Reading view

There are new articles available, click to refresh the page.

The Agentic Web

The Valuation Case for Near Protocol ($NEAR)

by Sheni Ogunmola.

Global financial markets are inherently slow to price fundamental transitions in technology infrastructure. At present, digital asset markets continue to value Near Protocol ($NEAR) as a standard smart-contract platform competing for retail application deployment. This represents a profound category mispricing. By engineering a deeply integrated network architecture optimized for decentralized artificial intelligence, Near has built a structural utility moat tailored specifically to the requirements of the emerging autonomous agent economy.

When autonomous software agents handle high-velocity operations, data filtering, asset management, and cross-border financial reconciliation, they cannot rely on centralized cloud systems without exposing private credentials, corporate API keys, and proprietary weights to server operators. Near provides a neutral, hardware-secured execution environment where machine-to-machine commerce scales with absolute data confidentiality and friction-free multi-chain settlement.

The Operational Engine: Nightshade Sharding & Dynamic Resharding

The core architectural requirement for an ecosystem driven by software agents is the ability to absorb massive, unpredictable transaction spikes without causing fee degradation or consensus delays. Traditional layer-1 blockchains suffer from structural limitations where localized micro-caps or retail trading waves congest the entire global ledger.

Near’s implementation of Nightshade sharding splits transaction processing across parallel computing lanes. The milestone network upgrade automatically introduces dynamic resharding. This mechanism acts as an autonomous infrastructure manager: the moment specific computational demands surge, the network creates and deploys additional shards in real-time, isolating high-volume traffic without impacting the speed or cost profile of the broader network.

The production state of the network reflects this scalability:

  • Active Network Shards: The ecosystem has transitioned from 4 static shards to an infrastructure that dynamically scales beyond 70 shards.
  • Average Block Finality: Transactions achieve finality in under 1.2 seconds, with block times consistently hitting the 600-millisecond mark.
  • Transaction Processing Cost: Computational fees remain stable at flat, predictable machine rates, removing the volatile gas spikes that plague older networks.
  • Core Chain Interoperability: The network bypasses manual third-party bridging entirely by utilizing universal chain signatures via Near Intents.

The Agentic Web: Universal Chain Abstraction

Software tools operating at machine speed do not manually manage public keys, compute gas limits across multiple separate layer-1 or layer-2 environments, or accept the smart-contract vulnerabilities inherent to traditional cross-chain token bridges. Near eliminates this operational friction through its Chain Abstraction and Near Intents framework.

Through an open intent-based routing system, an AI agent simply declares a targeted economic outcome — such as deploying capital from Bitcoin into a localized yielding protocol on Solana — and the infrastructure manages the underlying cryptographic proofs, transaction execution, and state routing automatically. The data verifies that this architecture has graduated from a speculative design into a high-volume processing hub.

The network traction variables confirm this growth:

  • Total Near Intents Processing Volume: The system has surpassed $15 Billion in cross-chain routing across more than 35 integrated blockchains.
  • Average Monthly Protocol Swap Volume: Growth metrics show an acceleration of 5x relative to the initial platform launch pacing.
  • Wallet & Browser Integration Base: The intent-routing technology is now natively integrated across all 5 major ecosystem wallets and the Brave Browser.
  • Alternative Settlement Fee Multiple: The network is trading at approximately 57x annualized fees, making it deeply discounted relative to its major layer-1 peers.

Cryptographic Security & Private Inference

Autonomous workflow tools require ironclad security parameters when interacting with legacy enterprise software databases, internal communication nodes, or financial treasuries. Near addresses this challenge by pioneering localized hardware-enforced security boundaries.

  • Trusted Execution Environments (TEEs): Computational data remains completely encrypted at rest and in transit, shielding sensitive operational logs even from the validator nodes processing the transactions.
  • Confidential Intents: Deployed via isolated private shards, this allows enterprise agents to shield proprietary order books, trading volumes, and strategic asset balances from the public mempool while preserving regulatory audit compliance.
  • Verified Private Inference: Strategic integrations allow external platforms to run complex large language models in isolated, tamper-proof hardware enclaves where prompts and outputs are completely invisible to the host infrastructure provider.

