Methodology
CheckCrypto does not assess a coin's value or price. It estimates only the "likelihood of being a scam," based on verifiable on-chain and off-chain indicators. For the detailed numbers, see why we don't disclose them.
Methodology
Below are the details of the current assessment system. Detailed numbers such as per-signal weights, decision thresholds, and the combination formula are not disclosed — see 'why we don't disclose the exact numbers'.
What we show
- Scam-risk grade (A–F) + estimated scam probability (%) — A = low risk, F = avoid
- Coin type (stablecoin / wrapped / derivative / meme / general) — the assessment criteria differ by type
- Decisive facts · risk signals · positive signals (Green Flags) — with an explanation of why each signal is risky/safe
Two-tier assessment system
① Decisive facts (Hard Facts) — on-chain facts anyone can reproduce and verify, such as a honeypot (sell block), owner balance changes, self-destruct, or extreme trading tax. If even one is found, the risk grade is strongly downgraded regardless of other signals. This is not a value judgment that the coin is "bad," but a report on the existence of a capability that can seize funds.
② Risk signals (Soft Signals) — circumstances that are not decisive on their own but correlate with fraud patterns. Several signals are weighted and combined into an estimated probability. The design prevents overlapping signals from adding up without limit.
③ Confirmed scam records (Confirmed Records) — tokens whose rug pull or sell-block execution is publicly confirmed (e.g. court ruling, major press coverage, directly observed conversion to sell-blocking) are kept as separate confirmed records and shown at risk 100% with a ☠ confirmed-scam badge, regardless of current on-chain indicators. This is because a token whose rug is already over may look quiet on current indicators. Each record's verdict source, confirmation time, basis, and evidence links are published as-is on the detail page, and if you dispute a record you can let us know via the dispute page. These records are for display only; for machine-learning training we use only labels individually approved by the operator during a review process.
What we inspect
- Contract mechanics: sell-block (honeypot) simulation, additional minting, ownership state / revocability, balance changes, self-destruct, blacklist, transfer pause, trading tax and its changeability, proxy upgradeability, source-code verification status
- Liquidity / finance: LP lock status, liquidity size, trading-pair freshness
- Holder distribution: concentration among few wallets (excluding locked supply; burned supply is excluded on EVM chains), creator holding ratio
- Deployer history: whether the same wallet previously deployed a confirmed scam token (serial deployer)
- Identity: whether a famous coin's symbol is impersonated (checked against the legitimate contract)
- Development activity: GitHub commits and stars (only measured positive evidence is reflected)
- Social: Twitter / Telegram size
- Whitepaper: fraudulent phrasing such as 'guaranteed profit / principal protection', thin content
Assessment by coin type
Judging every coin by one yardstick produces false positives. So we classify the token first and lower the impact of signals that are normal by design per type. For example, wrapped / stablecoin / derivative tokens normally have additional minting and concentration among few wallets, so we don't penalize them heavily. This mitigation applies only to tokens confirmed via a legitimate-contract whitelist or independent listing — an unverified token merely named like "OO Vault" is subject to full inspection, and a token impersonating a famous coin's symbol is caught as a separate risk signal.
Omnichain tokens — the same coin on multiple chains
Some coins, like AAVE and USDC, exist as the same coin on multiple chains, each with a different address (omnichain tokens). CheckCrypto confirms the identity of such tokens and groups them together — the "🔗 Omnichain identity confirmed" panel on the detail page shows the per-chain instances at a glance.
Why it matters — not grouping them causes misjudgment in two directions: ① one chain's instance of a legitimate coin may look risky merely because liquidity is thin on that chain, or ② conversely a fake token can pose as a famous coin with weak grounds to tell them apart.
How we confirm it — the standard is unforgeability: we require cryptographic on-chain proof that it is the same identity across chains, corroborated by human review (we do not auto-confirm from third-party data alone). We never group by name or symbol alone — that would become a channel for impersonation tokens to receive legitimate treatment.
Even when grouped, risk is assessed per chain — so that problems arising on only one chain within a genuine group (liquidity evaporation, etc.) are not missed.
Positive signals (Green Flags)
We also show verifiable positive facts such as ownership renounce, LP lock, source-code verification, minting disabled, and mention of a third-party audit. To avoid double-counting with the absence of risk signals, these are not reflected in the score but provided as material for a balanced judgment.
⚠ Being "listed" is not being vetted. A signal saying a coin appears on a data service or listing only means a profile exists there — not that anyone reviewed or approved the project, and not evidence of safety. Widely listed coins have collapsed before. Every positive signal is a statement of fact, never a guarantee.
What the grades mean
- A · B — no known risk signals, or minor ones. (This is not a guarantee of safety.)
- C — caution. Circumstantial signals have accumulated and direct verification is needed.
- D — high risk. Overlaps with many fraud patterns.
- F — highest risk band. A decisive fact was confirmed, or risk signals are overwhelming.
Data sources
- On-chain contract security — honeypot, minting, ownership, tax, holders
- Liquidity / trading pairs
- Development / social metrics and the coin universe
- Web reputation / whitepaper — only when viewing a detail page
Each of these currently comes from one provider per item — we will not claim we blend several. Exactly one item — whether the token can be sold (honeypot) — is cross-checked against a second, independent source, and that comparison (agreement or disagreement) is published in the second-source cross-check box on the detail page. Depending on one source means that when it is wrong we can be wrong too, which is also why we do not interpret missing data as safe — or as guilty (absence ≠ innocent, absence ≠ guilty).
