Every trade of this coin pushes a slice of its liquidity out of an account held by a normal Solana key and into a vault that only a hash signature can open. Buys push. Sells push twice as hard. Nothing ever comes back the other way. When the last slice crosses, no elliptic curve key can touch any of it, and a quantum computer has nothing left to break. The coin is a standard pump.fun coin paired with SOL, the coin on pump.fun.
A quantum computer big enough to run Shor's algorithm can work a private key out of a public key. Every normal Solana account is guarded by exactly that kind of key. The bunker mode idea is simple: if that day comes early, anything that matters should already be sitting behind hash signatures, which a quantum computer cannot shortcut the same way.
This is that idea run as a live test on one pump.fun coin. The coin's own liquidity, built from its creator fees, starts in an exposed account. Each trade moves part of it into the bunker. Nobody votes on it and nobody can reverse it. The number below is how far the test has got.
| price | |
| value | |
| pool liquidity | |
| phase | |
| pressure | |
| from buys | |
| from sells | |
| exposed share | |
| bunkered share | |
| halvings | |
| trades counted | |
| counting from | |
| holders | |
| contract |
| moves on | every trade |
| buy weight | 1 |
| sell weight | 2 |
| pressure per halving | 2,048 SOL |
| halvings to seal | 8 |
| pressure at seal | 16,384 SOL |
| direction | exposed to bunkered only |
| reverse path | none |
| team cut | 0% |
| runs on a timer | no |
| pressure now | |
| next halving at | |
| that is, in buys | |
| or, in sells | |
| exposed after it |
| move | |
| when | |
| side | |
| size | |
| weight | |
| pressure added | |
| share moved | |
| bunkered after | |
| wallet | |
| transaction |
| time | side | size | moved | bunkered | tx |
|---|
| when | side | size | moved | wallet |
|---|
Fees build the liquidity. Every trade of the coin pays pump.fun's standard fee, on the curve and on PumpSwap after graduation. The creator's share is claimed into the exposed account. That is the experiment's liquidity. There is no extra tax on the coin and nothing is taken out for a team.
A trade adds pressure. Each trade adds its SOL size to a running total called pressure. A buy adds its size once. A sell adds its size twice. Pressure never goes down, and there is no timer anywhere in the rule. If nobody trades, nothing happens.
Pressure sets the split. The exposed share is one half raised to the power of pressure divided by 2,048 SOL. So every 2,048 SOL of pressure cuts what is still exposed in half. The difference between the share before a trade and the share after it is what that trade sends to the bunker.
The bunker keeps it. The bunker is a program vault. Anyone can put funds in. The only instruction that acts on what is inside needs a one time hash signature, and that instruction can only place the funds as liquidity for this coin. After eight halvings the remainder crosses in one move and the exposed account's authority is closed.
The whole experiment is one line: E = 2 ^ ( 0 − P / 2,048 ). E is the share still exposed and P is pressure in SOL. Because the split depends only on total pressure, the order of trades does not matter and splitting one trade into many small ones changes nothing. The only way to move the curve is to trade, and trading pays fees, which add to the liquidity being moved.
| halving | pressure | exposed | bunkered | cells | crossed | tx |
|---|---|---|---|---|---|---|
| 0 | 0 SOL | 100% | 0% | 0 | ||
| 1 | 2,048 SOL | 50% | 50% | 128 | ||
| 2 | 4,096 SOL | 25% | 75% | 192 | ||
| 3 | 6,144 SOL | 12.5% | 87.5% | 224 | ||
| 4 | 8,192 SOL | 6.25% | 93.75% | 240 | ||
| 5 | 10,240 SOL | 3.125% | 96.875% | 248 | ||
| 6 | 12,288 SOL | 1.5625% | 98.4375% | 252 | ||
| 7 | 14,336 SOL | 0.78125% | 99.21875% | 254 | ||
| 8 | 16,384 SOL | 0% | 100% | 256 |
| size | as a buy | as a sell |
|---|---|---|
| 0.1 SOL | ||
| 0.5 SOL | ||
| 1 SOL | ||
| 5 SOL | ||
| 10 SOL | ||
| 50 SOL |
A normal Solana key is an ed25519 key. Its safety rests on one math problem, the elliptic curve discrete logarithm. Classical computers cannot solve it. A large, error corrected quantum computer running Shor's algorithm can, and once it can, a public key is enough to forge a signature. On Solana an account's address is its public key, so every funded account is already showing the thing an attacker needs.
