Back

Rug-pull anatomy

P07-L08 · P07 · P07-M02

Reconstruct observable changes before and after a historical liquidity event

HISTORICAL · needs_review

Prerequisites: P07-L07

Learning objectives

  • Reconstruct a source-reported historical event sequence without hindsight.
  • Separate symptoms, mechanism and actor attribution.
  • Calculate the depth consequence of a fictional proportional withdrawal.

EN source master · P07-L08 · 45 minutes estimated · needs_review

Learning objectives:

  • Reconstruct a source-reported historical event sequence without hindsight.
  • Separate symptoms, mechanism and actor attribution.
  • Calculate the depth consequence of a fictional proportional withdrawal.

Why this matters

A collapsing price can reveal a serious economic change without revealing its cause. A creator withdrawing liquidity, a privileged account being compromised, ordinary selling into a shallow pool and a routing failure can produce superficially similar screens. This lesson teaches you to reconstruct changes and classify evidence before assigning a narrative.

“Rug pull” is a conclusion about conduct, not a unit of measurement. Learn to describe what changed, who could perform the relevant action, what the records actually establish and what remains unknown. A precise limited finding is more useful than an accusation built from a chart.

Explanation

Separate the symptom, mechanism and actor

Begin with a symptom: reserves decreased, an exchange failed, an authority changed or a holder transferred tokens. Then test a mechanism. Was liquidity withdrawn through a position, were tokens sold, was a permission exercised, or did an interface stop returning data? Finally ask about actor attribution. A transaction signer identifies an account's participation; it does not establish the human operating it or whether credentials were compromised.

Keep three columns in your notes. “Reserve decrease” belongs in the observation column if supported by a matching snapshot. “Liquidity withdrawal” requires operation-level evidence. “Creator intentionally stole funds” requires both attribution and intent evidence beyond a price chart. If the supplied source only reports an exploit, preserve that label rather than rewriting it as creator misconduct.

Token authority and pool control are separate surfaces. A revoked mint authority does not answer whether a pool position can be withdrawn. A claimed liquidity lock needs its own scope: exact position, relevant fraction, mechanism, expiry and any exceptions. Even a verified restriction on one action cannot establish that all other actions are harmless. Do not substitute a general safety score for these distinct questions.

Reconstruct state around a bounded event

Specify the network and exact asset or protocol, the time window, source and measurement coverage. Choose a before observation and an after observation that measure the same objects. Token reserves, quote reserves, liquidity positions and permissions are different variables. If one snapshot aggregates several pools while another describes one pool, their difference is not a valid single-pool change.

A sound event table contains event time, evidence locator, reported action, consequence and confidence boundary. Missing snapshots remain missing. Do not fill a before balance from a later article or a present-day dashboard. If no frozen reserve records are supplied, you can reconstruct a publisher's reported incident chronology but cannot independently calculate historical pool losses or trader execution.

A price chart alone cannot distinguish liquidity withdrawal from a sale. Removing proportional reserves can leave the reserve ratio unchanged while reducing depth. Selling into a constant-product pool changes the ratio through a different operation. To distinguish them, seek the transaction and position-level changes, not merely a descending candle.

Keep knowledge time separate from event time

Historical reporting has at least two clocks. Event time is when an action is reported to have occurred. Knowledge time is when the analyst had access to evidence about it. An article published tomorrow can describe an event today; that does not make its contents available to an analyst today.

This distinction matters when grading early warning claims. If a postmortem later attributes an event to a compromised privileged account, you cannot assume an observer knew that attribution before the report appeared. A fair reconstruction says “the later report describes this event at this time” and separately identifies what an earlier observer could have inspected. Where publication timing is known only by date, do not invent an exact release hour.

Your investigation can be useful without claiming predictive power. A mitigation timeline shows which controls reportedly changed after an incident. It does not prove that a particular alert would have prevented the incident or that future protocols with similar controls are safe.

Use the comparative historical case carefully

The historical example below is Raydium's December 2022 protocol exploit, used to compare a privileged-account compromise with a creator-withdrawal narrative. It is not presented as a memecoin creator rug pull. The official postmortem is the primary publisher's account; this lesson has not independently replayed the ledger.

A first-party report can establish what its publisher stated. Independent confirmation of each statement requires matching transactions, archived state and reproducible decoding. Preserve this distinction in the evidence panel. It is acceptable to cite an official report while stating that its proposed initial intrusion explanation was not established.

Historical comparisons should transfer a method, not a verdict. Ask which privilege was implicated, which remediation reportedly removed or relocated it, and which evidence would be needed to establish losses and control independently. Then apply the same questions to a memecoin case only after obtaining that case's own records.

Model depth without pretending to measure the incident

For the separate fictional model, use a zero-fee two-reserve constant-product pool with base reserve X and quote reserve Y. A quote input q returns Xq/(Y+q) base units. The marginal quote price is Y/X. This is the same restricted model introduced in P07-L03 [S-PRICING]; it is not a reconstruction of Raydium's exploited pools.

