DogecoinVM technical roadmap
DogecoinVM is a Dogecoin-compatible chain running as a Layer 1 on Metal Blockchain, joined to Dogecoin by a one-for-one DOGE bridge. This page covers what is running today, how it works, what it doesn't do yet, and the order in which we'll close those gaps.
Where it stands. DogecoinVM is live on Metal Blockchain mainnet with real DOGE, limited by alpha caps, and the bridge has completed its first round trip: DOGE moved from Dogecoin to DogecoinVM and back, with every step on chain. Since 27 September 2026 the bridge holds no keys: each key runs in its own signer service. One operator still holds all of them, so you are trusting that operator. Bringing in independent operators, through the setup ceremony that is already built, is next.
The first round trip
23 September 2026. Dogecoin transactions open on a public Dogecoin explorer, DogecoinVM ones in this site's explorer.
| Step | Chain | Transaction | Amount |
|---|---|---|---|
| Deposit to a personal deposit address | Dogecoin | 74e053f6…ea11b9 | 1 DOGE |
| Credit, after 20 confirmations and the 0.01 DOGE bridge fee (the confirmation tiers came on 25 September; before that every deposit waited 20) | DogecoinVM | 39a6c47e…7d8475 | 0.99 DOGE |
| Withdrawal to the bridge, naming a Dogecoin address | DogecoinVM | 4a447aff…6c3852 | 5 DOGE |
| Payout, after the 0.1 DOGE Dogecoin fee, about a minute later | Dogecoin | 8be21486…ec9737 | 4.9 DOGE |
The wallet's one-click move, from its Dogecoin balance to its deposit address after review, worked the same evening (0c7de3ce…7b9f68). Proof of reserves matched throughout: DOGE locked on Dogecoin equalled DOGE circulating on DogecoinVM plus deposits waiting to be credited.
What is running
| Component | What it does | State |
|---|---|---|
| DogecoinVM L1 | Dogecoin's transaction and script rules (legacy, pre-SegWit) and Dogecoin 1.14 fee and dust policy, with Snowman consensus: a transaction is final once it is in a block, usually in under a second. | Live |
| Peg reserve | DOGE is created only in the chain's reserve blocks, which consensus enforces. That supply is locked to the peg signers and released only against DOGE locked on Dogecoin. | Live |
| Bridge | Watches both chains. It credits deposits after 1 to 20 Dogecoin confirmations, depending on the amount, and pays out withdrawals once they are final on DogecoinVM. It stops moving funds if the solvency check fails. | Live |
| Web wallet | One key, one address on both networks: Dogecoin and DogecoinVM balances side by side, and a one-click move between them. Keys stay in the browser, optionally encrypted to a passkey, and every payment is shown for review, read from the transaction itself, before it's signed there. The page checks the deposit address and every coin it spends itself, rather than trusting the server. It installs as an app on Mac, iPhone and Android. | Live |
| Explorer | Shows bridge activity with the transaction on each chain, proof of reserves output by output, and DogecoinVM blocks, transactions and addresses. | Live |
| Monitoring | Checks the peg, overdue transfers, both nodes and the validator's fee balance every minute, and sends Telegram alerts. | Live |
| Separate signers | A signer service for each key holder, and dogevm signer-setup, the ceremony that brings new signers in. Running since 27 September 2026: each live key in its own signer service, and a bridge that holds none, with the peg address unchanged. One operator still holds all three keys; independent operators are next. | Live, one operator |
| macOS wallet | A native Mac app for both networks: review every payment before it's signed, Touch ID for each signature, the key kept encrypted to the Mac's Secure Enclave, and signed automatic updates. Signed and notarized by Apple for download outside the App Store, and open source. | Live |
| Dogecoin node | The bridge's own Dogecoin Core node, with a full transaction index, which the bridge and the wallet's Dogecoin balances read. | Live |
Anyone can check these IDs on Metal Blockchain:
- Subnet
- 2t2zEB1T3mNUE2WoheMFMjfhAvQJawtgiwnKPJz2NsFk7FDgyN
- Chain
- 2hFCfzdMmfXBxYgvvdL7BYiJAxdejyn4AksMYUM2eM5gN7Xrjy
- VM ID
- mEUwHwfd8UTHf23UYkQxHvy1n1EGwWieXQnjmtzSryJRZckzu
- Validator
- NodeID-5qeQJPktXm63RrXxxkfjunFJPQCP7YeeK
- Dogecoin peg address
- AAvNfukpAa4iTcRJPetxuxX8XxbC5gFqUM
How DOGE moves
Every DOGE on DogecoinVM is backed by a DOGE locked on Dogecoin, and anyone can check both sides. The bridge enforces one invariant: locked on Dogecoin ≥ circulating on DogecoinVM + pending. If that ever fails, it stops.

