initialising secure element

Solana·pump.fun·born in Mayhem Mode·minted: 2,000,000,000·burnt: 1,000,000,000·keys: 2256

Cold storage was protected by a very large number.

The number held. The dice did not.
A commemorative token, in memory of the firmware.

Acquire on pump.fun View chart
Price
$0.00001226
Market cap
$12,260
24h
+20,125%
24h volume
$11,470
Pair age
Keyspace
2256 ±0%

06Market · live

The chart. Fully generated from hardware randomness, probably.

Price · USD— SOL
Market cap / FDVFDV —
Liquidity24h vol —
24h flowbuys — · sells —
Δ 1h / 6h / 24hupdating…
1 SOL buys$115792 at the current pool rate
Pool reserves— SOL
Turnover · 24hvolume ÷ liquidity. the pool works overtime.
Live supplyon-chain, refreshed each minute
Burnt1,000,000,000of 2,000,000,000 minted — sent somewhere with provably no firmware
Activitym5 — · h1 — · h6 —
Pair agecounting since the pumpswap pool opened
Trend · reconstructedfrom Δ buckets: −24h · −6h · −1h · −5m · now
Share of 2²⁵⁶≈ 1.06 × 10⁻⁷¹%of the keyspace, if market cap were keys. a decimal point and seventy zeros. room to grow.
Mint authorityNobody can print more. The supply you see is the supply there is.
Freeze authorityNobody can freeze your balance. Not us, not anyone.
Metadata authorityThe name and ticker are immutable — unlike certain firmware.
Token programToken-2022Read the mint yourself: it's four lines of RPC. Don't trust — verify.
COINKITE / SOL · pumpswapCW959iWe…UeBmvV
loading chart… if it hangs, try another source above

Chart won't load? Some content blockers reject embeds on principle. Switch source above, or open DexScreener · Jupiter directly.

10The airdrop · paid on the floor

200,000,000 tokens, free, paid on your floor.

Twenty per cent of circulating supply, committed to a fixed pool before the window opened. Anyone holding can qualify — but an entropy failure is a floor problem, a seed is only as strong as the weakest moment in its generation, and this distribution works the same way on purpose. You are not paid on what you hold at some announced instant. You are paid on the least you ever held, multiplied by how early you were holding it.

the whole thing, no reading

One base, one multiplier.

The base — what you're measured on. Five checkpoints land at undisclosed times inside the window, and a sixth measurement is taken at the close, whose time is public. Your base is the minimum balance across the anchor slot, every checkpoint, and the close. Sell at any point and it is permanently capped at that trough, including at the checkpoints you haven't seen yet. Claim-and-dump pays you what you dumped to.

So there is a cutoff, and you cannot see it. Because the base is a minimum across all of those readings, a wallet that arrives after the last secret checkpoint holds zero at the earlier ones — and a minimum containing a zero is zero. Buy late enough and the allocation is not smaller, it is nothing. Nobody knows when that line passes, which is the only honest reason to buy now rather than later.

The multiplier — when you got here. The anchor is a slot that had already passed before any of this was published; you cannot farm a block that is behind you. Being there pays triple. Arriving later still pays — just less, on a scale that only goes down.

Pool $115792 · % of circulating · hard cap
Anchor slot ·
Checkpoints · times undisclosed, committed below
Final measurement · public · hold to here
Window
Pool custody ·
Excluded
Dust floor $115792 minimum to qualify
Commitment · SHA-256, published before the window opened This hashes the five checkpoint timestamps and a secret nonce. The times stay secret so nobody can trade around them; the hash proves they were fixed in advance. When the window closes, the timestamps and nonce get published — hash them yourself and they must equal the string above. Cherry-picking after the fact is not possible without breaking SHA-256, which would be a considerably bigger story than this token.
Every address this depends on
The whole mechanism is six accounts and a hash. Nothing here asks you to trust a screenshot — open any of them and check the balance yourself. The list is generated from airdrop.json, so the page cannot show an exclusion the terms do not contain.
status —

Am I in?

