Every coin hides the next one.
Hold $CAPSULE and you open the capsule: the next coin's contract address, minutes before it launches. Then a drand timelock reveals it to everyone. Nobody can hide it or delay it. Not even us.
Capsule #3 · $MOTH
SealedRipens in
11:56
fee is in · waiting for the 60 min minimum
Opened
0
125 holders
Next CA · coin #4
hidden until you open the capsuleThe latest trades. Buys and sells both fill the capsule.
01The vault
Your wallet. Your first look.
A demo wallet with 5 made-up SOL and a bag of $ECHO, held since before $MOTH launched. Buy a key, open the capsule when it's ripe, and see the next CA before everyone else. Then do it again with a double key.
Demo wallet
QvF8…fUFv5.00 SOL
+ 0.392 SOL in coins · all made up
Keys for Capsule #3
Key · $MOTH
0 / ≈613K
Double key · $ECHO
1.12M / 699K
held at launch ✓
Holdings
- #2$ECHO1.12M · 0.392 SOL
Capsule #3 · $MOTH
SealedRipens in
11:56
fee is in · waiting for the 60 min minimum
Price
0.326 SOL/M
mcap 326.4 SOL
Trade $MOTH · fills the capsule either way
The capsule isn't ripe yet. It opens once the fee is in and the coin is an hour old.
Capsule log
11:27:50 · #2
Handoff: 0.75 SOL from Capsule #2 bought and burned $MOTH.
11:27:50 · #2
drand round reached. Capsule #2 held $MOTH. Commit matched. 18 wallets saw it first.
11:26:50 · #2
Handoff: 0.75 SOL bought and burned $ECHO.
11:22:50 · #3
Commit for Capsule #3 published: bf4a7f3e16…
11:22:50 · #2
Coin #3 launched from a fresh wallet. Snapshot of $ECHO holders taken. Public at drand round.
11:11:00 · #1
Afterglow: 0.186 SOL of $CAPSULE fees bought and burned it.
11:11:00 · #2
Capsule #2 is ripe with 1.28 SOL inside. Key: 699,312 $ECHO.
10:16:00 · #1
Handoff: 0.82 SOL from Capsule #1 bought and burned $ECHO.
10:16:00 · #1
drand round reached. Capsule #1 held $ECHO. Commit matched. 49 wallets saw it first.
10:15:00 · #1
Handoff: 0.82 SOL bought and burned $CAPSULE.
10:11:00 · #2
Commit for Capsule #2 published: 6c6e0aa987…
10:11:00 · #1
Coin #2 launched from a fresh wallet. Snapshot of $CAPSULE holders taken. Public at drand round.
10:00:00 · #1
Capsule #1 is ripe with 1.42 SOL inside. Key: 598,878 $CAPSULE.
09:00:00 · #1
Commit for Capsule #1 published: 19e4c6e240…
02How it works
Four steps. One capsule inside another.
1Commit
The next CA is locked before you ever see this one.
We generate the next coin's mint keypair ourselves. The moment a coin launches, its launch tweet and this page carry sha256(next CA ‖ salt). It can't be swapped later without breaking the hash.
Next CA (kept secret)
hidden until you open the capsuleSalt
████████████████████████████████
sha256( CA ‖ salt )Commit · published at launch
bf4a7f3e16dcc51188ffc38f90db2c418fdc7b52b72504d99db2f7a3a00f2265
In the launch tweet, on this page, on the rings of the capsule.
2Fill
Every trade fills the capsule.
All of the creator fee goes in, from buys and sells. At 1 SOL of fee, and once the coin is at least an hour old, the capsule is ripe. That's ~333 SOL of volume; wash trading it costs more than it holds.
Fee inside
100%
Coin age
80%
- + buy 0.34 SOLfee 0.0010
- + buy 0.52 SOLfee 0.0016
- + buy 0.64 SOLfee 0.0019
- + buy 1.77 SOLfee 0.0053
- + buy 1.08 SOLfee 0.0032
- + buy 0.69 SOLfee 0.0021
3Open
Holders open it with a signature. Free.
Hold a key (0.2 SOL of the coin) and sign one message. No transaction. You see the next CA and the exact second it launches, 8–12 minutes later. From capsule 2 on you need a double key: this coin and the one before, held through the launch.