Deposit: Dogecoin to DogecoinVM
- The wallet gives each user a personal Dogecoin deposit address. Its script commits to the user's DogecoinVM address, followed by a 2-of-3 multisig of the peg signers. The browser derives the address itself and refuses to show one that doesn't match.
- After enough Dogecoin confirmations for the deposit's size (1 for 1 DOGE, up to 20 above 50 DOGE), the signers release the same amount from the peg reserve to the user's DogecoinVM address, less a 0.01 DOGE fee. The release is tagged with the deposit it pays for, so a deposit can't be credited twice.
- Deposits over the alpha cap, or arriving while the total is at its limit, are held and can be refunded on Dogecoin. To ask for a refund, use the contact details in the terms.
Withdrawal: DogecoinVM to Dogecoin
- The user sends DOGE back to the peg reserve with a tag naming a Dogecoin address.
- Once that transaction is final on DogecoinVM, usually in under a second, the signers pay the Dogecoin address from the locked DOGE, less a 0.1 DOGE network fee. The minimum withdrawal is 2 DOGE.
Who holds the keys
The peg is a 2-of-3 multisig: any two of the three signer keys together can move funds. Those keys control both sides of the bridge.
On Dogecoin
The locked DOGE: the peg address and every personal deposit address. These are the real coins users sent in.
On DogecoinVM
The reserve created at genesis. Releasing it is how a deposit is credited, so it decides how much bridged DOGE exists.
Two key holders acting together could take the locked DOGE, or credit DOGE with nothing behind it. The defence is independence: separate people, on separate machines, each checking the chains through their own nodes. That defence isn't in place yet. During the alpha, one operator holds all of the bridge's signing keys, so you are trusting that operator. Caps and daily limits are enforced by the signer software; they don't limit what someone holding the keys could take. Moving the keys to independent operators is planned.
Since 27 September 2026 the bridge process holds no keys. It proposes each transaction, and every signer service checks it against both chains:
- The action is really owed: a confirmed deposit not yet credited, a final withdrawal not yet paid, or a refund its operator approved.
- The transaction is exactly the one the signer would build itself, down to every amount and address.
- The signer has not already signed another transaction that could pay the same thing twice.
- It stays within that signer's own daily limit.
Once the signers are run by independent operators, each through their own nodes, a compromised bridge can delay transfers but can't move locked DOGE. Until then these checks catch a faulty bridge, not whoever holds the keys.
Signing is automatic. Each signer is a service that applies these rules by itself, so deposits and withdrawals go through in the time it takes to reach the required confirmations, with no one approving them by hand. People act only to approve refunds and to change the rules, which means a new signer set that every operator joins.
Bringing signers in: the setup ceremony
dogevm signer-setup takes each operator through setup. Only public information changes hands: no private key, password or token is ever sent to anyone. It runs interactively for a person, or with flags for automated operators. Without a terminal, the join step requires the fingerprint the operators confirmed, so no script can approve a signer set on its own.
| Step | Who | What happens |
|---|---|---|
init | Each operator | Makes a key on their own machine, or imports one at a hidden prompt, and produces a public signer card signed with that key. |
coordinator | Bridge operator | Makes the key that signs every request to the signers. |
assemble | Bridge operator | Checks the cards and builds the signer set: the keys, how many must sign, the networks, the fees and caps. Prints a short fingerprint. |
join | Each operator | Shows the set; operators confirm the fingerprint with each other on a call; writes a ready-to-install service. |
check | Anyone | Checks the key, both nodes, sync, and that the service refuses unsigned requests. |
Each operator runs a full Dogecoin Core node, a DogecoinVM node and the signer service. The tests run the whole ceremony, then a deposit and a withdrawal signed by separate signers.
