NYC Memecoin Hack
Incident Overview
On January 13, 2026, former NYC Mayor Eric Adams allegedly executed a rug pull on the newly launched $NYC memecoin, removing liquidity approximately 30 minutes after promoting it on his personal social media, resulting in reported losses of $2.5-3.4 million for investors who purchased the token following his promotional posts.
According to reports from PeckShield and blockchain analysts, former NYC Mayor Eric Adams promoted a new memecoin called $NYC through his official social media channels, presenting it as "the NYC token" and claiming it would "change the game." Approximately 30 minutes after the token launch and promotion, the liquidity pool was abruptly drained, with blockchain data showing the removal of over $2.5 million initially, with updated reports indicating the total drain exceeded $3.4 million. This action represents a classic "rug pull" scheme where a token creator or controller removes liquidity from a trading pool after attracting investors, leaving holders unable to sell their tokens at meaningful value. Blockchain analyst Rune noted that Adams' reported net worth was only $2 million prior to this incident, making the alleged rug pull amount significantly larger than his previously disclosed wealth.
The rapid timeline between promotion and liquidity removal, combined with the use of an official social media account to drive investor interest, characterizes this as a coordinated rug pull rather than a technical exploit.
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to NYC Memecoin, these are the critical security checks that could have prevented this incident (January 2026).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next NYC Memecoin
The NYC Memecoin hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.