DogecoinVM technical roadmap

DogecoinVM is a Dogecoin-compatible chain running as a Layer 1 on Metal Blockchain, joined to Dogecoin by a one-for-one DOGE bridge. This page covers what is running today, how it works, what it doesn't do yet, and the order in which we'll close those gaps.

Status as of 1 October 2026 · Source: github.com/MetalBlockchain/dogecoin-vm · Live: metaldoge.com

Where it stands. DogecoinVM is live on Metal Blockchain mainnet with real DOGE, limited by alpha caps, and the bridge has completed its first round trip: DOGE moved from Dogecoin to DogecoinVM and back, with every step on chain. Since 27 September 2026 the bridge holds no keys: each key runs in its own signer service. One operator still holds all of them, so you are trusting that operator. Bringing in independent operators, through the setup ceremony that is already built, is next.

The first round trip

23 September 2026. Dogecoin transactions open on a public Dogecoin explorer, DogecoinVM ones in this site's explorer.

StepChainTransactionAmount
Deposit to a personal deposit addressDogecoin74e053f6…ea11b91 DOGE
Credit, after 20 confirmations and the 0.01 DOGE bridge fee (the confirmation tiers came on 25 September; before that every deposit waited 20)DogecoinVM39a6c47e…7d84750.99 DOGE
Withdrawal to the bridge, naming a Dogecoin addressDogecoinVM4a447aff…6c38525 DOGE
Payout, after the 0.1 DOGE Dogecoin fee, about a minute laterDogecoin8be21486…ec97374.9 DOGE

The wallet's one-click move, from its Dogecoin balance to its deposit address after review, worked the same evening (0c7de3ce…7b9f68). Proof of reserves matched throughout: DOGE locked on Dogecoin equalled DOGE circulating on DogecoinVM plus deposits waiting to be credited.

What is running

ComponentWhat it doesState
DogecoinVM L1Dogecoin's transaction and script rules (legacy, pre-SegWit) and Dogecoin 1.14 fee and dust policy, with Snowman consensus: a transaction is final once it is in a block, usually in under a second.Live
Peg reserveDOGE is created only in the chain's reserve blocks, which consensus enforces. That supply is locked to the peg signers and released only against DOGE locked on Dogecoin.Live
BridgeWatches both chains. It credits deposits after 1 to 20 Dogecoin confirmations, depending on the amount, and pays out withdrawals once they are final on DogecoinVM. It stops moving funds if the solvency check fails.Live
Web walletOne key, one address on both networks: Dogecoin and DogecoinVM balances side by side, and a one-click move between them. Keys stay in the browser, optionally encrypted to a passkey, and every payment is shown for review, read from the transaction itself, before it's signed there. The page checks the deposit address and every coin it spends itself, rather than trusting the server. It installs as an app on Mac, iPhone and Android.Live
ExplorerShows bridge activity with the transaction on each chain, proof of reserves output by output, and DogecoinVM blocks, transactions and addresses.Live
MonitoringChecks the peg, overdue transfers, both nodes and the validator's fee balance every minute, and sends Telegram alerts.Live
Separate signersA signer service for each key holder, and dogevm signer-setup, the ceremony that brings new signers in. Running since 27 September 2026: each live key in its own signer service, and a bridge that holds none, with the peg address unchanged. One operator still holds all three keys; independent operators are next.Live, one operator
macOS walletA native Mac app for both networks: review every payment before it's signed, Touch ID for each signature, the key kept encrypted to the Mac's Secure Enclave, and signed automatic updates. Signed and notarized by Apple for download outside the App Store, and open source.Live
Dogecoin nodeThe bridge's own Dogecoin Core node, with a full transaction index, which the bridge and the wallet's Dogecoin balances read.Live

Anyone can check these IDs on Metal Blockchain:

Subnet
2t2zEB1T3mNUE2WoheMFMjfhAvQJawtgiwnKPJz2NsFk7FDgyN
Chain
2hFCfzdMmfXBxYgvvdL7BYiJAxdejyn4AksMYUM2eM5gN7Xrjy
VM ID
mEUwHwfd8UTHf23UYkQxHvy1n1EGwWieXQnjmtzSryJRZckzu
Validator
NodeID-5qeQJPktXm63RrXxxkfjunFJPQCP7YeeK
Dogecoin peg address
AAvNfukpAa4iTcRJPetxuxX8XxbC5gFqUM

How DOGE moves

Every DOGE on DogecoinVM is backed by a DOGE locked on Dogecoin, and anyone can check both sides. The bridge enforces one invariant: locked on Dogecoin ≥ circulating on DogecoinVM + pending. If that ever fails, it stops.

