Skip to main content
Risk Modeling, Compliance Architecture & Regulation8 Min Read

Red-Flag Taxonomy: A Quantitative Framework for Scoring Crypto Presale Risk Signals

Red-Flag Taxonomy: A Quantitative Framework for Scoring Crypto Presale Risk Signals

Between January 2021 and March 2022, more than 46,000 consumers reported losing over $1 billion to cryptocurrency scams, according to a report by the Federal Trade Commission based on voluntary consumer complaint data. Presales are one high-risk area within the broader crypto-scam landscape because buyers often commit funds before a project has a functioning product, public trading history, verified liquidity, or an independently testable operating record.

This article provides a simple screening framework for identifying presale risk before capital is committed. It adapts broader crypto due-diligence principles into a checklist that non-technical readers can apply.

The weights below are screening heuristics, not statistically validated fraud probabilities. They are designed to standardize review, not predict with certainty whether a project is fraudulent. Let's walk through five core categories of red flags, see how you can score each one, and then run two real case studies through the checklist to see how it applies in practice.

What Is a Presale, Exactly?

A presale is when a crypto project sells its tokens to buyers before the token is available on any public exchange. The idea is that early buyers get a lower price in exchange for taking on more risk, since the project hasn't launched yet and has nothing proven.

That's a legitimate structure when done properly. It's also the exact structure scammers prefer, because it lets them collect real money from a large number of people before anyone can verify whether the project actually works, or whether it exists at all beyond a webpage.

The Five Categories That Matter Most

Not every red flag carries equal weight. Some are genuinely disqualifying on their own. Others are only concerning when they show up alongside other flags. This checklist assigns points to five categories, and adds them up into a single risk score at the end.

  1. Anonymous Team and Lack of Legal Accountability (up to 25 points)

Who is actually running this project? A complete answer requires both named individuals and a verifiable legal entity (such as a registered company, clear jurisdiction, and traceable corporate address). An anonymous or pseudonymous team isn't automatically a scam some legitimate developers use pseudonyms for privacy but it removes personal accountability. Conversely, a public profile alone is not foolproof, as fabricated identities and fake social profiles are common.

  • Public identities with verified history, registered legal entity, and corporate records: 0 points
  • Pseudonymous team with a long, independently verifiable track record: 5 points
  • Partial identities, weak verification, or unverified corporate structure: 12 points
  • Fabricated identities, no verifiable legal entity, or fully anonymous team: 25 points

  1. Unaudited or Inadequately Audited Contract (up to 20 points)

An audit is a technical security review of a smart contract's code conducted by an independent firm to check for bugs and code vulnerabilities. However, an audit is strictly a technical review it does not guarantee team honesty, legal compliance, or protection against operational risk. Furthermore, a report with unresolved critical findings can be riskier than no audit at all.

  • Full report from a recognized firm, material findings resolved, and deployed bytecode matched: 0 points
  • Limited scope audit, outdated report, or unclear deployment match: 8 points
  • Audit report exists, but material or critical security findings remain unresolved: 15 points
  • No credible report, unverified claims, or unreleased source code: 20 points
  1. Unverifiable Claims and Unrealistic Promises (up to 20 points)

This covers unverified partnership logos, fabricated team backgrounds, unrealistic product roadmaps, or false media endorsements.

  • Claims are specific, modest, and independently verifiable: 0 points
  • Some vague or unconfirmed claims mixed with reasonable milestones: 10 points
  • Unverifiable major partnerships, copied whitepapers, or fabricated credentials: 20 points

The FTC warns that promises of guaranteed or fast profits are a common crypto-scam indicator. Promises of fixed returns or guaranteed profits should be treated as an automatic severe risk signal.

  1. Manipulative Promotion and Incentives (up to 15 points)

Not every countdown timer or early-bird pricing tier is fraudulent; these can be standard promotional mechanics. The risk arises when marketing uses artificial urgency, fake scarcity, or multi-level referral commissions funded purely by new buyer deposits to discourage proper due diligence.

  • Transparent pricing, clear allocation terms, and no pressure tactics: 0 points
  • Moderate bonus tiers or standard time-limited promotional pricing: 8 points
  • Constantly resetting timers, aggressive recruitment pressure, or multi-level commission payouts: 15 points
  1. Unprotected Liquidity and Presale Fund Custody (up to 20 points)

Liquidity locks prevent developers from immediately draining trading pools post-launch, which has historically contributed to a large share of documented rug pulls. However, a basic lock alone does not ensure safety if the team retains unrestricted minting rights, high transfer taxes, or control over presale contributions before launch. A basic check is quick, but validating the full liquidity and fund custody structure requires reviewing the pool, LP token ownership, and contract permissions.

