Skip to main content

What is a honeypot scam?

Learn what a honeypot scam is, how it typically plays out, and how Token Audit and a few safety habits can help you avoid getting stuck holding a token you can't sell.

A honeypot is a malicious smart contract built to look like a normal token, but coded so you can buy in without ever being able to sell or withdraw. The token might be marketed as the next big opportunity, but underneath, the code is rigged so users get stuck holding an asset they can't move.

How does a honeypot scam work?

Most honeypot scams follow the same basic cycle.

  1. Scammers create a new token and promote it heavily on social platforms, often with fake ads and hype campaigns.

  2. They inject liquidity and generate fake trading activity to make the token look popular. As more users buy in and the price rises, fear of missing out (FOMO) pulls in even more buyers.

  3. Once enough users have bought in, the trap closes. Sell attempts fail or get blocked, since the scammers have coded the contract to restrict selling, pumped the price using manipulated trades, or drained the liquidity behind the scenes. They disappear with the money while users are left holding tokens they can't sell.

  4. The cycle starts again with a new token targeting a new group of users.

Staying safe with Token Audit

Binance.US Wallet includes Token Audit, a feature that flags risky or malicious tokens before you interact with them.

To find it, tap the token you're checking on the app's homepage or market pages. You'll see an Audit tab below the token's name and address. Tapping it shows any flagged risks, such as suspicious exchange rates, contract irregularities, or other signs that a token could put your assets at risk.

Token Audit is a tool to support your own research and doesn't guarantee a token is safe to buy or sell. Always do your own research before interacting with any token.

Best practices to avoid honeypot scams

Before you interact with any new token, do your own research (DYOR). Don't rely on hype or a recommendation alone, check whether the contract code is verified on a reputable blockchain explorer, and if you're comfortable reading code, look for functions that restrict selling or charge unusually high fees. Review the token's trading history for warning signs, like a lack of sell transactions, supply concentrated in a small number of wallets, or liquidity that developers have suddenly pulled out. You can also run the contract through a reputable security tool built to catch common vulnerabilities before you buy in.

Checking a token before you buy takes a few extra minutes. Getting stuck holding one you can't sell costs a lot more.

Did this answer your question?