A million Meteora pools, most emptied within the hour
More than a million trading pools for new coins opened on one Solana exchange in eight months. We followed each from the minute it opened to the minute its money left, and checked who the buyers were.
- 1,015,687
- 70%
- 586
- 97%
- $630 million
- 18,449
01 · Twenty-three secondsThe coin that lasted 23 seconds
Trading apps list new crypto coins the moment they go on sale. Each one comes with a price chart and a count of buyers. A coin that draws a crowd in its first minute looks like a coin worth buying. On one exchange in the past year, most of those crowds were fake. In most cases, the money was gone within the hour.
The exchange is Meteora, one of the busiest on the Solana blockchain. Any user can list a new coin on Meteora. On 15 November 2025, a coin called egglon ended its launch sale there. A launch sale sells a fixed stock of a new coin at a rising price. One wallet had bought every coin in the sale in a single purchase of 85 SOL, Solana's own currency, worth about $12,000 at the time. In the same second, Meteora moved that money and a stock of egglon into a pool, a pot of coins and SOL that anyone can trade against.
Buyers turned up at once, and 19 wallets traded egglon over the next 22 seconds. Then the wallet behind the launch sale took everything out of the pool: 91.4 SOL, its own 85 plus what the buyers had paid in. The pool had lasted 23 seconds.
The buyers were not strangers. 17 of the 19 had received SOL from that same wallet in the six seconds before the sale ended. Traders call this a bundle. The dev, crypto slang for whoever is behind a coin, buys through many wallets at once so the coin looks popular. Of the two that had not, one bought 0.1 SOL of egglon and lost it.
The egglon pool was one of 1,015,687 opened on Meteora's newest pool design in the eight months to July 2026. Bitquery records every trade and every pool event on the Solana blockchain, so we followed each of them from the minute it opened to the minute its money left. 70% were emptied within an hour of opening. Until February, the crowd in the pools we checked was almost always the dev's own wallets. From March, more of the money came from outside, much of it from trading bots, and it was lost.
02 · The machineWhat is a Meteora DAMM v2 pool?
Meteora is a decentralised exchange: a set of programs that run on Solana itself, with no company in the middle to approve a listing. It is where the LIBRA token launched in February 2025. To sell a new coin there, someone deposits the coin and some SOL into a pool, and buyers trade against it. The pool sets the price from the mix of coins and SOL inside it. Each purchase adds SOL to the pool and takes coins out.
The money in a pool is called liquidity, and it belongs to whoever put it there. The depositor holds a position, a claim on the pool's contents, and can withdraw it at any time. If they take it all out, the coin is left with nowhere to be sold, because nothing is left in the pool to pay for it. Crypto calls that a rug pull.
Meteora's current pool design is called DAMM v2. Pools reach it in two ways. Some are opened directly by a wallet. Others come out of Meteora's launch curve, the program that runs those launch sales. When a sale hits its target, the coin graduates: the SOL raised and a stock of coins move into a new DAMM v2 pool. Depending on how the sale was set up, the coin's dev can end up holding that pool's position, and can withdraw it straight away. That is what happened to egglon.
03 · The countHow many Meteora pools are created?
Meteora saw about 4,100 new ones per day over those eight months. Most of them came out of launch-curve graduations, and the rest were opened directly by a wallet.
New pools peaked in November, 80% of them graduations. Graduations then fell away until April and came back in June, while pools opened directly peaked in April.
Many of those launch sales were bought by the coin's dev in one go, as egglon's was. We checked every graduation from 6 November onwards, whose whole launch sale sits inside our data. In 72% of them, a single transaction paid 95% or more of everything the sale took in. In 61%, the wallets that later ran the pool paid at least 90% of it themselves.
The transaction that then moves the money into the pool is usually sent by someone else. 59 wallets sent it for two in three of all graduations, and never withdrew from any of them. They act as helpers that run the paperwork, so in pools where that is all they did, we leave them out of what follows. Five of them also emptied 761 pools of their own elsewhere, and there they count as devs. The wallet that later empties the pool is the one that matters.
Almost none of these coins trade anywhere else. For 95% of the graduated coins, the launch sale and the one DAMM v2 pool were the only places the coin traded in our data. When that pool is emptied, a holder has no other market to sell in.
04 · The clockHow fast are Meteora pools rug pulled?