Valuation Mismatch & The Tokenomics Flywheel

The ultimate validity of any infrastructure investment depends heavily on the alignment between network utility and token value capture. Historically, layer-1 blockchains functioned as highly inflationary networks where massive validator token emissions diluted long-term holders. Near has executed a systematic structural overhaul to reverse this trend.

First, a comprehensive protocol upgrade halved the maximum annual network inflation rate from 5% down to a highly constrained 2.5%, significantly reducing systematic sell pressure from network validators.

Second, the activation of the protocol fee conversion mechanism directs 100% of all generated cross-chain Intents transaction revenue straight into open-market $NEAR asset purchases.

This architecture creates a powerful supply-demand mismatch. As autonomous AI platforms, high-velocity trading agents, and cross-border remittance engines expand their adoption of Near’s intent-routing pipeline, the protocol captures an accelerating volume of fees to aggressively buy back and remove tokens from the circulating supply. The market currently treats $NEAR as a speculative asset dependent on retail human activity, creating a compelling entry window for an operational protocol powering the scaling infrastructure of the automated machine economy.

Legal Disclaimer & Financial Guardrail: We are not licensed financial advisors, certified tax professionals, or registered broker-dealers. The technical data, asset analysis, and market observations presented in this document are compiled strictly for educational, research, and informational purposes. Capital allocation in digital assets and emerging infrastructure technologies carries an inherent risk of volatility and total loss. Readers must conduct exhaustive independent due diligence and consult with professional financial counsel before executing any market positions.

The Agentic Web was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Everyone’s Asking the Wrong Question About AI Chatbots

Forget “which one is smarter.” The real shift is happening quietly, under the hood, and most people won’t notice until it’s already changed how they work.

I keep seeing the same debate pop up: is Claude smarter than Gemini, is Chat GPT still ahead, whatever. Honestly? Wrong question entirely. The stuff that’s actually going to matter is happening quietly, in places most people aren’t even looking.

I’ve been using these tools since they were basically novelties the kind of thing you showed your coworkers as a party trick. Ask around now and most people will tell you the future is “better answers” or “smarter writing.” That’s not really where this is going.

The bigger shift is in what these things fundamentally are, not how well they perform on some benchmark. Here’s my read on it, based on where the money and the engineering effort have actually been going.

Image Generated by chatgpt

We’re moving past chatbots into agents that do stuff

Right now you type a question, you get an answer, that’s the whole interaction. That model has an expiration date on it.

The next phase is AI that actually does things instead of just describing them: books your flight, cleans up your spreadsheet, pushes a code fix. This isn’t a prediction; it’s already happening in early form. The labs have shipped versions of this that can browse the web, click through interfaces, run code.

What’s holding it back isn’t capability, it’s trust. Nobody wants software that deletes the wrong file or emails the wrong person by mistake. So a lot of what’s coming isn’t going to be flashier intelligence — it’s going to be boring stuff like permission systems, confirmation steps, undo buttons. The unglamorous plumbing that makes people comfortable handing over real responsibility.

Memory that doesn’t reset every conversation

Most AI still forgets you exist the second you close the tab. A few companies have bolted memory features on top, but it’s early.

What’s coming is assistants that actually track your ongoing projects and how you write and what you keep running into problems with — without you re-explaining your whole situation every single time. That’s genuinely useful. It also raises uncomfortable questions about data retention and consent. My guess is the tools that win here won’t just remember more — they’ll let you actually see what’s stored and delete it, rather than just saying “trust us.”

Multimodal stops being a bragging point

“It can look at pictures now” used to be a headline feature. Soon that’ll just be table stakes. Voice, video, live camera feeds — these are going to merge into one conversation rather than sitting in separate menus you have to hunt for.

Point your phone at something broken, get spoken help back instead of typing out three paragraphs describing the problem. This stuff already exists in rough form. What’s actually improving is speed and reliability, not whether it’s possible at all.

A quieter race: running well on your own device

There’s a whole separate competition happening that has nothing to do with which model tops the leaderboard. It’s about which company can get something genuinely useful running on your phone without needing a data center behind it.

