Cold storage was protected by a very large number.
The number held. The dice did not.
A commemorative token, in memory of the firmware.
- Price
- $0.00001226
- Market cap
- $12,260
- 24h
- ▲ +20,125%
- 24h volume
- $11,470
- Pair age
- —
- Keyspace
- 2256 ▲ ±0%
06Market · live
The chart. Fully generated from hardware randomness, probably.
Chart won't load? Some content blockers reject embeds on principle. Switch source above, or open DexScreener ↗ · Jupiter ↗ directly.
10The airdrop · paid on the floor
200,000,000 tokens, free, paid on your floor.
Twenty per cent of circulating supply, committed to a fixed pool before the window opened. Anyone holding can qualify — but an entropy failure is a floor problem, a seed is only as strong as the weakest moment in its generation, and this distribution works the same way on purpose. You are not paid on what you hold at some announced instant. You are paid on the least you ever held, multiplied by how early you were holding it.
One base, one multiplier.
The base — what you're measured on. Five checkpoints land at undisclosed times inside the window, and a sixth measurement is taken at the close, whose time is public. Your base is the minimum balance across the anchor slot, every checkpoint, and the close. Sell at any point and it is permanently capped at that trough, including at the checkpoints you haven't seen yet. Claim-and-dump pays you what you dumped to.
So there is a cutoff, and you cannot see it. Because the base is a minimum across all of those readings, a wallet that arrives after the last secret checkpoint holds zero at the earlier ones — and a minimum containing a zero is zero. Buy late enough and the allocation is not smaller, it is nothing. Nobody knows when that line passes, which is the only honest reason to buy now rather than later.
The multiplier — when you got here. The anchor is a slot that had already passed before any of this was published; you cannot farm a block that is behind you. Being there pays triple. Arriving later still pays — just less, on a scale that only goes down.
—
—
This hashes the five checkpoint timestamps and a secret nonce. The times stay secret so nobody can trade around them; the hash proves they were fixed in advance. When the window closes, the timestamps and nonce get published — hash them yourself and they must equal the string above. Cherry-picking after the fact is not possible without breaking SHA-256, which would be a considerably bigger story than this token.
Am I in?
The checker reads the chain live, in your browser. Nothing is submitted, nothing is stored, and no list is kept anywhere — submitting an address does not make you eligible and never could. Holding does. It shows what a checkpoint taken right now would record against you, which is the number your allocation tracks downward if you sell.
Or verify by hand: getTokenAccountsByOwner against mint Fwxt…pump. The site is doing nothing you can't do from a terminal — which is the only claim on this page worth making.
The device asked for six digits. It is still asking.
Season two, and why you're being told about it now
An airdrop normally gets sold within the hour, because a token you were handed for free has no anchor holding it down. So here is the rule for the next one, published before this one has even landed: your season-two weight counts what you still hold of season one. Up to fifty per cent of circulating supply sits behind that rule.
Nothing is locked and there is no vesting contract, no cliff, and no code that could be drained — the mechanism is a published sentence, not a program. You are simply told in advance what selling costs you. And it needs no special tracking: retention is measured with the same instrument as everything else here, the minimum balance across undisclosed checkpoints, so your season-one tokens are just part of the floor you are measured on. Sell them and the floor drops. The rule never has to know which tokens were which.
—
Nothing here is a promise of value, and no allocation is owed to anyone. Figures load from airdrop.json in the public repository, so any change to the terms is a visible commit with a timestamp on it — including the amendment that replaced version one of these rules, which is recorded in that file with its reasoning rather than quietly overwritten. That is the entire point.
08The pool · x·y = k, observed live
One hyperbola holds the whole thing together.
The pool reserves, TOKEN:SOL bar and metrics refresh on a fixed 15-minute snapshot (the countdown above shows the next one). Drag the marker (or use the steppers — they're the keyboard path) to simulate a buy or sell against the real constant-product curve and watch the price impact. Simulations stay in your browser. Obviously.
