Quick answer
Verify the mint and pool. Then check concentration, linked wallets, liquidity control, repeat buyers, funding, and exit depth. No metric proves safety or future performance. Identify the risks, who controls them, and whether your intended position can exit under stress.
A fast due-diligence framework
Run the checks in four layers: identity, distribution, behavior, and exitability. Identity verifies the mint, pool, and important addresses. Distribution asks who controls supply. Behavior checks what those wallets are doing. Exitability tests whether the pool can support your sell when conditions deteriorate.
Work through these in order. The early checks are cheap to run and kill most bad tokens fast; the later ones are for anything that survives.
Identity check: mint, canonical asset, and variant
Start with the exact Solana mint from the transaction or pool account. A symbol, logo, social link, or search result is not an identifier. Copycats can reuse all of them.
Then separate two questions:
- What does this mint claim to represent? Check name, symbol, decimals, authorities, issuer references, and the pool where it trades.
- Is it one variant of a broader asset? Wrapped assets, bridged assets, stablecoins, liquid-staking tokens, and tokenized equities can have several mints tied to one economic asset.
The Solana Foundation's open-source Tokens registry and API can resolve a mint or alias to a canonical asset group and show known variants. Its public documentation says unknown mints fall back to a deterministic solana-<mint> record. That fallback is useful for stable grouping, but it is not issuer verification or a safety endorsement.
Keep the mint-level record even when a canonical mapping exists. Holder concentration, pool depth, authorities, first buyers, and sellability belong to the specific mint you may trade. Two variants of the same underlying asset do not share the same on-chain risk.
Use a conflict protocol when sources disagree
Do not settle a disagreement by choosing the cleaner dashboard. Classify each disputed field by the evidence that can establish it:
| Disputed field | Verification evidence | Safe state before resolution |
|---|---|---|
| Mint or token program | Transaction accounts and mint account | Identity unresolved |
| Decimals or supply | Mint account at a saved slot | Valuation and concentration unresolved |
| Pool identity | Pool state plus swap transaction path | Venue unresolved |
| Holder owner | Token-account owner and program ownership | Actor unresolved |
| Price or market cap | Time-matched pool state and executable route | Marked value unresolved |
| Lock or burn status | Controlling account, program, amount, and unlock condition | Liquidity control unresolved |
Save the conflicting values, sources, and observation times. A later correction should update the conclusion without erasing why the original claim failed. This makes the review reproducible and stops one stale enrichment field from contaminating every downstream percentage.
1. Holder concentration
Pull the top holders and look at how supply is distributed once you exclude the LP, burn addresses, and known CEX wallets. What you care about is how much of the circulating float sits with the top handful of non-infrastructure wallets, and whether those wallets look independent or coordinated.
There's no universal safe number. A token five minutes old will always look concentrated. What matters is trajectory and structure: is concentration falling as real buyers come in, or is one cluster quietly holding a dominant share behind a wall of small decoy wallets?
False positive: a market maker or staking contract can look like a whale. Check what the address actually does before writing the token off.
Separate token accounts, owner wallets, and actors
Solana's token-account model allows one wallet to own multiple token accounts for the same mint. A raw holder export can therefore overstate wallet count before any deliberate wallet splitting occurs.
First aggregate token-account balances by the account's controlling owner. Preserve delegate, frozen-state, and program-custody evidence instead of assuming every owner can sell the full displayed amount. Then apply funding and behavior evidence to estimate independent actors.
Use three explicit denominators in the review:
- nonzero token accounts covered by the source
- unique controlling owner wallets after account aggregation
- estimated independent actors after supported clustering
If the source does not expose owner resolution or complete pagination, label actor concentration unresolved. Do not turn a partial account table into a precise decentralization score.
What does healthy holder distribution look like?
Healthy distribution is boring: many mid-sized wallets with different funding sources, creation dates, and trading histories.
Unhealthy distribution is theatrical: dozens of wallets holding similar amounts, created in the same hour, and funded from the same place. If top holders look like siblings, treat them as one actor.
Calculate raw and adjusted concentration
Keep two concentration figures. The raw figure includes every top token account. The adjusted figure separates pool vaults, burns, programs, lockers, bridges, and known custody accounts from wallets that can sell at an owner's discretion.
