What we find when we actually measure it

On-chain research on how Solana tokens are launched, manipulated and mis-read by the tools meant to catch them — including our own.

13 findings · every one states its sample size and its method · negative results published on the same footing as positive ones.

Original research

Measurement
Bundle checkers report the same block. One launch in six shares something stronger: the same transaction.

Question. Every bundle checker reports wallets that bought in the same block. A busy launch block also holds strangers, so how often are the wallets in a launch window funded by literally the same transaction — one signer paying for several at once?

Finding. Often enough to name. Of 1,920 launch windows with at least two tracked buyers, 314 (16.4%) contain two or more wallets that received their supply in a SINGLE transaction. Where such a group exists it takes a median 12.8% of supply, 24.6% at the 75th percentile and 53.7% at the 90th, with a maximum of 79.5%; in 87 windows (27.7% of those with a group) one transaction bought a fifth of the token or more. The groups are small and tight — 208 pairs, 69 triples, 37 quads — and 1,460 of 28,524 tracked wallets (5.1%) sit inside one.

Method. Read from the creation slot plus 30 slots on 2,023 tokens whose creation our own stream witnessed, excluding the liquidity pool and the deployer. A wallet's receipt is the transaction that gave it the tokens; a group is two receipts carrying one signature. The denominator is windows with 2+ tracked buyers, because a lone buyer cannot share with anybody. We follow the 30 largest buyers per window, so this is a FLOOR — sharing among smaller buyers is invisible to it. Exactly one window had every tracked wallet on a single signature, so the result is not an artefact of the creation transaction itself.

Measurement
A still-loaded launch bundle does not predict the token falling

Question. If the wallets that took the launch are still holding, is the token more likely to fall than one whose launch bundle has already sold out?

Finding. Not at the thresholds anyone acts on. Over the 24 hours after the holdings reading, tokens whose bundle still held 5% or more fell by half 28.4% of the time against 24.8% for bundles already under 1% — a 1.14x lift, z=0.66, p=0.51, n=656. Something appears only at catastrophic falls: at a 70% drop it is 23.3% against 14.0% (z=2.22, p=0.026, n=872), consistent at 6, 24 and 48 hours and absent at both 30% and 50%. Nine cells were tested, so that one result does not survive correction for multiple comparisons, and we publish it as an untested lead rather than a signal. Liquidity carries no warning either: over the same windows the median liquidity drawdown is 10.7% against a median price drawdown of 14.9%, so the pool drains more slowly than the price falls (n=501).

Method. Forward-only by construction: the reference price is the first price at or after the holdings reading, so nothing that happened before it can contaminate the move. Bundle-holding bands compared across 6, 24 and 48 hour horizons at 30%, 50% and 70% fall thresholds, on tokens whose creation our stream witnessed.

Measurement
Holders do not sell before the price falls — 10,070,756 rows say the premise is wrong

Question. Every exit-alert product rests on one assumption: that a cluster starts reducing its position before the price reflects it. Is that true?

Finding. No, and not marginally. Of 271 tokens that fell at least 30% from their in-window peak, the top-holder cohort sold first in 13 (5%) while the price moved first in 94 (35%), and in 164 (61%) the cohort never sold 15% at all. Price leading 94 to 13 gives p=2.6e-16 against a coin. The apparent 1.89x lift over tokens that did not fall is 4.8% against 2.5% — z=1.16, p=0.25, on 13 events against 4. As a product it would have given an hour of warning on 9 of 271 collapses.

Method. The top 20 token accounts for a rolling watch set of 250 tokens, every 15 minutes for 23 days: 10,070,756 rows across 920 mints at 100% collector uptime, 429 of them usable. The cadence deliberately matches the price polling, because sampling holders more coarsely than price makes it structurally impossible to observe holders leading. THE TRAP, found the hard way: that top-20 list is ranked by CURRENT balance and churns about 45%, so summing ranks cannot see a seller — whoever replaces them refills the sum. Our first pass did exactly that and produced a number we threw away. Track a FIXED COHORT of token accounts forward.

Measurement
Wallets with a record predict the next graduation. Busy wallets predict the opposite.

Question. Every smart-money product sells a wallet list. Tested honestly out-of-sample, does a wallet's past record predict the next token it turns up in — or is it just measuring which wallets trade a lot?

Finding. It predicts, and the dose-response is monotonic. Against a 25.1% base graduation rate, tokens holding no wallet with a prior record graduate 21.7% of the time (n=11,682); one such wallet 33.1% (n=1,488); two 44.5% (n=301); three to four 52.3% (n=262); five to nine 73.7% (n=137); ten or more 96.8% (n=125, 95% CI 92.1-98.7%). The control runs the OTHER WAY: selecting wallets on activity alone — how many tokens they have touched, ignoring whether those worked — gives lift 0.62x, 0.52x and 0.41x across three cutoffs. Busy wallets sit in worse tokens. A signal that survives a confound pointing the opposite direction is the rare kind worth believing.