How DOGE moves: DOGE sent to a personal deposit address on Dogecoin is locked there; after 1 to 20 confirmations, depending on the amount, the bridge credits the same amount on DogecoinVM from the peg reserve; a withdrawal sent back to the reserve is paid out from the locked DOGE on Dogecoin.

Deposit: Dogecoin to DogecoinVM

  1. The wallet gives each user a personal Dogecoin deposit address. Its script commits to the user's DogecoinVM address, followed by a 2-of-3 multisig of the peg signers. The browser derives the address itself and refuses to show one that doesn't match.
  2. After enough Dogecoin confirmations for the deposit's size (1 for 1 DOGE, up to 20 above 50 DOGE), the signers release the same amount from the peg reserve to the user's DogecoinVM address, less a 0.01 DOGE fee. The release is tagged with the deposit it pays for, so a deposit can't be credited twice.
  3. Deposits over the alpha cap, or arriving while the total is at its limit, are held and can be refunded on Dogecoin. To ask for a refund, use the contact details in the terms.

Withdrawal: DogecoinVM to Dogecoin

  1. The user sends DOGE back to the peg reserve with a tag naming a Dogecoin address.
  2. Once that transaction is final on DogecoinVM, usually in under a second, the signers pay the Dogecoin address from the locked DOGE, less a 0.1 DOGE network fee. The minimum withdrawal is 2 DOGE.

Who holds the keys

The peg is a 2-of-3 multisig: any two of the three signer keys together can move funds. Those keys control both sides of the bridge.

On Dogecoin

The locked DOGE: the peg address and every personal deposit address. These are the real coins users sent in.

On DogecoinVM

The reserve created at genesis. Releasing it is how a deposit is credited, so it decides how much bridged DOGE exists.

Two key holders acting together could take the locked DOGE, or credit DOGE with nothing behind it. The defence is independence: separate people, on separate machines, each checking the chains through their own nodes. That defence isn't in place yet. During the alpha, one operator holds all of the bridge's signing keys, so you are trusting that operator. Caps and daily limits are enforced by the signer software; they don't limit what someone holding the keys could take. Moving the keys to independent operators is planned.

Since 27 September 2026 the bridge process holds no keys. It proposes each transaction, and every signer service checks it against both chains:

Once the signers are run by independent operators, each through their own nodes, a compromised bridge can delay transfers but can't move locked DOGE. Until then these checks catch a faulty bridge, not whoever holds the keys.

Signing is automatic. Each signer is a service that applies these rules by itself, so deposits and withdrawals go through in the time it takes to reach the required confirmations, with no one approving them by hand. People act only to approve refunds and to change the rules, which means a new signer set that every operator joins.

Bringing signers in: the setup ceremony

dogevm signer-setup takes each operator through setup. Only public information changes hands: no private key, password or token is ever sent to anyone. It runs interactively for a person, or with flags for automated operators. Without a terminal, the join step requires the fingerprint the operators confirmed, so no script can approve a signer set on its own.

StepWhoWhat happens
initEach operatorMakes a key on their own machine, or imports one at a hidden prompt, and produces a public signer card signed with that key.
coordinatorBridge operatorMakes the key that signs every request to the signers.
assembleBridge operatorChecks the cards and builds the signer set: the keys, how many must sign, the networks, the fees and caps. Prints a short fingerprint.
joinEach operatorShows the set; operators confirm the fingerprint with each other on a call; writes a ready-to-install service.
checkAnyoneChecks the key, both nodes, sync, and that the service refuses unsigned requests.

Each operator runs a full Dogecoin Core node, a DogecoinVM node and the signer service. The tests run the whole ceremony, then a deposit and a withdrawal signed by separate signers.