The checker reads the chain live, in your browser. Nothing is submitted, nothing is stored, and no list is kept anywhere — submitting an address does not make you eligible and never could. Holding does. It shows what a checkpoint taken right now would record against you, which is the number your allocation tracks downward if you sell.

no wallet connection, ever

Or verify by hand: getTokenAccountsByOwner against mint Fwxt…pump. The site is doing nothing you can't do from a terminal — which is the only claim on this page worth making.

The device asked for six digits. It is still asking.

Season two, and why you're being told about it now

An airdrop normally gets sold within the hour, because a token you were handed for free has no anchor holding it down. So here is the rule for the next one, published before this one has even landed: your season-two weight counts what you still hold of season one. Up to fifty per cent of circulating supply sits behind that rule.

Nothing is locked and there is no vesting contract, no cliff, and no code that could be drained — the mechanism is a published sentence, not a program. You are simply told in advance what selling costs you. And it needs no special tracking: retention is measured with the same instrument as everything else here, the minimum balance across undisclosed checkpoints, so your season-one tokens are just part of the floor you are measured on. Sell them and the floor drops. The rule never has to know which tokens were which.

Nothing here is a promise of value, and no allocation is owed to anyone. Figures load from airdrop.json in the public repository, so any change to the terms is a visible commit with a timestamp on it — including the amendment that replaced version one of these rules, which is recorded in that file with its reasoning rather than quietly overwritten. That is the entire point.

08The pool · x·y = k, observed live

One hyperbola holds the whole thing together.

drag the dot · simulate a trade
loading reserves…
$115792— in pool — per SOL SOL— in pool
Liquidity · total
Price
Constant · k
Pooled supply
1 SOL buys
liquidity per snapshot · this session
pool snapshot · updated · next refresh in 15:00

The pool reserves, TOKEN:SOL bar and metrics refresh on a fixed 15-minute snapshot (the countdown above shows the next one). Drag the marker (or use the steppers — they're the keyboard path) to simulate a buy or sell against the real constant-product curve and watch the price impact. Simulations stay in your browser. Obviously.

09Flow monitor

Live transactions. Watched openly, which is more than some firmware can say.

FwxtoAzK…jFepump · Solana mainnet · public RPCconnecting…
AgeSide$115792SOLUSDSignatureLinks
Listening for movements. The keyspace remains extremely large.

Signatures via getSignaturesForAddress, amounts parsed from each transaction's balance deltas (pool vaults are owned by CW959iWe…UeBmvV, so sides classify themselves), refreshed every ~12 seconds while this tab is visible. Click a signature for the full forensic experience on Solscan.

12Entropy ceremony · roll your own

Beat the firmware by hand.

The vendor said seeds made from fifty fair dice rolls were never at risk. So here are the dice. Every roll pulls fresh randomness from your device's cryptographic generator — the hardware source the firmware was supposed to use — and stacks it into a seed. It is a toy. That is the whole point.

0 rolls · 0 bits · the firmware managed ~40–72

every four rolls → one word

Dice Rolls

0 / 99
This is a novelty. It runs inside a webpage on a memecoin site. Never secure real funds with a phrase generated here — or on any website. The lesson worth keeping is the method: real dice and a real random source beat broken firmware every time. For actual cold storage, roll physical dice into a device you trust, offline.

07Swap console · simulated locally, settles elsewhere

The console. No wallet attached. No seed requested. Ever.

A swap interface that cannot touch your funds — rendered in loving memory of interfaces that could.

Quotes are computed in your browser from the live pool reserves: constant-product arithmetic, no oracle, no middleman, no March-2021 firmware anywhere in the pipeline. Execution happens on Jupiter or pump.fun under your own wallet's supervision. We never ask for a connection — we wouldn't know what to do with one.

coinkite swap console v2.56solana · pumpswap

> entropy HARDWARE ✓

> route SOL → WSOL → $115792

> slippage 50 fair dice rolls

You give SOL ≈ $—
You receive · est. $115792 ≈ $—

rate —impact —fees: the pool's business

Execute on Jupiter or pump.fun quote refreshes with the market · 30s

> this console is a visualization. amounts are estimates from live reserves. the button opens Jupiter; your keys remain yours, which is the entire point of this website.

