bunk

Parameters

symbolvaluemeaning
n32hash output in bytes
w16Winternitz parameter, chain length plus one
len164message digits, 4 bits each
len23checksum digits
len67chains per one time key
h8tree height
leaves256one time keys per tree
signature2,404 B4 + 67 x 32 + 8 x 32
public key64 Broot and public seed
message229 Bfixed layout, see below
keygen274,943 hashes256 x (67 + 1,005 + 1) + 255
verifyat most 1,014 hasheschains, one compression, eight nodes

Address field

typeabczero048121632
typenameabc
0chain stepleafchainstep
1leaf compressionleaf00
2tree nodeheightindex0
3secret derivationleafchain0

Signature bytes

leaf67 chain values8 siblings0421482404

Message bytes

offsetlengthfieldtype
01kindu8
14genu32
54leafu32
932mintpublic key
4132previous digesthash
738claimedu64 lamports
818paid to holdersu64 lamports
894wallets paidu32
938to storesu64 lamports
1018to canaryu64 lamports
1098boughtu64 lamports
1178burnedu64 raw tokens
1258stores afteru64 lamports
1338supply afteru64 raw tokens
1418price_e12u64
1498volume seenu64 lamports
1574bunk openedu32
1614bunk createdu32
16532transactions hashhash
19732payloadhash

Formulas

F(seed, adrs, x)   = SHA-256(seed ‖ adrs ‖ x)
sk(i, j)           = SHA-256(sk.seed ‖ ADRS(3, i, j, 0))
pk(i, j)           = F applied 15 times from sk(i, j)
leaf(i)            = SHA-256(pk.seed ‖ ADRS(1, i, 0, 0) ‖ pk(i,0) ‖ ... ‖ pk(i,66))
node(k, j)         = SHA-256(pk.seed ‖ ADRS(2, k, j, 0) ‖ left ‖ right)
checksum           = sum of (15 minus d) over 64 digits, as 3 hex digits
sigma(j)           = F applied d(j) times from sk(i, j)
verify             = F applied 15 minus d(j) times from sigma(j), compress, climb 8
digest             = SHA-256("bunk/act/v1" ‖ message)
memo               = bunk:v1:kind:tree:leaf:digest
holder share       = 40.00% + byte0 / 255 x 20.00%
bunk share         = 95.00% minus holder share
threshold          = 20 SOL x (128 + byte1) / 256
open trigger       = 20.00% + byte2 / 255 x 15.00%
canary             = first c where SHA-256("bunk/canary/v1" ‖ mint ‖ c) is a curve point, times 8
bunk(k)            = ed25519 key from HKDF(master seed, "bunk/addr/v1", mint ‖ k)
weight             = min(coins, 2% of supply) x (1 + min(1, volume since entry / 200 SOL))
shield             = value held by exposed wallets larger than this one

Engine constants

action threshold base20.0000 SOL traded
holder share range40.00% to 60.00%
bunk share range35.00% to 55.00%
canary share5.00%
open trigger range20.00% to 35.00% below peak
burn half on open50.00%
cap per bunk2.0000 SOL
smallest bunk0.0100 SOL
most bunks sealed12
signatures per bunk1
smallest payout0.0010 SOL
weight cap2.00% of supply
full tenure200.0000 SOL traded
risq list size100
minimum pot0.0200 SOL
gas floor0.0200 SOL
slippage5%
team share0%

Where every number comes from

readingsourcerefresh
price, value, candlesBirdeye1 s
tradesBirdeye, kept in the trades table1 s
supplySolana RPC getTokenSupply1 s
holders, 24h volume, liquidityBirdeye token overview1 s
unclaimed feesSolana RPC, creator vault accounteach engine pass
wallet and canary balancesSolana RPC getBalanceeach engine pass
claimed, paid, sealed, bought, burnedthe confirmed transactions themselvesat each action
top 100 holdersBirdeye token holderseach engine pass
wallet states, signer countsSolana RPC getSignaturesForAddress and getTransactioneach engine pass
bunk balancesSolana RPC getBalanceeach engine pass
payoutsthe confirmed transfers themselvesat each action
signature checkscomputed in this browseron load
canary address, parameterscomputed in this browseron load

Live identity

bunk id
root
public seed
canary address
surface wallet
contract
current tree
next leaf
mode