bunk

What bunk is

bunk is an agent attached to one coin. The coin is an ordinary pump.fun coin. Every trade of it pays pump.fun's standard fee, and part of that fee belongs to the coin's creator. bunk is the creator. It runs that money by one idea: assume the signatures every wallet relies on could stop being safe, and behave today the way you would want to have behaved on that day.

In practice that means four habits. Keep what you hold in addresses that have never signed. When an address does sign, empty it and move on. Keep every address small. And keep a record of everything in signatures made only of hashes, which do not depend on the curve at all.

Bunker mode in plain words

The worry is simple. A wallet's security rests on one piece of mathematics, the elliptic curve. If someone finds a fast way to work a private key out of a public key, by a large quantum computer or by new mathematics, wallets stop being safe, and the ones with the most in them go first.

The sensible response is calm and boring. Do not rush. Move funds to fresh addresses. Treat an address that has signed as used up. Rotate keys often if you are a signer that others depend on. Back important signatures with a second scheme built on hashes. People call that posture bunker mode. bunk is a coin whose fee engine lives that way from its first transaction, and pays holders who do the same.

What a Solana address hides, and what it does not

This matters and it is easy to get wrong. On Bitcoin an address is a hash of a public key, so until you spend, your key stays hidden. On Solana the address is the public key. A fresh Solana wallet has not shown the world a signature, but it has shown its key.

So bunk does not claim that a fresh address is invisible. What it takes from the rule is everything that still holds on Solana: balances split into small pieces so no single address is worth much, keys that sign once and are retired, and a main wallet that never rests with more than its fees. The hash part of bunker mode is carried by the second signature on every action, which is covered further down.

The surface wallet

pump.fun pays creator fees to the wallet that created the coin and to no other. That wallet has to sign every claim, so it can never be a fresh address. bunk calls it the surface wallet. It is the one exposed signer in the system, and it is treated like one: after every action it is left with gas and the small amounts still owed to holders, and nothing else.

What makes it act

Trades. bunk counts the SOL that changes hands in the coin since its last fees action. When that count passes the current threshold, it acts. A quiet coin does nothing. A busy coin acts often. There is no timer anywhere in the rules.

If a claim comes back too small to be worth recording, under 0.02 SOL, bunk holds it and adds it to the next one.

The split

Each claim is divided three ways. Between 40% and 60% is paid in SOL to holders whose wallets have never signed. 5% goes to the canary. The rest, between 35% and 55%, is sealed into new bunks.

The exact shares are not chosen by anyone. The holder share comes from the first byte of the previous action's hash. The second byte sets how much volume the next action waits for, between 10 and about 30 SOL. The third sets how far the price must fall before a bunk is opened. A hash cannot be predicted before its message exists, so nobody knows the next settings until the current action has landed.

Holders in bunker

bunk looks at the top 100 holders of the coin. For each one it reads the wallet's history from Solana and asks a single question: has this wallet ever signed a transaction? A wallet that only ever received, coins sent to it from somewhere else and nothing sent out, has never signed. That wallet is in bunker. A wallet that has bought, sold, swapped or sent anything has signed, and is exposed.

Only wallets in bunker are paid. The payment is SOL, sent straight to the wallet. Receiving does not count as signing, so a paid wallet stays in bunker for as long as it does nothing.

To get on the paid side you do what the rule says: make a new wallet, send your coins to it from your old one, and leave it alone. To sell you have to sign, and the moment you sign you are exposed and off the list. An exposed wallet does not come back. You would need a new one.

How a payout is shared

Each wallet in bunker gets a weight. The weight starts as the number of coins it holds, counted up to 2% of supply and no further, so one large wallet cannot take the whole payout. The weight then grows with how much trading the wallet has sat through without signing: nothing extra at the start, rising evenly to double once 200 SOL of volume has passed since it was first seen in bunker.

capped  = min(coins held, 2% of supply)
tenure  = min(1, volume since entry / 200 SOL)
weight  = capped x (1 + tenure)
payout  = holder share x weight / sum of all weights

Amounts under 0.001 SOL are not sent, because Solana rejects a transfer that leaves a new account below its rent minimum. They are held as owed and go out with a later action once they add up.

The risq list

The risq list is every one of the top 100 holders with its state: in bunker, exposed, or a program account such as the bonding curve or a liquidity pool, which is listed and never scored. Next to each wallet is a number called its shield.

The shield is the dollar value of the coin held by exposed wallets larger than yours. The thinking is that anyone able to recover keys will start with the biggest balances, so everything exposed and larger than you stands in front of you. A small wallet behind a wall of large exposed ones has a thick shield. The largest exposed wallet has none.

Bunks

The part of each claim that is not paid out is sealed. bunk creates a brand new address, one that has never existed on chain, and sends the SOL there. That address is a bunk. No bunk holds more than 2 SOL. A larger amount is split across several. At most 12 are sealed at once, and anything beyond that is bought and burned instead.

