Meme Desk

~/blog/bubblemaps-against-rugcheck-holder-map-and-risk-score

~5 min read By Max Vandel

Bubblemaps Against RugCheck: What a Holder Map Shows and What a Risk Score Certifies

Two instruments pointed at the same question from opposite ends — a graph that infers who is connected, and a scanner that counts what has gone wrong — read against their own documentation and ten live token reports pulled the same day.


Two questions get typed into this market at three in the morning, and they are not the same: who actually holds this, and is this safe. Bubblemaps is adjacent to the first, RugCheck to the second, and the gap is the interesting part.

What each is documented to do

Bubblemaps lists fourteen chains, Ethereum and Solana through Tron, Monad, Aptos and Robinhood. Its developer docs say what the picture is made of: the base map is the top 80 holders, with magic nodes and time nodes computed by default and folded into the relationships, score and clusters, each switchable off.

The published metric definitions are refreshingly plain. Fresh wallets are those under ten days old. bundles is the top ten clusters once exchanges, DEXs and the like are set aside. The Bubblemaps Decentralization Score runs 0 to 100, less decentralized to more; beside it a Nakamoto coefficient, the minimum number of independent entities needed to reach half the supply.

RugCheck’s own page title calls it a Solana and Fogo token risk scanner — two chains against fourteen. Its public API specification is candid about the customer it has in mind, offering the same scoring for detecting scams and for “providing strong trading signals to applications and AI agents”.

What a cluster is evidence of

Magic Nodes carries the marketing; the wiki explains the trick plainly: it surfaces clusters the default map misses by pulling in intermediaries holding none of the token — wallets funded for gas by one address, or paying into a shared deposit address. Time nodes split an exchange into one node per time window, joining wallets only if they passed through together.

Good instrumentation, and inference. Shared gas funding is evidence of common origin, not proof of common control, and the wiki goes no further than saying wallets acting in the same moments “often share intent”. The docs add a limit the picture never advertises: relationships between two supernodes — addresses with a high volume of transfers — are ignored, so the graph declines to join its busiest corners.

What a score certifies

RugCheck’s number is not on the scale most users assume. Two mint addresses from its own new-token feed, detected about three seconds apart on 29 August and read back at 14:52 UTC, mark the flagged case and the clean one.

7hxEFvG3Qw2E1QK8b32XU9eTXf98LoZNKCCZcNBTpump returned one named risk — a creator with a history of rugging tokens, scored 21,600 at level “danger” — for a raw score of 21,601, normalized to 61, LP locked at 100%. CejYgUSFu5WsY19ZZeWPV2RZNyhhJyvMTDhEyGuBpump returned an empty risks array, a score of 1, and the same 100% LP lock.

The arithmetic is the tell. Across all ten summaries we pulled, the raw score was one plus the sum of the named contributions — a running total, not a grade, and a clean sheet reads 1 because 1 is the floor. The spec documents score and score_normalised as bare integers, with no scale.

That clean sheet is the specimen worth keeping: a true statement about checks that passed, on a token the feed had picked up seconds earlier — a record seconds long. RugCheck publishes the base rate itself — on 29 August its analytics endpoint put pump.fun above 330,000 launches against more than 215,000 rug events on a rolling seven-day window. The two counts need not describe one cohort, but the ratio is not subtle.

Every figure here is a snapshot, not a certificate. Both mints were pulled again at 16:17 UTC, under ninety minutes later: the flagged one now returns an empty risks array and a score of 1, and LP locked has gone from 100% to 0% on both. Neither reading is wrong. Each is what the scanner could see at that hour — not a verdict.

Bottom line

The head-to-head the search box wants — which one tells me whether this is a rug — has no winner, because neither is entered. A map shows structure, a scanner shows checks; neither shows intent, which is the question.

As complements they work. Both inherit the limit set out in our review of DEX Screener: the reading is faithful to what happened, and what happened is not what is about to.

We will be reading them from outside the fence, as ever.

Filed with the specimens: a clean reading is not a safe token. These things go to zero as their ordinary outcome, and a shrug from a scanner is the weakest reason to buy anything yet invented. None of this is advice.