Pre-release. Nothing here handles real funds yet.
This page describes how Bunker is designed to sit beside a trading setup. No Bunker program is deployed on mainnet. Do not send assets to any address on the strength of this page.
The idea: a one-way valve
Trading terminals, bots and browser wallets hold keys that sign quickly and often. That is what makes them useful and what makes them the wallets that get drained. A Bunker is a second place with a different rule: anything can be sent in by any wallet, and nothing comes out without the Bunker key, which the trading wallet never has.
So the habit is simple. Trade from the hot wallet. When you take profit, send it to the Bunker. If the trading wallet is drained tomorrow, what you swept yesterday is not in it.
How it fits a trading setup
- Your Bunker has an ordinary Solana address. Save it as a withdrawal or transfer destination in your terminal, exchange or wallet.
- SOL can be sent to it directly from anywhere.
- Tokens need the Bunker’s token account. A Bunker address is a program address, and some wallets and terminals refuse to send tokens to one. Until they support it, deposit tokens through the Bunker app, which creates the right account. Only SOL and classic SPL tokens are supported.
- Getting money back out is deliberate. A withdrawal needs your Bunker key, never the trading wallet’s. The protocol sends at once to addresses you listed as trusted when you built the Bunker, and makes anything else wait so you have time to cancel it. A Bunker is for what you are holding, not for what you need in the next trade.
What it does not do
- It does not protect the trading wallet. Whatever is still there can still be drained.
- It does not trade, swap, stake or lend. The program can only hold and release.
- It does not help if the recovery kit is kept on the same machine as the trading setup. Keep the kit off that device.
For terminal and wallet developers
Supporting a user’s Bunker needs very little, because deposits are plain transfers and the program has no deposit instruction.
- Send to Bunker. Let users save a Bunker address and send SOL with a System transfer. For classic SPL tokens, create the associated token account with the Bunker address as an off-curve owner, then transfer. Do not block the destination for being a program address.
- Show it, read-only. A vault is one program-owned account with a fixed layout. Its balance and whether a withdrawal is pending can be read with ordinary RPC calls; no key is needed and nothing can be moved.
- Never ask for the recovery kit. An integration that handles the kit or its password is not an integration; it is the attack this product exists to stop.
The account layouts are specified in the protocol specification. It is a draft and will change before mainnet; build against a reviewed release.
Planned, not built
A deposit link any wallet can open, a “Send to Bunker” action that terminals and wallets can render as a button, and a public read-only status lookup for a Bunker address. None of these exist yet, and none will ship before the program has been reviewed. If you build a terminal or a wallet and want to shape them, reach out on X or open a GitHub issue.