On-device matters because it’s faster, it’s private, and it’s cheaper to run. Expect a split forming — giant models for heavy lifting, small efficient ones baked directly into your phone for everyday tasks.

Personality is turning into an actual product decision

Most assistants sound pretty interchangeable right now — competent, a little bland. That’s going to change. Some will stay blunt and no-nonsense. Others will lean warm, or get tuned specifically for law or medicine or teaching.

This matters more than it sounds like it should, because tone is tied directly to trust, and trust is what decides whether someone actually uses this thing for something that matters health, money, their kid’s homework.

Regulation is going to shape this more than any competitor will

This is the part that gets ignored in most of these takes. Governments in the US, EU, and across Asia are actively writing the rules right now around transparency, copyright, data use. These aren’t theoretical debates. They decide what actually ships.

Expect more labeling on AI-generated content, clearer ways to opt out of training data, tighter restrictions around healthcare and hiring and anything involving kids. The companies that get ahead of this instead of fighting it are probably going to end up with an advantage that outlasts a few missed product launches.

In the end, it’s a trust problem, not an intelligence problem

Benchmark scores make for good headlines. They don’t decide who actually wins long-term. What decides that is whether people trust a tool enough to hand it something real.

That trust gets built through consistency and honesty about limitations and through how a company handles it when something breaks. An assistant that says “I’m not sure” when it isn’t sure will probably earn more loyalty over years than one that scores a point higher on some test nobody outside a research lab has heard of.

So what should you actually expect?

Not some dramatic leap forward. More like a slow accumulation of smaller changes tools that remember more, act more on their own, run faster locally, and get shaped as much by regulators as by engineers. What you’re using today is a rough draft, not a finished product.

The real race isn’t about who has the smartest model. It’s about who builds something boring enough, reliable enough, that you stop noticing you’re even using it.

Curious what you think — five years from now, do these feel more like tools to you, or more like teammates? Drop your take below.


Everyone’s Asking the Wrong Question About AI Chatbots was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Authorizing AI Agents on Payment Rails That Don’t Forgive

Reversibility-Aware Authorization — the missing axis for irreversible agent payments, and a pattern called Progressive Commitment.

In the previous piece, Agent Governance Assumes Reversibility. Payment Systems Do Not, I argued that the hard part of agentic payments isn’t making agents smarter. It’s that on an irreversible rail, a confident mistake has no rollback.

If that’s true, then a natural follow-up question emerges: What should authorization look like when mistakes can’t be taken back?

That’s the question this piece attempts to answer.

An agent can be wrong. The cause varies — stale data, retrieval error, faulty integration, flawed reasoning — and you won’t anticipate each and every failure mode. What matters is not the cause. What matters is that the error survives long enough to reach an irreversible rail, where it stops being a recoverable mistake and becomes a permanent loss.

The pattern I want to describe doesn’t prevent those mistakes. It makes them survivable. Here are two ways the failure happens, on two different rails.

Failure 1: The Right Address on the Wrong Chain

An agent runs USDC payouts to creators, workers, and vendors. It pulls the recipient’s wallet address from its records, selects a chain, signs the transfer, and submits. All standard checks pass: amount is normal, recipient is on the allowlist, address format is valid, transaction simulates cleanly.

Yet the funds end up inaccessible to the recipient.

The agent sent to the right address on the wrong chain.

In many institutional and contract-based setups, a wallet address by itself is not sufficient identity. Exchange deposit addresses, custody contracts, Safe multisigs, and other smart-contract systems are chain-specific. A contract deployed at address X on Ethereum may not exist — or may not be controlled the same way — at X on Base.

The agent validated the address string successfully while still sending funds somewhere the recipient cannot access on that chain.

A similar failure could occur with the wrong asset representation. The recipient expects native USDC on a given network, while the agent sends a bridged variant (USDC.e being the classic example) that their infrastructure doesn’t support.

Either way, the result is a payment that is syntactically correct but operationally wrong.

This is the trap.