Web reputation is "for reference"
Web search cannot distinguish "Is X a scam? (no)" from "X is a scam," so its false-positive rate is high. Therefore scam suspicions and incidents are not reflected in the score and are provided only as "needs verification" information with source links. Only whitepaper fraud phrasing confirmed as fact is reflected in the score.
Current stage of the score
The current public score is an expert rule-based uncalibrated estimate. We are separately training and validating a machine-learning model internally, but we do not reflect it in the public score until its performance is proven with real outcome data. We will announce it on this page when we make the switch.
Limits of the score — what it catches, what it can't
Honestly stated: our strength is catching reproducible risks built into the contract, and fraud carried out later through human behavior is hard to predict in advance.
What a low risk % (high grade) does not guarantee
- A future rug pull — even if liquidity is locked now, it can be pulled after the lock expires.
- Off-chain fraud — schemes like profit promises or Ponzi structures, where money moves off the blockchain, are invisible to on-chain inspection.
- Insider action with no on-chain trace — team dumping or a social exit (disappearing) come with no advance signal.
- Regulatory / exchange risk — external events like delisting or legal action are not within the score's scope.
- Changes after assessment — the score is an observation at the time of assessment. As long as contract authority is alive, the state can change.
| Types we catch well | Types that are structurally hard |
|---|---|
| Sell block (honeypot) — verified by simulation | Slow rug — gradual liquidity withdrawal over a long period |
| Owner-authority abuse (unlimited minting, balance changes, freezing trades) | Mass dumping by team / influencers (hard to distinguish from normal selling) |
| Extreme / changeable trading tax | Off-chain Ponzi / profit promises (money circulates externally) |
| Pre-rug risks such as unlocked liquidity and few-wallet dominance | Social exit (operators disappear) — no on-chain signal |
| Famous-coin symbol impersonation, unverified source code | Planned fraud that only reveals itself at a future point |
So we are a "probability estimate," not a "verdict," and the absence of risk signals does not guarantee safety. Many of the right-hand types are recorded and learned after the fact once real incidents are observed over time (data accumulation).
Independence pledge
We do not accept listing fees, advertising fees, or requests to adjust scores. No project can change its score, grade, or exposure with money. If this principle is ever broken, we will disclose it on this page.
How we validate our own verdicts
We don't stop at producing a score — we keep observing what actually happened after a verdict and score ourselves: ① we re-observe inspected tokens and record real outcomes such as conversion to a rug or honeypot, ② we continuously re-audit confirmed verdicts and, if a false positive is confirmed, retract or correct it (with a correction history), and ③ we will compile and publish a verdict scorecard (hits / false positives) by pre-registered criteria (August 2026). The machine-learning score is applied to the public score only when it passes this validation.
Incident chronology — what our signals turned on
The relationship between past confirmed incidents and our signals. Incidents observed since we began collecting are actual measurements from stored assessment records, while earlier historical incidents are estimates of "the signals that would have fired under today's data standard." We keep the two separate and do not mix them.
- 2018-01 — BitConnect: collapsed (1/16) 12 days after the Texas emergency order (1/4). Estimate (pre-collection incident): whitepaper 'guaranteed profit' phrasing and Ponzi structure — under today's standard the fraud-phrasing signal would fire. Can be cross-checked against the confirmed record in Coin lookup.
- 2021-11 — SQUID (Squid Game token): sell block + liquidity-withdrawal rug. We hold a confirmed record — the sell-block structure is a type caught by simulation. View record
- 2022-05 — Terra LUNA/UST: algorithmic stablecoin collapse. We hold a confirmed record (an incident under legal proceedings) — we also note that structural risk is a type hard to confirm in advance from on-chain signals alone (consistent with our limits statement).
- 2019~2023 — Domestic incidents: Coinup, Ado (finalized at the Supreme Court), Furiever. Recorded in the confirmed-scam archive based on court / press evidence — many are off-chain profit-promise types (our score's limit type), so they are caught by record matching on a name search.
- 2026-07 — Self-observed confirmations (post-collection measurements): Honeypot conversion and liquidity evaporation captured by re-observation and confirmed after human review — e.g. VITBULL (sell block observed live). The full record is in the confirmed-scam filter.
This chronology is a factual record, not material for investment decisions. Incidents that would not have fired are not listed; instead they are recorded as types in 'Limits of the score' above.
Why we don't disclose the exact numbers
We disclose which items are inspected, as above, but we do not disclose the per-signal weights, decision thresholds, or combination formula. If the exact boundaries were known, scam creators could design tokens "just under the threshold" to evade detection (e.g. raising tax only up to just before the decision line). Instead, every assessment result discloses which signals were found and what the basis was, with sources, so the judgment process can be verified even without the numbers.
Automated collection & community
Every hour we automatically inspect collectible coins and stack them by risk on the list. Community votes are for reference and are not reflected in the score.
Beware of symbol theft
A coin's true identity is its contract address. Names and symbols (e.g. "WBNB", "USDT") can be copied by anyone, so separate contracts impersonating famous coins exist.
Disclaimer
These results are uncalibrated estimates and not investment advice. Assessments are as of the time shown, and coin states change frequently. Risks outside the inspected items are not detected, and "no risk signals" does not guarantee safety. False positives and correction requests are accepted via the contact channel.