How we protect agent wallets
The model never decides alone
We assume a model can be tricked by a web page, a tool result or a message. So every payment goes through a policy engine the model can't change. It checks, in order: is the wallet frozen, is the service on the owner's allow-list, is the amount under the per-payment cap, and does it fit the daily budget. The details are in Spending rules for AI agents.
Agents never hold the main key
Each client connection, such as a Claude Code session, gets a session key that is limited in scope, set to expire, and can only ask for signatures through the policy engine. Owners can revoke a session key at any time without moving funds.
Owners stay in control
- Payments above the cap wait for the owner's approval, and approvals expire.
- A freeze switch stops all payments from a wallet immediately.
- Every payment, refusal and approval is logged with the reason the agent gave.
How we build
- All traffic to minagent.xyz uses HTTPS, with HSTS so browsers refuse plain connections.
- Money amounts are handled as whole numbers in the token's smallest unit, never as decimals.
- Each payment carries a unique ID, so the same payment can't be settled twice.
- Access to production systems is limited to the people who need it.
Audits
The wallet contracts and the policy engine are being audited during the private beta. We will publish the results here before the public launch in 2027. Until then, please treat MinAgent as beta software and keep only small amounts in agent wallets.
Reporting a vulnerability
If you think you have found a security problem in minagent.xyz or in MinAgent, please email hello@minagent.xyz. Include:
- what the problem is and where you found it;
- steps to reproduce it, or a proof of concept;
- what an attacker could do with it.
What we ask
- Give us reasonable time to fix the problem before you tell anyone else.
- Don't access, change or delete other people's data, and stop once you have shown the issue.
- Don't run tests that degrade the service for others, such as denial-of-service attacks.
- Don't use social engineering or physical attacks against our team.
What we promise
- We will reply within 3 working days to confirm we received your report.
- We will keep you updated while we work on a fix.
- We won't take legal action against research done in good faith under these rules.
- With your permission, we will thank you publicly once the issue is fixed.
A paid bug bounty programme will start with the public launch. Reports made before then will be considered for a reward when it opens.
Machine-readable contact details are in /.well-known/security.txt.