Eleven minutes of conviction
Damn. A wallet trading as gakeflower (7xKQ…9mAe) took supply in the opening bundle and sold the lot 63.4% below where it got in. Eleven minutes, start to finish.
$LOG reads it for you — and tells you, where you already are, at the moment it matters.
Every section carries a status marker. Nothing here asks you to guess whether a capability exists today.
SHIPPED running in production, on real tokens, now. IN PROGRESS specified and locked; being built. ROADMAP designed, dated, not started.
Solana settles a token’s entire history in public and in permanent form. Every launch, every buy, every transfer, every exit is on-chain and free to read. And almost nobody reads it, because reading it means walking thousands of transactions across accounts that do not announce what they are.
The tools that fill this gap mostly return scores. A number between 0 and 100, a colour, a risk band — an opinion with the evidence removed. When the score is wrong there is no way to tell, because there was never anything to check.
$LOG takes the opposite position. It reconstructs a token’s launch from the chain, identifies who acted inside it, and publishes each finding as a short entry tied to a transaction anyone can open. Every number traces to a signature. Anything that cannot be established is printed as unmeasured — never as zero.
The system runs today on bonding-curve launches, publishing to a public feed and a Telegram bot. Its architecture is venue-agnostic by construction: the forensic logic depends on a launch slot, slot offsets and priority fees, none of which are specific to any one launchpad. Extending to Bonk, Raydium, Jupiter and Meteora is the addition of an anchor, not a rewrite.
The information is public and unusable.
A trader deciding whether to buy a token wants to know a small number of things: did the team keep supply, did bots take the launch, is the float concentrated, is whatever coordination exists still holding or already gone.
Every one of those is answerable from chain data. None is answerable quickly. The bonding curve does not label itself. A bundle is not a transaction type — it is a pattern across several wallets in one slot. A sniper is not a flag on an account; it is a wallet that arrived machine-fast and paid to get there.
So the market runs on screenshots, screener percentages, and trust.
Scores make it worse. A single number compresses away exactly the thing a reader needs: which wallets, how much, and can I see it myself. A score of 17 cannot be argued with, corrected, or checked. It can only be believed or ignored.
A forensic narrator. It watches tokens, establishes what happened from chain data, and writes it down as short entries — chapters — each carrying the transaction that proves it.
Three surfaces, one record:
Two properties define the product, and everything downstream follows from them:
At the moment a token launches, its structure is known — precisely, immediately — to exactly the people positioned to exploit it. The deployer knows what was kept. The bundler knows how many wallets took supply in block 0. The sniper knows it arrived first and paid to.
Retail finds out later, or never. Not because the information is secret, but because it is expensive to read: thousands of transactions across accounts that do not announce what they are.
That asymmetry is what makes a predatory launch profitable. It is not a consequence of bad actors being clever; it is a consequence of the record being public and illegible at the same time. Close the gap and the strategy stops paying.
The chain already records every launch in full. $LOG turns that into a record people can actually read — and the record itself has the two properties that define a public good:
It is also permanent. Removing a token stops future coverage; it does not retract the forensic record behind it. The register only grows.
The concrete form of all of this: every token that goes under coverage joins a public register. The verdict, the block it was derived from, the wallets behind each number, and the time it was last read. The forensic layer of every tracked token is permanent and public.
It stays current in three ways, and only one of them costs anything: a token still tracked reads live state; a token someone new tracks refreshes as part of their coverage; and a token nobody is tracking can be refreshed by anyone, rate-limited.
The third is affordable because of a split that matters — the launch half of a verdict never goes stale. Bundlers, snipers and the launch block are history and cannot change. Only current state drifts, and re-reading that is a handful of RPC calls.
And a token we never reconstructed says so. Where coverage bought no history, or the venue is not yet integrated, the launch signals read — and the entry states that the launch was not reconstructed. We did not look is a different claim from we looked and found nothing, and the register is where that distinction does the most work — it is the one place a reader compares tokens side by side.
This is what the grant buys. Not features on a product: rows in a public register. Every venue integrated widens what can be recorded, and the register is permanent.
Because the wallet graph keys on wallets, not tokens, a fresh address does not clear the record. An operator who ran one launch is recognised on the next one, on a different venue, months later.
