Summary
The agent never holds the money. A vault contract does, and it only lets the agent act inside rules that a person sets. If the model is wrong or tricked, or its key leaks, the most it can lose is what’s left of one day’s limit.Why
Instructions in a prompt aren’t a security boundary. A model can misread a request or follow text planted in something it reads. A contract check runs every time and can’t be talked out of it. See AI agents on BOT Chain.How
The planned design has two roles, and they must be different wallets:
On top of the contract:
- The operator key holds no funds. It only needs gas.
- Every send is simulated first, so a call that would revert never reaches the chain.
- A person approves payments and larger swaps in the terminal. This is a second line of defence, not the main one.
If something goes wrong
- The agent misbehaves. Pause the vault from the owner wallet, then change the operator.
- The operator key leaks. The attacker can spend at most what’s left of today’s limit, and only to allowed recipients. Pause, change the operator and withdraw.
- The owner key leaks. The vault offers no protection. Keep the owner key off any server the agent runs on.
Do it today
The Agent vaults and Spending limits guides build the same owner and operator split by hand. Then go through the security checklist.Agent vaults
Build the vault on testnet.
Human approval
Add approvals above a threshold.
Identity hooks
Check whether a recipient is trusted.
Security checklist
Common risks to check before mainnet.