11Acquisition procedure

Three steps. Zero firmware.

Obtain SOL

Any exchange, any wallet. Generated after March 2021, ideally, but we are not your auditors.

Verify the address

Paste the contract, check the first and last characters like your grandfather taught you. Fwxt…pump. Don't trust — that other slogan.

Swap & hold

On pump.fun or any Solana DEX. Custody it however you like. We hear hardware wallets are excellent.

Acquire $115792

04Incident metrics · as reported · ongoing

Quarterly highlights, involuntary edition.

attack ongoing $86M at BTC $63,000 as of Aug 2, 2026 · 05:30 EDT figures still climbing
BTC relocated1,367.05▲ climbingacross three waves · one operator
Addresses swept4,585derived offline, matched on-chain
Held, unspent76%the rest has left its first destination
Advertised keyspace2256effective, for some wallets: nearer 2⁴⁰ – 2⁷²

Every swept address, one square

swept · one square ≈ 10 addresses the rest of the cohort, so far untouched
Four waves, and they stopped rhyming. bar scaled to BTC · hatched where the figure was never broken out

Where it is sitting

still at the address it landed in moved on at least once

A caveat that matters more than the number: wave four sent to a fresh address per victim instead of shared collectors, so a wallet "moving" can be ordinary topology rather than a cash-out. Nobody has published a named address set for wave four, which means this split is reported, not verified — the distinction is the whole point of the pips below.

Tier 1 · read live from mempool.space · trust nobody, including us
Chain tipcurrent block height
Wave 4 depthconfirmations on the last sweep block
Fastest feesat/vB to get into the next block
BTC spotused for the dollar figure above

Wave four ran in blocks 960,778960,792 — 112 minutes, fifteen blocks, roughly 13.8 sweeps per block against a normal rate around a fortieth of that. Every block above is a link; the transactions are public and the timestamps are not ours to adjust. The attacker broadcast with replace-by-fee enabled, so a victim who spotted their own address in an unconfirmed sweep could spend the same UTXOs to a wallet they still controlled at a higher fee and win the race. At the fee rate shown above, that rescue currently costs about — which is the single cruelest number on this page, because it was always this cheap to win and almost nobody was watching. Open the last sweep block

Counts load from incident.json and waves.json (re-verified on a schedule against named sources only)1; the dollar figure updates live against the Bitcoin price. This is an ongoing event — totals have only gone up2. Vendor remediation is documented, but patched firmware cannot repair an already-weak seed3. Seeds generated from fifty fair dice rolls are unaffected4. If any of this touches you personally: close this meme site and go move your coins.

05Evidence · we did not invent the news

Ordered newest first. The pip on each is the source tier: 1self-verifiable on-chain, 2named attribution research, 3vendor statement, 4press aggregating the above. Unattributed social posts are tier 5 and never make it onto this page as a number6.


Notes

  1. Cumulative counters are read from incident.json and the per-wave ledger from waves.json, both in this repository and both re-verified against the sources above on a three-hour schedule. The dollar figure is not stored: it is the BTC total multiplied by the live Bitcoin spot price at the moment you loaded this page. The chain tip, confirmation depth and fee rates are not stored either — they are fetched from mempool.space when you load the page, and you can run the same requests yourself. ↩ back
  2. The event is ongoing and the shape of it has changed. Reported totals rose from roughly 594 BTC on 30 July to over 1,800 BTC across more than five thousand addresses within ninety-six hours, and the fourth wave broke the pattern of the first three: fresh destination addresses instead of shared collectors, and analysis pointing at multiple operators racing the same disclosure rather than one group working through a list. Treat any number on this page as a floor rather than a total. ↩ back
  3. Per the vendor's own advisory, emergency firmware closes the generation flaw but cannot repair a seed that was already produced with insufficient entropy. Affected users are directed to generate a new seed on patched firmware and move their funds. ↩ back
  4. Also per the vendor: seeds created from fifty fair dice rolls are unaffected, because the entropy never passed through the defective generator. This is the entire premise of the ceremony at the foot of this page. ↩ back
  5. This site is an unaffiliated parody. It reproduces no vendor material, quotes reporting only in headline form under the linked sources, and holds no position on the merits of any product. ↩ top
  6. The rule for what gets published here: no figure without a named claimant. Tier 1 is on-chain and you can reproduce it from any node — block heights, timestamps, confirmations, fee rates. Tier 2 is the attribution work that decides which addresses belong to the attack, which no block explorer can tell you and which currently rests on Galaxy Research and Block's security teams. Tier 3 is the vendor's own statements. Tier 4 is press aggregating tiers 2 and 3 — citable, but the figure belongs to whoever the outlet is quoting, and that name is what gets recorded. Tier 5 is an unattributed post on a timeline; it is a lead to chase into a higher tier, never a source. Where a claim cannot be raised above tier 5 the previous value stands and the discrepancy is written into the unverified list in waves.json rather than shown as a number. That is why the custody split is labelled reported rather than verified. ↩ back