A hash signature rests on something different: that a hash function cannot be run backwards. The best known quantum attack on that, Grover's algorithm, only gives a square root speedup. A 256 bit hash keeps about 128 bits of strength against it, which is still far out of reach. That is why hash signatures are the fallback people point to when they talk about bunker mode.
The price is size and reuse. A hash signature is over a thousand bytes and each key can sign exactly once. That is awkward for a wallet and fine for a vault that almost never needs to sign. The bunker is built around that tradeoff.
| exposed account | bunker vault | |
|---|---|---|
| guarded by | ed25519 key | Winternitz one time signature |
| rests on | elliptic curve discrete log | SHA 256 preimage resistance |
| best quantum attack | Shor, breaks it outright | Grover, square root only |
| strength left after | none | about 128 bits |
| public key | 32 bytes | 32 byte tree root |
| signature | 64 bytes | 1,088 bytes plus a 256 byte path |
| uses per key | unlimited | one |
| keys available | one | 256 |
| what it can do | claim fees, deposit to the bunker | reseat liquidity into the coin's pool |
| can send to a wallet | yes, until sealed | never |
| funds flow | out only, to the bunker | in from anyone, out only to the pool |
The bunker does not hold one hash key. It holds the root of a tree of 256 of them. Each leaf is a one time key. To act on the bunker, the signer shows a signature made with the next unused leaf and the eight hashes that connect that leaf to the root. The program checks both, then retires the leaf for good. That gives the bunker exactly 256 actions in its whole life. The seed the leaves are grown from is kept offline, and even with it, the only thing a signature can do is reseat the bunker's funds as liquidity for this coin.
| hash | SHA 256 |
| width | 256 |
| message digits | 32 |
| checksum digits | 2 |
| chains | 34 |
| chain length | 255 hashes |
| signature | 1,088 bytes |
| auth path | 8 hashes, 256 bytes |
| total proof | 1,344 bytes |
| transaction limit | 1,232 bytes |
| so the proof is | written in two parts, then checked |
| worst case check | 8,670 hashes plus 8 |
| tree root | |
| next leaf | |
| leaves used | |
| leaves left | |
| reseats so far |
Everything the program knows fits in one account of 120 bytes. The map below is that account, byte by byte. When the account exists on chain the cells show its real contents, read straight from a Solana node, and the table decodes them. The site also computes the same quantities on its own from the coin's public trades, so the two can be compared. If they ever disagree, the row marked drift says by how much.
| offset | bytes | field | type | value |
|---|---|---|---|---|
| 0 | 8 | discriminator | bytes | |
| 8 | 32 | mint | pubkey | |
| 40 | 32 | tree root | bytes | |
| 72 | 2 | next leaf | u16 | |
| 74 | 1 | halvings | u8 | |
| 75 | 1 | sealed | u8 | |
| 76 | 4 | trades counted | u32 | |
| 80 | 8 | pressure | u64 lamports | |
| 88 | 8 | buy volume | u64 lamports | |
| 96 | 8 | sell volume | u64 lamports | |
| 104 | 8 | exposed balance | u64 lamports | |
| 112 | 8 | bunkered balance | u64 lamports |
| bunkered share, by the rule | |
| bunkered share, in the account | |
| drift | |
| pressure, site | |
| pressure, account | |
| trades, site | |
| trades, account | |
| account read at |
| account | role | address | SOL |
|---|---|---|---|
| coin | the pump.fun mint | ||
| program | the bunker program | ||
| state | the 120 byte account mapped above | ||
| exposed | holds liquidity under a normal key until it is moved | ||
| bunker | holds liquidity behind the key tree |
| rule | detail |
|---|---|
| Trades are the only trigger | Pressure changes when the coin is traded and at no other moment. There is no schedule, no countdown and no manual step. |
| Buys count once, sells count twice | A buy adds its SOL size to pressure. A sell adds double. Selling into the coin hardens it faster than buying does. |
| Standard fees, nothing extra | The coin carries no tax. pump.fun's standard fee applies on the curve and on PumpSwap. The creator share is the experiment's liquidity and all of it enters the exposed account. |
| One direction | Funds go from the exposed account to the bunker. No instruction moves funds from the bunker to the exposed account or to any wallet. |
| Half per 2,048 SOL | Each 2,048 SOL of pressure halves the exposed share. The amount a trade moves is the drop in exposed share that its pressure causes. |
| Eight halvings, then sealed | At 16,384 SOL of pressure the remaining exposed share crosses in a single move. The exposed account's authority is closed in the same transaction. |
| The bunker signs with hashes | The only instruction that acts on bunkered funds is reseat. It requires a Winternitz signature from the next unused leaf of the key tree and it can only place funds as liquidity for this coin. |
| 256 signatures, ever | Each reseat retires one leaf. When the leaves are gone the bunker can never act again and whatever it holds stays where it is. |
| The program cannot change | The program's upgrade authority is removed at launch, so no key of any kind, broken or not, can rewrite the rule. |
| A normal key only pays the fee | Transactions that touch the bunker are still paid for by an ordinary Solana account. That account pays network fees and nothing else. It has no power over the funds. |
Pressure cannot fall. It is a sum of positive numbers. No trade, account or signature subtracts from it.