Sign · free · no transaction
CAPSULE #3 · open · 9xVi…Qm2a · k2f8xq1z · 2026-10-01T11:48:12Z
Key · this coin
held ✓
Double key · coin before
held ✓
First look
8fTq2mWcXy7PnL4vR9sKdJ3hGbZ1aUeYxN5oQwpumpRipe
0:00
Launch
+8–12 min
Public
+5 min
4Reveal
drand opens it for everyone. Then the handoff burns.
Five minutes after launch, a drand timelock round unlocks the CA for the whole internet. Nobody can hide it or push it back. The site checks it against the commit, and the capsule's SOL buys and burns both the old coin and the new one.
drand quicknet
a new round every 3 s
Timelock ciphertext → plaintext
-----BEGIN AGE ENCRYPTED FILE----- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHRsb2NrIDUxODQyMjAg…
sha256(CA ‖ salt) = commit
Old coin bought & burned
½ capsule · 5 slices
New coin bought & burned
½ capsule · after reveal
Next CA (kept secret)
hidden until you open the capsuleSalt
████████████████████████████████
Commit · published at launch
bf4a7f3e16dcc51188ffc38f90db2c418fdc7b52b72504d99db2f7a3a00f2265
In the launch tweet, on this page, on the rings of the capsule.
03The chain
Each capsule held the next coin.
- Capsules opened
- 2
- First looks
- 67
- Burned
- 3.33 SOL
- Matched
Capsule #1
$CAPSULE
- Ripe after
- 1:00:00
- First looks
- 49
- Fee in capsule
- 1.64 SOL
- Burned
- 1.01 SOL
- Peak mcap
- 387.3 SOL
- Held
- $ECHO
commit 19e4c6e2…a35148
- Matched
Capsule #2
$ECHO
- Ripe after
- 1:00:00
- First looks
- 18
- Fee in capsule
- 1.51 SOL
- Burned
- 1.57 SOL
- Peak mcap
- 438.5 SOL
- Held
- $MOTH
commit 6c6e0aa9…20438d
- Now
Capsule #3
$MOTH
- Ripe after
- 48:04…
- First looks
- 0
- Fee in capsule
- 1.01 SOL
- Burned
- 0.753 SOL
- Peak mcap
- 326.4 SOL
- Held
- sealed
commit bf4a7f3e…0f2265
Capsule #4
$??????
Not launched. Its CA is already chosen and committed. Hold the chain to see it first.
04Proof lab
Don't trust us. Run it yourself.
Both tools run in your browser. The commit check is sha256 through WebCrypto. The timelock is the real drand network: your message is encrypted to a future round and nobody, including us, can read it before that round is published.
Verify a commit
Was the CA the same from the start?
Simulation data, real math. Try editing one character of the salt.
drand timelock · live network
round —Seal a message into the future.
Uses tlock-js against drand quicknet (52db9ba70e…). The capsule's public reveal works the same way, sealed to the round five minutes after launch.
05 · Specification
Matryoshka Protocol, MP-1.
Status: proposal v1
Changes only between capsules, with notice
- §1
Commit
When coin N launches, sha256(CA of coin N+1 ‖ salt) is published here and in the launch tweet.
whyThe CA is chosen before anyone has seen coin N. It can't be swapped later.
- §2
Fill
100% of coin N's creator fee fills its capsule, from buys and sells alike.
whyTrades are the clock. More trading, sooner reveal.
- §3
Ripening
Fee ≥ 1 SOL and the coin is at least 60 minutes old. At the latest 24 h after launch.
whyEvery coin gets its own hour. The chain never stalls on one quiet coin.
- §4
Key
Holding coin N worth at least 0.2 SOL at the price when the capsule ripened. The token amount is fixed and published then.
whyA small bar, but a bar. It doesn't move while the capsule is open.
- §5
Opening
A free wallet signature. No transaction. The server checks the signature and the balance on-chain.
whyNobody pays to take part.
- §6
Double key
From capsule 2 on, you need the key of coin N and of coin N−1.
whyYou hold the chain, not a flip.
- §7
Hold rule
The N−1 key counts only if the wallet also held it in the snapshot taken when coin N launched. The snapshot is published.
whySold before the launch? Buying back doesn't restore it.
- §8
Launch
8–12 minutes after ripening, from a fresh wallet, neutral name, no links. The exact second is inside the capsule.
whySnipers see ~100 launches in that window. Holders see one.
- §9
Public reveal
5 minutes after launch. The CA is timelock-encrypted to that drand round and the ciphertext is published at ripening.
whyNobody can hide it or delay it. Not even us.