How far the trust can be spread
Releasing locked DOGE will always need a threshold of signers: Dogecoin's script can check signatures and time locks, but not what happened on another chain. So the bridge can be decentralised, with many independent signers, but not made trustless on the Dogecoin side until Dogecoin itself changes. What can change is how many parties must collude, who they are, and what it costs them.
| Stage | What you trust | State |
|---|---|---|
| One operator | The alpha: one operator holds every signing key, so you are trusting that operator. The caps are enforced by the signer software; they don't limit what someone holding the keys could take. | Today |
| Independent signers | That fewer than the threshold of known, separate key holders collude: 2 of 3, then 3 of 5. | Next |
| Metal validators as signers | That no two-thirds of the chain's own validators collude: the same assumption that secures DogecoinVM itself. | Planned |
| Bonded signers | As above, but signing anything the rules don't allow forfeits collateral worth more than the signer could take. | Planned |
| Deposits on proofs | No one, for deposits: validators check the Dogecoin deposit themselves. Signers only guard withdrawals. | Planned |
What an operator runs. Metal validators already run metalgo, so a signer adds a Dogecoin Core node with a transaction index (about 230 GB of SSD today, growing by roughly 25 to 30 GB a year, a few GB of memory, and a day or so to sync), DogecoinVM on their node, and the light signer service. The plan is to package all of it as one install, plus the ceremony.
Two limits. A Dogecoin multisig script holds at most about 15 keys, so a larger signer set needs threshold signatures, where many signers produce one ordinary signature together. And every change to the signer set moves the locked DOGE to a new multisig address, which is what key rotation does.
Safety built in today
- Consensus-enforced supply. Blocks that create reserve DOGE in the wrong amount, to the wrong address or at the wrong height are invalid, so no other code path can create DOGE.
- Solvency check before every action. The bridge audits both chains and moves nothing unless locked DOGE covers circulating DOGE plus pending transfers.
- Alpha caps. 100 DOGE per deposit, 4,200 DOGE in total, and 4,200 DOGE a day through each signer. The signer software enforces them, so they bound what the bridge itself can do; they don't limit what someone holding the keys could take.
- A wallet that checks the server. The browser verifies deposit addresses and the value of every coin it spends against the raw transactions, caps fees, and computes transaction IDs itself. A strict content security policy limits what the page can load.
- Refunds and alerts. Held deposits can be returned on Dogecoin. Health checks alert on insolvency, overdue transfers, stalled nodes and a low validator balance.
- No secrets in the source. Every commit and push is scanned for private keys, tokens and passwords, both locally and in CI, and GitHub push protection is on. Keys live only on the machines that use them.
- Tests. Consensus, VM, bridge and wallet tests, including one that runs the browser's signing code and checks its transactions against the Go script engine.
Known limits
These are the gaps between today's alpha and a bridge that can hold significant value. Every phase below closes one or more of them.
| Limit | Why it matters | Closed in |
|---|---|---|
| Signer keys aren't yet held by independent operators | Until they are, the 2-of-3 multisig doesn't protect against a single operator. The software and setup ceremony to fix this are built; switching over needs independent operators. | Phase 3 |
| One validator | The chain stops if that node stops, and consensus is only as trustworthy as one operator. | Phase 3 |
| The signers credit deposits | Two signers acting together could credit DOGE on DogecoinVM that isn't backed on Dogecoin. | Phase 5 |
| No external audit | The bridge and consensus changes have only been reviewed internally. | Phase 4 |
| A single Dogecoin node | The bridge sees Dogecoin through one node it runs itself. | Phase 4 |
| Alpha caps | Deliberate for now; they're raised only once the items above are done. | Phase 7 |
Roadmap
Each phase ends at a check anyone can verify, and the next phase starts only once it passes.
-
Build and launch the alpha
Done- DogecoinVM running on Metal Blockchain's current release, with Dogecoin chain parameters, fee and dust policy, and the consensus-enforced peg reserve.
- Bridge with personal deposit addresses, solvency audit, caps, refunds and a health monitor.
- Web wallet, explorer and proof of reserves at metaldoge.com; the L1 created and converted on Metal mainnet.
-
Prove the round trip
Done- The bridge's Dogecoin node synced; the first deposit credited and a withdrawal paid back to Dogecoin, on 23 September 2026 (transactions above).
- The wallet's one-click move from its Dogecoin balance, reviewed and signed in the browser.
- HTTPS enforced, daily encrypted off-server backups of bridge state and the deposit registry, and a restore tested against the live keys.
Done: each direction has transaction IDs on both chains, visible in the explorer, and proof of reserves matches.
-
Remove single points of failure
In progress- BuiltSigner service. A bridge process that holds no keys, and a signer service per key holder that checks every transaction against both chains, through the nodes it is given, before signing, with a signing log and a daily limit.
- BuiltSetup ceremony (
dogevm signer-setup): cards, a signer set with a fingerprint, service files and health checks. The existing keys can be imported, so the peg address and the funds stay where they are. - LiveSeparate signers with the live keys (27 September 2026). Each key in its own signer service and a coordinator that holds none, with the peg address unchanged; one operator still holds all three. Next: prove a round trip through them.
