SECURITY & CUSTODY

You Cannot Export Your Key

The single most important thing to understand about GMGN is who holds the keys. This section covers custody, the withdrawal locks, fake domains, and what the MEV record actually shows.

Key Custody: the Headline Fact

GMGN's documentation, read 6 August 2026, states that private key export is prohibited on all chains, Solana, EVM and Tron alike, and it says the same is true of wallets you imported yourself. There is no seed phrase to write down and no way to move a GMGN wallet into Phantom or a hardware device. Connecting Phantom does not change this: GMGN's own docs describe that flow as creating a “custodial wallet account” with fresh addresses generated per chain. The practical consequence is that funds in a GMGN wallet can only leave through GMGN's withdrawal flow, so treat it as a hot trading account rather than storage. GMGN's terms of service say the opposite, claiming you “retain control over your private keys”, and that contradiction is worth reading in full in is GMGN safe and who holds your private keys. Keep long-term holdings in a wallet you control, and fund the trading account from it as described in connecting Telegram and funding your wallet.

Withdrawal Locks: the Holds GMGN Documents

Most “my withdrawal is stuck” complaints match a hold GMGN documents rather than a fault. Its documentation, read 6 August 2026, states that withdrawals are web-only, so the Telegram bot cannot send funds out at all; that Google Authenticator is required before your first withdrawal; and that funds go only to addresses on your whitelist. Adding or changing a whitelist entry blocks withdrawals for three hours, re-binding Google Authenticator blocks them for 24 hours, and the Max button retains a small balance for rent and gas rather than sending everything. Each of those is a documented behavior, and each one will strand you if you meet it for the first time in a hurry. If something is genuinely not moving, work through the troubleshooting hub before assuming the worst.

Does GMGN Front-Run Its Own Users?

We have seen no evidence for it, and what published research on Solana sandwich attacks does describe is third-party MEV bots targeting order flow from terminals like this one rather than the terminal skimming its own users. Reports of GMGN order flow being sandwiched are about those third-party bots. On GMGN's side, a co-founder posted publicly about validators leaking transaction data to sandwich bots, GMGN announced hardened MEV protection in July 2025, and after the anti-MEV protection was breached in October 2025 GMGN said it compensated affected users automatically with no claim to file. Enabling anti-MEV requires a priority fee of at least 0.002 SOL and costs you some speed, and GMGN states that the protection is not perfect. We have not published a figure ranking GMGN against other venues for sandwich exposure, because we have no primary dataset we can point you at. The fee guide covers the priority fee and tip settings that decide how exposed you are.

What Do GMGN's Token Security Checks Actually Screen For?

Every token page carries a panel of automated contract checks, and the fields differ by chain. All of the definitions and thresholds below are quoted from GMGN's CA Security Checks documentation, read 18 August 2026. That page opens with GMGN's own disclaimer, which is worth reading before any of the individual fields: the checks “are for reference only and cannot guarantee 100% accuracy,” and it tells you to compare multiple security tools before trading. Nothing below is a safety rating, ours or GMGN's.

Honeypot: what it tests, and what it cannot catch

On the EVM chains, GMGN's Honeypot field flags a contract where, in its wording, “the token creator uses technical measures to restrict the sale of tokens.” You can buy; you cannot sell. Two limits are stated on the same page rather than inferred by us. First, the detection is not GMGN's own: it “relies on third-party data sources such as Goplus.” Second, GMGN says the website “may display this information with some delay, thus not guaranteeing timeliness or accuracy.” So a clean honeypot flag means the third-party source had not flagged it at the moment GMGN last read it. A contract that becomes a honeypot after that read is exactly the case the check cannot cover, and GMGN separately warns that a contract can appear renounced while still being updated into one. There is no honeypot field documented for Solana, where the mechanic is different.