Method. Strictly out-of-sample. A wallet qualifies on 5 or more prior tokens and a 60% or better graduation rate, and its record is built ONLY from tokens first seen before the cutoff, then tested on tokens first seen after it. Three cutoffs — 15 July, 25 July, 5 August 2026 — give skill lift 1.52x, 1.22x and 1.97x. 24,955 tokens and 317,495 holding rows, 15 June to 28 August 2026; every holdings row is snapshotted within an hour of the token being first seen, so there is no look-ahead. Popularity is controlled: we store only the top ~15 wallets per token, so holder count is near-constant and predicts little on its own (20.1-26.2% across bands), and inside a fixed band the effect holds at 3.18x (11-13 holders) and 2.57x (14-17). THE LIMIT THAT MATTERS: this predicts GRADUATION, not profit. On a peak-of-2x definition the same test gives only 1.37x, 1.12x and 1.88x on 486, 865 and 451 tokens, and by our own earlier measurement a peak is not a realisable return. We publish this as a measured track record, never as a follow-this-wallet signal.

Article
24 hours after its peak, the median token is worth 8% of it

Question. Everyone knows these tokens fall. Nobody publishes how fast. Measured from each token's own peak, how much of it is still there an hour later, and a day later?

Finding. The median token retains 59.1% of its peak after one hour, 33.0% after six hours and 8.0% after 24 hours. Our own lowest-risk band is not spared: tokens where none of our coordinated-control checks fired still keep only 6.6% of their peak a day later. The bands are also not a ladder — ELEVATED holds value better than LOW SIGNAL, because the score detects one specific thing rather than grading quality. In both the graduated and never-graduated cohorts the HIGH band is MORE likely to reach a 10x (13.3% vs 9.0%, and 0.5% vs 0.2%) as well as more likely to end near zero.

Method. 22,893 tokens risk-scored BEFORE their outcome was known, first seen 15 June to 24 August 2026, mean observation window 584 hours, polled at roughly 15-minute resolution from DexScreener. Decay is measured from the highest price observed for each token, using stored price history only — no live price — so the figures cannot drift after publication. 1,435 tokens are EXCLUDED as unmeasurable rather than counted as failures. Two limits stated in the piece: our first observation lands a median 34.9 minutes after the pair is created, so multiples are measured from first sight and understate any earlier move; and where a token was already falling when we found it, the observed peak is a local maximum — on a 3,000-token sample that is 39.6% of LOW SIGNAL, 52.8% of ELEVATED and 50.8% of HIGH, so the true fall is steeper than published. n=21,181 at the one-hour horizon.

Read the full method →
Article
97.5% of pump.fun launches never graduate — and graduating is not safety

Question. Graduation is the line the whole ecosystem uses to separate a real token from a joke. How many launches cross it, and does crossing it predict anything about survival?

Finding. 2.5% cross it, and crossing it predicts almost nothing. Of 32,260 launches with an observed peak, 97.5% never reached the ~$69k threshold and the median launch peaked at $4k. Of the 817 that did graduate, 673 — 82.4% — now trade under $5k, including 68 that peaked above $1m and 16 above $10m. Every conventional safety check reads clean at the top of that move; only the deployer's record is available beforehand.

Method. Peak market cap from pump.fun hourly USD candles over each token's full trading life, max hourly high × 1B supply; current market cap from the deepest DexScreener pair. 18.1% of indexed launches were EXCLUDED as unmeasured rather than counted as failures — the indexer caps candle fetches at 20 per wallet inside an 8s budget and falls back to current-as-peak, which would have recorded dead tokens as 'never came close'. Excluding them biases against our own headline. n=32,260 launches across 2,852 wallets, 14 August 2026.

Read the full method →
Article
We took the funder hop. It identifies almost nothing.

Question. A Create transaction's fee payer is a stable ID, not a real identity — fund a fresh signer per launch and every token reads FIRST_LAUNCH. Does clustering on whoever funded that signer recover the operator?

Finding. Almost never. Across 941 resolved deployers, 85.4% were funded from exchange or infrastructure addresses. Private funders are 14.6%, and four of the 127 distinct ones have now funded more than one deployer — the largest funded eight, which is the first structure this check has surfaced. It stays a weak signal: a single infrastructure address accounts for 151 of the 941, so naive funder clustering would have produced one phantom 151-wallet cabal, and only 58 of the 941 have any outcome sampling at all.

Method. Walked each deployer wallet to its first inbound SOL transfer, then classified the sender as exchange, program-owned infrastructure, or private wallet. Deployers whose own history is too deep to walk return UNKNOWN rather than a guess. Shipped as a live check; it is deliberately silent when the funder carries no signal. n=941 and growing, 11 August 2026 — published at n=15, corrected to n=190 the same day, and corrected again at n=941 when the 'no private funder appears twice' claim was overturned.