The agent treated “address X” (plus some chosen chain) as the recipient’s full identity. In practice, stablecoin payouts often require a richer destination specification: at minimum [address X + chain Y + token Z]. Address validation alone does not guarantee the payment will reach the intended recipient in a usable form.

This risk becomes more pronounced in institutional, custody, and smart-contract-based environments (Safe multisigs, exchange deposit systems, custody platforms, etc.), where the recipient’s identity often extends beyond a wallet address alone.

Basic retail wallet-to-wallet transfers are typically more forgiving, but as agentic payment volume shifts toward professional counterparties, treating an address as sufficient identity becomes increasingly risky.

How existing guardrails evaluated it:

Policy & amount limits — Pass. Focused on who and how much, not destination chain.
Address allowlist — Pass. Validated the wallet address string, not the chain where it is live.
Capability guards — Pass. Confirmed permission to send payouts, nothing about semantic correctness.
Simulation / dry-run — Pass. Checked whether the transaction will succeed, not whether success is what was intended.
Evaluation layer — No flag. The transaction is well-formed and the decision looks reasonable. It checks output shape and internal consistency, not whether the chain (or token) is correct for this recipient.
Audit trail — Logged, but too late. The payment is already irreversible.

Simulation deserves a closer look. It might work perfectly for mechanical failures (e.g., attempting a time-locked withdrawal before unlock, which I’ve seen firsthand in an earlier on-chain experiment). Even sophisticated fork-based or multi-step simulations can catch some semantic issues if they accurately replay external state.

But they have a hard limit: they validate whether a transaction succeeds, not whether success matches the intended outcome. A wrong-chain transfer or bridged token still succeeds on-chain.

Catching “Will this revert?” and “Is this the right thing?” are different problems.

The Missing Axis

Look again at that list of guardrails. Every check is asking a real question.

  • Policy asks: Is this allowed?
  • Capability guards ask: Can the agent do this?
  • Simulation asks: Will this transaction succeed?
  • Evaluation asks: Is the output well-formed?
  • Audit trail asks, after the fact: What happened?

None of these guardrails treats reversibility as an explicit authorization input.

In other words: if this is wrong, can we take it back?

That’s the missing axis.

Existing frameworks primarily evaluate permission, policy, and confidence. Some use informal risk tiers or human approval for high-value actions — but reversibility is rarely an explicit, first-class input in the authorization decision itself.

On final-settlement payment rails, that omission is especially costly.

I’ll call authorization that treats reversibility as a first-class input Reversibility-Aware Authorization.

On top of the usual permission, policy, limits, and confidence checks, it asks one more:

  • And — crucially — are the consequences of being wrong reversible, at acceptable cost and speed?

The same permission checks still apply. The difference is that reversibility becomes part of the decision itself.

That’s the framework. The behavior that implements it is Progressive Commitment.

Two-column diagram. Left, “Immediate Commitment”: Initial Assessment leads straight to Execute, committing based on the initial assessment alone. Right, “Progressive Commitment”: Initial Assessment leads to a small, cheap, low-stakes action, then new evidence, then higher confidence, looping until a confidence threshold is met before full commitment. Illustrates Reversibility-Aware Authorization for AI agent payments.
Figure 1: Reversibility-Aware Authorization in practice. Progressive Commitment replaces one large irreversible commitment with a sequence of smaller, cheaper, low-stakes steps — each generating evidence that raises confidence before the full, irreversible action.

Progressive Commitment: Operationalizing Caution

If you can’t undo an action, don’t commit to it all at once.

Progressive Commitment means taking a smaller, cheaper, more reversible, or lower-stakes step first, then generating new evidence from that step and using it to update confidence. The cycle repeats until confidence exceeds a predefined risk threshold, at which point the agent advances to a higher level of commitment.

The value comes from information and context gain, not merely smaller size.

A dust-sized test transfer before the full payout. A probe before a large purchase. A temporary hold before releasing funds.

This doesn’t improve the model’s raw reasoning. It changes what the model gets to reason over. Each low-stakes step produces fresh information that wasn’t available before. Authorization decisions are therefore informed by evidence generated through interaction with the world rather than relying solely on the agent’s initial prediction.