That changes the incentive rather than merely reporting on it: a strategy that depended on nobody joining the dots stops working once the dots are public.
| screeners | rug scanners | $LOG | |
|---|---|---|---|
| output | prices, holders | a score or a verdict | entries with transaction references |
| launch cohort | no | percentages | percentages and the wallets |
| unmeasured | shown as 0 | shown as 0 or “pass” | shown as unmeasured |
| history | current state | current state | reconstructed to block 0 |
| memory across tokens | no | no | yes — wallets are remembered |
The distinction that matters is the last two rows. A screener tells you a token’s top-10 hold 61%. $LOG tells you which ten, what each holds, whether any of them took supply at launch, and what those same wallets did on other tokens.
And the benefit does not depend on trusting us. Every claim carries the transaction that proves it, so a reader can verify the record without believing the publisher. That is the line between a public record and an opaque risk score — and it is why this works as infrastructure rather than as a service.
Defined before use, because most disagreements about token forensics are disagreements about definitions.
| Slot | Solana’s block unit, ~400ms. All launch timing is measured in slots, never in seconds. |
| Anchor / block 0 | The slot at which a token became tradeable. Everything below is measured as an offset from it. |
| Bonding curve | A per-token account holding pre-graduation trades. Its oldest signature is block 0, by construction. |
| Bundle | Transactions executed atomically in one slot — typically a Jito bundle, up to 5 transactions, all-or-nothing, uninterruptible. |
| Priority fee | Payment above the base fee to be included sooner. Evidence of automation. |
| Cohort | The set of wallets identified as acting inside the launch window. |
| Overhang | Supply held by wallets that are both launch-cohort and current top-10 — coordinated supply still in place. |
| Coverage | What $LOG buys about a token: full reconstructs its launch, watch follows current trades only. |
| Floor | The SOL size below which ordinary market trades are not published. Seven rungs. |
| Chapter | One published entry. Permanent, public, transaction-referenced. |
Four rules govern every claim in section 07. They are not editorial preferences; they are enforced in code and pinned by automated checks.
If the launch window could not be reached, bundlers is unknown — not 0%. The distinction is the whole product. A token nobody looked at and a token that was looked at and found clean produce identical-looking numbers unless the system refuses to conflate them.
Naming a wallet a bot is a claim about a person’s behaviour. One signal is never enough, because each one alone names the innocent: slot position alone makes a lucky human in the first two seconds a sniper; priority fee alone makes an ordinary buyer paying for speed at slot 40 one. A bot is the conjunction — it arrived machine-fast and bid to get there.
“3% bundled” is unreadable without knowing whether that is three wallets or three hundred. Every cohort figure publishes both. A cohort that has fully exited renders as “66 wallets, all exited” rather than a green 0%, because the wallets existed and the record should say so.
Every derived figure carries the completeness of the walk that produced it: complete — the full window was read; incomplete — the walk could not finish, so the figure is a floor rather than a total; not-bought — coverage did not include this work, so nothing was looked for.
The last two are different claims and are never merged. One says we tried and could not; the other says we did not try.
Everything else is an offset from this, which makes it the highest-stakes value in the system.
Curve-anchored. The token’s bonding curve account is walked to its oldest signature. That signature is block 0 by construction, not by inference: the curve did not exist before the token did. The derived birth time is cross-checked against the launchpad’s own published birth time before anything downstream uses it. A window that cannot be corroborated is rejected rather than used.
Pool-anchored ROADMAP — for tokens with no curve, the anchor is the pool creation transaction: the first slot at which the token could be traded. This is the correct analogue because snipers front-run liquidity — the LP add is the starting gun.
No anchor — returns unknown. Launch-derived signals publish as unmeasured.
Rule: two or more wallets buying in the same slot as the anchor.
A bundle is atomic. No external transaction can be interleaved between the launch and the buys inside it, which is what distinguishes coordination from coincidence — those wallets did not race each other, they were submitted together.
A Jito bundle carries at most 5 transactions. A launch with many wallets in block 0 therefore used several bundles in the same slot, which is a stronger signal than any single bundle — it is coordination that had to be assembled deliberately.
Rule: bought within 5 slots of the anchor (~2 seconds) and paid a priority fee.
Both conditions, per 6.2. The window is deliberately tight: at ~400ms per slot, 5 slots is short enough that a human cannot be inside it while long enough to include a bot that lost the block-0 race and retried.
Jito is not the test. A Jito tip proves automation when present — no human assembles a bundle and submits it to a block engine — but a bot on a public RPC paying an ordinary priority fee leaves no tip. Absence of a tip proves nothing, so it is recorded as corroboration and never as the criterion.