09Flow monitor
Live transactions. Watched openly, which is more than some firmware can say.
| Age | Side | $115792 | SOL | USD | Signature | Links |
|---|---|---|---|---|---|---|
Listening for movements. The keyspace remains extremely large. | ||||||
Signatures via getSignaturesForAddress, amounts parsed from each transaction's balance deltas (pool vaults are owned by CW959iWe…UeBmvV, so sides classify themselves), refreshed every ~12 seconds while this tab is visible. Click a signature for the full forensic experience on Solscan.
12Entropy ceremony · roll your own
Beat the firmware by hand.
The vendor said seeds made from fifty fair dice rolls were never at risk. So here are the dice. Every roll pulls fresh randomness from your device's cryptographic generator — the hardware source the firmware was supposed to use — and stacks it into a seed. It is a toy. That is the whole point.
0 rolls · 0 bits · the firmware managed ~40–72
Dice Rolls
Generate Recovery Phrase
Derived by hashing your exact roll sequence — the same rolls always yield the same words, because that is how entropy is supposed to work.
07Swap console · simulated locally, settles elsewhere
The console. No wallet attached. No seed requested. Ever.
A swap interface that cannot touch your funds — rendered in loving memory of interfaces that could.
Quotes are computed in your browser from the live pool reserves: constant-product arithmetic, no oracle, no middleman, no March-2021 firmware anywhere in the pipeline. Execution happens on Jupiter or pump.fun under your own wallet's supervision. We never ask for a connection — we wouldn't know what to do with one.
> entropy HARDWARE ✓
> route SOL → WSOL → $115792
> slippage 50 fair dice rolls
> this console is a visualization. amounts are estimates from live reserves. the button opens Jupiter; your keys remain yours, which is the entire point of this website.
11Acquisition procedure
Three steps. Zero firmware.
Obtain SOL
Any exchange, any wallet. Generated after March 2021, ideally, but we are not your auditors.
Verify the address
Paste the contract, check the first and last characters like your grandfather taught you. Fwxt…pump. Don't trust — that other slogan.
Swap & hold
On pump.fun or any Solana DEX. Custody it however you like. We hear hardware wallets are excellent.
04Incident metrics · as reported · ongoing
Quarterly highlights, involuntary edition.
Every swept address, one square
—
Where it is sitting
—
A caveat that matters more than the number: wave four sent to a fresh address per victim instead of shared collectors, so a wallet "moving" can be ordinary topology rather than a cash-out. Nobody has published a named address set for wave four, which means this split is reported, not verified — the distinction is the whole point of the pips below.
Wave four ran in blocks 960,778–960,792 — 112 minutes, fifteen blocks, roughly 13.8 sweeps per block against a normal rate around a fortieth of that. Every block above is a link; the transactions are public and the timestamps are not ours to adjust. The attacker broadcast with replace-by-fee enabled, so a victim who spotted their own address in an unconfirmed sweep could spend the same UTXOs to a wallet they still controlled at a higher fee and win the race. At the fee rate shown above, that rescue currently costs about — — which is the single cruelest number on this page, because it was always this cheap to win and almost nobody was watching. Open the last sweep block ↗
Counts load from incident.json and waves.json (re-verified on a schedule against named sources only)1; the dollar figure updates live against the Bitcoin price. This is an ongoing event — totals have only gone up2. Vendor remediation is documented, but patched firmware cannot repair an already-weak seed3. Seeds generated from fifty fair dice rolls are unaffected4. If any of this touches you personally: close this meme site and go move your coins.
05Evidence · we did not invent the news
Ordered newest first. The pip on each is the source tier: 1self-verifiable on-chain, 2named attribution research, 3vendor statement, 4press aggregating the above. Unattributed social posts are tier 5 and never make it onto this page as a number6.