Then collapse strongly linked wallets into estimated actors. Ten addresses funded by one fresh parent do not create ten independent sources of demand. Record unresolved accounts instead of forcing a label.
The full Solana holder-distribution framework explains how to compare raw accounts, adjusted actors, concentration trajectory, and realistic exit depth. This matters because a percentage that looks acceptable against total supply may still represent severe control over the liquid float.
2. Insider and team wallets
Team supply is rarely labeled "team." It may be spread across first-block buyers, deployer recipients, or wallets funded by the deployer's source.
A per-token insider scan surfaces these relationships in one view, including deployer-linked wallets, early buyers, and their combined supply.
The red flag isn't insiders existing. Every token has them. It's insiders holding enough combined supply to nuke the chart, especially when their wallets have a history of doing exactly that on previous deploys from the same funding trail.
False positive: early conviction buyers who found the token organically can look insider-ish. Check whether their wallet has a broader trading history or exists only for this token.
3. Fresh-wallet clusters
New wallets buying a new token is normal. It can also camouflage insider accumulation.
The tell is clustering: wallets funded minutes apart from the same source, buying the same token in the same window. That can be one actor manufacturing the appearance of organic demand.
Watching the fresh wallets feed regularly builds your eye for the difference between scattered new buyers and a coordinated batch. We covered how to read these patterns in depth in our guide to fresh-wallet signals on Solana.
False positive: a viral moment genuinely mints new wallets. Organic fresh wallets have varied funding sources (different CEXs, different amounts, different timing). Coordinated ones look photocopied.
Record an evidence ledger before calling a cluster
Do not save only a screenshot or a wallet count. For each relevant row, record the full wallet, full funder, first funding time, transaction signature, token mint, direction, raw token amount, estimated USD value, and what the wallet did next.
The production Fresh Wallets Feed showed why on July 29, 2026. Three four-hour-old wallet labels shared the same visible funder and sold USWR or USOS into SOL. Two wallets appeared more than once, so five visible rows represented three wallets before any deeper funding analysis.

The correct conclusion is not "insider proven." The defensible conclusion is that the cohort deserves actor-level verification. Open the full funding transfers and transaction signatures, then collapse only strongly linked addresses. The fresh-wallet clustering guide walks through that decision in detail.
4. LP status and lock
If liquidity isn't locked or burned, the trade has a single point of failure that isn't you. Check where the LP tokens sit: burned is cleanest, locked is acceptable if the lock is long and verifiable on-chain, and sitting in the deployer's wallet is a live grenade regardless of what the Telegram says.
Also check the pool's depth relative to the market cap being quoted. A token can print a big number on a screener with a puddle of actual liquidity behind it.
False positive: some legitimate setups use migration mechanics or protocol-owned liquidity that don't look like a classic burn. Verify what the addresses holding LP actually are before assuming the worst.
How do you check if a Solana token's liquidity is locked?
Find the pool's LP token mint and inspect its holders. A majority at a burn address is burned. For a recognized locker contract, verify the unlock date yourself rather than trusting a badge.
If LP tokens sit in a normal wallet, that wallet may be able to pull the pool. Pulls, adds, and migrations also appear on Liquidity Radar.
Verify removal power, not only the lock label
Record the exact LP token or concentrated-liquidity position, its controller, the amount covered by the lock or burn, and any other material positions. A verified lock on one position does not prevent another controller from removing a separate pool or moving active liquidity out of range.
Then test the market rather than stopping at custody evidence. Compare quote-side reserves, alternative routes, and fresh sell quotes for your intended position. The Solana liquidity-removal guide shows how to reconstruct a withdrawal, distinguish extraction from migration, and measure the exit depth that remains.
5. Repeated buyers vs one-shot snipers
Volume tells you nothing about conviction; buyer behavior does. A token where the same wallets keep coming back to add across hours or days has a fundamentally different holder base than one where every buyer is a sniper bot that entered once at launch and is waiting to dump on the first pump.
Review wallet histories for repeated entries, then compare the pattern with the whale accumulation framework. Multiple independent wallets re-accumulating is harder to fake because it costs the faker real spread and fees over time.