How far the trust can be spread

Releasing locked DOGE will always need a threshold of signers: Dogecoin's script can check signatures and time locks, but not what happened on another chain. So the bridge can be decentralised, with many independent signers, but not made trustless on the Dogecoin side until Dogecoin itself changes. What can change is how many parties must collude, who they are, and what it costs them.

StageWhat you trustState
One operatorThe alpha: one operator holds every signing key, so you are trusting that operator. The caps are enforced by the signer software; they don't limit what someone holding the keys could take.Today
Independent signersThat fewer than the threshold of known, separate key holders collude: 2 of 3, then 3 of 5.Next
Metal validators as signersThat no two-thirds of the chain's own validators collude: the same assumption that secures DogecoinVM itself.Planned
Bonded signersAs above, but signing anything the rules don't allow forfeits collateral worth more than the signer could take.Planned
Deposits on proofsNo one, for deposits: validators check the Dogecoin deposit themselves. Signers only guard withdrawals.Planned

What an operator runs. Metal validators already run metalgo, so a signer adds a Dogecoin Core node with a transaction index (about 230 GB of SSD today, growing by roughly 25 to 30 GB a year, a few GB of memory, and a day or so to sync), DogecoinVM on their node, and the light signer service. The plan is to package all of it as one install, plus the ceremony.

Two limits. A Dogecoin multisig script holds at most about 15 keys, so a larger signer set needs threshold signatures, where many signers produce one ordinary signature together. And every change to the signer set moves the locked DOGE to a new multisig address, which is what key rotation does.

Safety built in today

Known limits

These are the gaps between today's alpha and a bridge that can hold significant value. Every phase below closes one or more of them.

LimitWhy it mattersClosed in
Signer keys aren't yet held by independent operatorsUntil they are, the 2-of-3 multisig doesn't protect against a single operator. The software and setup ceremony to fix this are built; switching over needs independent operators.Phase 3
One validatorThe chain stops if that node stops, and consensus is only as trustworthy as one operator.Phase 3
The signers credit depositsTwo signers acting together could credit DOGE on DogecoinVM that isn't backed on Dogecoin.Phase 5
No external auditThe bridge and consensus changes have only been reviewed internally.Phase 4
A single Dogecoin nodeThe bridge sees Dogecoin through one node it runs itself.Phase 4
Alpha capsDeliberate for now; they're raised only once the items above are done.Phase 7

Roadmap

Each phase ends at a check anyone can verify, and the next phase starts only once it passes.

  1. Build and launch the alpha

    Done
    • DogecoinVM running on Metal Blockchain's current release, with Dogecoin chain parameters, fee and dust policy, and the consensus-enforced peg reserve.
    • Bridge with personal deposit addresses, solvency audit, caps, refunds and a health monitor.
    • Web wallet, explorer and proof of reserves at metaldoge.com; the L1 created and converted on Metal mainnet.
  2. Prove the round trip

    Done
    • The bridge's Dogecoin node synced; the first deposit credited and a withdrawal paid back to Dogecoin, on 23 September 2026 (transactions above).
    • The wallet's one-click move from its Dogecoin balance, reviewed and signed in the browser.
    • HTTPS enforced, daily encrypted off-server backups of bridge state and the deposit registry, and a restore tested against the live keys.

    Done: each direction has transaction IDs on both chains, visible in the explorer, and proof of reserves matches.

  3. Remove single points of failure

    In progress
    • BuiltSigner service. A bridge process that holds no keys, and a signer service per key holder that checks every transaction against both chains, through the nodes it is given, before signing, with a signing log and a daily limit.
    • BuiltSetup ceremony (dogevm signer-setup): cards, a signer set with a fingerprint, service files and health checks. The existing keys can be imported, so the peg address and the funds stay where they are.
    • LiveSeparate signers with the live keys (27 September 2026). Each key in its own signer service and a coordinator that holds none, with the peg address unchanged; one operator still holds all three. Next: prove a round trip through them.
    • NextIndependent operators. At least two people or organisations besides us, each running their own Dogecoin and DogecoinVM nodes and a signer, brought in through the ceremony. Then grow from 2-of-3 to 3-of-5.
    • NextMetal validators as signers. A one-command install of the signer, a Dogecoin node and DogecoinVM for Metal validators, who already run the infrastructure. Grow to 5 to 7 validator signers with a two-thirds threshold, so the bridge is secured by the same operators as the chain.
    • NextKey rotation. Move the locked DOGE and the reserve to a new signer set made entirely by the new operators, retiring the alpha's keys.
    • NextHardware-backed storage for signer keys.
    • NextAt least three validators run by different operators, with a validator manager, so validators can be added and replaced without relaunching the chain.

