the bunker experiment

Every trade of this coin pushes a slice of its liquidity out of an account held by a normal Solana key and into a vault that only a hash signature can open. Buys push. Sells push twice as hard. Nothing ever comes back the other way. When the last slice crosses, no elliptic curve key can touch any of it, and a quantum computer has nothing left to break. The coin is a standard pump.fun coin paired with SOL, the coin on pump.fun.

value
Value as a line, one point per minute, oldest on the left, the last point live. Each mark underneath is one minute of trading: taller means more liquidity went into the bunker in that minute.

What this is

A quantum computer big enough to run Shor's algorithm can work a private key out of a public key. Every normal Solana account is guarded by exactly that kind of key. The bunker mode idea is simple: if that day comes early, anything that matters should already be sitting behind hash signatures, which a quantum computer cannot shortcut the same way.

This is that idea run as a live test on one pump.fun coin. The coin's own liquidity, built from its creator fees, starts in an exposed account. Each trade moves part of it into the bunker. Nobody votes on it and nobody can reverse it. The number below is how far the test has got.

Bunkered

of the experiment's liquidity is out of reach of any elliptic curve key, by the rule, after moves.
price
value
pool liquidity
phase
pressure
from buys
from sells
exposed share
bunkered share
halvings
trades counted
counting from
holders
contract

The rule

moves onevery trade
buy weight1
sell weight2
pressure per halving2,048 SOL
halvings to seal8
pressure at seal16,384 SOL
directionexposed to bunkered only
reverse pathnone
team cut0%
runs on a timerno
exposedbunkered
Each cell is one 256th of the experiment's liquidity. A filled cell is in the bunker. The outlined cells are still held by a key a quantum computer could break. Cells only ever fill.

Next halving

012345678
pressure now
next halving at
that is, in buys
or, in sells
exposed after it

Latest move

trade
pressure
moved
move
when
side
size
weight
pressure added
share moved
bunkered after
wallet
transaction

Moves

timesidesizemovedbunkeredtx

Largest moves

whensidesizemovedwallet

How it moves

Fees build the liquidity. Every trade of the coin pays pump.fun's standard fee, on the curve and on PumpSwap after graduation. The creator's share is claimed into the exposed account. That is the experiment's liquidity. There is no extra tax on the coin and nothing is taken out for a team.

A trade adds pressure. Each trade adds its SOL size to a running total called pressure. A buy adds its size once. A sell adds its size twice. Pressure never goes down, and there is no timer anywhere in the rule. If nobody trades, nothing happens.

Pressure sets the split. The exposed share is one half raised to the power of pressure divided by 2,048 SOL. So every 2,048 SOL of pressure cuts what is still exposed in half. The difference between the share before a trade and the share after it is what that trade sends to the bunker.

The bunker keeps it. The bunker is a program vault. Anyone can put funds in. The only instruction that acts on what is inside needs a one time hash signature, and that instruction can only place the funds as liquidity for this coin. After eight halvings the remainder crosses in one move and the exposed account's authority is closed.

The curve

The whole experiment is one line: E = 2 ^ ( 0 − P / 2,048 ). E is the share still exposed and P is pressure in SOL. Because the split depends only on total pressure, the order of trades does not matter and splitting one trade into many small ones changes nothing. The only way to move the curve is to trade, and trading pays fees, which add to the liquidity being moved.

halvingpressureexposedbunkeredcellscrossedtx
00 SOL100%0%0
12,048 SOL50%50%128
24,096 SOL25%75%192
36,144 SOL12.5%87.5%224
48,192 SOL6.25%93.75%240
510,240 SOL3.125%96.875%248
612,288 SOL1.5625%98.4375%252
714,336 SOL0.78125%99.21875%254
816,384 SOL0%100%256
Fixed points of the curve, and when the live coin crossed each one.
what a trade would move right now
sizeas a buyas a sell
0.1 SOL
0.5 SOL
1 SOL
5 SOL
10 SOL
50 SOL
Computed from the pressure at this moment. A sell always moves what a buy of twice the size would. The numbers shrink as the exposed side empties.