  • Presale funds managed via multi-sig/escrow; post-launch liquidity materially locked or burned with transparent terms and restricted admin privileges: 0–5 points
  • Partial, short-term, or vague liquidity lock with unverified presale fund custody: 10 points
  • No credible liquidity lock, team-controlled LP tokens, or unconstrained owner withdrawal permissions on presale deposits: 20 points

Hard-Stop Override Rules: Certain critical findings should bypass numerical scoring and immediately flag a project for Severe Risk Review. These include: code that prevents token selling, owner permissions to mint unlimited tokens or pause trading arbitrarily, fake audit claims, guaranteed fixed returns, or unconstrained developer access to presale deposits.

Scoring the Total

  • Total Score: 0 to 20 Risk Level: Low Observed Risk What It Means: Fewer observed red flags; full due diligence still required.
  • Total Score: 21 to 45 Risk Level: Moderate Risk What It Means: Material concerns requiring independent verification before proceeding.
  • Total Score: 46 to 70 Risk Level: High Risk What It Means: Multiple serious concerns; elevated loss and operational risk.
  • Total Score: 71 to 100 Risk Level: Severe Risk What It Means: Severe warning profile; do not rely on the offering without independent professional review.

Note: If key project details (such as source code, legal identity, or tokenomics) are missing or unpublished, mark the result as Insufficient Evidence rather than assigning a passing score.

Running the Checklist Against Two Real Cases

The examples below illustrate how to apply the screening checklist to real-world events. They demonstrate how risk signals manifest in practice, though historical application does not validate predictive accuracy for future projects.

Case One - SQUID Token (October 2021)

SQUID launched riding on the popularity of the Netflix series without official authorization. The team was anonymous, there was no independent audit, and whitepaper promises were unverifiable. While CoinGecko's breakdown of the case notes the absence of audits and vague documentation, the primary issue was an anti-dump mechanism embedded in the smart contract that restricted ordinary buyers from selling.

Within days of trading, the price spiked dramatically before the creators drained the pooled funds, resulting in an estimated $3.3 million extracted by the developers.

Under this checklist, SQUID demonstrates an anonymous team (25), no verifiable audit (20), unverifiable claims (20), aggressive promotion (15), and unconstrained liquidity/sell controls (20), totaling a Severe Risk score of 100/100. Furthermore, its sell-restriction code would have triggered an automatic Hard-Stop Override.

Case Two - Frosties NFT (January 2022)

Frosties involved an NFT presale rather than a fungible token presale. Two anonymous operators raised approximately $1.1 million to $1.3 million by promising community giveaways and future game development before abandoning the project. The U.S. Department of Justice charged the individuals with wire fraud and money laundering.

NFT presales differ from fungible token sales because DEX liquidity locks do not apply in the same manner. Adapting the framework requires focusing on team verification (25), unverifiable utility claims (20), aggressive promotional tactics (15), and lack of fund custody or escrow (20). This yields an adjusted score of 80/80 across applicable categories, highlighting how screening principles must be tailored when evaluating non-fungible token offerings.

What These Cases Demonstrate

Several material warning signs were publicly observable before or during these sales. While risk factors vary and no framework captures every scam variation, systematic screening helps highlight unverified claims and restrictive contract mechanics before capital is committed.

Bottom Line

Running a new project through the five core categories team accountability, contract audits, claim verification, promotional tactics, and liquidity/custody controls provides a structured framework for evaluating presale risk. While no screening tool provides guarantees, identifying elevated risk profiles helps investors avoid unmitigated exposures.

Frequently Asked Questions

What's the difference between a rug pull and a project that fails honestly?

A rug pull generally refers to project insiders abruptly withdrawing liquidity, abandoning the project, or exploiting privileged contract permissions to harm token holders. Establishing legal criminal intent requires formal evidence and legal process. By contrast, an honest failure occurs when a team attempts to deliver on its roadmap but fails due to market conditions, technical obstacles, or insufficient funding.

I already bought into a presale, and I'm now noticing red flags. What should I do?

Stop committing additional funds, preserve relevant transaction and communication records, and review the current contract and liquidity status using independent blockchain explorers. Report suspected fraudulent activity to relevant financial regulators, law enforcement agencies, and platform providers in your jurisdiction. Be extremely cautious of recovery scams: do not pay anyone who promises guaranteed recovery of lost cryptocurrency.

Does a project scoring moderately on this checklist mean it's definitely a scam?

No. A moderate score indicates that evidence is incomplete or that material risk signals are present. It serves as a prompt for deeper verification rather than an immediate determination of fraud. Reassess the project only when independently verifiable information changes.

Disclaimer: This article is for educational purposes only and is not financial, legal, investment, or tax advice. This checklist is a risk-assessment tool, not a guarantee that a project scoring low is safe or that one scoring high is fraudulent. Always do your own research and consider speaking with a licensed financial advisor before investing.

Get Pre-IPO Insights Weekly

Join 5,000+ investors getting exclusive deal alerts.

Key Terms to Know

New to investing? Explore our glossary for more terms.

Related Articles

More from IPO Genie

Buy Now