← Research
SEPTEMBER 2026 · BYTECODE ANALYSIS

Rug-pull fingerprints from bytecode

Five documented BSC rug pulls, read from the code actually deployed on-chain rather than the source a project chose to publish. They now power the known-scam matching in our free Contract Reader.

Why bytecode

The Contract Reader compares every contract it checks against a library of real rug pulls. It looks for the same combination of owner powers — mint, pause trading, blacklist, mutable fees, upgradeability, privileged withdrawal, and whether an owner is still in control. The library is only as good as its entries, and our first entry was wrong. The Squid Game token's published source is nearly double the length our source reader handles, so the read was truncated and missed most of what mattered.

Bytecode doesn't have that problem. It's the code that actually runs, it can't be selectively published, and it's the same size whether or not the project verified anything. So we rebuilt the library from it.

Method

  1. Decompile. Each contract's deployed bytecode was decompiled with Ghidra and the open-source Mothra EVM extension. Every function was recovered in all five contracts: 50/50, 27/27, 194/194, 54/54, and 13/13 for Squid's proxy plus 94/94 for its implementation.
  2. Name the functions. Function selectors were pulled from each contract's dispatcher and resolved against public signature databases.
  3. Prove who can call them. A function name is a claim, not evidence. Each privileged function was simulated from a random address and from the real owner, as read-only calls. It had to fail for the first and succeed for the second to count.
  4. Run what can't be simulated. For behaviour that needed real execution, we used a local copy of the chain (a fork running on our own machine) and traced every storage write. No transaction was ever sent to the live network.

What Squid Game was really hiding

The deployed Squid Game token is an upgradeable proxy. Its only function is named approveTo(address), which sounds like an ordinary token approval. It isn't one. The decompiled code checks whether the caller is the proxy admin, then replaces the contract's entire logic and emits the standard Upgraded event. It's an upgrade switch with a harmless name.

The bigger finding is a role that has nothing to do with the owner. A variable called _masterChef holds a plain wallet address, not a contract, and that wallet can call burn(address, uint256) against any holder. On the local fork, it burned the liquidity pool's entire token balance in one call. Two more functions, callable only by that wallet, force the pool to re-sync its reserves. Together they let one wallet wipe out the pool's token side and reprice everything left in it.

Squid Game's ownership was renounced. That's the check most people look at, and here it proved nothing, because the dangerous power was never the owner's.

The five fingerprints

Squid Game (SQUID)Nov 2021 · $3.38M pulled from liquidity

Owner blacklist · disguised upgrade function · hidden wallet that can burn any balance

0x87230146E138d3F296a9a77e497A2A83012e9Bc5
DeFi100 (D100)May 2021 · ~$32M

Owner can pause all transfers, ban wallets, and rebase every balance

0x9d8AAC497A4b8fe697dd63101d793F0C6A6EEbB6
Arbix Finance (ARBX)Jan 2022 · ~$10M

Owner-only mint, used to create and dump 10M tokens before renouncing

0xD20ef93050c0943F74f5F8Ff0CC97c74139d6437
Save The Kids (KIDS)June 2021 · influencer pump-and-dump

Owner-set fees with no upper cap (1000% accepted) and adjustable transaction limits

0x7AcF49997e9598843CB9051389fA755969E551Bb
TurtleDex (TTDX)Feb 2021 · ~$2.5M

Owner can mint and pause transfers — the token is still paused today

0xc4957a864245AA4373Be1f33ae24E93876b7Dfe1

Each fingerprint records whether an owner was in control at the time of the rug, not today. Several of these owners renounced afterwards, but the Contract Reader checks live contracts before anything goes wrong, so rug-time state is what has to match.

What a match means — and doesn't

A match means a contract gives its owner the same combination of powers one of these rugs had. It does not mean the code is the same, or that the owner will use those powers. Plenty of legitimate projects keep an owner who can mint. We tested the matching before it went live: a contract whose only flag is an active owner, and a stablecoin-style profile with mint, pause, blacklist and upgrade powers, both stay below the match threshold.

The reverse holds too: no match is not a clean bill of health. It only means the contract doesn't look like these five.

Limits

Squid Game's implementation contains 22 functions that no public signature database can name. We probed all of them on the fork. None changed total supply or credited a target wallet, but we only tried one argument shape, so we score its trading-halt and fee powers as undetermined rather than guessing. The known-scam library is small by design: every entry has to be backed by this kind of evidence before it goes in.

Check a token yourself

Paste any contract address into the free Contract Reader to see its owner powers and whether it matches a known rug pull.

Open the Contract Reader