Two kinds of key

A normal Solana key is an ed25519 key. Its safety rests on one math problem, the elliptic curve discrete logarithm. Classical computers cannot solve it. A large, error corrected quantum computer running Shor's algorithm can, and once it can, a public key is enough to forge a signature. On Solana an account's address is its public key, so every funded account is already showing the thing an attacker needs.

A hash signature rests on something different: that a hash function cannot be run backwards. The best known quantum attack on that, Grover's algorithm, only gives a square root speedup. A 256 bit hash keeps about 128 bits of strength against it, which is still far out of reach. That is why hash signatures are the fallback people point to when they talk about bunker mode.

The price is size and reuse. A hash signature is over a thousand bytes and each key can sign exactly once. That is awkward for a wallet and fine for a vault that almost never needs to sign. The bunker is built around that tradeoff.

exposed accountbunker vault
guarded byed25519 keyWinternitz one time signature
rests onelliptic curve discrete logSHA 256 preimage resistance
best quantum attackShor, breaks it outrightGrover, square root only
strength left afternoneabout 128 bits
public key32 bytes32 byte tree root
signature64 bytes1,088 bytes plus a 256 byte path
uses per keyunlimitedone
keys availableone256
what it can doclaim fees, deposit to the bunkerreseat liquidity into the coin's pool
can send to a walletyes, until sealednever
funds flowout only, to the bunkerin from anyone, out only to the pool

The key tree

The bunker does not hold one hash key. It holds the root of a tree of 256 of them. Each leaf is a one time key. To act on the bunker, the signer shows a signature made with the next unused leaf and the eight hashes that connect that leaf to the root. The program checks both, then retires the leaf for good. That gives the bunker exactly 256 actions in its whole life. The seed the leaves are grown from is kept offline, and even with it, the only thing a signature can do is reseat the bunker's funds as liquidity for this coin.

rootleaves
256 one time keys under one root. A lit leaf has been used and can never sign again. The lit path is what the next signature has to prove.
hashSHA 256
width256
message digits32
checksum digits2
chains34
chain length255 hashes
signature1,088 bytes
auth path8 hashes, 256 bytes
total proof1,344 bytes
transaction limit1,232 bytes
so the proof iswritten in two parts, then checked
worst case check8,670 hashes plus 8
tree root
next leaf
leaves used
leaves left
reseats so far

The bunker account

Everything the program knows fits in one account of 120 bytes. The map below is that account, byte by byte. When the account exists on chain the cells show its real contents, read straight from a Solana node, and the table decodes them. The site also computes the same quantities on its own from the coin's public trades, so the two can be compared. If they ever disagree, the row marked drift says by how much.

000020040060080100
offsetbytesfieldtypevalue
08discriminatorbytes
832mintpubkey
4032tree rootbytes
722next leafu16
741halvingsu8
751sealedu8
764trades countedu32
808pressureu64 lamports
888buy volumeu64 lamports
968sell volumeu64 lamports
1048exposed balanceu64 lamports
1128bunkered balanceu64 lamports
site against chain
bunkered share, by the rule
bunkered share, in the account
drift
pressure, site
pressure, account
trades, site
trades, account
account read at

Accounts

accountroleaddressSOL
cointhe pump.fun mint
programthe bunker program
statethe 120 byte account mapped above
exposedholds liquidity under a normal key until it is moved
bunkerholds liquidity behind the key tree

The rules

ruledetail
Trades are the only triggerPressure changes when the coin is traded and at no other moment. There is no schedule, no countdown and no manual step.
Buys count once, sells count twiceA buy adds its SOL size to pressure. A sell adds double. Selling into the coin hardens it faster than buying does.
Standard fees, nothing extraThe coin carries no tax. pump.fun's standard fee applies on the curve and on PumpSwap. The creator share is the experiment's liquidity and all of it enters the exposed account.
One directionFunds go from the exposed account to the bunker. No instruction moves funds from the bunker to the exposed account or to any wallet.
Half per 2,048 SOLEach 2,048 SOL of pressure halves the exposed share. The amount a trade moves is the drop in exposed share that its pressure causes.
Eight halvings, then sealedAt 16,384 SOL of pressure the remaining exposed share crosses in a single move. The exposed account's authority is closed in the same transaction.
The bunker signs with hashesThe only instruction that acts on bunkered funds is reseat. It requires a Winternitz signature from the next unused leaf of the key tree and it can only place funds as liquidity for this coin.
256 signatures, everEach reseat retires one leaf. When the leaves are gone the bunker can never act again and whatever it holds stays where it is.
The program cannot changeThe program's upgrade authority is removed at launch, so no key of any kind, broken or not, can rewrite the rule.
A normal key only pays the feeTransactions that touch the bunker are still paid for by an ordinary Solana account. That account pays network fees and nothing else. It has no power over the funds.