- NextIndependent operators. At least two people or organisations besides us, each running their own Dogecoin and DogecoinVM nodes and a signer, brought in through the ceremony. Then grow from 2-of-3 to 3-of-5.
- NextMetal validators as signers. A one-command install of the signer, a Dogecoin node and DogecoinVM for Metal validators, who already run the infrastructure. Grow to 5 to 7 validator signers with a two-thirds threshold, so the bridge is secured by the same operators as the chain.
- NextKey rotation. Move the locked DOGE and the reserve to a new signer set made entirely by the new operators, retiring the alpha's keys.
- NextHardware-backed storage for signer keys.
- NextAt least three validators run by different operators, with a validator manager, so validators can be added and replaced without relaunching the chain.
Done when no single machine or operator can move locked DOGE or halt the chain.
-
Audit and harden
Planned- External security audit of the consensus changes, bridge and wallet signing, then fix what it finds.
- Have signers cross-check Dogecoin through more than one node.
- More transfers from separate wallets, including a deposit over the alpha limit, held, and its refund.
- BuiltAn emergency pause that stops all signing (the operator pauses each process where it runs; a pause other operators can trigger remotely isn't in the live bridge yet), and a written runbook for incidents, refunds and restoring from the daily encrypted backups. Next: rehearse it once, and a public bug bounty.
- Bonded signers. Each signer locks collateral that is forfeited if they sign anything the rules don't allow. Theft stays possible in principle, but it becomes costly.
- Delays on large withdrawals. Withdrawals above a set size wait a few hours before they're paid, giving the monitor and the other signers time to pause the bridge if anything looks wrong.
Done when the audit report is published with every finding closed or explained.
-
Deposits without signers
Planned- A DogecoinVM upgrade in which the validators follow Dogecoin's block headers themselves, and the reserve releases a deposit's DOGE only with proof that the deposit is buried 20 blocks deep in Dogecoin's chain.
- No signer is involved in crediting a deposit, and nobody, the signers included, can create DogecoinVM DOGE that isn't backed by DOGE locked on Dogecoin.
- Signers remain for withdrawals only. Dogecoin's script can check signatures and time locks but not another chain, so releasing locked DOGE needs signers on every DOGE bridge until Dogecoin itself changes.
Done when the upgrade has been audited, activated by the validators, and deposits are credited on proofs alone.
-
Native passkey accounts
Planned- A DogecoinVM upgrade that accepts passkey signatures (WebAuthn, P-256) alongside Dogecoin's own, as Ethereum is doing with RIP-7212. Touch ID, Face ID, 1Password, and any FIDO security key (even older U2F-only keys) can then sign DogecoinVM transactions directly.
- No seed phrase and no private key held in the browser: the passkey is the account, backed up and synced by the user's password manager or kept on a hardware key.
- Recovery built in: an account can name a second passkey or a time-delayed recovery key.
- Today's wallet already uses passkeys to encrypt the key. That works only where the passkey supports the PRF extension, such as 1Password. Native accounts remove that limit.
- Scope: DogecoinVM only. DOGE on Dogecoin itself still needs a Dogecoin key, since Dogecoin's rules are not ours to change.
Done when the upgrade has been audited, activated by the validators at a set block height, and a passkey-only wallet has made a round trip through the bridge.
-
Open up
Planned- Raise the caps in steps, with the proof of reserves at each step.
- Threshold signatures. Beyond about 15 signers, a Dogecoin multisig no longer fits, so every Metal validator could sign only through threshold ECDSA: many signers producing one ordinary signature. It's substantial cryptography, taken on once the signer set needs to grow past a multisig.
- Atomic swaps. DogecoinVM runs Dogecoin's own script language, so DOGE on Dogecoin can be swapped for DOGE on DogecoinVM with hash-locked payments: both sides complete, or both are refunded. It needs no bridge and no signers, only someone on the other side of the swap, such as a market maker, which makes for fast, trustless exits alongside the bridge.
- Support for wallets and developer tools beyond the web wallet: standard RPC endpoints and a documented API.
- Public infrastructure: open RPC nodes and a hosted explorer with an uptime history.
Done when the caps are lifted without new trust assumptions.
Verify it yourself
- Use the bridge and explorer at metaldoge.com. Proof of reserves lists every locked Dogecoin output, and each links to a public Dogecoin explorer.
- Read or build the source at github.com/MetalBlockchain/dogecoin-vm, which has the VM plugin, bridge, wallet and deployment scripts.
- Look up the subnet, chain and validator IDs above on Metal Blockchain's P-Chain.
This roadmap describes engineering work and its order; it isn't a schedule.