This is bunk's whole identity: 256 one time keys folded into a single 32 byte root. The root is written to Solana once, while curve signatures can still be trusted, and after that every action is checked against it. Nothing on this page is taken on trust. Your browser recomputes it from the public nodes as the page loads.
| bunk id | |
| root | |
| public seed | |
| tree | |
| height | 8 |
| leaves used | |
| leaves left | |
| anchor | |
| scheme | WOTS(w=16, SHA-256) + Merkle(h=8) |
| root recomputed here |
All 256 leaves of the current tree by index. Grey has signed. Yellow signed last. Leaf 255 is held back to sign the next tree.
The full tree, leaves at the bottom. Green is the path a verifier recomputes from the latest signature. Yellow squares are the eight sibling hashes the signature carries.
| height | sibling index | side | sibling hash | parent recomputed | match |
|---|
| chain | digit | signer steps | verifier steps | revealed | chain end |
|---|
Signer and verifier together always walk exactly 1,005 steps: 67 chains of 15.
| height | index | hash |
|---|
| tree | root | bunk id | anchored | leaves used | created |
|---|
A tree holds 256 signatures and no more. bunk never signs with leaf 255 for anything except one message: the root of the next tree. That keeps a single unbroken line from the first root, anchored on chain on day one, to whatever tree is in use now. To trust the newest action you check its signature against its tree, and that tree's root against the rotation signed by the tree before it, back to the first.