A proportional withdrawal changes X and Y by the same factor. The ratio can remain unchanged while a fixed order becomes large relative to remaining reserves. This illustrates why a stable displayed price is insufficient evidence of stable executable depth. Fees, concentrated liquidity, other routes, transfer restrictions and intervening trades require different calculations.

Do not conflate model conclusions with observed facts. The model shows a possible mechanical consequence under declared assumptions. The historical report supplies a chronology. Neither supplies a measured return, an investment recommendation or an identification of a memecoin perpetrator.

Key terms

  • Symptom: a visible change that may have several causes.
  • Mechanism: the operation connecting a state change to its result.
  • Attribution: a supported link from an action to an actor.
  • Event time: the reported time of an action.
  • Knowledge time: when evidence became available to an observer.
  • Postmortem: retrospective incident account with its own evidentiary limits.
  • Depth: available reserves relevant to a specified order and route.

Historical example

HISTORICAL SOURCE RECORD — HIST-P07-08. Frozen editorial summary of Raydium's official postmortem [S-INCIDENT], published December 17, 2022 and inspected September 30, 2026. All times below are publisher-reported UTC event times. No transaction replay, reserve snapshot or independent human attribution is supplied.

RecordReported event time UTCPublisher's reported eventBoundary
H12022-12-16 10:12Incident began; compromised pool-owner/admin account implicatedInitial intrusion vector not established
H22022-12-16 14:16Hot patch revoked compromised authority and moved authority to a new hardware accountSource-reported mitigation, not proof of recovery
H32022-12-17 10:27AMM V4 upgrade removed administrative parametersDoes not measure historical reserves
H42022-12-17 approximately 15:00Remaining administrative functions moved to Squads multisigApproximate time must remain approximate

The article reports an exploit involving privileged functions and fee accounting. It discusses a possible intrusion explanation without establishing the exact initial vector. This is a protocol exploit comparison, not a documented creator rug-pull classification.

ILLUSTRATIVE MODEL — FIX-P07-08. Fictional base and quote units; no Raydium historical reserves.

StateBase reserve XQuote reserve YMarginal quote price Y/X
Before proportional withdrawal100,0001000.001
After 90% proportional withdrawal10,000100.001

Assume zero fees, unrestricted transfers, no other routes and no intervening trades. Apply a hypothetical quote input of 1 unit separately to each starting state.

What the evidence proves

OBSERVED SOURCE STATEMENT: H1–H4 are inspectable statements in the cited publisher report. Their event times are source-reported, not independently verified here.

INFERRED: In FIX-P07-08, proportional removal preserves the marginal ratio but increases the average execution premium for the specified input. This follows from the supplied model, not the incident.

What the evidence does not prove

UNKNOWN: Actual historical pool reserve snapshots, each transaction's independently decoded effects, exact initial intrusion vector and what a particular observer knew before publication.

INSUFFICIENT EVIDENCE: The historical records do not establish a memecoin creator rug pull, an earlier predictive warning or safety after remediation. A fictional reserve calculation cannot establish real incident losses.

Common mistakes

Assigning the “rug pull” label from a falling chart; treating compromised credentials as proof of creator intent; confusing publication date with event time; calculating historical reserves from fictional inputs; and interpreting an unchanged reserve ratio as unchanged depth.

Practical exercise

Inputs are H1–H4 and FIX-P07-08. Work offline without connecting a wallet.

  1. Write the four reported events in chronological order and preserve approximate timing.
  2. Assess the claim “At 11:00 UTC on December 16, the analyst already knew the official postmortem's attribution.” Use only supplied records.
  3. Calculate base output and average quote price for q=1 in both fictional states. Compare each average price with its initial marginal price.
  4. Write a bounded three-sentence incident finding and list the additional records required to test a liquidity-withdrawal claim independently.
Show worked correction

Worked correction and expected reasoning

The order is H1, H2, H3, H4. H4 stays approximate. The article's publication date is December 17; the fixture does not supply an earlier availability record. Therefore the earlier knowledge claim is unsupported. This does not prove that nobody had earlier evidence; it means this dataset cannot establish that they did.

Before withdrawal, output = 100,000×1/101 = 990.0990 base units. Average quote price = 1/990.0990 = 0.00101, a 1% premium over 0.001. After withdrawal, output = 10,000×1/11 = 909.0909 units. Average quote price = 0.0011, a 10% premium. The initial marginal ratios are equal, but the same input receives fewer base units after reserves shrink. These percentages describe average execution premiums in this model, not historical losses or final marginal-price changes.

A defensible finding: “Raydium's December 17 postmortem reports a December 16 privileged-account exploit and subsequent authority changes. The initial intrusion vector and independent historical reserve reconstruction remain unverified in this lesson. This source does not establish a memecoin creator rug pull.” Request matching signatures, decoded operations, frozen before/after reserves and position/authority records to test a withdrawal mechanism. Human attribution requires additional evidence.

Score out of ten: chronology and precision (two), knowledge-time boundary (two), both model calculations with assumptions (four), bounded finding and evidence requests (two). Unsupported actor attribution or invented historical balances receive no evidentiary credit.

Checklist

  • Identify the object, mechanism and attribution claim separately.
  • Record source, event time and knowledge-time limits.
  • Compare matching before/after state.
  • Preserve unknown causes and alternative explanations.
  • Keep illustrative mathematics separate from historical measurement.
  • Report the narrow supported conclusion without a financial call.