The key shift is from prediction alone to prediction plus evidence. Instead of asking the model to be perfectly right upfront, the system generates new information through low-stakes actions before authorizing greater commitment.

In the payout example, instead of acting solely on the model’s prediction that an address-chain-token triplet is correct, the system first generates additional evidence through a cheaper, more reversible or low-stakes action.

A small test transfer is one example. If acknowledged by the intended recipient through a trusted out-of-band channel, that new evidence can increase confidence enough to justify the next level of commitment.

This pattern isn’t new — careful treasury teams already do versions of it manually.

Progressive Commitment simply encodes that caution into the authorization layer, so authorization decisions are informed by evidence gathered incrementally through cheap, reversible, or low-stakes actions.

Spend a trivial sum to avoid a catastrophic loss.

But what if confidence never clears the bar?

If the evidence fails to raise confidence past the threshold — the test transfer goes unconfirmed, the probe comes back wrong — the agent doesn’t advance.

It abstains.

That’s the other half of acting safely on irreversible rails: not just committing carefully, but knowing when not to commit at all.

I explored that idea in an earlier piece on Principled Abstention.

What Counts as Reversible?

Reversibility isn’t binary. It depends on how likely recovery is, how long it takes, and how much cost or effort it requires.

Card payments can be charged back (slowly, not guaranteed). Wires can sometimes be recalled (difficult in practice). On-chain settlements, once confirmed, are typically final.

The goal isn’t perfect classification. It’s recognizing that “we can probably recover” and “we probably cannot” are fundamentally different risk categories — and should be authorized differently.

A practical spectrum can look roughly like this:

  • Highly reversible: Card chargebacks, some ACH returns (days to months, but possible)
  • Medium: Bank wires (recall possible but difficult), certain escrow setups
  • Low / Irreversible: Most on-chain settlements once final, instant rails with no clawback

The less recoverable the action, the higher the bar for further commitment.

Failure 2: Death by a Thousand Micropayments

The first failure was one catastrophic transaction. The second is the opposite — many tiny ones — and it shows the same pattern holds on newer rails.

An agent pays other agents (or agent-accessible services) for data, compute, or answers over emerging pay-per-use rails (e.g., HTTP 402-style challenges).

It finds a service, gets back a 402 challenge with a price, signs a USDC micro-payment, and gets served. Each payment is tiny. The loop is fast and autonomous.

The failure isn’t one wrong transaction. It’s the pattern — and it lives in the payments that succeed.

Sometimes the agent can catch a bad result on its own: pay for a number, get back “purple,” the reasoning rejects it. But agents pay external services precisely for things they can’t produce or verify themselves — a real-time price, a fact they don’t independently know, a result they have no ground truth for. A stale price looks identical to a fresh one. The payment clears, the result looks plausible, and the agent has no basis to reject it.

Multiply that across an autonomous loop and the bleed is structural: successful, irreversible payments for results that look fine and aren’t, no single transaction ever looking wrong enough to trip a limit.

This isn’t a widespread problem today — agent-to-agent payment volume is still tiny — but it is exactly the kind of failure the model invites as these systems scale.

How existing guardrails evaluated it:

Per-transaction cap — Pass. Each micropayment is under the limit. The cap is per-action; the harm is cumulative.
Capability guards — Pass. The agent is allowed to make 402 payments. Not whether it should pay this specific endpoint.
Allowlists — Pass. In an open agent economy, services are discovered on the fly. Often there may be nothing to check against.
Evaluation layer — No flag. The payment is well-formed; the judgment that this endpoint was relevant is what’s wrong.

The micropayment model’s greatest strengths — frictionless, autonomous, tiny — are precisely what strip away every natural circuit-breaker.

Progressive Commitment applies directly here too. Because commitment compounds with every successive micropayment, the discipline is to validate before continuing the loop: confirm that the previous payment actually delivered useful results before issuing the next one.

Gate on cumulative spend and observed delivery quality, not just per-transaction caps. An endpoint that keeps getting paid without delivering gets cut off automatically. Earn confidence from real outcomes, not merely settlement — because a payment that clears for a useless result is still a failure.