We call a pool drained when a transaction that withdrew liquidity left it with less than 1% of the SOL it held just before. By that rule, 81% of all pools were drained. A looser count, any position withdrawn in full, catches 97%.
In 123,507 of them, the withdrawal alone does not show how the money left. Many graduated pools keep part of their money in a second share that the dev's withdrawal does not touch, about 10% in the cases we checked. In a pull-and-dump, the dev pulls its own share and then, in the same transaction, sells coins into that second share and takes its SOL too. Counting only the withdrawal step finds 70% drained. The pull-and-dump first shows up in January, and it made up 52% of all drains in February.
| What we counted | Meteora DAMM v2, 30 October 2025 to 5 July 2026 |
|---|---|
| Pools opened | 1,015,687 |
| Made by a graduation | 576,719, 57% |
| Drained (under 1% left) | 818,094, 81% |
| Drained only by a pull-and-dump | 103,683 |
| Drained within an hour | 715,137, 70% of all pools |
| Median time to drain | 7 minutes |
| A position fully withdrawn | 982,267, 97% |
| Wallets that drained one | 281,338, of which 237,459 drained just one |
| Drained 100 pools or more | 586, with 207,037 pools between them |
| Round-trip pools | 18,449 |
Half of the drained pools were emptied within 7 minutes of opening, and 87% within an hour. Measured against every pool that opened, 70% were drained inside the hour, most of all in November and December.
05 · The devsWho is behind the Meteora rug pulls?
Most of the wallets that drained a pool did it only once. A small group did a large share of the work: 586 wallets drained 100 pools or more each, 25% of the drained total. The busiest drained 5,111 graduated pools in eight weeks at the end of 2025.
They are not one big crew. We took the 500 wallets that drained the most pools and looked for the first SOL each one received before its first pool. Most had one in our data, from 350 different sources. Two sources stand out: a group of eight wallets that sent equal amounts in the same second paid 54 of the 500, and another such group paid 40. In 95 cases the money came from one of the 500 themselves, so some of these wallets come in chains, each one paying for the next. That is a looser shape than the single crew we traced on Robinhood Chain, where one group ran every launch.
06 · The crowdAre the buyers in a new Meteora pool real?
egglon's crowd was typical of the first four months. We call a pool's own wallets the ones that opened it, added money to it, took money out of it or held its position; below, "the dev's wallets". We then picked 393 drained pools at random, from all eight months and every size of pool, and checked where their buyers' money came from. In each pool we traced the SOL of the biggest buyers and of a random set of the smaller ones, from two days before they bought to a day after the drain.
Until February, the money came almost entirely from the dev's side. In pools opened from November to February, buyers with a money link to the dev's wallets put in 97% of what buyers spent, net of what they got back. From March onwards that share fell to 71%. Across both periods, 83% of the top buyers we checked had such a link: they had received SOL from one of the dev's wallets, or from a wallet that also funded one, shortly before buying, or they sent SOL back to one of them afterwards.
The clearest case is a coin called LILPEPE. Its pool opened in December with 50 SOL. In the same second, one wallet bought 1,000 SOL of the coin. Over the next four minutes 861 more wallets traded it, and then the dev withdrew 1,153 SOL. Two minutes later, a single transaction moved 118.8 SOL from seven of the buyers to the dev. It carried eight signatures: the dev's, and one from each of the seven buyers. A signature needs the wallet's private key, so whoever sent that transaction almost certainly controlled all eight wallets.
Coins named after famous brands got the same treatment. A pool for a coin called USAOIL opened in March with just 0.1 SOL. In its first second, one wallet spent 40 SOL buying almost every coin in it, so the chart showed a coin worth real money. 47 minutes later the dev drained 139.4 SOL. Every one of the big buyers we checked had received SOL from the dev or sent SOL to it.
Why fake a crowd? A coin with heavy trading in its first minutes looks popular on the screens that list new coins, and that can draw in outside buyers. The fake crowd costs the dev little, because the money its own wallets spend flows back when the pool is drained, less trading fees.
07 · The lossesHow much do real buyers lose?
The rest of the money came from wallets with no link to the devs that we could find, and that money was lost. Scaled up from our samples, those buyers put about 6.7 million SOL more into drained pools than they got back, about $630 million. That is 14% of what all buyers outside the dev's wallets put in net, and 81% of it was lost in pools opened from March onwards. The losses sit in a minority of pools: in an estimated 66% of drained ones, wallets with no link lost less than 0.1 SOL between them. The pull-and-dump cases hold only 3% of the loss, because their buyers were almost all the dev's own wallets.
