By Bryan Martin - founder of RektRadar. Ethereum scam-detection infrastructure since 2024. GitHub - LinkedIn.
Two months ago I posted 76% of new Ethereum tokens are scams. It got a fair pushback on Reddit that I want to answer with data instead of a comment: a single “76%” blends two very different things. Some of those tokens are already detectable as scams the second they deploy. Others look clean at launch and only rug days later. A buyer at block zero cannot see the second kind. So which number is it?
The honest answer is two numbers, and we now publish both. I tracked the same 24,150 token launches from the moment they deployed through 30 days of on-chain life. At launch, 48% scored as scams. By day 30, 91% did.
Dataset snapshot
Snapshot: 2026-07-20. We re-score every token at three ages and keep each result: J0 (at deploy), J7 (day 7), and J30 (day 30). The J0 score is exactly what a buyer can see at block zero; J7 and J30 are what the contract turns out to be once it has had time to act.
- Cohort: 24,150 tokens that have all three snapshots (deploy + 7d + 30d).
- Same fixed 70+ risk threshold as the earlier posts, held constant across every age.
- All-time table for context: 110,012 analyzed contracts, 60.5% flagged.
- The numbers below are live at
api.rektradar.io(endpoint/v1), recomputed hourly.
The scam rate climbs with time, on the same tokens
Because it is the same 24,150 tokens measured at three ages, this is not a population trick. It is one cohort revealing itself:
| Observation age | Scam rate | What it means |
|---|---|---|
| J0 (at launch) | 48.0% | The decision-time rate. What you can detect at block zero. |
| J7 (day 7) | 76.8% | A week of behaviour later. |
| J30 (day 30) | 90.6% | The matured rate. What the contract turned out to be. |
Scores only move one way here: not a single token went from scam back to clean. Every point of that climb is a contract that looked acceptable at launch and then did something a scam does - pulled liquidity, flipped a transfer gate, went silent. The 76% from the last post was a mixed bag of tokens at every age; let a cohort fully mature and it is 91%, but at the only moment that matters to a buyer, it is 48%.
The gap is late rugs, and it is 43%
Split the cohort by where each token started and ended:
- Clean at launch, scam by day 30: 43% of all tokens.
- Scam at launch and still scam: the rest of the 48%.
- Clean at launch and still clean at day 30: the honest survivors.
So more than four in ten tokens are late rugs - they pass a launch-time check and betray it later. This is the single most important thing for anyone buying fresh pairs: a green result at block zero is a snapshot, not a guarantee. Our own funding-graph and kill-switch detectors exist because the launch-time picture is deliberately incomplete.
”It only matters if they get traded” - so we checked
The most-upvoted reply to the last post argued the scam rate only matters if these tokens get real trading volume. Fair, so here is the volume cut, from the first-week swap counts we store per token:
| First-week activity | Share of flagged scams |
|---|---|
| Never traded (dead junk) | 23.9% |
| Traded at all | 76.1% |
| Heavy (100+ swaps) | 12.3% |
Only 24% of the tokens we flag are dead on arrival. The other 76% got traded. And the contrast is the surprise: among non-scam deploys, 67% never trade at all. Scams are roughly three times more likely to attract volume than legitimate tokens, because they are engineered to - fake momentum, sniper fleets, hype. The volume filter does not make scams look harmless; it makes them look worse.
How we hold the measurement honest
Two methodology questions came up that are worth answering directly, because they are the difference between a real number and a vanity one.
Threshold drift. The risk threshold is fixed at 70 and never moves month to month. When our detector gains a signal, we re-score, but the bar to be called a scam is constant, so a rising rate cannot be an artifact of a moving line.
Observation window. Comparing a fresh cohort against an old one is biased - young tokens have not had time to rug. The J0/J7/J30 design removes that: every token is compared to itself at matched ages, so the 48-to-91 climb is a real change in each contract, not a cohort-age illusion.
Limits of our data
- Scorer-conditional. “Scam” means our multi-flag scorer put the contract at 70+. It has false positives and false negatives like any classifier; these are “share our pipeline flags”, not ground-truth fraud.
- Swap counts include bots. First-week swaps count all trades, including wash and sniper-bot volume. “Traded” is a strong activity signal, not a clean count of human victims - a chunk of that 76% is manufactured demand.
- J0 is a re-scoreable snapshot. The deploy-time score reflects what our detector knew at that pass; a detector that improves later would score some historical J0s differently. We keep the original J0 rather than rewrite it, which is honest but means J0 is our launch-time verdict, not an oracle.
- Cohort selection. This tracks tokens that have all three snapshots, which skews slightly toward contracts that survived long enough to be re-scored at 30 days. Pure flash-rugs that vanish in hours are under-represented here.
TL;DR
- Same 24,150 token launches, tracked from deploy to day 30.
- Scam rate: 48.0% at launch, 76.8% at day 7, 90.6% at day 30 - one cohort, three ages.
- 43% are late rugs: clean at launch, scam within a month. Scores never move the other way.
- 76% of flagged scams got traded (only 24% dead), versus 67% of non-scam deploys that never trade - scams pull ~3x the volume.
- Threshold fixed at 70, tokens compared to themselves at matched ages.
A launch-time check is a snapshot, not a promise. Check any token, and re-check it a week later - free, no signup, no card.