NexFlow › Honeypot check vs rug check
Honeypot check vs rug check: "can I sell" is not the same question as "can they drain it"
People say "is it safe?" as if that were one question. It is at least two. A honeypot check asks whether the token's own mechanics can stop you from selling. A rug check asks whether the people behind it can pull the value out from under you while you can still technically sell. A token can pass one and fail the other, and the failure you did not check for is the one that gets you.
The honeypot question: can the token itself trap you?
On Solana a honeypot is not usually a clever contract; it is an authority or an extension the mint carries. The NexFlow honeypot check reads three things directly from the mint account. Freeze authority: if it is set, whoever holds it can freeze your token account and your balance stops moving. Mint authority: if it is set, supply can be inflated on top of you. And the Token-2022 extensions, which is where the modern traps live: transfer fee (a cut taken on every move, which can be set punitively), default frozen (new accounts start frozen), non-transferable, permanent delegate (an address that can move your tokens without your signature), transfer hook (arbitrary program logic on every transfer), and pausable mint.
The check fails closed. If it cannot positively clear the mint — the account is unreadable, an extension is unrecognised, the data is inconsistent — it reports that it could not clear it rather than defaulting to a green light. That design choice is the most important thing on the feature page and it is worth understanding why: a honeypot detector that says "fine" when it does not know is worse than no detector, because it manufactures confidence.
The rug question: can the people behind it drain it?
A rug does not need the token to be broken. The mechanics can be perfectly clean — no freeze, no mint authority, no dangerous extensions — and you can still lose almost everything because the deployer held most of the supply and sold it into you, or because the liquidity that made the price real was theirs to remove. The rug check reads the human side of the mint: live authorities (overlapping the honeypot check), dev-wallet status (has it sold, is it still holding), bundled supply (how much was bought in the launch bundle and by whom), whale concentration, cloned tickers (is this the "real" one of several with the same name), and the same Token-2022 danger extensions. It rolls those into a grade, and it applies hard caps: some findings pin the grade down no matter how good everything else looks.
Its own limit is stated plainly on the feature page: a clean check is not a guarantee against future liquidity removal. It tells you what the wallets and the pool look like now. It cannot tell you what a holder will do in ten minutes.
Side by side, with sources
Every row is read from the feature page in the source column on the date shown. These describe what each check reads; they are not claims about how often either check is right.
| Dimension | Honeypot check | Rug check | As of · source |
|---|---|---|---|
| Question answered | Can the token's mechanics stop me selling or take my tokens? | Can the holders / deployer drain the value while I can still sell? | as of 2026-09-27 · /features/honeypot-check/ and /features/rug-check/ |
| Freeze and mint authority | Read | Read (as part of live authorities) | as of 2026-09-27 · both feature pages |
| Token-2022 danger extensions | Transfer fee, default frozen, non-transferable, permanent delegate, transfer hook, pausable mint | Same set, folded into the grade | as of 2026-09-27 · /features/honeypot-check/ |
| Dev-wallet status | Not read | Read | as of 2026-09-27 · /features/rug-check/ |
| Bundled supply and whale concentration | Not read | Read | as of 2026-09-27 · /features/rug-check/ |
| Cloned tickers | Not read | Read | as of 2026-09-27 · /features/rug-check/ |
| Output | Cleared / not cleared, fails closed when uncertain | Graded, with hard caps on the grade | as of 2026-09-27 · both feature pages |
| What it cannot see | Holder intent, future liquidity removal | Future liquidity removal (stated on the page) | as of 2026-09-27 · /features/rug-check/ |
| Pricing | Free, keyless via the scanner | Free, keyless via the scanner | as of 2026-09-27 · /features/scanner/ |
Where they overlap and why that is not redundancy
Both checks read the authorities and the Token-2022 extensions. The overlap is intentional: those fields are the intersection of "mechanically trapped" and "structurally rigged", because a live mint authority is simultaneously a honeypot vector (inflate on top of you) and a rug vector (dilute the pool). What differs is what each does with the finding. The honeypot check treats it as a binary blocker. The rug check treats it as one input into a grade that also weighs who holds what. If you only look at the grade you can miss that a single mechanical finding should have ended the conversation; if you only look at the honeypot result you can clear a token whose top holder is the deployer's second wallet.
The order matters: run the honeypot question first, because a "cannot sell" answer makes every other number irrelevant. Then run the rug question, because a "can sell" answer tells you nothing about whether there will be anything to sell into.
What neither check can tell you
Neither reads the future. A pool whose liquidity is unlocked can be drained after the check ran; a dev wallet that had not sold can sell now. Neither reads off-chain promises — a "locked liquidity" claim on a website is not the same as a lock the scanner can verify on-chain, and the checks report what they can verify. Neither reads whether the narrative is real, whether the volume is organic, or whether the people in the group chat are the same people holding the bundled supply. Our guide on first-hour token checks covers what to look at by hand around the two automated results.
And critically: a clean result from both is a dated snapshot. If you are sizing into a position over an hour, rerun them. The scanner is free and keyless precisely so that rerunning costs you nothing.
Who should run the honeypot check
Everyone, first, on every new mint, before any buy. It is the fastest possible filter and it answers the only question that can make a position literally unexitable. It is especially non-negotiable for Token-2022 mints, where the extension set is where the modern traps live and where a glance at "freeze authority: none" is not enough. If you are buying from the Trenches feed or with an automated setup, the honeypot check is the one you should be running before the automation, not after.
Who should run the rug check
Anyone holding for longer than the first few minutes, anyone sizing beyond a throwaway amount, and anyone who has ever been surprised by a dev wallet. The rug check is the one that tells you the shape of the holder base, whether the launch was bundled, and whether the ticker you are looking at is the original or a clone that borrowed its name. It is slower to interpret than a pass/fail — the grade and the caps take a minute to read — and that minute is the price of knowing what you are actually buying into.
Run both from the check-token entry point, read the honeypot answer, then read the grade, then read the reasons under the grade. The reasons are the product; the grade is a summary of them.
Frequently asked
What is the difference between a honeypot and a rug?
A honeypot is a token whose own mechanics — freeze or mint authority, or a Token-2022 extension like permanent delegate or transfer hook — can stop you selling or take your tokens. A rug is when the holders or deployer drain the value (selling bundled supply, removing liquidity) while you can still technically sell. A token can pass one check and fail the other.
Which Token-2022 extensions does the honeypot check flag?
As of 2026-09-27 the feature page lists transfer fee, default frozen, non-transferable, permanent delegate, transfer hook and pausable mint as dangerous extensions, alongside live freeze and mint authority.
What does "fails closed" mean?
If the honeypot check cannot positively clear a mint — unreadable data, an unrecognised extension, inconsistent state — it reports that it could not clear it rather than returning a pass. It never manufactures a green light from uncertainty.
Does a clean rug check mean the liquidity cannot be pulled?
No. The rug check feature page states that a clean result is not a guarantee against future liquidity removal. It reports what the wallets and pool look like at the moment of the check; rerun it if you are building a position over time.
Which check should I run first?
The honeypot check, because a "cannot sell" answer makes every other number irrelevant. Then the rug check, because being able to sell says nothing about whether there will be value left to sell into. Both are free and keyless from check-token.