Who were they? Line up the buyers with no link in our sample who lost money by how much they traded, and the one in the middle made 4,680 trades on Solana over the eight months, about 19 per day. Of those buyers, 43% made 500 or more trades in a single day at least once, the pace of trading software, and those wallets lost 92% of the SOL this group lost. No single one of them lost more than 272 SOL in a sampled pool.
A pool for a coin called LEVERAGE10 shows such bots at work. It opened in mid-June with 85 SOL, and less than half an hour later its dev drained 525 SOL. Not one of its 36 biggest buyers had a money link to the dev. Ten of them each traded in about 2,000 different DAMM v2 pools in June, around 200,000 times apiece, and on every day of the month. One of them bought into the pools of 1,876 different devs, and more than 99% of those were drained, against 85% of all pools opened directly that month.
Such bots could belong to the pool devs, funded long before the two days we checked, or they could be snipers, bots that buy a new coin in its first seconds and bet they can sell before the drain. They are not arbitrage or sandwich bots: wallets on those lists from our other Solana studies account for less than 1% of what the group lost, while wallets that made 10,000 or more swaps in a single month account for 75%. The chain does not tell us who owns them. Either way, part of the outside loss may be the devs' own money.
08 · Fake volumeWhat is fake volume on Meteora?
Another kind of pool was built to fake trading volume. From March, thousands of DAMM v2 pools were opened with about 70 SOL each and then traded at a scale nothing else in this study comes close to. In these pools one wallet buys the coin and sells it straight back inside the same transaction, over and over, so the pool records heavy trading while hardly any money stays in it. The best known carried coins named VANGUARD or Vanguard: 848 such pools, most opened between late March and mid-April.
The biggest of them borrowed the money for each round trip. In a transaction we checked on a public Solana node, the dev of a Vanguard pool took a flash loan, a loan taken out and paid back inside one transaction, from Jupiter Lend, a Solana lending service. It bought VANGUARD from its own 70-SOL pool, sold it straight back and repaid the loan, all in one go. Jupiter's own documentation says its flash loans carry no fees, and the wallet's balance moved by a fraction of a cent. Repeated tens of thousands of times, that one pool showed 204 million SOL of trading in 1.5 hours.
We count a pool as a round-trip pool when trades bought and sold back inside the same transaction make up at least half of its trading, with at least 100 SOL traded. 18,449 pools pass that test, 739 of them Vanguard-named, and others carry names like C0IN. Together they show 13.2 billion SOL of trading, about $1.1 trillion at each day's SOL price. Most of it, 71%, came in the single week from 6 April, and 91% of that week was in Vanguard pools. We checked three round trips in each of the ten pools with the most trading, which hold 13% of it: in eight of them every trade we checked was funded by a Jupiter flash loan. In ten picked at random, only one used flash loans; in the other nine, the wallet bought and sold back with its own SOL.
Buyers outside the dev's wallets put a net of nearly half a million SOL into these pools, a sliver of what was traded through them. The dev of the Vanguard pool we checked put in 70 SOL and took 70.01 back out. What these pools inflate is trading volume, the same kind of fake volume as the counterfeit SOL pairs we found earlier, so we count them apart from the drained pools with buyers in them.
09 · Before you buyHow can you spot a rug pull before you buy?
Watch the pool's opening second. Among pools for coins with no market anywhere else, which is most of the coins here, those with a purchase of 1 SOL or more in their opening second were drained 94% of the time, against 82% for the rest.
Look at who holds the pool's position, and whether it is locked; a locked position cannot be pulled. Check whether the first buyers got their SOL from the coin's dev shortly before they bought; any block explorer will show it, and Bitquery's address labels mark exchange wallets so that a common exchange withdrawal is not mistaken for a link. Treat a fast-rising buyer count as noise. In our samples, most of the buying money came from the dev's own wallets.
Every pool in this study can be checked one by one through Bitquery's Solana DEX API, with ready-made queries for Meteora DAMM v2 pools and the launch curve. A dev's wallets can be followed with the Bitquery MCP, and anyone who lost money to a drained pool can ask our investigation team to trace it.