- §10
Handoff
At launch, 50% of the capsule buys and burns coin N in 5 slices, one a minute. After the reveal, the rest buys and burns coin N+1.
whyThe old coin gets a buy as attention moves on, and pays for the new coin's first burn.
- §11
Afterglow
After the handoff, coin N's later fees buy and burn it once an hour.
whyOld coins in the chain keep living.
- §12
Team
A dev buy only inside the create transaction, at most 0.5 SOL, printed in the capsule before anyone opens it. Team wallets never open capsules and never buy before the reveal.
whyHolders know the dev bag before they buy.
Early access is time, not profit. Holders see the CA a few minutes before the public. Nothing here promises a price, a return or a pump.
Everything is checkable. Commits, ciphertexts, snapshots, burns and every trade are public. The rules are one file of pure functions.
Late buyers are exit liquidity for early ones. True for every launch, and designed in here. That's why the rules are this plain.
06Verify
Every number is on-chain or on drand.
Wallets
- published at launch
Capsule vault
every creator fee lands here
- published at launch
Keeper
claims fees, runs handoff and afterglow burns
The rule that decides who opens · rules.ts
export function canOpen(input: OpenInput) {
const blocks: OpenBlock[] = [];
if (input.phase === "sealed") blocks.push("sealed");
if (input.phase === "revealed") blocks.push("public");
if (input.isTeam) blocks.push("team");
if (!(input.balance >= input.keyTokens)) blocks.push("no-key");
if (input.index > 1) {
const prev = input.prev;
if (!prev || !(prev.balanceNow >= prev.keyTokens)) blocks.push("no-prev-key");
else if (!(prev.balanceAtSnapshot >= prev.keyTokens)) blocks.push("sold-before-launch");
}
return { ok: blocks.length === 0, blocks };
}The site, the keeper and anyone replaying a capsule run this same function, with 36 tests behind it.
Commits and reveals
| Capsule | Commit | drand round | Openers | Status |
|---|---|---|---|---|
| #3 $MOTH | bf4a7f3e…0f2265 | — | 0 | sealed |
| #2 $ECHO | 6c6e0aa9…20438d | 32,680,686 | 18 | matched |
| #1 $CAPSULE | 19e4c6e2…a35148 | 32,680,650 | 49 | matched |
The ciphertext for capsule #3 is published the moment it ripens.
07FAQ
Questions snipers ask.
Can't snipers just find the next coin on pump.fun?
Every launch is public within a second, so we don't hide the coin. We hide which one it is. About 25 coins launch every minute. Ours comes from a fresh wallet, with a neutral name, no links and a normal-looking address. The public only knows a 4-minute window (~100 launches). Holders know the exact second.
What if a sniper just buys $CAPSULE and opens it?
Then they're a holder, and that's a buy. That's the whole trick. And from capsule 2 on they need a double key, held through the previous launch.
Can you peek, or delay the public reveal?
We know the CA, obviously; we made the keypair. What we can't do is swap it (the commit is public from the start) or keep it private longer: the CA is timelock-encrypted to a drand round, and when that round is published anyone can decrypt it. If our servers died, the reveal would still happen.
Does opening cost anything?
No. You sign a message with your wallet. It's not a transaction, it moves nothing and costs no gas. The server only checks that the signing wallet holds the key.
What's a double key and the hold rule?
From capsule 2 on, you need the current coin and the coin before it. The older one must also have been in your wallet when the current one launched: we take a snapshot at that moment and publish it. Sell before the launch and buying back doesn't count.
Where does the capsule's SOL go?
It's the creator fee of that coin. When the next coin launches, half buys and burns the old coin in five slices. After the public reveal, the other half buys and burns the new coin. Later fees of the old coin buy and burn it once an hour.
Does the team buy the next coin early?
Only inside the create transaction, at most 0.5 SOL, and the amount is printed in the capsule before anyone opens it. Team wallets can't open capsules and don't buy before the reveal.
Is early access a guarantee of profit?
No. It's a few minutes of time. New coins can go to zero in those minutes. Late buyers are exit liquidity for early ones — true for every launch, and designed in here — which is why every rule is on this page.
Is this live?
Not yet. What you see is a labelled simulation: the rules are real, the coins, wallets and trades are made up. The drand timelock in the Proof lab is the real network.
Hold this one.
See the next one.
One capsule at a time. Every one holds a coin nobody has seen, and the key is simply holding the one you're looking at.