The deployer and wallets evidenced as connected to it — by direct funding, by launch behaviour, or by the token’s own creator authority. Deployer identity does not depend on the launch window, which is why dev/team survives on tokens whose launch could not be reconstructed.
Claimed from structure, not from suspicion. Two independent methods, published separately: by similarity, wallets holding near-identical fractions of supply — independent balances landing on the same number is not a coincidence a market produces; and by creation time, wallets created in the same window — the one attribute an operator sets once and can never change afterwards.
Wallets that received tokens from a cohort wallet rather than buying on the market. This exists because a bundle that transfers its position looks identical to a bundle that sold, if you only watch sales.
Membership and holdings are two questions with two answers. A wallet that received a third of a bundle and dumped it contributes a wallet to the count and zero to the percentage. It is not the same as a wallet that never existed, and the record says so.
Current-state, venue-independent, works on any SPL token: holder count and distribution; top-10 concentration taken from a balance-ordered source and excluding AMM pools, program-owned accounts and locked positions, because those are not holders in any meaningful sense; and overhang — supply held by wallets that are both cohort and top-10.
Overhang is the sharpest single number the system produces: coordinated supply that has not left. It is null, never 0, when the launch was not analysed or the bundler origin was not verified — a clean zero there would be an accusation-shaped mistake in the opposite direction.
Static analysis of the token itself rather than its trades. Venue-independent, and it applies to curve launches too: can more supply still be minted; can holders be frozen; can transfers be blocked selectively; can the program rules change after launch; is liquidity burned, locked, or still pullable.
This is what makes every project on Solana honest. A token deployed straight to a pool has no launch to reconstruct, but it always has a contract to read.
A composite of the signals above, published beside the evidence rather than instead of it. It exists to order a list, not to replace a reading. A component that is unmeasured does not contribute a zero — it reduces the number of signals the score is computed across, and the count is published: “0 of 4 signals elevated” rather than “0 of 6” when two could not be read. Overhang floors the label: coordinated supply still in place cannot be scored away by clean readings elsewhere.
Four words, and it never softens:
Clean · Risky · High Risk · Rugged / Farmed
Every post-collapse state that did not recover is Rugged / Farmed. Which collapse it was — abandoned, farmed, open to a community takeover — goes in the reason line, where it belongs.
This is a deliberate correction of an earlier design in which a collapsed token whose cohort had cleanly exited could be headlined as an opportunity. A tidy wreck is still a wreck. Reports published before the rule changed keep their original wording: the record is fixed forward, never rewritten.
A token launched on a bonding curve, read end to end:
At every step, a value that could not be established stops that branch rather than defaulting.
Five layers. Four of them are venue-independent.
5. PUBLICATION floors, narration, delivery, share text
4. CONTRACT AUDIT authorities, upgradeability, liquidity ROADMAP
3. UNIVERSAL holders, concentration, coordination,
transfer networks, the wallet graph
2. LAUNCH COHORT bundlers, snipers, dev/team
1. VENUE ADAPTER the only venue-specific codeThe seam is Layer 1. Layers 2–5 consume an anchor and do not know or care where it came from.
One forensic engine, many anchors.
The cohort rules in 7.2–7.3 depend on exactly three things: a launch slot, slot offsets, and priority fees. None is specific to a launchpad. The only venue-specific question is where the launch slot comes from.
So a venue is an interface, not a subsystem:
interface VenueAdapter {
claims(mint): boolean; // does this venue own this token?
resolveAnchor(mint): { // THE question
launchSlot: number;
launchBuys: LaunchBuy[];
complete: boolean;
} | null; // null -> unmeasured, never zero
defaultSupply(): number | null;
lifecycle: LifecycleVocabulary; // "graduated" is not universal
}Adding a venue is: implement the adapter, register program ids, freeze a golden fixture against one real token, and diff it. Layers 2–5 are untouched. That is what makes each venue a dated, verifiable deliverable rather than an open-ended integration.
A venue not yet integrated returns null and its tokens publish launch signals as unmeasured. This behaviour is already shipped — it is what watch coverage does in production today.
History is reconstructed, not subscribed to. The forensic layer derives what it needs from account walks, which is why findings work independently of any live event feed and why a token can be added months after it launched.
Coverage is a purchasing decision, made once, at add time. The distinction is enforced at every path that can spend, not merely at the first one.
