The Rug Pull: How a Hidden Bitcoin Prize Was Extracted From SuperMassive's NFT Experiment
An NFT-based social experiment built on game theory and quantum superposition promised a Bitcoin prize to whoever ended up holding the right token. It ended instead with a quiet exploit, a profitable flip, and a project team that went silent — leaving observers to debate whether they'd witnessed an elaborate art piece running exactly as designed, or a cover-up dressed up as performance art.
The project, called "The Rug Pull," was built by SuperMassive. Its premise: 12 visually identical NFTs were minted, and a single Bitcoin was hidden inside one of them. Holders could "unlock" their NFT to learn whether they were the lucky one — but doing so would publicly reveal the result for everyone to see. The official rules, as described at launch, read as follows:

There are 12 NFTs . All seemingly identical. Hidden in one of those NFTs is a Bitcoin.**You do not know which one that Bitcoin is in. However you can find out by unlocking the NFT, which will tell you whether that NFT holds the bitcoin or not.
However, the moment you do so, the status of your NFT - whether it holds the BTC or not - will be viewable.
So there is a 1 in 12 chance that you are in possession of a bitcoin. and there is an 11 in 12 chance that you are not.
What's it worth to take that risk and look inside? If Bitcoin is at $10K, what's it worth? If Bitcoin's at $100K, what's it worth?
Any one of the other 11 people who own the NFT could pull the rug by opening their NFT and finding the bitcoin, causing the value of the other NFTs to crash. Alternatively they could open their NFT and find no bitcoin, causing the value of the other 11 to rise.
In effect, unlocking your own token risked crashing (or inflating) the market value of everyone else's — a built-in incentive to keep the box closed.
At auction, the full set of 12 NFTs brought in roughly $65,000 in aggregate, paid entirely in $MEME. Individual sale prices ranged from about $4,080 to $8,400. Against Bitcoin's price at the time — around $18,450 — that put the combined bids at close to a 250% premium over the BTC prize each NFT theoretically had a 1-in-12 shot at containing.
The individual sales broke down as follows:
| NFT # | $MEME paid | Owner |
|---|---|---|
| NFT 70 | 21.50 | 0x196A3Dc8446920Cef0f0d1f6Bf7Ba5b40702C79f |
| NFT 71 | 23.12 | 0xca768c37ba6EC3d67bE7B47bbE1F1C94CA216f46 |
| NFT 72 | 21.50 | 0x6f9BB7e454f5B3eb2310343f0E99269dC2BB8A1d |
| NFT 73 | 35.01 | 0xf305F90B19CF66fC2D038f92a26440B66cF858F6 |
| NFT 74 | 33.00 | 0xCb28f90dCAb551f9FC17aFDd85a09495a87F078E |
| NFT 75 | 25.00 | 0xcbc7d0Ff51D37b60ba741bF566496BBa53b5eea2 |
| NFT 76 | 22.00 | 0x8B6250bAB1A60232e4154aB1F2EE7f5DF2A9C151 |
| NFT 77 | 35.00 | 0xb7fD6B9183fbb8aBb2A3066C41770635Babc433F |
| NFT 78 | 29.00 | 0x6f9BB7e454f5B3eb2310343f0E99269dC2BB8A1d |
| NFT 79 | 20.00 | 0x4F50d47D20380172746527bbeAa274940C38EFAC |
| NFT 80 | 17.00 | 0x6f9BB7e454f5B3eb2310343f0E99269dC2BB8A1d |
| NFT 81 | 25.00 | 0x1d5E65a087eBc3d03a294412E46CE5D6882969f4 |
Given the setup, the mathematically sound move for any holder was to sit tight and never unlock their token — leaving its value to track roughly one-twelfth of Bitcoin's price over time. As Robin of SuperMassive put it, the structure mirrored the classic prisoner's dilemma: collectively, everyone was better off if nobody looked.
That logic assumed, however, that opening your own NFT was the only route to the Bitcoin. It wasn't. Someone found a way to sidestep the entire dilemma: exploiting the underlying code let an attacker pull the BTC prize out of whichever of the twelve NFTs actually held it, without needing to own — or even risk opening — the winning token themselves.
Several disappointed participants brought the story to rekt, arguing not just that the experiment had failed, but that its creators had tried to quietly bury what happened. Rekt's OPSEC team looped in the NFT specialists at BlackPool to help dig into the transaction history.
The trail started early. On November 11th — the day the auction opened — an account called RStudios showed up in the project's Discord. That wallet doesn't appear to have any prior connection to MEME, but its on-chain history shows activity across other NFT projects, also visible via its OpenSea profile.
Roughly a month later, on December 26th, the exploit was executed. The relevant on-chain activity that day proceeded in three stages:
First, RStudios bought one of the twelve NFTs directly from a holder known as y_kymin, paying 13,000 DAI on the secondary market after negotiating the price down.
Second, through a chain of follow-up transactions (one, two, three), the attacker pulled the wrapped Bitcoin out of the NFT via the code flaw — without needing that specific token to be the "winning" one at all.
Third, RStudios resold the now-empty NFT for 1.7 ETH, walking away with 1 WBTC plus 1.7 ETH, minus the original 13,000 DAI purchase cost.
By RStudios' own account, the attack took a couple of days of preparation and "wasn't easy." Reselling the drained NFT afterward drew further criticism from the community, though RStudios did offer to buy the token back.