03The Number

A number so large it was the entire security model.

There are more possible private keys than atoms in the observable universe. If every human who has ever lived checked a trillion keys per second since the beginning of time, the search would not have meaningfully begun. This is not marketing. It is arithmetic, and it has never once failed.

It does, however, come with one assumption printed in very small type: you have to actually pick from all of it.

Between certain firmware versions, certain devices did not. The seed generator quietly reached for a deterministic function instead of the hardware's dice, and the haystack — advertised at 115 quattuorvigintillion straws — shrank, for some wallets, to a space a patient stranger could walk end to end. The needles stayed exactly where they were. As reported: 1,082 BTC, out of 1,196 addresses, in 41 minutes, on a Thursday.

The number never failed. Nothing about 2256 failed. Somewhere below the number, a shortcut was taken, and the shortcut was the whole ballgame.

$115792 is the first six digits of the number that worked — a ticker in memory of the firmware that didn't.

2256. The size of the private-key space. Elliptic-curve keys on secp256k1 live just under it, at n = 0xFFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFE BAAEDCE6 AF48A03B BFD25E8C D0364141. Your odds of guessing a specific key are 1 in this number. Your odds if the key came from a 2021 pseudorandom shortcut are, per the reporting, considerably more sociable.

The manufacturer's own guidance notes that seeds generated with 50 fair dice rolls are unaffected. Fifty casino dice, thrown by hand, out-performed the firmware. The dice were always the more rigorous engineer. This token honours the dice.

On July 30, 2026, per multiple outlets, an attacker who had reproduced weak seeds offline swept 1,196 funded addresses — roughly 1,082.65 BTC, about $70M at the time — in 41 minutes. Emergency firmware followed the next day, with a caveat worth framing: installing it does not repair an existing seed. See the Evidence section for the journalism; we only sell the commemorative ticker.

No. Absolutely not. In no jurisdiction, timeline, or keyspace. This is an unaffiliated parody / commemorative meme token. All trademarks belong to their owners; all firmware belongs to its consequences. The frog speaks only for the frog.

01The keyspace · a field, drawn from one seed

Every key that could ever exist, arranged by sunflower.

drag the field · click a node
seed · FNV-1a → mulberry32· nodes· identical on every device
untouched keyspace swept — the weak-seed cohort dice-rolled — never at risk placement: index × 137.5° · radius 106 + 46√index

No Math.random() anywhere in this field. Positions come from the contract address hashed to a single seed, then a golden-angle phyllotaxis — the packing that puts seeds in a sunflower head. Every visitor on every device sees the identical arrangement, with no server and nothing stored. Each node carries its own phase and frequency, so the field drifts forever without anything returning to sync. It is the whole argument of this website rendered as a layout: deterministic, reproducible, and only as strong as the seed you start from.

02Exhibit

Cartoon frog in a red cap reading MAKE COLD STORAGE SAFE AGAIN, urinating on a Coinkite sticker sheet of hardware wallet stickers.
Fig. 1 — Community sentiment analysis, week 31, 2026. Mixed media. Peer-reviewed. Not affiliated with, endorsed by, or in any way appreciated by the manufacturer.