Notes
- Cumulative counters are read from incident.json and the per-wave ledger from waves.json, both in this repository and both re-verified against the sources above on a three-hour schedule. The dollar figure is not stored: it is the BTC total multiplied by the live Bitcoin spot price at the moment you loaded this page. The chain tip, confirmation depth and fee rates are not stored either — they are fetched from mempool.space when you load the page, and you can run the same requests yourself. ↩ back
- The event is ongoing and the shape of it has changed. Reported totals rose from roughly 594 BTC on 30 July to over 1,800 BTC across more than five thousand addresses within ninety-six hours, and the fourth wave broke the pattern of the first three: fresh destination addresses instead of shared collectors, and analysis pointing at multiple operators racing the same disclosure rather than one group working through a list. Treat any number on this page as a floor rather than a total. ↩ back
- Per the vendor's own advisory, emergency firmware closes the generation flaw but cannot repair a seed that was already produced with insufficient entropy. Affected users are directed to generate a new seed on patched firmware and move their funds. ↩ back
- Also per the vendor: seeds created from fifty fair dice rolls are unaffected, because the entropy never passed through the defective generator. This is the entire premise of the ceremony at the foot of this page. ↩ back
- This site is an unaffiliated parody. It reproduces no vendor material, quotes reporting only in headline form under the linked sources, and holds no position on the merits of any product. ↩ top
- The rule for what gets published here: no figure without a named claimant. Tier 1 is on-chain and you can reproduce it from any node — block heights, timestamps, confirmations, fee rates. Tier 2 is the attribution work that decides which addresses belong to the attack, which no block explorer can tell you and which currently rests on Galaxy Research and Block's security teams. Tier 3 is the vendor's own statements. Tier 4 is press aggregating tiers 2 and 3 — citable, but the figure belongs to whoever the outlet is quoting, and that name is what gets recorded. Tier 5 is an unattributed post on a timeline; it is a lead to chase into a higher tier, never a source. Where a claim cannot be raised above tier 5 the previous value stands and the discrepancy is written into the unverified list in waves.json rather than shown as a number. That is why the custody split is labelled reported rather than verified. ↩ back
03The Number
A number so large it was the entire security model.
There are more possible private keys than atoms in the observable universe. If every human who has ever lived checked a trillion keys per second since the beginning of time, the search would not have meaningfully begun. This is not marketing. It is arithmetic, and it has never once failed.
It does, however, come with one assumption printed in very small type: you have to actually pick from all of it.
Between certain firmware versions, certain devices did not. The seed generator quietly reached for a deterministic function instead of the hardware's dice, and the haystack — advertised at 115 quattuorvigintillion straws — shrank, for some wallets, to a space a patient stranger could walk end to end. The needles stayed exactly where they were. As reported: 1,082 BTC, out of 1,196 addresses, in 41 minutes, on a Thursday.
The number never failed. Nothing about 2256 failed. Somewhere below the number, a shortcut was taken, and the shortcut was the whole ballgame.
$115792 is the first six digits of the number that worked — a ticker in memory of the firmware that didn't.
2256. The size of the private-key space. Elliptic-curve keys on secp256k1 live just under it, at n = 0xFFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFE BAAEDCE6 AF48A03B BFD25E8C D0364141. Your odds of guessing a specific key are 1 in this number. Your odds if the key came from a 2021 pseudorandom shortcut are, per the reporting, considerably more sociable.
The manufacturer's own guidance notes that seeds generated with 50 fair dice rolls are unaffected. Fifty casino dice, thrown by hand, out-performed the firmware. The dice were always the more rigorous engineer. This token honours the dice.
On July 30, 2026, per multiple outlets, an attacker who had reproduced weak seeds offline swept 1,196 funded addresses — roughly 1,082.65 BTC, about $70M at the time — in 41 minutes. Emergency firmware followed the next day, with a caveat worth framing: installing it does not repair an existing seed. See the Evidence section for the journalism; we only sell the commemorative ticker.
No. Absolutely not. In no jurisdiction, timeline, or keyspace. This is an unaffiliated parody / commemorative meme token. All trademarks belong to their owners; all firmware belongs to its consequences. The frog speaks only for the frog.
01The keyspace · a field, drawn from one seed
Every key that could ever exist, arranged by sunflower.
—
—
No Math.random() anywhere in this field. Positions come from the contract address hashed to a single seed, then a golden-angle phyllotaxis — the packing that puts seeds in a sunflower head. Every visitor on every device sees the identical arrangement, with no server and nothing stored. Each node carries its own phase and frequency, so the field drifts forever without anything returning to sync. It is the whole argument of this website rendered as a layout: deterministic, reproducible, and only as strong as the seed you start from.
02Exhibit