    Done when no single machine or operator can move locked DOGE or halt the chain.

  4. Audit and harden

    Planned
    • External security audit of the consensus changes, bridge and wallet signing, then fix what it finds.
    • Have signers cross-check Dogecoin through more than one node.
    • More transfers from separate wallets, including a deposit over the alpha limit, held, and its refund.
    • BuiltAn emergency pause that stops all signing (the operator pauses each process where it runs; a pause other operators can trigger remotely isn't in the live bridge yet), and a written runbook for incidents, refunds and restoring from the daily encrypted backups. Next: rehearse it once, and a public bug bounty.
    • Bonded signers. Each signer locks collateral that is forfeited if they sign anything the rules don't allow. Theft stays possible in principle, but it becomes costly.
    • Delays on large withdrawals. Withdrawals above a set size wait a few hours before they're paid, giving the monitor and the other signers time to pause the bridge if anything looks wrong.

    Done when the audit report is published with every finding closed or explained.

  5. Deposits without signers

    Planned
    • A DogecoinVM upgrade in which the validators follow Dogecoin's block headers themselves, and the reserve releases a deposit's DOGE only with proof that the deposit is buried 20 blocks deep in Dogecoin's chain.
    • No signer is involved in crediting a deposit, and nobody, the signers included, can create DogecoinVM DOGE that isn't backed by DOGE locked on Dogecoin.
    • Signers remain for withdrawals only. Dogecoin's script can check signatures and time locks but not another chain, so releasing locked DOGE needs signers on every DOGE bridge until Dogecoin itself changes.

    Done when the upgrade has been audited, activated by the validators, and deposits are credited on proofs alone.

  6. Native passkey accounts

    Planned
    • A DogecoinVM upgrade that accepts passkey signatures (WebAuthn, P-256) alongside Dogecoin's own, as Ethereum is doing with RIP-7212. Touch ID, Face ID, 1Password, and any FIDO security key (even older U2F-only keys) can then sign DogecoinVM transactions directly.
    • No seed phrase and no private key held in the browser: the passkey is the account, backed up and synced by the user's password manager or kept on a hardware key.
    • Recovery built in: an account can name a second passkey or a time-delayed recovery key.
    • Today's wallet already uses passkeys to encrypt the key. That works only where the passkey supports the PRF extension, such as 1Password. Native accounts remove that limit.
    • Scope: DogecoinVM only. DOGE on Dogecoin itself still needs a Dogecoin key, since Dogecoin's rules are not ours to change.

    Done when the upgrade has been audited, activated by the validators at a set block height, and a passkey-only wallet has made a round trip through the bridge.

  7. Open up

    Planned
    • Raise the caps in steps, with the proof of reserves at each step.
    • Threshold signatures. Beyond about 15 signers, a Dogecoin multisig no longer fits, so every Metal validator could sign only through threshold ECDSA: many signers producing one ordinary signature. It's substantial cryptography, taken on once the signer set needs to grow past a multisig.
    • Atomic swaps. DogecoinVM runs Dogecoin's own script language, so DOGE on Dogecoin can be swapped for DOGE on DogecoinVM with hash-locked payments: both sides complete, or both are refunded. It needs no bridge and no signers, only someone on the other side of the swap, such as a market maker, which makes for fast, trustless exits alongside the bridge.
    • Support for wallets and developer tools beyond the web wallet: standard RPC endpoints and a documented API.
    • Public infrastructure: open RPC nodes and a hosted explorer with an uptime history.

    Done when the caps are lifted without new trust assumptions.

Verify it yourself

This roadmap describes engineering work and its order; it isn't a schedule.