False positive: one wallet splitting buys across sub-wallets can imitate repeat accumulation. This is where the funding-trail check below pays off. Repeat buyers only count if they're actually different people.
Do not confuse a sniper with a bundled launch
A sniper is defined by execution behavior: it tries to land at or near the opening of trading. A bundle is an atomic submission of multiple transactions. Jito's bundle specification says bundles contain up to five transactions that execute sequentially and all-or-nothing.
One does not prove the other. The due-diligence question is not whether a dashboard shows a bundle badge. It is whether the earliest cohort gained meaningful supply through relationships or execution patterns that later buyers did not share.
Run these checks:
- Order successful acquisitions by slot and transaction position.
- Resolve versioned-transaction accounts plus outer and inner instructions.
- Compare signers, fee payers, direct funders, funding amounts, and first actions.
- Measure actor-adjusted supply acquired in the launch window.
- Follow transfers and sells through the first expansion in demand.
Solana's transaction introspection documentation notes that account indices, address lookup tables, and CPI instructions must be resolved to recover the execution tree. A surface-level transfer list can miss the router or program path that explains a balance change.
| Evidence | Risk weight |
|---|---|
| Early slot only | Weak: speed without relationship evidence |
| Same slot and matching sizes | Medium lead: investigate funding and instructions |
| Direct shared funder plus synchronized entries | Strong coordination evidence |
| Meaningful actor-adjusted supply plus synchronized exits | Strong exit-liquidity concern |
Use possible bundle when the submission relationship is not independently established. Same-slot ordering is valuable evidence, but it is not a universal on-chain bundle certificate.
Reconstruct net exposure before calling accumulation
A feed can show several buys from one wallet while omitting a nearby sale, transfer, failed transaction, or protocol movement from the analyst's mental summary. Build a chronological ledger from successful signatures and raw balance changes.
For each wallet and mint, track:
- covered tokens acquired through swaps
- covered tokens disposed through swaps
- transfers in and out with carried basis unresolved until traced
- tokens moved into pools, vaults, or staking positions
- current wallet and protocol-held exposure
- quote spent, proceeds received, and covered fees
On August 23, 2026, Stalkchain's public Smart Money Transactions table showed repeated CATE transactions from the same abbreviated address within seconds. Later records appeared in both asset directions.
That is evidence of active flow, not a ready-made accumulation verdict. Open the address and signatures, then calculate the net covered position across the sequence.
Build an actor-level exposure table
Wallet rows, holder rows, and token accounts are different units. Before calling several addresses independent accumulation, group each address's accounts by mint and then collapse only relationships supported by funding, transfers, synchronized behavior, or return flows.
Track four quantities:
- Raw address quantity: tokens controlled by the inspected address at the checkpoint.
- Covered protocol quantity: underlying tokens in verified LP, vault, stake, or escrow positions.
- Estimated actor quantity: combined exposure of corroborated related addresses.
- Executable quantity and value: the reviewed size that a current route can price under stated constraints.
| Evidence pattern | What it means |
|---|---|
| Five buys, one wallet, rising net quantity | One address accumulated in the covered sequence |
| Five wallets, one parent, synchronized buys | Independence is doubtful; estimate actor exposure |
| Falling wallet balance, tokens sent to a vault | Spot balance fell; economic exposure may remain |
| Large marked position, weak full-size quote | Headline value overstates current exitability |
On Solana, one owner can control several token accounts for the same mint. Summing holder-table rows without checking owners can overstate the number of independent holders. Conversely, reviewing only an associated token account can miss other accounts and protocol-held inventory.
Follow the Solana wallet holdings workflow to reconcile native SOL, token accounts, decimals, protocol positions, price coverage, and executable value. Keep the actor estimate separate from the raw holder count so relationship assumptions do not become hidden facts.
6. KOL involvement
Check whether tracked KOL wallets are in the token, then check how they are in it. A quiet holder is different from someone who bought, posted, and distributed into the attention they created.
The KOL feed shows entries and exits that an influencer's timeline may not.
False positive: KOL presence is not validation. Plenty of tracked wallets are in tokens as exit liquidity farmers themselves. Weight the wallet's track record, not its follower count.