10 · MethodHow did we measure this?
We used Bitquery's full Solana history: every successful trade, deposit, withdrawal and transfer on the chain. The same history is sold as files on the Bitquery Data Store. The table sets out what we counted and the rules we used.
| What | How we counted it |
|---|---|
| Pools | Every Meteora DAMM v2 pool opened between 30 October 2025 and 5 July 2026, where our pool data ends |
| Trades and transfers | Trades in those pools to 16 July 2026; transfers between wallets to 30 August 2026 |
| Drained | A transaction that withdrew liquidity left the pool with under 1% of the SOL it held just before, counting sales into the pool later in that transaction, or under 0.001 SOL; for the 27,871 pools without SOL, the other coin |
| Dev's wallets | Every wallet that opened the pool, added to it, withdrew from it or held its position, except 59 helper wallets in pools where all they did was send the graduation transaction |
| Round trips | When a wallet buys and sells a coin inside one transaction, only the difference counts as money in or out |
| Round-trip pools | Trades bought and sold back in one transaction make up half or more of the pool's trading, with 100 SOL or more traded |
| Sample | Drained pools in eight groups (before and after 1 March 2026, by four sizes of buyer money), in random order, the first of each group: 312 drained by the withdrawal, in two separate draws, and 81 by a pull-and-dump |
| Buyer money | Net SOL a wallet put into the pool and into the coin's launch sale, whose SOL moves into the pool; trades of the coin on other exchanges are left out |
| Buyers checked | Those that put in 99% of the money (up to 60), plus a random 40 of the rest, whose split between linked and unlinked money is applied to all the rest |
| Linked buyer | Sent SOL to or got SOL from a dev's wallet, or got SOL before buying from a wallet that also funded one, unless that wallet paid 1,000 or more wallets in the window |
| Scaling | Each group's average per sampled pool times the number of drained pools in that group |
Two separate counts of each pool agree. For drained pools, the SOL withdrawn minus the SOL deposited matches what traders put in, pool by pool, within 2% for 89% of them and within 0.2% in total. The five example pools were checked one transaction at a time on a public Solana node, and so was the drain rule, on 60 random cases it first missed. So were the samples behind a data fault we reported to our engineers along the way.
11 · EvidenceAddresses and transactions cited
| What | Address or transaction |
|---|---|
| egglon: launch buyer, drainer | 8B6pt7…y4YGVk |
| egglon: the pool | 7MWhNY…ogMZfT |
| egglon: launch-sale purchase | 3JKoB3…boiL |
| egglon: graduation | 4p7v1E…dFAX |
| egglon: SOL sent to buyers | Q8E2tE…Vku5 |
| egglon: the drain | 5aLDcK…WVyH |
| LILPEPE: opener, drainer | G2L1z5…DCEjNm |
| LILPEPE: the pool | 6975MR…yChUdT |
| LILPEPE: the drain | 67E9NG…v4Q1 |
| LILPEPE: 8-signature transfer | 4i547c…hT3P |
| USAOIL: opener, drainer | 7WdCvn…6Jz1cb |
| USAOIL: opening, drain | 3F4Kj6…1r3V, 5tPNhy…vpWU |
| Vanguard: opener, drainer | PhqE9E…AteThM |
| Vanguard: the pool | 9QuZkc…jePjJS |
| Vanguard: flash-loan trade | 3HVn5x…G43B |
| LEVERAGE10: opener, drainer | Apqt5U…3S9q9D |
| LEVERAGE10: the pool | 7u1ryU…5jr5UY |
| LEVERAGE10: opening, drain | ycaqmq…YHo8, 4X4p7P…TeYr |
| LEVERAGE10: a buyer, trading bot | 8hr3H1…JtkuGL |
| Busiest draining wallet | 6CvLjV…ro7nYY |
FAQ
What is a Meteora DAMM v2 pool?
DAMM v2 is Meteora's current design for trading pools on Solana. A pool holds a coin and SOL, sets the price from the mix of the two, and lets anyone trade against it. Whoever deposits the money can take it back out at any time unless the position is locked.
What is a rug pull in crypto?
A rug pull is when the people who put the money into a coin's pool take it all back out, leaving holders with nothing to sell into. On Meteora DAMM v2, 70% of the pools opened in eight months were drained within an hour of opening.