The model writes. It never decides.
Every forensic fact in a chapter is computed deterministically before generation begins. The model receives a structured object of already-decided values — who, what, how much, which transaction — and is constrained to render them as prose. It cannot compute a percentage, classify a wallet, infer a motive, or resolve an unknown into a value.
A field that arrives null stays absent from the output. There is no path by which a model’s fluency becomes a published claim, because the model is never given the inputs from which such a claim could be constructed.
Generation is followed by a rule-based scan that does not use a model. It enforces the evidence rules from section 06 on the output, independently of whatever the model was told. Anything that trips it goes to review rather than out.
12.1 is a claim about inputs. 12.3 is the check on outputs. Both exist because either alone is a single point of failure.
The register is flat and observational. One deliberate exception: when the outcome of a trade is known, an entry may open with a single human reaction before returning to flat.
Damn. A wallet trading as gakeflower (7xKQ…9mAe) took supply in the opening bundle and sold the lot 63.4% below where it got in. Eleven minutes, start to finish.
That reaction is gated on evidence. If the position history could not be established there is no reaction, no direction, and no implication — “damn” is a claim about whether a trade won or lost, and the system does not guess.
Laughing at a decision is allowed; it is what makes the record get read. Mocking a person, or implying anything was done to them, is not — that asserts a victim and an actor, which is an accusation rather than an observation.
Narration is the dominant variable cost, not chain data. Two mechanisms hold it: prompt caching, because narration is bursty and a short-lived cache means every burst starts cold and pays full price for the same fixed prompt; and the floor, an operator-set SOL threshold which is therefore the real cost dial. Coverage decides what is bought; the floor decides what is written.
A scanner starts from nothing every time you ask. $LOG does not.
Wallet fingerprints persist across every covered token. A wallet identified on one launch is already known the next time it appears on a different one. Operators who rotate wallets are fingerprinted by funding-source chains and behavioural timing, not by exact address match — so a fresh wallet does not reset the record.
The graph keys on wallets, not tokens. That makes it venue-independent by construction: a wallet first seen sniping a curve launch is recognised the moment it appears on an AMM pool, with no work required to connect them.
The chain is public and permanent, so it is worth being precise about what a competitor could not simply reproduce.
The wallet graph is reproducible, at a price. Anyone applying the walks above could reconstruct the same cohorts and funding chains. What they could not avoid is the bill: rebuilding a registry across thousands of launches at once, where we pay for each one incrementally, as it happens, at near-zero marginal cost. That is a real advantage — an accumulated one rather than an exclusive one.
The time series is not reproducible at any price. Significance is judged against each token’s own history: the distribution of its trade sizes, its normal rate of movement, what its baseline was before a burst. Those are sampled, not derived. Nothing in a snapshot taken today can say what a token’s trade distribution was last Tuesday — that record exists only for someone who was watching at the time.
So the moat is what was observed as it happened. Every token covered makes every future answer better, and the window to observe a given token’s past closes permanently once it passes.
Coverage — what is bought. Chosen once, at add time, because the add is what spends.
A watched token has no cohort — that follows from the definition rather than being a separate rule, since the launch walk is what identifies one.
The floor — what is published. Seven rungs, one ladder. Every rung is “the launch cohort, plus ordinary trades above n SOL”:
cohort only · 5 · 2.5 · 1 · 0.5 · 0.25 · 0.1 (SOL)
The launch cohort publishes at any size on every rung. The floor governs the ordinary market only.
Prepaid, SOL-denominated, no fiat rails. You buy credits; actions cost credits. There are no subscriptions, no recurring charges and no minimums.
1 credit = 0.00025 SOL at base rate, tapering with pack size.
| Pack | SOL | SOL / credit |
|---|---|---|
| 100 | 0.025 | 0.00025 |
| 250 | 0.06 | 0.00024 |
| 500 | 0.115 | 0.00023 |
| 1,000 | 0.22 | 0.00022 |
| 2,500 | 0.525 | 0.00021 |
| 5,000 | 1.0 | 0.00020 |
| 10,000 | 1.9 | 0.00019 |
SOL is the source of truth. No pricing logic converts through USD. The rate is a single configurable constant, reviewed on a stated schedule against infrastructure costs — which are USD-denominated even though revenue is not. Repricing follows a published trigger rather than a market move, so it is never arbitrary.
| Action | Credits |
|---|---|
| Watch chapter — current-state narration | 1 |
| Forensic chapter — includes launch-cohort context | 2 |
| Add Token — full coverage, launch walk to block 0 | 50 |
| Add Token — watch coverage | 20 |
| Wallet Roast | 8 |
| Pre-Buy Check | free, uncapped |
| Basic Forensic Report | 40 |
| Enhanced Forensic Report | 100 |
Pre-Buy Check is free and ungated by design. It is the question a trader asks most often and the one that demonstrates the product fastest.