The bunkered share cannot fall. It is a function of pressure alone, and that function only rises.
The bunker cannot pay a wallet. Its single outbound path ends in the coin's own pool. There is no withdraw instruction to call.
A leaf cannot sign twice. The account stores the index of the next unused leaf and only ever counts up.
Order cannot be gamed. The split depends on total pressure, so trading early, late, in one piece or in many gives the same result for the same SOL.
A keeper cannot pull funds back. The keeper that reports trades to the program can make hardening run ahead or behind. It cannot make it run in reverse, and this page shows the drift.
A broken key cannot reach the bunker. After a quantum break of ed25519, an attacker gains whatever the exposed key controls and nothing more. The bunker never trusted that key.
Sealing cannot be undone. Once the exposed authority is closed there is no account left for an elliptic curve key to control.
Is the coin itself quantum safe?
No. It is a normal pump.fun coin on Solana and holder wallets use normal keys. The experiment protects one thing, the liquidity it owns, and shows how far that protection has gone.
What exactly is being moved?
The experiment's own liquidity: SOL claimed from the coin's creator fees, and the pool position that SOL funds. It is not holders' tokens and not the main pump.fun pool.
Why do sells count double?
A wave of selling is when a pool most needs to be out of reach. Weighting sells at two means fear pushes liquidity into the bunker faster than calm does.
Can someone push it by wash trading?
Yes, and that is fine. Every trade pays fees, the fees add to the liquidity, and all the trade can do is bunker more of it sooner.
What happens if nobody trades?
Nothing. There is no timer. Pressure stays where it is and so does the split.
Who holds the hash keys?
The seed for the key tree is generated before launch and kept offline. Its only power is to sign a reseat, which sends bunkered funds into this coin's pool as liquidity.
What is a reseat for?
When the coin moves from the bonding curve to PumpSwap, or when new fees have piled up in the bunker, a reseat places those funds into the live pool so they work as depth. It is the one thing the bunker can do, and it can do it 256 times.
What does sealed mean?
Pressure reached 16,384 SOL. All of the experiment's liquidity is behind the key tree and the exposed account no longer has an authority. From then on new fees are claimed straight into the bunker.
Why not use a newer signature scheme?
Lattice schemes are smaller but newer and heavier to verify on chain. Hash signatures need nothing but a hash function Solana already runs natively, and their security argument is the oldest and plainest there is.
How can I check any of this?
Every move in the tables links to its trade. The accounts table links to the addresses. The byte map is the program's account as it sits on chain, and the drift row compares it with this page's own count.
| term | meaning |
|---|---|
| exposed | Held by an account whose authority is an ed25519 key. |
| bunkered | Held by the program vault that only acts on a hash signature. |
| pressure | Running total of trade size in SOL, with sells counted twice. |
| halving | Each 2,048 SOL of pressure, which halves the exposed share. |
| move | The transfer from exposed to bunkered caused by one trade. |
| share moved | The part of total liquidity one trade sent across, in percent. |
| cell | One 256th of the experiment's liquidity. |
| sealed | The state after eight halvings, with nothing left exposed. |
| reseat | The bunker's only action: placing its funds into the coin's pool. |
| leaf | One of the 256 one time keys under the bunker's root. |
| auth path | The eight hashes proving a leaf belongs to the root. |
| drift | Gap between this page's count and the program's account. |
| Shor | The quantum algorithm that breaks elliptic curve keys. |
| Grover | The quantum search that only halves a hash's bit strength. |