The project's creators have maintained that nothing technically went wrong, even as some participants call the outcome a failed experiment. Rekt put the question to Robin directly — was the ending an unfair result, or simply code exploits functioning as an accepted part of the game — in the interview below.
rekt: It's been just over a week since "The Rug Pull" experiment concluded. Are you satisfied with the way it played out?
Robin: That depends on what you mean by "the experiment." The Rug Pull was never just the auction and the NFT mechanic — it was the whole arc, including the build-up and the transmedia storytelling around greed and trust.
That said, how the Bitcoin actually got claimed felt like a flat, premature conclusion to what we'd envisioned. The game was designed to pressure participants into confronting their own greed. What actually happened was that one of the twelve holders sold their NFT for a modest profit, breaking the fragile trust the group had built. It just confirmed something we already knew — a chain is only as strong as its weakest link.
In this case, it didn't take much for someone to cash out. I'd flagged that exact risk in the original promotional video: how much can you really trust the other NFT holders? Cooperation was always the better outcome, but I'd hoped for more upward pressure from Bitcoin's price to really bring the tension to life.
So — not unhappy, but I do feel there was more potential left on the table. That said, we did get an answer to the underlying question: is the art worth more, or the crypto hidden inside it? In this case, the crypto won out. Disappointing, but not surprising.
rekt: RStudios was able to pull the Bitcoin out without anyone noticing. If they hadn't publicized what they'd done, what do you think would have happened?
Robin: Good question. We got lucky that this particular exploiter wanted credit for the cleverness of the move. To be clear, I didn't write the contracts or design the underlying mechanics myself — I can envision the concept, but execution is bound by what the network allows.
I still haven't really answered you, though. Realistically, probably nothing would have surfaced until someone opened the NFT. At that point there'd likely have been outrage, accusations, some FUD — the usual. I'd probably have then sold something, bought back a Bitcoin as restitution, and picked up some goodwill for being seen to make it right. Or something along those lines — this is crypto, we'd have found a way to land on our feet regardless. I'm not sure how badly that would have thrown off the lottery mechanics, though.
rekt: The launch was heavily promoted, but the ending passed with no real announcement. If this outcome was something you anticipated, why wasn't there a post-mortem or public statement?
Robin: Calling it an "anticipated outcome" implies we expected the code to be exploited this way — we didn't. We knew going in that the NFTs would be a target, but we were hoping that building an engaging, entertaining experience would raise the perceived value of the art itself to the point where people respected it more than they wanted to exploit it. The idea being: even knowing you could exploit something doesn't mean you will.
I'd actually tested that idea during the build-up — I deliberately exposed my own private keys and let people take my tokens. Almost everyone returned them. The one exception was someone outside our immediate community.
The timing of the exploit was rough for me personally — after the year we'd had, I'd stepped back from crypto for a stretch to spend time with family. I had actually been planning to cover it in an episode of The Defiant, but once you reached out, this felt like the better outlet for the story.
There's also a bigger assumption baked into your question — that this is over. It isn't. The NFTs still exist, there's still a community around them, and I don't see this as a full stop. Momentum has been slow heading into the new year, but the MEME team and I would like to build a next chapter — we just haven't worked out yet what that looks like.
Ultimately, we promised a rug pull, and that's exactly what happened.
rekt: The attacker apparently posted a public warning about the vulnerability a month before exploiting it. Do you think that was handled appropriately?

Robin: Depends on your framing. There's a real difference between dropping one message in a Discord channel versus privately reaching out to the team. I don't read every message in every app I use, and honestly, neither does most anyone. The team doesn't appear to have seen it.
If the goal had genuinely been to help us patch the issue, I'd expect more persistence in flagging it directly. As it stands, the attacker has a solid "told you so" on record, and I get the appeal of that. It wasn't addressed because it wasn't seen — I don't think that's a fair thing to pin on the team.
rekt: This was a genuinely novel concept, even if it didn't end cleanly. What's your boldest prediction for where NFTs go from here?
Robin: What strikes me is something like SOCKS — people buying an NFT that represents a pair of socks, never intending to actually own physical socks, just trading the represented value. That's essentially a derivative, but push the idea further and almost anything can become an NFT. Every physical object could eventually have a digital twin in some metaverse, and that opens up genuinely strange questions around production, fulfillment, sustainability, and beyond.
Digital fashion feels like the space most ready for a major moment in 2021. Once your digital record — your Instagram post, essentially — is what actually matters, owning the physical garment becomes secondary. You get into new forms of digital signaling and status without needing an actual sweatshop behind it.
I haven't thought this through nearly enough, honestly — there's clearly a lot more territory here that nobody's fully explored yet, and I'm glad to be one of the people experimenting in that space.
rekt: Thanks for your time, Robin. Anything you'd like to leave our readers with?
Robin: Don't overcommit to anything you don't fully understand. It's going to be a wild year — stay sharp.
They promised a rug pull, and a rug pull is what happened.
It's worth considering every angle here, even unlikely ones: there's no direct evidence this was an inside job, but nothing rules out involvement from someone loosely associated with the project rather than the core team itself. If so, the MEME team has good reason to be more guarded than usual right now.
The underlying code could certainly have been built more securely, but this reads more as a flawed experiment than outright negligence. Even so, it's understandable that some participants came away disappointed — in some respects, the outcome stings more than larger, more conventional hacks, precisely because of how it played out. It's the equivalent of card-counting at a children's poker game: not technically against the rules, but enough to ruin the fun for people who were simply trying something new.
Get new scam files the moment we publish them — usually 2–3 emails a week.