What to do if you have been rugged
The Editor·12 min read·Updated 31 Aug 2026
What to do after a rug pull: contain the damage, preserve evidence, and report it through the right channels. Why recovery is unlikely and who preys on victims.
Recovery is unlikely, and anyone who tells you otherwise is probably running the second scam. What is worth doing, in order and quickly: contain the damage in the wallet, preserve the evidence before it disappears, and report through the real channels. Speed is the only variable that reliably changes outcomes, and it still usually changes nothing.
Jurisdiction: United States, with a note on other jurisdictions below. Last reviewed 31 August 2026. This is general information about a fast-moving area of law, not legal or tax advice — consult a qualified attorney or accountant about your own facts.
Start with the honest picture
Most rug pulls produce no recovery at all. Deployers are frequently anonymous or offshore, self-custody means there is no intermediary holding the funds who can reverse anything, and on-chain settlement is final by design. There is no chargeback, no deposit insurance, no ombudsman, and no regulator who will make you whole.
Meaningful outcomes have come almost exclusively where two things were true at once: the perpetrator was identifiable and within reach of a US or allied court, and assets were traced and frozen fast. That is a narrow gate, and it is not the situation most people are in.
Knowing that changes what the next hour should be spent on. It is not spent chasing recovery. It is spent stopping the loss getting larger, building a record while it still exists, and putting the report into the systems that occasionally aggregate enough reports to matter.
The first hour: contain the wallet
Stop signing. Do not sign anything else from that wallet, including transactions that appear to be attempts to rescue funds. Some drainers monitor a compromised wallet and sweep any incoming gas, which means funding it to "move the rest out" simply donates the gas.
Work out which failure this was, because the response differs. If the loss came from a token approval you granted to a contract or a site, the wallet's private key is intact and revoking the outstanding allowances is the correct action — cutting off standing token permissions covers how, per chain. If the loss came from a leaked seed phrase or private key, revoking is pointless: the attacker can sign as you. In that case move everything of value to a wallet generated on a clean device, treat the compromised address as permanently unsafe, and never fund it again.
Check your other exposure. The same address usually carries independent allowance sets on every chain it has traded on, and people commonly reuse a seed across several accounts in one wallet. Check every chain and every derived account, not just the one where the loss appeared. If you used the same seed phrase anywhere else, it is compromised everywhere.
If a hardware wallet signed the malicious transaction, the device is not the problem. The device did what you approved. The fix is a review of what you sign, not new hardware.
Preserve the evidence before it disappears
Do this before you post about it, before you contact anyone, and before the project's channels are deleted — which typically happens within hours.
Record the transaction hashes for every relevant transfer, the token's contract address and chain, your own wallet addresses, the counterparty addresses funds moved to, and precise timestamps in UTC. Capture the amounts both in tokens and in the fiat value at the time, since a claim quantified later at a different price is a weaker claim.
Then capture the off-chain side, which is the part that vanishes. Screenshot the project's website, its social accounts, the specific posts that induced the purchase, any Telegram or Discord messages including your own, and any claim made about audits, locks, team identities or partnerships. Where possible, submit the URLs to a public web archive so there is a third-party record with a timestamp rather than an image file on your machine. Save the full page, not a crop, and keep the URL visible in the capture.
If the loss came through a cloned front-end rather than the token itself, record the exact domain you visited, including how you reached it — a search ad, a link in a post, a message. How drainer sites are distributed explains why that detail matters to investigators looking for a campaign rather than a single victim.
Where to report it
Reporting will probably not return your money. It is still worth an hour, because aggregated reports are how patterns get identified and how an actor who touches a US-reachable entity eventually gets pursued.
