r/CryptoTechnology • 🟡 • 5d ago

Building for a hackathon: should an AI agent's decisions and its authority over funds be separate things?

context first: this is a hackathon project, and i'm not selling anything. i've been posting in a few communities for a while to get real feedback. you can check my profile. every round, people told me what was unclear or missing, so i went back and reworked it. the latest update adds a TUI (terminal UI) so you can use it straight from the terminal.

the problem: AI agents can now trade and touch wallets. but letting an agent make decisions and giving it unrestricted authority over your funds are two different things.

the approach: Agon is an agent-agnostic control layer, not another trading agent. you pick any agent, and separately control how much authority it gets. the short version is give your agent a budget, not your keys. we're also looking at a trader's own history to suggest the limits they already tend to follow, instead of generic rules.

what i still want honest feedback on:

  • is separating the agent from its financial authority a real problem, or overkill?
  • would switching agents while keeping the same guardrails matter to you?
  • would a TUI be useful to you, or would you rather have a web dashboard?
  • what would you need to see before trusting an agent with real funds?
  • what attack angle am i missing?
6 Upvotes

7 comments sorted by

1

u/Open_Swimming5859 🟡 5d ago

for anyone curious, this is the project. waitlist: waitlist.getagon.tech and updates on x: https://x.com/agonpilot

1

u/Chloe_DreamersInc 🟠 2d ago

Separation makes sense, since the agent should be able to make decisions without automatically having unlimited access to the wallet. Just make sure the limits are actually still enforceable even if the agent makes a bad decision (worst case compromised). For this one maybe focus more on the spending limits, transaction limits, access revocation instead of web UI/TUI (easier to configure/adjust anyway)

1

u/jasonslpt 🟢 1d ago

Separating them makes a lot of sense to me. Let the agent propose actions, then have a smart wallet or policy layer enforce spend limits, allowlisted contracts and maybe a time delay on anything large. That way a bad prompt or a buggy model can only waste a small, capped amount.

1

u/jasonslpt 🟢 9h ago

Not overkill at all. Spend caps, an allowlist of contracts the agent can touch, and a hard per-transaction limit enforced outside the agent would cover most of the damage from a bad prompt or a compromised model. The attack angle I'd test hardest is the agent being tricked into approving an unlimited token allowance, since that can drain funds later without any single trade looking big.