Summary

Reconstructing an incident means preserving the chain from source to event to state change. A postmortem can teach that method without proving a creator rug pull. Historical outcomes cannot supply evidence to an earlier observer retroactively.

Summary

A label cannot replace a mechanism. Stable marginal price can coexist with reduced depth. Publisher attribution, independent verification and human intent remain distinct claims.

Visual specifications

Build H1–H4 UTC timeline using the publisher's report; separate event-time lane from publication-date lane, label H4 approximate and attribution source-reported. Add a separate explicitly illustrative inset for FIX-P07-08 with equal marginal ratios and q=1 outputs. Never plot fictional reserves as historical incident measurements.

Visual delivery rules: dark navy/black, cyan/electric-blue/violet accents, units and uncertainty explicitly labelled. Use deterministic charts or SVG, not fabricated screenshots. At 390 px stack annotations and provide the data table as a text alternative; verify 768 px and desktop later. In Arabic localize labels and layout with native RTL, while isolating addresses/hashes LTR and retaining the actual direction of transfers and chronology. Use only the supplied official ZECOIN logo if branding is added. No visual asset or mobile/RTL rendering is claimed ready.

Tools

Use RADAR only when the exact network, asset and needed fields are supported and their provenance is visible. This is a read-only educational inspection, not a trade or a token launch. Use the supplied offline dataset if access or data is unavailable; missing information remains unknown. A future Open in ZECOIN action needs validated runtime routing and source coverage. No executable asset CTA is supplied for illustrative identifiers. Academy participation and commercial status never change Radar observations.

Sources & claim boundaries

  • Raydium Detailed Post-Mortem and Next Steps — Issuer-reported Dec 2022 incident and mitigation timeline; not independent attribution or a memecoin rug-pull finding. Checked 2026-09-30.
  • Uniswap v2 Pricing — Two-reserve constant-product pool pricing; not a model for every launch or pool. Checked 2026-09-30.
  • Solana Set Authority — Specific authority roles and removal of a selected authority. Checked 2026-09-30.

The tables and exercise fixtures are original educational material unless explicitly designated HISTORICAL. Fictional identifiers are deliberately invalid as blockchain addresses. Documentation supports mechanism definitions, not the invented exercise values. Source inspection is editorial research, not a live-chain measurement. Sources may change; re-review before publication.

Next lesson

P07 is complete. Review your event chronology, liquidity model and evidence boundaries, then return to the Academy dashboard. Separate labs retain their listed prerequisites.

Visual specifications

P07-L08-V01

SPECIFICATION_ONLY · HISTORICAL

What changed when, and which facts were reported retrospectively?

Raydium publisher-reported exploit/mitigation chronology; comparative case, not a memecoin rug-pull finding. Reserve inset is illustrative.

Build H1–H4 UTC timeline using the publisher's report; separate event-time lane from publication-date lane, label H4 approximate and attribution source-reported. Add a separate explicitly illustrative inset for FIX-P07-08 with equal marginal ratios and q=1 outputs. Never plot fictional reserves as historical incident measurements.

Four reported historical events occur December 16–17, 2022; postmortem publication is December 17. Separate fictional pools share marginal ratio but differ in depth.

390px: stacked annotations and text table; 768px and desktop acceptance pending

RTL labels/layout; identifiers LTR; preserve factual axis, chronology and edge direction.

HIST-P07-08

P07-L08-V02

SPECIFICATION_ONLY · HISTORICAL

Which claims are observed, inferred, unknown or insufficiently supported?

Evidence classification for this lesson; no investment verdict.

Four labelled rows; show claim, evidence pointer, boundary and next verification step.

Text table of four evidence states and the limits of each conclusion.

390px: stacked annotations and text table; 768px and desktop acceptance pending

RTL labels/layout; identifiers LTR; preserve factual axis, chronology and edge direction.

HIST-P07-08

Sources & claim boundaries

Dataset provenance

id: HIST-P07-08

dataStatus: HISTORICAL

observedAt: 2022-12-16T10:12:00Z

historicalCoverage: 2022-12-16/2022-12-17

capturedAt: 2026-09-30

sourceId: S-INCIDENT

publishedAt: 2022-12-17

observationBasis: First publisher-reported event time; other source-reported times frozen in H1–H4; not independently replayed ledger measurements.

scope: Official report chronology only; no historical reserve dataset or creator-rug-pull attribution.

id: FIX-P07-08

dataStatus: ILLUSTRATIVE

observedAt: null

scope: Original zero-fee constant-product reserve model; separate from historical protocol incident.

Test your reasoning

P07-L08-Q1 · Which conclusion does the historical example support?
P07-L08-Q2 · Before the report's publication, can its later attribution be assumed available?
P07-L08-Q3 · After the fictional 90% proportional withdrawal, what happens to initial marginal price and depth?
P07-L08-Q4 · For q=1 in the smaller fictional pool, what is the average execution premium?
P07-L08-Q5 · Which missing evidence best tests a claimed real liquidity withdrawal?