In short: “Keep paying for results it never checks” becomes “Validate each result before paying again, and increase commitment only as confidence is earned.”

“We already budget for fraud. We’ll budget for this.”

This is the first objection a finance leader usually raises, and it deserves a real answer — because it’s half right.

Businesses absorb losses all the time: fraud, write-offs, operational errors, and disputed transactions.

They price expected loss into the cost of doing business rather than demanding zero-defect systems. So why should agentic loss be any different? Set a tolerance, budget for it, and let the agents run.

Here’s the half that’s missing.

Budgeting works best when losses are distributed across many independent events that average out to a reasonably predictable rate. Fraud, chargebacks, and operational errors are often manageable because no single incident determines the outcome.

The challenge with agentic systems is correlation.

A misjudging agent may not fail just once — it can repeat the same mistake at scale, rapidly, before anyone notices.

It might pay the wrong endpoint a thousand times. It could resolve one incorrect address and propagate that error across every subsequent payout.

The risk is not necessarily a higher overall error rate.

The risk is that a single root error can propagate across thousands of actions in a short time.

And there’s a deeper point: deciding how much loss to tolerate is an authorization decision. “We’ll accept $X in agentic losses” and “We’ll let agents auto-execute irreversible actions once confidence exceeds threshold Y” are the same policy, expressed in different languages.

The CFO who says “just budget for it” hasn’t escaped the design question. They’ve simply stated it in accounting terms.

So yes — budget for agentic loss.

Reversibility-Aware Authorization is how you keep that loss inside the budget. High-blast-radius irreversible actions should clear a higher bar, while cheap, reversible or low-stakes actions could run more freely.

It’s not an argument against accepting loss.

It’s the mechanism that helps keep loss bounded when mistakes can scale faster than humans can react.

What Both Failures Have in Common

Two different rails, one underlying shape: The failure is policy-conformant but semantically wrong — exactly the class of error that existing guardrails are not designed to catch. On an irreversible rail, that uncaught semantic error has no rollback.

One reliable defense is to stop committing the irreversible step until confidence has been earned through cheap, reversible or low-stakes actions.

Progressive Commitment doesn’t make the agent less fallible. It makes its fallibility survivable.

Where This Framework Won’t Save You

Three honest limits, because the pattern isn’t magic.

1. It depends on correctly classifying what’s reversible.

Mislabel an irreversible action as reversible, and the protection evaporates. Drawing that line — the reversibility spectrum from earlier — is the hard, unsolved part.

2. The probe is only as good as your ability to design it.

Progressive Commitment assumes the cheap test faithfully predicts the expensive action — and designing a test that actually does is the hard, situational part.

A probe that passes while the real action would fail produces false confidence, which is worse than no probe at all.

It can’t be solved once and reused; it has to be built per action type and kept current as the context and the threat landscape change.

3. The thresholds are product and risk decisions, not math.

Where you set the bar trades safety against throughput, and nothing about the pattern resolves that trade for you. It just gives you a place to make it on purpose, instead of by default.

Next, I plan to explore the practical implications of Reversibility-Aware Authorization in more depth — from how systems decide that enough evidence has been gathered, to building a prototype that tests the pattern in code.

Subscribe / follow along as this theory meets reality.

Update: The next piece is now live — Who Sets the Bar? — and it picks up exactly where this one ends: Who decides when the evidence is enough?

Payments, AI, and financial infrastructure through the lens of first principles and second-order effects. This is Base Layer.

Originally published at https://fintechpov.substack.com.


Authorizing AI Agents on Payment Rails That Don’t Forgive was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

Your Money Is About to Get an Agent: A Field Guide to Agentic Finance

How autonomous AI agents are learning to trade, invest, and move money on-chain — and the kind of infrastructure they actually need to be trusted with a balance.

For most of crypto’s history, the human has been the runtime. You watch the chart. You size the position. You sign the transaction. You bridge the funds, chase the yield, and wake up at 3 a.m. because a market that never closes doesn’t care that you need to sleep.