Read the full method →
Article
pump.fun's ownership transfer quietly broke every deployer check — ours included

Question. How often does a pump.fun token's on-chain `creator` field stop naming who actually deployed it?

Finding. 21% of aged graduations had transferred ownership (8 of 38, median age 47 days), against 0 of 20 fresh graduations. On one, the real deployer had 42 launches while the wallet named by `creator` had none — so a serial launcher read as a first-time creator.

Method. Compared the on-chain `creator` field against the fee payer of each token's actual Create transaction, walking the bonding-curve PDA to its oldest signature and confirming the `Instruction: Create` log before trusting any result. n=38 aged, n=20 fresh, measured 5–6 August 2026.

Read the full method →

Measurements

Measurement
By the time anyone scans the token, four in five launch bundles have already sold out

Question. "How much ammo is left" is the natural question to ask about a launch bundle. When a scanner first measures one, how much of what those wallets took are they still holding?

Finding. Almost none. Across 1,992 measured launch windows, 79.2% of bundles hold under 1% of supply at the moment they are first measured; 10.7% hold 1-5%, 8.8% hold 5-20%, and only 1.4% still hold 20% or more. It is sharpest where it matters most: of 439 windows where the bundle took at least HALF the supply, 342 (77.9%) were already under 1% by the time we looked.

Method. Holdings are read for the 30 largest buyers in each window, and 92.5% of those readings happen within an hour of the window itself being measured — so the lag is not in the measurement. It is that a token gets measured when somebody first asks about it, which is long after it launched. Anything built on remaining bundle inventory as a WARNING has to read the launch as it happens, not when a scanner is asked.

Article
Accuracy ledger: what each risk band did next

Question. Did the tokens we flagged actually behave worse than the ones we did not?

Finding. Across 30,354 tokens split by graduation, HIGH-band tokens sat 90%+ below their peak in 93.8% of graduated cases (LOW SIGNAL: 88.8%) and 89.3% of never-graduated (74.9%); they were less often up now and more often 10x'd. Forward return did not replicate and is not claimed.

Method. Score at first sight, outcomes polled every 15 minutes, checks >= 5, split by graduation so the pooled figure cannot be Simpson's paradox. Recomputed nightly; every cell shows n; misses stated first.

Read the full method →
Measurement
A peak is not an edge: why 78 exit rules all lost money on the same signal

Question. A set of token alerts had a median peak of +23% and 48% of them reached +25%. Is there an exit rule that converts that into profit?

Finding. No. All 78 tested cells lost money — trailing stops, fixed take-profits, timed exits, delayed arming, and every entry offset — on mean, median, ex-top-5 and in both time halves independently. The reason is upstream of the exit: median forward return from the alert price was negative at every horizon from 30 seconds to 60 minutes, and got worse the longer the hold.

Method. 304 alerts over 10.9 days, costs modelled at 1.72% round trip. The trap is that a PEAK is a maximum over a path, so it is positive by construction even for pure noise, while forward return is a point measurement. Test raw forward return before building any exit grid: if it is negative at every horizon, no exit rule can repair the entry.

Tool comparisons

Article
Best Solana bundle checkers in 2026

Question. Which tools actually detect same-block bundle buys on Solana, and what does each one miss?

Finding. Coverage differs more than the marketing suggests. Bundle detection, holder concentration and deployer history are three separate problems, and most tools solve one well and the others by proxy.

Method. Feature-by-feature comparison against live tokens, with the checks each tool actually performs.

Read the full method →
Article
RugCheck vs Bubblemaps vs Cabal-Hunter

Question. Three tools, three different answers on the same token. Which layer is each one actually measuring?

Finding. They are not competitors so much as different layers: contract safety, wallet-graph visualisation and deployer history answer different questions. Using one as a proxy for another is where people get caught.

Method. Side-by-side on shared tokens, with each tool's own stated methodology.

Read the full method →

A finding without an n is an opinion. If a measurement here is wrong, we would rather know — tell us. Scan a token yourself on the free map, or see the serial-launcher index.

Cabal-Hunter™ publishes automated assessments, not statements of fact. Contest a verdict.

On-chain signals, not financial advice and not a safety rating. We cannot see a community takeover, a KOL post or anything else off-chain that moves a price. Always do your own research.

Methodology · Contest a verdict · Terms · Privacy · Refunds · Docs · Contact

© 2026 Cabal-Hunter™ · Cabal Hunter is a registered business name (no. 791866) of Paul Fitzgerald, a sole trader established in Ireland. Business address: 18 Willow Wood Close, Hartstown, Clonsilla, Dublin, D15 XF5Y.