Top 10 holders: the threshold is 30%, and what it does not tell you

GMGN's Solana panel prints a Top10 hold field where, in its own words, “Yes” indicates a relatively safe condition, meaning the top 10 holders together hold less than 30% of supply. That 30% is the actual documented line, so a page telling you to worry above some other number is not reading GMGN's panel. What the field measures is addresses, not people. One holder splitting across twenty wallets reads the same as twenty holders, and a Yes is compatible with a single party controlling most of the float through addresses ranked eleventh and below. Read it as a fast disqualifier when it says No, not as clearance when it says Yes.

Mint authority, blacklist and renounced permissions

On Solana, MintDisable reading “Yes” means, per GMGN, that “the token creator cannot issue additional tokens to manipulate the market.” The Blacklist field is the inverse: “No” is the safe reading, and GMGN spells out what a Yes means for you specifically, that you are on the creator's blacklist, cannot sell, and will see a frozen-wallet alert. On the EVM side the parallel fields are Verified, meaning the contract source is open on Etherscan for review, and Renounced, meaning permissions were relinquished. GMGN attaches its own caution to that second one: some contracts “might fake renouncement and still update the code,” turning the token into a honeypot or blacklisting wallets afterwards. Verified is the one field here you can check yourself in a minute, because it points at source code you can open.

LP lock and burn status

The Solana panel prints Burnt as a percentage of the pool, and GMGN's reading is that higher is better, with 100% meaning the project cannot withdraw from the liquidity pool at all. The EVM equivalent is a Locked or Burned field, and GMGN distinguishes the two: locked LP tokens are “retrievable upon expiration,” burned ones went to a burn address and are “irretrievable.” That difference is the whole point and it is the one people skim past. Locked is a timer, not a guarantee, and the check does not tell you when the timer ends. Anything short of a full burn leaves a documented path back to the liquidity, which is the condition behind the D1 and L1 route failures in GMGN transaction failed.

Rug probability and rug history

These two are the least self-explanatory fields on the panel, and GMGN documents what drives them. Rug probability is derived from holder behavior: “the more holders who frequently buy rug pull tokens, the higher the likelihood that this token could be a rug pull.” So it is a statement about the wallets currently in the token, not about the contract. Rug History is the other axis, showing “which rug pull tokens may have been previously launched by the creator of this token,” and GMGN's own hedge in that sentence is the word may. Buy and Sell Tax sits alongside them on EVM as the transaction tax paid to the creator, where GMGN says an excessive sell tax, its example is 99%, indicates a honeypot.

What you still have to check yourself

Take the panel for what its own documentation says it is: automated, partly third-party, possibly stale, and explicitly not a guarantee. The gap between what it screens and what determines whether you can get out is real. It reads contract state, not intent, so nothing on it forecasts a creator selling into your buy. It samples at a moment, so a green panel on a token you buy an hour later is a stale panel. It does not price the pool, so it will not tell you that a $500 pool cannot absorb your position, which GMGN handles separately as an order10006 failure. And a locked LP is not a burned one. GMGN's own instruction is the right one: compare multiple security tools before trading, and treat the panel as a filter that removes obvious problems rather than as a verdict that a token is safe. None of this is financial advice, and no combination of green fields makes a memecoin a sound position.

Fake Domains and Wallet Hygiene

GMGN's documentation lists four hosts, read 6 August 2026: gmgn.ai, docs.gmgn.ai, papi.gmgn.ai for the API, and www.gmgn.cc for chart embeds and the support address. Anything outside that list is not covered by GMGN's own documentation, lookalike GMGN domains on other TLDs have been reported hosting wallet drainers, and the list can change, so check the address bar against the current docs before you connect a wallet to anything. On Telegram, lookalike handles that swap a lowercase L for a capital I are a known pattern, and GMGN states that its admins never message first and never ask for keys. Keep trading balances small, verify the group only through the official X account, and read the custody guide before you move real size. GMGN also runs a bug bounty on HackenProof covering unauthorized access to wallets or keys.

Trade on GMGN With Code ggguide

Our referral code is ggguide. GMGN pays us a share of the 1% fee you already pay. It gets you no discount and no bonus, so use it only if the guides here were useful.

Open GMGN