident.