TL;DR - Liquidity locks and contract audits catch some rug pulls, but the deployer wallet's own history and current holdings catch the ones those checks miss.
The chart is vertical, the buy button is one tap away, and the token only launched nine minutes ago. This checklist is for that exact moment - before you buy into a new token or add liquidity to a fresh pool, not after the chart goes flat. Most rug-pull guides stop at the contract: is it verified, is liquidity locked, has ownership been renounced. Those checks matter. They also miss the one thing that actually pulls the liquidity - the wallet holding the keys.
Before you start
This checklist applies to any new token launch, presale, or freshly created liquidity pool on an AMM - Uniswap, Meteora, PancakeSwap, whatever chain you're on. It doesn't apply to an established token with years of trading history behind it; that's a different risk profile entirely.
You can read a lot of this by hand. Open the pool on DEXTools or Etherscan, check the top-holder list, and see whether liquidity shows as locked. That tells you what the contract and the pool look like right now. It won't tell you whether the deployer wallet already funded ten other tokens that rugged last month, or whether that same address sits in a stolen-funds or scam-labeled dataset already. Rather than piecing that together by hand, screen the deployer wallet with Plastron and get one risk score covering scam, mixer, and sanctions exposure across Ethereum and six other chains.
A rug-pull checklist has four stages, not one: wallet history, lock and contract permissions, holder concentration, then a test buy and a re-screen after you interact.
The checklist
Work through these in order before you commit real money. Each step catches something the one before it can't.
Check whether the deployer wallet is brand new or has a real transaction history.
A wallet funded once, an hour before launch, straight from a fresh exchange withdrawal, is a pattern, not a coincidence.
Screen the deployer and contract-owner wallets for prior scam, mixer, or sanctions exposure.
An address that funded three other tokens that rugged in the past month usually carries that history already.
Confirm the liquidity lock on Team Finance, Unicrypt, or PinkSale, and read the actual duration.
A lock under 30 days is barely a lock. Six to twelve months is closer to a real commitment.
Verify the contract's mint function is disabled and ownership is renounced or sent to a burn address.
An active mint function lets the deployer create new supply out of thin air, lock or no lock.
Pull the top-holder list and check how much of the supply sits in a handful of wallets.
Across last year's tracked rug pulls, most involved at least one wallet holding more than 15 percent of total supply.
Check whether the deployer wallet has interacted with other known rug-pull or drainer addresses.
A shared funding source across several "unrelated" launches is the strongest signal a checklist can catch before launch.
Run a small test buy and sell before adding any meaningful size.
A sell that fails, or returns far less than expected, is the pool telling you something the contract page won't.
Screen your own wallet again after you interact with the contract, not just before.
Some rug-pull contracts embed a drainer that only fires on a second approval, once the first transaction looks clean.
Why isn't a liquidity lock enough to catch a rug pull?
A lock only constrains the pool that's locked. It says nothing about a second pool the same deployer opens on another DEX, or about a wallet that already pulled profit before locking what's left. On January 12, 2026, Eric Adams launched the $NYC token at a press conference in Times Square. Its market cap hit $580 million within minutes. About thirty minutes later, a wallet linked to the deployer withdrew $2.5 million in liquidity, and the token's value collapsed 81 percent to roughly $100 million in market cap. Some of that liquidity came back afterward. The confidence didn't.
The lock question and the wallet question are different questions. One asks what the contract currently permits. The other asks what the person behind it has already done, with this wallet or the last one.
What does the deployer wallet actually reveal?
A deployer wallet's history is a paper trail the contract itself never shows. Plastron's labeled address set carries 3,901 addresses drawn from real scam, hack, and sanctions cases, plus the full OFAC list of 780 sanctioned crypto addresses checked on every scan. A deployer wallet that funded a rug three weeks ago under a different token name usually still carries that label. A wallet with no history at all isn't automatically guilty, but it hasn't earned trust either - it's an unknown, not a green light.
Screening won't tell you whether a project has real utility or a working product. That part still comes down to judgment. What it removes is the guesswork on the one variable a locked pool can't hide: who's actually holding the keys.
Rug-pull red flags split into three columns - wallet, contract, and pool - and a checklist that only reads the contract page misses the wallet column entirely.
FAQ
Is it safe to buy a token the moment it launches?
Not if you skip the checklist first. Early buyers who screen the deployer wallet and check the liquidity lock before buying still face the same volatility as everyone else, but they've ruled out the two failure modes behind most launches that go to zero in the first hour: a wallet with a rug-pull pattern already attached, and liquidity that was never actually locked.
What if the deployer wallet is brand new with no history?
Treat it as unverified, not automatically dangerous. Every legitimate project's deployer wallet was new once. A clean-but-empty history just means the other checks - the lock, the mint function, the holder concentration - carry more weight, since the wallet itself can't vouch for anything yet.
Do liquidity-lock checkers like Team Finance replace wallet screening?
No. A lock checker confirms a pool's tokens sit in a locking contract for a set duration. It says nothing about whether the wallet that deployed the contract has a documented history of scams, mixer use, or sanctions exposure elsewhere. The two checks answer different questions, and neither substitutes for the other.
How much protection does a checklist like this actually give before launch?
Enough to skip the worst offenders, not enough to guarantee safety. A checklist catches known patterns: a labeled deployer wallet, an unlocked pool, an active mint function, a top-heavy holder list. It can't predict a first-time scam from a genuinely clean wallet with a locked pool and no prior red flags. Treat every pass as "nothing found yet," not "verified safe."
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.