7. DCA flow
Jupiter DCA orders are a quieter conviction signal. A recurring buy over days or weeks differs from one market buy.
Active orders on the Live DCA Feed can indicate a longer horizon. Widespread cancellations are the mirror-image warning. Read the Jupiter DCA lifecycle guide before counting headline deposits as future pressure.
False positive: a single large DCA can be a whale exiting a hedge or doing something unrelated to conviction in this token. Look for multiple independent orders, not one big one.
Run a DCA source-integrity check
Scheduled flow is useful only when the source and order are both current enough for the decision window. Record two clocks:
- Source clock: when the feed or indexer last updated.
- Order clock: when the order opened, last filled, and should fill again.
On September 2, 2026, the public Live DCA Feed warned that updates were delayed by about 13 days and two hours. Its first visible USDC-to-MET records came from the same abbreviated wallet and included completed, canceled, and overdue states. The overdue order displayed $2,000 remaining but no fills.
That sample cannot support a current-demand claim. The source delay exceeds an intraday or multi-day decision window, the rows do not represent independent buyers, and two terminal states have no remaining commitment.
Use this decision table before DCA affects the token verdict:
| Observation | Due-diligence treatment |
|---|---|
| Active, recently filled, fresh source | Count defensible remaining balance as possible future flow |
| Completed buy | Record as historical execution, not future demand |
| Canceled order | Exclude unused balance from pressure |
| Overdue order | Require a recent signature or account-state update |
| Several rows from one wallet or cluster | Count one estimated actor, then reconcile net exposure |
| Source older than the decision window | Keep as a historical lead only |
8. Funding trails
For any wallet that matters, including top holders, repeat buyers, and fresh clusters, trace where its SOL came from. Shared funding can collapse several addresses into one actor.
Intermediate hops that terminate at the deployer may reveal team control. The full method is in How to Track Solana Wallets Before the Crowd Moves.
False positive: popular CEX hot wallets fund thousands of unrelated users. A shared CEX withdrawal source is weak evidence; a shared fresh intermediate wallet is strong evidence.
9. Social vs on-chain divergence
When the Telegram is euphoric and the chain shows top holders trickling out, believe the chain. The divergence itself is the signal: loud social plus quiet distribution is the classic exit setup, because attention is being manufactured precisely to absorb the selling.
The inverse divergence is more interesting: quiet socials plus steady on-chain accumulation from credible wallets is what early positioning usually looks like.
False positive: holders moving tokens to a new wallet, a CEX for custody reasons, or into an LP position can look like distribution. Confirm the destination before calling it a sell.
10. The exit liquidity reality check
Last check, and the one that overrides everything above: can you actually get out? Take your intended position size and ask what the price impact of selling it would be against current pool depth. Ask it again assuming you're selling during a drawdown, when depth is thinner and everyone else has the same idea.
Caveat: thin liquidity is a real execution constraint, but the estimate still depends on route freshness, fees, slippage settings, transfer taxes or token restrictions, competing trades, and whether liquidity changes before execution. Save the quote time and test more than one size.
Require a cross-layer consistency check
Before writing the final verdict, compare the identity, distribution, behavior, and exitability layers against one another. The conclusion must explain any material contradiction rather than averaging it away.
- Broad raw holder counts do not offset one actor-adjusted cluster that can overwhelm the pool.
- Repeat buys do not prove accumulation when transfers or nearby sells leave net exposure flat.
- A verified LP lock does not offset shallow active liquidity or a concentrated token supply.
- A strong wallet history does not validate a different mint, pool, or newly funded sub-wallet.
- A fresh executable quote does not prove the route will survive simultaneous selling or liquidity removal.
Use pass, fail, or unresolved for each layer. An unresolved identity or exitability layer blocks a positive due-diligence conclusion because the asset or the practical exit is not yet established.