That model is quietly breaking. A new class of software — call them agents — is starting to sit between you and the market, holding a mandate instead of your private keys, and acting on your behalf inside rules you define. This is what people mean when they say agentic finance. And like most infrastructure shifts, it looks like a toy right up until it looks inevitable.

This piece is a plain-language map of what agentic finance is, why today’s blockchains struggle to support it, and what a chain built specifically for autonomous money would need to look like. We’ll use Hotstuff, a DeFi-native Layer 1, as a running case study — not because it’s the only answer, but because its architecture makes the design tradeoffs unusually easy to see.

First, what “agentic” actually means

An agent is not a chatbot with a wallet glued on. The useful definition is narrower: an agent is a piece of software that can perceive a situation, decide on an action against a goal, and execute that action — repeatedly, without a human clicking the button each time.

In finance, that loop maps onto things people already do by hand:

  • Perceive: read prices, funding rates, portfolio drift, an incoming payment, a payroll date.
  • Decide: “funding is negative and my target allocation slipped 4% — rebalance.”
  • Execute: place the orders, settle the transfer, log the result.

The leap from a trading bot to a financial agent is scope. A bot runs one strategy on one venue. An agent is trusted with a mandate — “keep me market-neutral,” “dollar-cost-average this paycheck,” “never let this position exceed 3x” — and figures out the steps. The 2018 academic HotStuff consensus paper and the current wave of AI agents share nothing technically, but they rhyme on one idea: systems get powerful when you can hand off decisions safely.

The trust problem nobody can skip

Here’s the uncomfortable part. The moment you let software move money on its own, you’ve created the most attackable object in finance: an automated thing with spending power. Every serious conversation about agentic finance eventually collapses into one question — how do you give an agent enough authority to be useful without giving it enough to ruin you?

There are four hard requirements underneath that question, and most existing rails satisfy maybe two.

1. Scoped authority, not custody

The naive approach — hand the agent your keys, or deposit into a black-box account it controls — recreates every custodial risk crypto was supposed to kill. The better pattern is delegation with a leash: the agent gets a scoped permission to do specific things (open and close positions, say) while being cryptographically blocked from others (withdraw, transfer out).

On EVM systems this increasingly looks like signature-based delegation — a user signs a typed message (the EIP-712 standard) that authorizes an “agent” address to act within limits, and can revoke it at any time. The funds never leave the user’s control; only a narrow slice of behavior is licensed. Any agent you’d trust with real size should be non-custodial by construction, not by promise.

2. Speed that’s actually deterministic

Agents act in loops, and loops compound latency. If every decision has to wait 12 seconds for probabilistic finality and then pray for no reorg, an agent managing risk across volatile markets is flying blind between blocks. Autonomous strategies need fast, final, and predictable settlement — not “fast on average.” A rebalance that might land now or might land in three blocks isn’t a strategy, it’s a gamble.

3. Verifiable contact with the real world

Most money that matters lives off-chain: bank balances, equities, FX, payroll, invoices. An agent that can only touch native tokens is a very expensive way to trade memecoins. To manage real money it needs trustworthy bridges to real-world data and rails — and “trustworthy” has to mean provable, not “a middleman swore it was true.”

4. Compliance that doesn’t leak your life

If agents are going to move fiat across borders, someone has to answer for KYC, sanctions screening, and qualified-investor checks. Doing that on a public ledger naively would broadcast your financial identity to the world. The requirement is compliance that is verifiable but private — proven, not published.

Hold those four in mind, because they’re the lens for the rest of this article.

A case study in building for agents: the Hotstuff L1

Hotstuff is a Layer 1 with an unusually blunt pitch: trade, invest, and bank from one account. One margin balance spans perpetual futures, spot markets, tokenized real-world assets, vaults, cards, and local fiat rails — aimed at retail users outside the US. Underneath that consumer promise is a set of architectural choices that read, in hindsight, like a checklist for the four requirements above.[1]

The consensus layer: DracoBFT

Hotstuff runs on a custom consensus engine called DracoBFT. It borrows the backbone of the well-known HotStuff BFT family — stake-weighted leader selection, pipelined block production, two-round deterministic finality, and Byzantine tolerance under partial synchrony (the classic n = 3f + 1). The published numbers are aggressive: ~200,000+ TPS, 75ms block times, and 150ms finality.[2]

The word that matters there is deterministic. There’s no probabilistic tail, no 12-second voting window, no “wait for confirmations.” For a human, sub-second finality is a nicety. For an agent running a tight control loop, it’s the difference between managing risk and hallucinating about it. That’s requirement #2, handled at the base layer.

