Assets
Exchange
Buy Crypto
Products

A honeypot in crypto is a scam designed to let users buy a token or deposit funds while making it impossible — or deliberately expensive — to get their money back out.
The most common version is a honeypot token. Its smart contract allows normal wallets to buy, but selling may fail, trigger an extreme fee, or work only for privileged addresses controlled by the scammer. Its the same basic pattern: users can enter the position, but the contract or wallet mechanics prevent a normal exit.
That makes honeypots different from an ordinary token crash. The defining problem is not that the price falls — it is that the exit itself is manipulated.
A token honeypot creates an asymmetric market: buying works normally, while selling follows different rules.
A scammer launches a token and provides enough liquidity for trading to begin. Buyers can swap ETH, BNB, SOL, or another asset for the token, so the market initially appears functional.
The problem only becomes obvious when they try to leave. Malicious contract logic may reject the sell transaction, blacklist the buyer after purchase, or impose a sell tax so high that almost nothing can be recovered. Some contracts exempt the deployer or selected wallets from those restrictions, allowing the scammers to sell while everyone else remains trapped.
Honeypot scams can operate like automated factories. CertiK traced one operation that funded 979 wallets used to deploy honeypot tokens in just over two months, with some scam campaigns creating a new contract as often as every 30 minutes.
And seeing a few successful sells onchain does not necessarily prove the token is safe. Those transactions may come from the deployer, whitelisted addresses, or other wallets that are exempt from the restrictions.
The key question is therefore not “Has anyone sold this token?” but “Can an ordinary wallet buy it and then sell it under the same rules?”
Honeypot tokens usually trap buyers by using smart-contract permissions that treat selling differently from buying.
The exact mechanism varies by token and blockchain, but four patterns are especially common:
CertiK has documented honeypots that use blacklist logic as well as more unusual balance-manipulation techniques designed to make holders’ tokens unsellable.
The implementation also depends on the blockchain. On EVM networks such as Ethereum or BNB Chain, malicious restrictions are often embedded directly in token-contract logic. On Solana, relevant controls can include freeze authorityor Token-2022 extensions such as transfer hooks and configurable transfer behavior. These features are not inherently malicious, but they are important permissions to understand before buying an unfamiliar token.
The best time to detect a honeypot is before the first swap, by checking whether an ordinary wallet can exit and whether the token owner can change the rules later.
Use several checks together:
A single green signal is not enough. A verified contract, visible liquidity, successful sells, or a clean scanner result each answer only part of the question.
Even the holder list can be manipulated. Ethereum.org documented a scam token that sent about 16% of its supply to the real Arbitrum Foundation deployer address, making its holder distribution appear more legitimate.
The goal is not merely to prove that selling works now — it is to understand who can change whether selling works tomorrow.
Honeypot checkers are useful screening tools, but a clean result only shows that the token passed the checks performed under its current contract state.
A typical checker simulates a buy and sell, estimates transaction taxes, and looks for restrictions that would prevent an ordinary wallet from exiting. If the simulated sell fails, that is an obvious warning sign.
The harder problem is what can happen after the scan. A token owner may still be able to:
This means a result such as “Not a honeypot” is not a permanent safety certificate. It means the scanner did not detect a honeypot under the conditions it tested at that moment.
Use a checker as one layer of due diligence, then inspect owner permissions, contract upgradeability, liquidity, and real buy-to-sell activity separately.
A honeypot primarily traps holders by restricting their exit, while a rug pull extracts value by removing liquidity, dumping insider supply, or abusing privileged control.
The two scams can overlap. A malicious project can prevent ordinary holders from selling and later withdraw liquidity or dump insider-controlled tokens.
A useful shorthand is: a honeypot locks the exit; a rug pull removes the value behind it.
For a deeper breakdown of liquidity pulls, insider dumps, and contract-based rugs, see our guide to rug pulls in crypto.
A wallet honeypot tricks users with a seed phrase or private key for a wallet that appears to contain valuable crypto, then steals the gas they send in trying to withdraw it.
A typical version looks surprisingly tempting: someone publicly posts the recovery phrase for a wallet containing USDT or another valuable token. Anyone can import the wallet and see the balance, but there is not enough ETH, BNB, or another native asset to pay the transaction fee.
The victim sends a small amount of crypto for gas. That deposit is then automatically swept to another address, often before the victim can make the intended transfer. Other variants use multisig requirements or token restrictions that make the displayed assets impossible to move. Binance documents all of these patterns in its current honeypot guidance.
The trap works because the exposed seed phrase creates the illusion of access. In reality, a seed phrase posted publicly should be treated as compromised from the start — not as free money waiting to be claimed.
If you are trapped in a honeypot, stop sending more funds and focus on protecting the rest of your wallet rather than trying to force the token to sell.
Take these steps:
Disconnecting a wallet from a website is not the same as revoking an approval. Ethereum.org notes that an existing token allowance can remain usable until it is explicitly revoked, potentially even years later.
Be especially cautious after the loss. The FTC warned again in August 2026 that recovery scammers actively target previous scam victims, often posing as government agencies, law firms, or recovery specialists and asking for an upfront fee.
If someone says they can definitely recover trapped crypto after you pay them first, that is another major warning sign.
Managing unfamiliar tokens starts with keeping control of your own keys. Get Atomic Wallet to manage crypto in one self-custody wallet — and always verify a token before you swap or interact with it.

Learn what DeFi means, how decentralized finance works, how lending, DEXs, liquidity pools, and yield work, and the key benefits and risks.