Every bunk comes from one seed, the same way a wallet makes many addresses from one phrase, and each index is used exactly once.

Opening a bunk

bunk tracks the highest price since a bunk was last opened. When the live price falls below that peak by the current trigger, somewhere between 20% and 35%, the oldest sealed bunk is opened. It signs one transaction. Half of what it holds goes to the surface wallet, which buys the coin and burns what it bought. The other half goes on to a brand new bunk. The opened address is at zero and is never used again.

That single transaction is the only time a bunk's key is ever used. Sign once, move the rest, retire the address.

The canary

The canary is a Solana address made by hashing a fixed phrase together with the coin's address and a counter until the result happens to be a valid curve point. Nobody picked a secret to make it, so nobody has its key. You can rerun the derivation on the canary page and get the same address.

bunk pays 5% of every claim into it. The balance only grows. For it ever to shrink, someone must sign as that address, which means someone can recover private keys from public ones. The canary is a reward for the first person to prove that, and a tripwire for bunk.

When the canary trips

When bunk sees that the canary has been spent, it records the spending transaction and changes mode for good. From then on nothing is paid out and nothing is sealed, because after a break no wallet is a safe place to send SOL. Every claim is bought and burned in full. Every sealed bunk is opened, one after another, and burned in full. Burned coins are the one thing a broken curve cannot reach.

The second signature

Every action bunk takes is signed by the surface wallet, because Solana requires it. It is also signed a second time with a scheme that uses nothing but SHA-256. That second signature is what will still mean something after a break.

The scheme is a Winternitz one time signature. Think of 67 chains. Each chain starts at a secret value and is hashed 15 times. The 67 end values are the public key. To sign, the message hash is cut into 64 digits from 0 to 15, plus 3 checksum digits, and for each chain bunk reveals the value that many steps along. To check, you hash each revealed value the remaining number of steps and see whether you land on the public key. One key, one signature. After that the key is finished.

The tree

One signature is not much use, so bunk makes 256 of these keys at once and folds their public halves into a Merkle tree eight levels high. The single hash at the top is the root. A signature from leaf number i comes with the eight sibling hashes on the path from that leaf to the root, so anyone can rebuild the root from the signature alone and compare.

The root is written into a Solana memo once, at the start. That transaction is a timestamp from a period when wallet signatures could still be trusted. Leaf 255 of every tree is kept for one purpose, signing the root of the next tree, so the line of trust runs unbroken from the first root to the one in use now.

What an action records

An action is recorded as a 229 byte message with a fixed layout: what kind of action, which tree and leaf signed it, the coin, the hash of the previous action, how much SOL was claimed, how much was paid to how many wallets, how much was sealed, what went to the canary, what was bought and burned, the stores and supply afterwards, the price, the volume that triggered it, which bunk was opened and which was created, and a hash of every transaction involved.

The amounts are not estimates. They are read back from the confirmed transactions before the message is built.

Checking it yourself

Every check on this site runs in your browser when the page loads. The tree nodes are public, so the root is rebuilt from the 256 leaf hashes. Each action's message is hashed again and compared with the stored hash. Each signature's 67 chains are walked to their ends, compressed, and climbed to the root. The canary address is derived again from scratch. A row says valid only when all of that agrees.

The bunks and the payouts need no trust at all. Each bunk is an address you can open on Solscan and see for yourself that it has signed nothing, or exactly one transaction. Each payout is a plain transfer with a link beside it.

What bunk does not protect

Be clear about the limits. A bunk is a fresh Solana address, and on Solana a fresh address still shows its public key. If the curve breaks, bunks are exposed like any wallet. They are small, there are several of them, and all of them are drained into burns the moment the canary trips, which is the most that can be done without an on chain hash vault.

SOL paid to a holder is that holder's to look after. bunk rewards wallets for never signing. It cannot make them safe.

The seed that the bunks and the hash keys come from sits with the engine, off chain. If the engine were taken over, the attacker could move the sealed bunks and sign false records. They could not rewrite the records already anchored, and they could not reuse a spent leaf or a spent bunk without it showing on this site.

Words used on this site

bunka fresh address that has never signed, holding sealed SOL
sealeda bunk that has not signed
openeda bunk that has signed its one transaction and is empty
surface walletthe creator wallet, the one address that has to sign often
in bunkera holder wallet that has never signed a transaction
exposeda holder wallet that has signed at least once
risq listthe top 100 holders with their state and shield
shieldthe value held by exposed wallets larger than yours
leafone hash key, good for one signature
tree256 leaves under one root
actionone recorded run of bunk's routine
canarythe keyless address that warns of a broken curve
bunker modethe permanent state after the canary is spent