ArbiLayer
ArbiLayerGuides

Honeypot Tokens on Solana and EVM: How They Work and How to Spot Them

A honeypot is a token you can buy but cannot sell. The common patterns on Ethereum and EVM chains (sell blocks, adjustable taxes, blacklists, fake renounce) and on Solana (freeze authority, permanent delegate, transfer hooks), and a checklist to run before you buy.

ALArbiLayer ResearchOctober 6, 20265 min read
Honeypot Tokens on Solana and EVM: How They Work and How to Spot Them
ArbiLayer Research

A honeypot is a token you can buy but cannot sell — or can only sell at a loss so large that it amounts to the same thing. The chart looks healthy, buys keep coming in, the price climbs, and every attempt to exit fails or returns a fraction of the money. The trap is not in the price. It is in the token's code or its settings.

Honeypots exist on every chain, but they look different on EVM networks (Ethereum, BNB Chain, Base, Arbitrum) and on Solana, because the two token models are built differently. This guide covers the patterns on both, how to check a token before buying, and the related traps that are not strictly honeypots but end the same way.

Why honeypots work

Every token is a program. On EVM chains each token is its own smart contract, and whoever deploys it can write any rule into the transfer function: who may sell, how much tax is taken, when trading is allowed. On Solana most tokens share one standard program, but the creator controls powerful settings on each token — and the newer Token-2022 standard adds extensions that can change how transfers behave.

A buy is a transfer from the liquidity pool to you. A sell is a transfer from you to the pool. A honeypot simply treats those two directions differently.

Honeypots on EVM chains

These are the patterns that come up again and again in honeypot contracts on Ethereum and EVM networks:

  • Sell blocking. The transfer function checks whether the recipient is the liquidity pool and reverts unless the seller is on a private whitelist. Buys pass; sells fail with a vague error.
  • Blacklists. The owner can add any address to a blacklist, often automatically right after it buys. Blacklisted wallets cannot transfer at all.
  • Adjustable tax up to 100%. The token advertises a 3–5% tax, but the owner can raise the sell tax at any moment. At 99% a sell technically succeeds and returns almost nothing.
  • Trading switches and pauses. Trading can be "paused" for everyone except the owner, or a cooldown blocks sells for hours after each buy.
  • Tiny max-sell limits. A maximum transaction size so small that you would need thousands of sells — each paying gas — to exit.
  • Hidden mint. A function, often behind an innocent name, that lets the owner mint new tokens and dump them into the pool.
  • Fake renounce. The contract shows ownership "renounced" to the zero address, but the real control sits in a second variable or a separate admin role that was never given up.
  • Upgradeable proxy. The token sits behind a proxy and its logic can be replaced later. A clean contract today can become a honeypot tomorrow.
  • External fee contract. The transfer function calls another contract — "for fees" or "anti-bot" — that reverts on sells. The token's own code looks clean; the trap lives elsewhere.

Honeypots on Solana

On Solana the danger is usually not custom code but authorities and extensions that the creator kept:

  • Freeze authority. If the token still has a freeze authority, the creator can freeze any holder's token account. A frozen account cannot send — so it cannot sell. This is the classic Solana honeypot, and legitimate memecoin launchpads revoke it at creation for exactly this reason.
  • Mint authority. An active mint authority lets the creator print unlimited new supply and sell it into the pool.
  • Token-2022 Permanent Delegate. A permanent delegate can transfer or burn tokens from any holder's account without permission. Your balance can simply disappear.
  • Token-2022 Transfer Fee. A fee taken on every transfer. Like EVM tax, it can be set very high.
  • Token-2022 Transfer Hook. Every transfer calls a program chosen by the creator. That program can reject sells, exactly like an EVM sell block.
  • Default frozen accounts and pausing. Token-2022 can make every new token account start frozen, and newer versions let the issuer pause transfers entirely.
  • Mutable metadata. If the update authority is kept, the name, symbol and image can be changed later — useful for impersonating another project after the fact.

Not every token with these features is a scam. Regulated stablecoins and tokenized stocks keep freeze and pause powers for compliance. The question is whether an anonymous memecoin has any reason to keep them.

Traps that are not technically honeypots

  • Liquidity pull (rug pull). The token sells fine — until the creator removes the liquidity from the pool. Check whether LP tokens are burned or locked, and for how long.
  • Concentrated supply. A handful of wallets, often funded from the same source, hold most of the supply. They can sell into you whenever they want.
  • Same name, different token. A copycat uses the same ticker and logo as a real project. Always check the contract or mint address, not the name. We covered how a fake "GALA" cost buyers millions in the pGALA case study.
  • Approval drainers. A fake "claim" or "airdrop" site asks you to sign an approval that lets it move your other tokens. Your new token may be fine; your wallet is not.

How to check a token before you buy

CheckEVMSolana
Buy/sell simulationhoneypot.is, GoPlus, De.Fi ScannerRugCheck, SolSniffer
Contract codeVerified source on the block explorer; owner functions, proxyToken program: SPL or Token-2022, extensions enabled
ControlOwner, admin roles, renounce statusMint, freeze and update authorities revoked?
TaxesCurrent buy/sell tax and who can change itTransfer fee extension and its maximum
LiquidityLP burned or locked, lock end dateLP burned or locked
HoldersTop-10 share, linked walletsTop-10 share, bundled buys at launch
  1. Use two scanners, not one. Each catches different patterns.
  2. Read who can change what. A clean token today with an owner who can raise taxes or upgrade the contract is still a risk.
  3. Test with a tiny amount. Buy a few dollars' worth and sell it back before committing more. If the sell fails or loses far more than the advertised tax, stop.
  4. Look at real sells in the transaction history. Many buys and no successful sells from ordinary wallets is the clearest sign of all.
  5. Check the contract address against official sources — the project's site, its verified social accounts, or a listing on a major exchange.
  6. Be most careful in the first hours. Most traps are set at launch, when excitement is highest and checks are skipped.

Scanners reduce risk; they do not remove it. New tricks appear faster than detection rules, and a token that passes every check can still be abandoned. Never put in more than you can afford to lose on a token you cannot verify.

This article is for information only and is not investment advice.

This article is for information only and is not investment advice.