From June 10 to June 12, 2026, we ran the deepest review Divine has ever had: five full adversarial audit passes over the entire codebase, with every pass hunting both for bugs the previous one missed and for bugs the previous fixes might have introduced. The final pass put a dedicated deep-dive on our wallet-coordination engine.

The result is roughly 70 commits of fixes and improvements, all verified by the full test suite (4,300+ tests green) and already live in production.

Coordination detection got serious teeth

The headline work happened inside Aegis, in the engine that detects coordinated wallet rings behind pump-and-dump launches. The audits found — and we closed — several patterns a sophisticated operator could have used to slip a ring past detection:

  • Decoy-follower evasion. A ring could hide its bulk volume in wallets that traded in the exact same block as the leader, behind a single small "copy-trader" decoy. Approving the visible copy-trading pattern used to end the analysis; now the unexplained remainder of every group must independently pass the peer-network check before any approval stands.
  • Score dilution. Padding a ring with weakly-connected wallets (or relying on an unrelated weak cluster in the same window) could drag the ring's coordination score below the flagging threshold. Group strength is now computed from the connections that actually bind the cluster, and detection triggers on the strongest group, not a diluted average.
  • Sybil splitting. Spreading a ring's buys across many wallets, each just below the per-wallet volume floor, used to make the ring invisible to per-wallet analysis. A new Sybil-tail guard notices when these mid-size sub-threshold wallets collectively control a meaningful share of volume and pulls the largest of them back into deep analysis — without spending extra lookups on organic dust.
  • Same-block MEV misclassification. A windowing bug meant any buy that was later sold could be mislabeled as MEV activity — and a separate casing bug silently disabled wallet cooldown checks for most real Solana addresses. Both fixed, both regression-tested.
  • Multi-group masking. When several wallet clusters appeared in one scan, a benign cluster could mask a malicious one depending on evaluation order. Flag decisions are now merged across all groups before any approval is returned.

On top of the evasion fixes, Lucifer signals now run full volume analysis, Jesus signals are rejected outside the viable 5-minute momentum band, and extreme volume-turnover launches are filtered at the liquidity check.

Signals you can actually rely on

A scam-free signal is worthless if it never reaches your Telegram. A large share of the campaign went into making delivery loss-proof:

  • Outbox journaling. Every alert is journaled to disk the moment its scan completes, so a crash or restart between scan and Telegram send replays the alert instead of losing it.
  • Shutdown-proof retries. Tokens waiting in the retry queue now survive restarts in every scenario the audits could construct — including shutdowns landing in the narrowest timing windows.
  • No more silent drops. Fixed a family of stream bugs where a busy dashboard could permanently hide pairs from the scanner, where a poisoned data frame could wedge an endpoint in an infinite parse loop, and where a Jesus emission could suppress a Lucifer dump alert for the same pair seconds later.
  • Telegram hardening. Flood-wait handling is now shared across all senders per chat, caption budgets are computed exactly the way Telegram counts them (including emoji), and duplicate-suppressed scans no longer fire duplicate alerts.
  • Filters that actually filter. Several spam-prevention and minimum-buys filters were silently never being sent upstream to DexScreener. They are now — which means less junk enters the pipeline at all.

Faster and cheaper under the hood

  • Holder snapshots are fetched concurrently with trade preparation instead of after it.
  • Repeat lookups during retries are sharply reduced (longer wallet-history caching, single-flight RugCheck fetches, smarter speculative pagination).
  • Fresh signals always take priority over the retry backlog, so retries can never starve a hot launch.
  • Rate-limit responses from upstream APIs are now honored precisely instead of hammered through generic retries.
  • Shutdowns that used to take up to a minute (or hang entirely under rare conditions) now complete in seconds.

Groundwork for data-driven tuning

We also shipped a rejected-outcome ledger: Divine now tracks what happens to tokens it rejected — including an early 2–6 hour snapshot — so the next round of threshold tuning will be driven by measured outcomes instead of intuition. Expect follow-ups as that data accumulates.

Why this matters

Detection systems decay: the obvious manipulation patterns disappear first, and what remains is built specifically to slip past the checks you already have. The only honest answer is to attack your own system harder than the operators do. That is what this campaign was — five passes of structured adversarial review, every claim verified against the code before fixing, every fix regression-tested.

Divine is now measurably harder to evade, harder to crash, and harder to silence.