Credits buy coverage — which tokens are followed, how closely, and how much of their past is reconstructed.
The forensic layer of every tracked token is permanent and public — the verdict, the signals behind it, the block it was derived from and the wallets that produced each number, in the register described in section 04.
The stories and chapters on your watchlist are yours. Coverage is what turns a static verdict into a running narrative — the cohort wallet that moved, the liquidity that changed, the name that showed up somewhere new — delivered on the tokens you chose, as it happens.
Stopping is not deleting. The token's forensic record stays in the register. Retraction is a separate, deliberate act.
Two things drive everything below: the bot that tells you when a wallet does something worth knowing, and the feed that keeps the record in public. Everything else exists to make those two better. Nothing here is a promise about a price.
Coverage widens, and the checks widen with it.
Bonding-curve launches were the proof. The same screening now extends to Bonk, Raydium, Jupiter and Meteora — and to tokens that never had a fair launch at all, deployed straight to a pool. Wherever a token started, $LOG walks back to find who took the supply.
Alongside it, the token's own contract is read, not just its trades: can more supply still be minted, can holders be frozen, can transfers be blocked, is the liquidity burned or still pullable. A token with no launch to reconstruct still has a contract that answers.
And paste any contract address to get the forensic read free — holders, concentration, who is coordinated, what the contract still permits. No account, no charge.
A venue we haven't reached yet says so. It never shows a clean zero it didn't earn.
The read and the trade stop living in two tabs.
Every chapter tells you what a wallet did. Next it tells you what to do about it — buy or sell from inside the chapter itself, on web and in Telegram.
More venues land through the same door, each one adding to something that compounds: $LOG remembers wallets across tokens. A wallet that sniped a launch in August is recognised the moment it appears on a token in December — not because we watched that token, but because we watched that wallet.
Premium opens on prepaid credits — you buy coverage, you see exactly what it costs, and it never bills you for a token you stopped watching.
Everything above, carried over — not rebuilt.
The feed, the chat and the buy bot as a real app, not a page you bookmark.
Alerts that reach you the moment a chapter is worth reading — a cohort wallet moving, liquidity pulled, a name you have seen before showing up somewhere new.
Every wallet, every token, every project on Solana — verifiable receipts, not probabilities.
The wallet memory stops being something only $LOG reads. It becomes infrastructure other builders can query — the accumulated record of who did what, across every launch on the chain, with every number still traceable to a transaction anyone can open.
Not a score. Not a probability. A receipt.
Every wallet, every token, every project on Solana — verifiable receipts, not probabilities.
$LOG — receipts only.
The endpoint of everything above.
Layers 2–5 already work on any Solana token. Layer 1 makes them work on every venue. The wallet graph accumulates across all of it. What remains is to open it: a queryable record of who did what, across every launch on the chain, where each answer still carries the transaction that proves it.
Not a risk score other builders have to trust. A receipt they can check.
Section 05 carries the working vocabulary. Additional terms used above:
| ATA | Associated Token Account — the per-wallet, per-mint account holding a balance. Walking it reconstructs a position. |
| Jito bundle | Up to 5 transactions executed atomically in one slot, all-or-nothing, uninterruptible by outside transactions. |
| Reference-counted coverage | Coverage that persists while any watcher remains, rather than being owned by one subscriber. |
| Structure score | The composite in 7.9. An ordering aid, never a substitute for the evidence. |
| signal | anchor required | refuses to claim when |
|---|---|---|
| Bundler | yes | anchor unknown |
| Sniper | yes | priority fee not established |
| Dev / team | no | no deployer identifiable |
| Coordination — similarity | no | fewer than two comparable holders |
| Coordination — creation time | no | creation times unread |
| Transfer network | yes | scan incomplete → published as partial |
| Top-10 concentration | no | supply unreadable |
| Overhang | yes | launch unanalysed or origin unverified |
| Contract audit ROADMAP | no | authority state unreadable |