Add a stop rule and an evidence-expiry time
A checklist is useful only if it changes the decision. Define the stop conditions before research begins so excitement cannot turn every failed check into a request for more evidence.
| State | Decision |
|---|---|
| Wrong or unresolved mint, pool, or token program | Stop; identity is not established |
| Material actor concentration cannot be bounded | Stop or size as an unresolved concentration risk |
| LP controller or withdrawal power is unresolved | Stop until the removal path is understood |
| Full-size sell has no acceptable protected output | Reduce size to a tested rung or skip |
| Evidence is older than the decision window | Re-run the affected checks |
Assign an expiry trigger to each passing layer. Mint identity may remain stable until an authority or canonical mapping changes. Holder, wallet, DCA, and liquidity evidence can expire much faster after transfers, fills, pool changes, or volatility.
The final note should say which evidence is still current, which evidence is historical, and which event forces a new review. A ten-minute check performed before a liquidity withdrawal is not a current pass afterward.
How long should Solana token due diligence take?
For most tokens, spend under ten minutes because concentration, insider share, and LP status filter out many weak candidates early.
Reserve the full pass for tokens that clear those filters and justify real size. The goal is not a perfect score. It is knowing which risks you accept and sizing accordingly.
Run the checklist, starting with the scan
Checks 1, 2, and 3 cover concentration, insiders, and clusters. Stalkchain compresses them into one view.
Paste the token into insider scan, inspect holders and connections, then cross-reference wallet histories with the fresh wallets feed. Wallet evidence is more useful than a clean chart when supply control is the risk.
During the September 26, 2026 public verification, Insider Scan loaded its beta ranking interface but showed no ranking rows. Fresh Wallets Feed loaded its filters and transaction columns but reported zero covered rows and a warming-up state.
Those routes remain useful workflow entry points, but neither empty state is evidence that a mint has no insiders or fresh-wallet activity.
When a native feed is empty or stale, continue with the exact mint, signatures, token-account owners, and current pool state through a compatible explorer or RPC source. Record that the product discovery layer had no usable rows at the checkpoint; do not silently substitute missing coverage with a pass.
If the launch cohort matters, reconstruct the first buyers of the Solana token, collapse linked wallets into estimated actors, and follow their later sells. Early access is useful evidence only when paired with funding and current exposure.
Final checklist
- Verify the token mint, pool, and venue.
- Distinguish the exact mint from its canonical asset and other variants.
- Record token program, decimals, authorities, source, and checkpoint time.
- Exclude infrastructure wallets from concentration calculations.
- Trace deployer, insider, first-buyer, and fresh-wallet funding.
- Separate early-execution evidence from bundle and ownership claims.
- Check LP ownership, lock conditions, and removal rights.
- Compare repeat buyers with top-holder selling.
- Reconcile successful signatures into net wallet and actor exposure.
- Treat KOL and DCA activity as context, not validation.
- Verify transfers before labeling them buys or sells.
- Estimate slippage for your full intended exit.
- Record missing data and unresolved attribution.
- Define stop conditions and expiry triggers before entering.
- Size only for risks you can explain and absorb.
FAQ
What is the fastest Solana token check?
Verify the mint, inspect non-infrastructure holder concentration, identify deployer-linked or coordinated wallets, and test liquidity depth. These checks eliminate many weak launches before deeper research.
Does a canonical token mapping prove a Solana token is safe?
No. A canonical mapping helps identify and group known variants. It does not prove issuer authorization, contract safety, holder quality, liquid exits, or future value. Run mint-level authority, pool, holder, and transaction checks separately.
What holder concentration is safe?
There is no universal percentage. Token age, circulating supply, LP and burn addresses, vesting, and wallet relationships all change the interpretation. Several linked wallets should be treated as one actor.
Does locked liquidity make a token safe?
No. A lock can reduce immediate LP-removal risk while insiders still control supply, contracts retain dangerous permissions, or the pool remains too shallow for a practical exit.
Can first buyers reveal insiders?
They can reveal coordination signals such as shared funding, synchronized entries, and deployer adjacency. Those patterns support a risk assessment, but they do not prove real-world identity.
Do several buys from one wallet prove accumulation?
No. Reconcile the complete sequence, including sells, transfers, failed attempts, routed legs, and protocol positions. Accumulation means covered net exposure increased over the stated window, not merely that several buy-labeled rows appeared.
How long should due diligence take?
Most weak tokens fail a focused first pass in minutes. Spend longer on funding graphs, wallet histories, contract controls, and exit modeling when the position size or uncertainty is material.