What cannot happen

Pressure cannot fall. It is a sum of positive numbers. No trade, account or signature subtracts from it.

The bunkered share cannot fall. It is a function of pressure alone, and that function only rises.

The bunker cannot pay a wallet. Its single outbound path ends in the coin's own pool. There is no withdraw instruction to call.

A leaf cannot sign twice. The account stores the index of the next unused leaf and only ever counts up.

Order cannot be gamed. The split depends on total pressure, so trading early, late, in one piece or in many gives the same result for the same SOL.

A keeper cannot pull funds back. The keeper that reports trades to the program can make hardening run ahead or behind. It cannot make it run in reverse, and this page shows the drift.

A broken key cannot reach the bunker. After a quantum break of ed25519, an attacker gains whatever the exposed key controls and nothing more. The bunker never trusted that key.

Sealing cannot be undone. Once the exposed authority is closed there is no account left for an elliptic curve key to control.

Questions

Is the coin itself quantum safe?

No. It is a normal pump.fun coin on Solana and holder wallets use normal keys. The experiment protects one thing, the liquidity it owns, and shows how far that protection has gone.

What exactly is being moved?

The experiment's own liquidity: SOL claimed from the coin's creator fees, and the pool position that SOL funds. It is not holders' tokens and not the main pump.fun pool.

Why do sells count double?

A wave of selling is when a pool most needs to be out of reach. Weighting sells at two means fear pushes liquidity into the bunker faster than calm does.

Can someone push it by wash trading?

Yes, and that is fine. Every trade pays fees, the fees add to the liquidity, and all the trade can do is bunker more of it sooner.

What happens if nobody trades?

Nothing. There is no timer. Pressure stays where it is and so does the split.

Who holds the hash keys?

The seed for the key tree is generated before launch and kept offline. Its only power is to sign a reseat, which sends bunkered funds into this coin's pool as liquidity.

What is a reseat for?

When the coin moves from the bonding curve to PumpSwap, or when new fees have piled up in the bunker, a reseat places those funds into the live pool so they work as depth. It is the one thing the bunker can do, and it can do it 256 times.

What does sealed mean?

Pressure reached 16,384 SOL. All of the experiment's liquidity is behind the key tree and the exposed account no longer has an authority. From then on new fees are claimed straight into the bunker.

Why not use a newer signature scheme?

Lattice schemes are smaller but newer and heavier to verify on chain. Hash signatures need nothing but a hash function Solana already runs natively, and their security argument is the oldest and plainest there is.

How can I check any of this?

Every move in the tables links to its trade. The accounts table links to the addresses. The byte map is the program's account as it sits on chain, and the drift row compares it with this page's own count.

Terms

termmeaning
exposedHeld by an account whose authority is an ed25519 key.
bunkeredHeld by the program vault that only acts on a hash signature.
pressureRunning total of trade size in SOL, with sells counted twice.
halvingEach 2,048 SOL of pressure, which halves the exposed share.
moveThe transfer from exposed to bunkered caused by one trade.
share movedThe part of total liquidity one trade sent across, in percent.
cellOne 256th of the experiment's liquidity.
sealedThe state after eight halvings, with nothing left exposed.
reseatThe bunker's only action: placing its funds into the coin's pool.
leafOne of the 256 one time keys under the bunker's root.
auth pathThe eight hashes proving a leaf belongs to the root.
driftGap between this page's count and the program's account.
ShorThe quantum algorithm that breaks elliptic curve keys.
GroverThe quantum search that only halves a hash's bit strength.