Skip to main content
Understand how the planned AI agent template limits what an agent can do with funds, and apply the same model today with the hand-written guides.
In development. This template is not published yet and details may change. Follow progress on GitHub. Until it ships, use the hand-written guide linked on this page.

Summary

The agent never holds the money. A vault contract does, and it only lets the agent act inside rules that a person sets. If the model is wrong or tricked, or its key leaks, the most it can lose is what’s left of one day’s limit.

Why

Instructions in a prompt aren’t a security boundary. A model can misread a request or follow text planted in something it reads. A contract check runs every time and can’t be talked out of it. See AI agents on BOT Chain.

How

The planned design has two roles, and they must be different wallets: On top of the contract:
  1. The operator key holds no funds. It only needs gas.
  2. Every send is simulated first, so a call that would revert never reaches the chain.
  3. A person approves payments and larger swaps in the terminal. This is a second line of defence, not the main one.

If something goes wrong

  • The agent misbehaves. Pause the vault from the owner wallet, then change the operator.
  • The operator key leaks. The attacker can spend at most what’s left of today’s limit, and only to allowed recipients. Pause, change the operator and withdraw.
  • The owner key leaks. The vault offers no protection. Keep the owner key off any server the agent runs on.
These details come from work in progress and may change before release.

Do it today

The Agent vaults and Spending limits guides build the same owner and operator split by hand. Then go through the security checklist.

Agent vaults

Build the vault on testnet.

Human approval

Add approvals above a threshold.

Identity hooks

Check whether a recipient is trusted.

Security checklist

Common risks to check before mainnet.
Last modified on October 2, 2026