| Channel | What it is | Why it matters here |
|---|---|---|
| IC3.gov | The FBI's Internet Crime Complaint Center | The primary federal intake for fraud with an online component. This is the first report to file, and the one law enforcement most often works from |
| CFTC complaint | Commodity Futures Trading Commission tip and complaint portal | Non-security crypto assets, memecoins included, sit on the commodity side for anti-fraud and anti-manipulation purposes. The CFTC has enforcement authority over fraud in commodity spot markets even without comprehensive spot regulation |
| SEC TCR | Tips, Complaints and Referrals system | Applies where the token's facts make it a security, or where the promotion suggests it was. Worth filing even if classification is contested — the SEC decides, not you |
| FTC | ReportFraud.ftc.gov | Consumer fraud intake. Broad, low-friction, and feeds a database shared with law enforcement |
| State attorney general | Your state's consumer protection division | State consumer protection statutes apply independently of any federal position, and state AGs have been active on crypto fraud |
| State securities regulator | Your state's blue sky administrator | State securities law is not bound by federal classification. New York's Martin Act is notably broad and does not require proof of intent to deceive |
File all of them where the loss is material. They are separate systems that do not share intake, and each has a different trigger for acting.
If the amount is large, speak to counsel about civil options immediately rather than after the reports. The one widely cited example of real money being recovered came from emergency civil process: in the LIBRA litigation, a class action filed in the Southern District of New York pleading fraud, RICO, conspiracy and unjust enrichment resulted in roughly $110M being frozen, with the court denying a motion to unfreeze. That freeze came from a private civil action moving fast, not from a criminal prosecution — no US criminal charges in that matter have been confirmed. It is the outlier that proves the rule about speed, and it required identifiable defendants and traceable assets.
Outside the United States, the channels differ and so does the underlying law. Report to your national cybercrime reporting service and your financial conduct or securities regulator. Note that regulatory coverage is often narrower than people assume: in the UK, for instance, the FCA's final crypto rules were published on 30 June 2026 but the mandatory regime does not come into force until 25 October 2027, and until then FCA oversight of crypto is limited to financial promotions and anti-money-laundering. Memecoins there carry no FSCS protection and no Financial Ombudsman access.
The second scam: people who target rug victims
This is the part that does more additional damage than anything else in this article, and it starts almost immediately.
Within hours of posting publicly about a loss, you will be contacted. The approaches are consistent: a "blockchain recovery specialist" or "certified crypto investigator," a firm with a professional-looking site and fabricated case studies, a fake law firm, a "white hat" claiming to have already located your funds, or an account impersonating support for your wallet or the exchange you used. Some pose as regulators or as law enforcement following up on a report you actually filed — which is why filing through official portals and keeping the reference numbers matters.
The rules are absolute:
Never pay an upfront fee. Every advance-fee variant ends the same way, with new fees appearing after each payment — taxes, gas, unlocking costs, an escrow deposit — until you stop paying.
Never share a seed phrase or private key with anyone, for any reason. No legitimate recovery process, no regulator and no wallet support team ever needs it. A request for it is definitionally a theft attempt.
Never grant a wallet connection or signature to a "recovery" tool. The typical result is that whatever survived the first loss goes in the second.
Do not trust an unsolicited approach, ever, including one that correctly cites details of your loss. Those details are public — your transactions are on a block explorer, and so is your post about them. Knowing your loss is evidence of nothing.
Legitimate blockchain analytics firms exist and work for law enforcement, exchanges and litigants. They do not cold-DM individuals. If you engage professional help, initiate the contact yourself, through a licensed attorney you found independently, and expect the honest advice to be that the prospects are poor.
Report the recovery approach as well. It is a separate offence against a victim who has already been identified as vulnerable, and the pattern is what investigators are looking for.
Was it a rug at all, and does it change anything?
Legally, there is no offence called a rug pull. Conduct is prosecuted as ordinary fraud: wire fraud is the workhorse, with commodities fraud and the CFTC's anti-fraud authority also in play, alongside state consumer protection and blue sky provisions and private civil claims. Every one of those theories needs a misrepresentation or a deceptive act.
That is why the distinction between an abandoned token and a drained one matters to your report. A hard rug — liquidity pulled, supply minted and sold, a tax raised so sells fail — usually leaves a specific transaction and often a specific false claim next to it. A soft rug, where the team stopped working and quietly sold, frequently supplies neither, and "they gave up and sold their own tokens" is not by itself unlawful.