How many Meteora pools are rug pulls?
Of the DAMM v2 pools opened in the eight months we studied, 81% were drained, left with less than 1% of their SOL. In an estimated 66% of drained pools, buyers with no link to the dev lost less than 0.1 SOL between them.
Is Meteora safe?
Meteora is the exchange software; anyone can open a pool on it. In our data, 81% of new DAMM v2 pools were drained by the wallets that put the money in, so a new pool is only as safe as its dev. Check who holds the pool's position and where the first buyers got their SOL before buying.
What does it mean when a coin graduates on Meteora?
A coin graduates when its launch sale on Meteora's launch curve reaches its target. The SOL raised and a stock of coins then move into a new DAMM v2 pool where the coin trades freely. A wallet can buy a whole launch sale itself and make a coin graduate in seconds.
What were the Vanguard pools on Meteora?
They were 848 DAMM v2 pools for coins named VANGUARD, opened mostly between late March and mid-April. Their devs bought and sold back in the same transaction, which made the pools show enormous trading volume. The ten busiest round-trip pools all carried the Vanguard name, and in eight of them every trade we checked was paid for with a free flash loan from Jupiter Lend. Vanguard was the biggest name by trading volume among the 18,449 round-trip pools.
How can I check if a meme coin is a rug pull?
Nothing tells for sure. In this study, pools for coins with no other market that saw a purchase of 1 SOL or more in their opening second were drained 94% of the time, against 82% for the rest. It also helps to check whether the first buyers got their SOL from the coin's dev shortly before they bought.
Pool events in our tables stop on 5 July 2026, so pools opened later are not counted, and pools opened in the last weeks before that date had less time to be drained.
Our Solana archive misses about 1.6% of blocks, worst on 22 April, 4 April and 29 November to 2 December, and it also holds a few trades (about 0.03%) from blocks the network skipped. Both have been reported to our engineers. Even if every drain in a missing block were lost, the share of pools drained would move by 1.0 percentage points at most.
For the 180 of the 500 biggest drainers whose first pool opened on 30 October 2025, the first day of our data, the first SOL we see is not necessarily the first they ever got.
Transfers between wallets run only to 30 August 2026. The money links in the sample need transfers within two days of a purchase, so they cover the whole study window.
A link is evidence, not proof, that one person runs both wallets. A wallet with no link found can still belong to the dev through routes we did not check, so part of the outside loss may be the devs' own money, and the linked share is a lower bound on the fake crowd.
The outside-loss figure comes from samples of 393 pools scaled up by group. Resampling them 2,000 times puts it between 4.4 million and 9.2 million SOL in nine runs out of ten. The two separate samples of withdrawal drains give 7.1 million and 6.3 million SOL on their own, and scaling up each pool's smaller buyers by headcount instead of by their share of the money gives 8.9 million.
That figure covers the 639,752 drained pools where buyers after the opening moment, outside the dev's wallets, put in at least 0.01 SOL net. We did not sample the other 162,609; all buyers outside the dev's wallets together put about 1,590,000 SOL net into them.
Dollar figures use the SOL price of the minute of each trade, or the day's average for volume totals.
Some swap venues on Solana are not yet parsed in our data. A coin that traded only there would look like a coin with no other market. Meteora's own pools and launch curve are fully parsed.
Check a Meteora pool before you buy
Every trade and withdrawal above comes from Bitquery's Solana data. The Bitquery MCP server puts that data behind an AI assistant, so you can ask who opened a pool, who bought in its first minute, where those buyers got their SOL, and whether the dev has emptied pools before, without writing a query yourself. The full history of Solana trades and transfers is also sold as files on the Bitquery Data Store.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.
The findings describe Meteora DAMM v2 pools opened on Solana between 30 October 2025 and 5 July 2026 and the trades and transfers around them. A pool is counted as drained, and a wallet as linked to a pool, by the rules set out in the method section; the counts depend on those rules and on Bitquery's records of the chain. Wallets are described by their behaviour on the chain. None of them is attributed to a named person or group, and a drained pool is not by itself proof of fraud.
Meteora and Jupiter are named because their programs ran the pools, launch sales and flash loans described here. That says nothing about the conduct of those projects, which did not open, fund or empty the pools in this study. Coin names such as Vanguard are names chosen by whoever made the coins and imply no link to any company of that name.
Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.