Sellability & honeypots
The richest attack surface on an EVM chain: a token is a program the deployer wrote, and it can let you buy but never sell. So Hoodini measures sellability two independent ways and never blends them into false confidence:
- GoPlus — is it flagged a honeypot, can you sell all, what's the sell tax.
- Our own round-trip — a simulated buy then sell on the token's real route: the v2 router, the v3 quoter or the v4 quoter, resolved from the chain, in the pool DexScreener names as the token's market and in that pool's own quote token — USDG, GME, NVDA, whatever the creator paired with. If the sell route quotes nothing, or the round-trip is catastrophically lossy, it isn't sellable in practice. A fee-ladder pool reads as sellable with its fee shown; a quote far below the market price means a decoy pool and reads unknown, never a verdict.
If the two disagree, the result is labelled conflicting and fails safe (treated as not sellable) — a honeypot that happens to quote fine is exactly the EVM attack, so we don't resolve a disagreement to "safe".
Taxes are shown as measured. An empty tax reading is unknown, never 0 — a tax we couldn't read is not a 0% tax.
