CJ Deployment · first transaction only
First mainnet mint
This page is public, but its signing and submission route is locked and inert. It makes no RPC, browser-storage, wallet, signing, or broadcast call on load. All wallet and transaction controls are disabled. A separately reviewed future release could consider only the exact CJ Deployment wallet; this page does not approve or enable any signing or submission. Do not use another device or browser origin to repeat a previously consumed mint attempt.
Public locked page; signing and submission are unavailable.
Local timing only: no measurements yet. Stage durations, observed block margin, and expiry reason stay on this page and are never submitted as telemetry. A post-tap expiry is terminal.
Exact reviewed identity
- Release
- LOCKED / NOT APPROVED
- Preparation packet SHA-256
- Canonical payload SHA-256
- Audited zero-blockhash template SHA-256
- 2850b4f66f30109ef473481a6bb97a1be5dcbe32d2df926c070786d4023fd188
- Only signer and payer
- Seed-derived original SPL mint
- Treasury ATA
- Founder ATA
- Five instructions
- CreateAccountWithSeed → InitializeMint2 (9 decimals, no freeze) → Treasury ATA idempotent → Founder ATA idempotent → MintToChecked exactly 1 billion CJ to Treasury.
- Reviewed first-transaction modeled debit / client-side stop
- 4,048,680 lamports under the exact current fee and rent: 5,000 fee + 1,066,800 mint rent + 2 × 1,488,440 ATA rent; zero priority fee. Any drift stops this route. The separate $100 acquisition-basis cap requires a fresh owner ledger attestation; this page cannot observe off-chain costs. Neither is a cap on separately gated later actions.
0 · Durable one-shot proof
The local safety marker must survive one reload. Any consumed signing or broadcast latch makes a reloaded page terminal. Browser data can be cleared or another device used, so the no-retry rule is not globally enforced by this marker.
1 · Fixed identity and read-only mainnet readiness
Review the fixed signer, mint, five instructions, debit, and byte-exact zero-blockhash template before starting the short blockhash window. Solana Tracker is the primary read endpoint. Require at least one fresh independent confirmed/finalized account witness from Pocket Network or PublicNode, with matching mainnet genesis, exact account absence, payer balance, and exact rent. This step does not request a blockhash or connect a wallet.
This is the immutable 529-byte legacy message template with exactly its structurally parsed 32-byte blockhash field set to zero. The independent fingerprint below must match; the final live hash is NOT yet known.
- Audited normalized template SHA-256
- Zero-blockhash 529-byte template · base64
2 · Irreversible first-tap and bounded-blockhash consent
Only CJ Deployment may connect. Connection requests the public account only; it cannot sign or submit. You review the fixed five-instruction template above. The first eligible Sign tap atomically consumes the same permanent browser SIGN_KEY used by v1, before any Sign-click RPC or provider read. It authorizes inserting ONLY one newly fetched confirmed 32-byte blockhash into its structurally parsed field. There is NO separate leisurely review of the final 529-byte message before the Bitget prompt. If any check, RPC, storage binding, or expiry fails after this tap, the attempt is over even if no Bitget prompt appears. Do not choose this changed consent model unless separately approved.
Final H1 message proposed for binding to the already-consumed sign record: the base64 below encodes all 529 bytes including the one late-fetched hash. Its digest must be durably bound before the Bitget prompt; it was NOT separately approved byte-for-byte after the Sign click. Do not treat an old screenshot as current.
- Exact 529-byte message · base64
- 529-byte message SHA-256
- Recent blockhash
- Last valid block height
- Deployment balance
- Exact fee
- Maximum debit
- Blockheight margin at check (not live)
Final one-shot H1: SHA-256 ; blockhash ; fee ; maximum debit . At check: . The margin is not a live countdown.
After the Sign attempt is already consumed, read-only checks perform fresh primary-plus-independent accounts, exact rent/fee/simulation, structural template proof, and a final Tracker 100-block validity read. The complete H1 SHA-256 is then atomically bound in that same durable record before at most one Bitget signTransaction prompt. A pre-prompt expiry or any uncertainty is terminal; no new-hash loop, retry, or automatic send.
Verified public signature: Not signed
3 · Separate one-shot broadcast
Never automatic. Rechecks the exact signed H1 bytes without fetching H2, primary-plus-independent absence and balance, live fee/rent/simulation, at least 40 blocks of life, and final validity. A second durable latch is consumed before one candidate PublicNode sendTransaction call with maxRetries: 0. A slow Bitget prompt plus separate human broadcast choice may leave signed-but-unsent terminal state. Errors, timeouts, uncertainty, or reload are terminal; reconcile without resending.
Hard boundary
There is no seed phrase or private-key handling, funding, artwork or metadata upload, vesting, liquidity, authority change, platform submission, or public launch in this route. A returned RPC signature is not finality. All later token actions remain locked pending independent finality and their own approval.