Skip to content
Risks & Security

Honeypot

Honeypot Contract

Malicious contract that traps user funds with hidden withdrawal restrictions

Definition

A honeypot is a token contract engineered so that buying works and selling does not. The trap lives in the transfer logic: a hidden blacklist, a sell path that only whitelisted addresses can take, a sell tax the owner can raise to 99% after launch, or a modifier that silently reverts any transfer to the pool. Because nobody can sell, the chart only goes up, which is exactly the bait. Many honeypots are deployed from a verified, clean-looking source with the trap hidden in an inherited contract, a proxy implementation the owner can swap, or an innocuous-sounding variable. The result is not a risky trade, it is a one-way door, and there is no recovery once the funds are in.

A honeypot is a token you can buy but cannot sell. The contract blocks the exit, so the chart looks perfect right up until you try to leave.

Example

A token launches with a 2% buy tax and a 2% sell tax, source verified on the explorer, liquidity seemingly locked. The sell tax is stored in a variable the owner can update with no cap and no timelock. Buyers pile in over two days, the chart triples, and then a single owner transaction raises the sell tax to 99%. Anyone who now sells $10,000 of the token receives $100. The owner drains the tax wallet and the liquidity, and the contract keeps 'working' the whole time.

1

How it works

The trap sits in the transfer function or in an owner-controlled parameter: a blacklist, a whitelist-only sell path, an uncapped sell tax, or a proxy whose implementation can be swapped. Buys succeed, sells revert or return dust.

2

Why it matters

It is one of the few DeFi losses that is total and immediate rather than probabilistic. No liquidation to watch, no unwind, no partial exit: the money is gone the moment it goes in.

3

What to check

Simulate a sell before you buy. Look for owner-settable taxes with no cap, blacklists, pause functions and upgradeable proxies. Confirm that other holders have actually sold. Revoke stale approvals regularly.

Risks to Consider

  • The price chart of a honeypot looks better than a legitimate token precisely because no sell pressure exists
  • Sell simulators can be evaded: some contracts allow sells until a block number, a holder count, or a liquidity threshold is reached
  • A verified contract only means the source matches the bytecode, not that the source is safe; upgradeable proxies can turn safe into hostile after launch
  • Any approval you granted to the token or its router stays live and can be used later, so funds are at risk even after you stop trading it

Common Questions

How do I check a token before buying?

Simulate a sell, do not just simulate a buy: tools such as honeypot.is or Token Sniffer will attempt both against a forked chain. Then read the contract yourself for owner-settable taxes, blacklists and pause functions, check whether it is behind an upgradeable proxy, and look at the holder list for wallets that have successfully sold. A token where every transaction is a buy and none is a sell is the clearest signal there is.

Can a token become a honeypot after launch?

Yes, and that is the common case now. An owner-settable fee with no cap, an upgradeable proxy, or a pause function are all enough to flip a normal token into a trap in one transaction. This is why 'I already sold once, so it is fine' is not evidence of anything. Check who holds the owner key and whether privileged functions sit behind a timelock or a multisig.

If I am stuck in a honeypot, can I get my money back?

No. The contract is behaving exactly as written and there is no counterparty obliged to make you whole. The only useful actions are defensive: revoke every approval you granted to the token and its router so nothing else can be drained, and stop sending gas after the loss. Treat the amount as gone.