Federal enforcement posture supports the distinction: the Department of Justice narrowed its crypto focus in April 2025 away from registration-based offences, while explicitly retaining fraud against victims as the priority. That means an actual, documented misrepresentation is the strongest thing you can put in front of a prosecutor. Note also that classification is contested territory — what the SEC has actually said about memecoins covers why an agency statement is not law and why private plaintiffs continue to plead securities claims regardless.
The tax question
A memecoin that lost most of its value produces no deduction while you still hold it, and the US position on worthlessness is stricter than people expect — an asset still trading at a fraction of a cent is generally not "worthless" for tax purposes. The mechanics, including why disposal rather than abandonment is usually the operative step and why an individual investor's theft-loss theory is genuinely unsettled, are in whether a worthless or rugged memecoin is deductible. Get that specific fact pattern reviewed by a CPA before filing anything.
What this doesn't tell you
It does not tell you that you will get your money back, because in most cases you will not, and no article that says otherwise is being honest with you.
It also cannot tell you whether your particular facts support a claim. Whether a token was a security, whether a statement was a misrepresentation, whether a loss is a capital loss or a theft loss, and whether a civil action is worth its cost are all fact-specific and jurisdiction-specific questions for a professional who has seen your documents.
Finally, the reporting channels above are US-centric, current as of 31 August 2026, and subject to change — this area moved substantially through 2026. Check each agency's own site before filing rather than relying on a summary.
Going forward, the practical defences are the boring ones: a separate wallet for launch-day activity, periodic approval revocation, and checking each token's contract and safety report before buying rather than after. Meme Central publishes a per-chain safety report on each token page in its live launch feed, covering tokens indexed by Meme Central rather than the whole market.
Frequently asked questions
Can you get your money back after a rug pull?
Usually not. Anonymous deployers, offshore actors, self-custody and irreversible settlement mean most rug pulls produce no recovery. The exceptions involve identifiable defendants within reach of a court and assets frozen quickly — the roughly $110M frozen in the LIBRA litigation came from emergency civil process. Treat recovery as unlikely and act accordingly.
Where do I report a memecoin scam in the US?
File with IC3.gov first, then the CFTC complaint portal, the SEC's Tips, Complaints and Referrals system, and the FTC at ReportFraud.ftc.gov. Also file with your state attorney general's consumer protection division and your state securities regulator, since state law applies independently of any federal position. They are separate intakes.
Should I hire a crypto recovery service?
No, not one that contacts you. Unsolicited recovery offers targeting rug victims are a standard follow-on scam: advance fees, escalating "unlocking" costs, requests for seed phrases, or a wallet connection that takes what is left. If you seek help, initiate it yourself through an attorney you found independently, and expect a realistic assessment.
Does revoking approvals help after I have already been drained?
Only if the loss came from an approval rather than a compromised key, and only for what remains. Revoking does not reverse a completed transfer. If your seed phrase leaked, revocation is useless because the attacker can sign as you — move everything to a new wallet created on a clean device instead.
Is a soft rug reportable?
You can report it, but expect less traction. Fraud theories need a misrepresentation or deceptive act. A team abandoning a project and selling its own allocation may involve neither, whereas a false claim about a lock, an audit, a partnership or a team identity is exactly the evidence that makes a report actionable. Report the claim, not the disappointment.
The check that would have answered one of these questions in advance
Nothing here undoes a loss. What it does suggest is which claims are worth verifying before money moves, and a liquidity lock is one of the few that a stranger can confirm without trusting anyone. Team Finance liquidity locking — built by TrustSwap, which also builds Meme Central — locks LP tokens for a fixed term on Ethereum, Robinhood Chain, Polygon, Base and BNB, and shows as a verified badge on that token's page in the Meme Central feed. It rules out one failure mode. It would not have stopped most of what is described above.
Nothing here is financial, legal or tax advice. Memecoins are extremely high-risk: most lose most of their value, and the majority of tokens launched never reach a decentralised exchange at all. Never spend money you cannot afford to lose entirely. Meme Central does not recommend any specific token. Data described as Meme Central's own reflects tokens indexed by Meme Central and is not whole-market data.
This article is general information about a fast-moving area of law and was last reviewed on 31 August 2026. It is not legal or tax advice, rules differ materially by jurisdiction, and your facts matter. Consult a qualified attorney or accountant before acting.