reading the seat pool .......... state .......... creator seat .......... keys exposed .......... [..........] waiting for a mint
move your coin
to bunker mode.
a coin you already launched on meteora keeps its ticker, chart and ca. one signature from the dev hands its fee seat to a shelter nothing can sign for. nothing for holders to do.
live on mainnet: the seat checker, the meteora watch and the migrate program itself. the signing flow ships next.
live from mainnet
every tile reads live: any meteora coin's seat through the real checker, the dbc program's latest transactions, the sol price from jupiter. nothing here is a mockup.
> tail -f meteora.dbc
reading the dynamic bonding curve program, mainnet
- connecting
[..........] 0 / 8 read
program GopP..qmyp [mainnet]
one signature. no key.
> quote sol/usd
- sol
- ...
- 24h
- ...
- fees to burn
- 10%
- $migrate
- not launched
[..........] price from jupiter
| who signs | scheme | rests on | status |
|---|---|---|---|
| dev wallet | ed25519 | elliptic curve | key public from day one |
| holders | ed25519 | elliptic curve | untouched by migrate |
| shelter | winternitz | hash | no key to expose |
the seat is the key.
a meteora coin has a creator seat: the address its fees are paid to. today that seat is a normal wallet, and on solana the address is the public key. if elliptic-curve math is ever reversed, every visible key is enough to forge a signature, and every seat pays whoever got there first.
migrate moves the seat to a shelter: a program-owned address that nothing can sign for. meteora's program then pays the shelter and only the shelter. the way out is a one-time hash signature made from 24 words, in your browser. no curve anywhere in the path.
same ticker. same chart. same ca. the dev signs once. holders do nothing.
=> the seat is a public key. exposed from day one.
=> meteora's own instruction. the new seat has no private key.
=> 30 hash chains, 840 bytes, at most 7,650 hashes on chain. every withdrawal rotates the key.
no attack has been demonstrated.
no break of ed25519 has been published. the debate is about how much warning there would be. migrate is for the people who would rather not find out with their fees in a hot wallet. last checked 9 oct 2026.
how migrate works
free to migrate. 10% of migrated fees buy back and burn $migrate once it exists. checking a seat is always free.
sign
the dev signs one transaction: the creator seat moves to the shelter. for graduated coins the damm v2 lp position moves in the same transaction.
/migrate ->sweep
anyone can sweep the coin's fees from meteora into the shelter. meteora's program pays only the seat's owner, and the owner is the shelter.
/watch ->withdraw
the owner types 24 words into the page. the page signs the exact amount and destination with a one-time hash key. the words never leave the browser.
/how ->burn
10% of every sweep buys back and burns $migrate. every coin that migrates is buy pressure for the one that protects it.
/token ->
in the bunker
eight cubes. one lights up per migrated coin. the first one gets the first cube.
-
01
empty
-
02
empty
-
03
empty
-
04
empty
-
05
empty
-
06
empty
-
07
empty
-
08
empty
- coins in bunker mode
- 0
- sol secured
- 0.00
- fees swept, sol
- 0.00
- keys exposed
- 0
what is proven
each line carries its evidence. proven means a transaction or a test you can rerun. stated means someone said it. not shown means nobody has.
- proventhe creator seat moves to a keyless address and the old creator is refused by meteora's program.devnet tx ->
- provenbonding-curve coin: a stranger sweeps fees into the shelter; the wrong key is refused; the right key withdraws; the old key is dead after rotation.localnet against meteora's programs
- provengraduated coin: one signature moves the seat and the damm v2 lp position; damm refuses the dev; fees sweep into the shelter.localnet against meteora's programs
- proventhe withdraw transaction fits in 1230 of 1232 bytes and verifies in about half a million compute units.measured
- statedjustin drake: start planning calmly for bunker mode; a break before quantum computers is possible.public post, oct 2026
- not shownany break of ed25519 or ecdsa.nothing published
- proventhe migrate program is deployed on solana mainnet. it keeps an upgrade authority until it is audited.deploy tx ->
- pendingthe signing flow in this page: open a shelter, hand over the seat, show the 24 words once.next
read the instruction yourself: transfer_pool_creator on github ->
what it can't do
- your own wallet.migrate protects the coin's fees and keys. it does not protect the sol or tokens sitting in your wallet.
- pump.fun coins.pump has no way to hand over a creator seat. meteora coins only, bonding curve or graduated.
- solana itself.if the chain fails, a shelter fails with it.
- lost words.a shelter with no words is sealed forever. there is no reset, by design.
migrate a coin
three steps. the third unlocks when the signing flow ships.
-
1
connect the dev wallet
the wallet that launched the coin on meteora. we only read from it until you sign.
-
2
find your coin
paste the coin's mint address. we read its meteora pool and check who holds the creator seat.
coinpoolstatecreator seatkeys exposed -
3
sign once
one transaction: the creator seat and, if graduated, the lp position move to the shelter. your 24 words are generated here, in the browser, and shown once.
the program is on mainnet. the signing flow in this page ships next; this step unlocks with it.
token
$migrate is not launched. when it is, the ca goes in the top bar and the burn tile starts counting. 10% of every migrated fee buys it back and burns it, with the transaction on this page.