One clever efficiency: instead of recomputing a giant global state root every block, DracoBFT uses Chained Change-Log Commitments — it only hashes the keys that actually changed. Less redundant work per block is part of how you keep finality tight while throughput stays high.[2]

The real-world layer: validators as service providers

The most interesting idea in the design is what Hotstuff calls side-loops. Normally a validator’s whole job is producing blocks. DracoBFT gives validators auxiliary execution domains where they perform real-world work in parallel to consensus — without slowing block production. When a side-loop task finishes, the validator submits the result back to the main chain.[2]

What kind of work?

  • zkTLS verification: validators cryptographically prove that an API response genuinely came from a specific server — Chase, Coinbase, Plaid, wherever — rather than “we asked 20 nodes and trusted the median.”
  • Cross-chain state verification: verifying state proofs from other chains as a native validator duty instead of trusting a bridge operator.
  • Private computation: compliance checks, identity verification, credit scoring, and qualified-investor gating done off the main chain but cryptographically bound to it.
  • Payment orchestration: validators route payments and operate fiat on/off-ramps directly — and get paid for it.[2]

Stack that against the requirements. Verifiable contact with the real world (#3) becomes a validator duty backed by proofs, not a trusted middleman. Compliance that stays private (#4) runs in private computation bound to the chain. Hotstuff Labs has described the result as an “Uber-style routing layer,” where validators act as last-mile gateways to trading, payments, and fiat — earning fees for services, not just block rewards.[3]

Why the “one account” model matters for agents

The unified margin account isn’t just a UX flex. Fragmentation is an agent’s enemy: capital stranded across chains, venues, and wrappers means an agent spends its intelligence on plumbing instead of strategy. When perps, tokenized equities, vault yield, and fiat all settle against a single balance, an agent can reason about one portfolio and act across all of it. Hotstuff currently spans 22+ perpetual markets with up to 50x leverage, 200+ tokenized real-world assets including names like the S&P 500 and Nasdaq-100 ETFs, and fiat rails covering USD, EUR, GBP, BRL, MXN and more across 190+ countries.[4]

Context for the skeptics: this isn’t a whitepaper-only project. Hotstuff evolved out of Syndr, ran a public testnet in late 2025, surpassed $1 billion in derivative trading volume, extended into 24/7 tokenized-equity spot trading in 2026, and is backed by DeFi-native investors including Delphi Ventures, Dialectic, Stake Capital, 1inch, and Gnosis.[4]

From “a chain with features” to an Agentic Finance OS

Put the pieces together and a bigger idea emerges — one Hotstuff itself has started to articulate: the goal isn’t a faster exchange, it’s an operating system for autonomous money.

Think about what an OS actually does. It manages resources, enforces permissions, and exposes a clean interface so applications don’t each have to reinvent the hardware. Map that onto finance:

  • Permissions → scoped, revocable delegation so agents act within a mandate (requirement #1).
  • Scheduler → deterministic sub-second settlement so agent loops run on a reliable clock (requirement #2).
  • Drivers → validator side-loops that turn messy real-world rails into verifiable system calls (requirements #3 and #4).
  • Filesystem → one unified account as the single source of truth an agent reads and writes.

An “Agentic Finance OS” is what you get when those primitives are native rather than bolted on. Developers stop building agents that fight the chain and start building agents that call it like an API. It’s worth saying plainly: this is a thesis, not a finished reality. But it’s a coherent one, and the architecture lines up behind it.

What builders can actually do with this

The practical test of any platform is whether independent developers can build on it without permission. A few concrete shapes of agentic app become possible on rails like these:

  • Autonomous portfolio managers that hold a scoped mandate — target allocations, risk limits — and rebalance across perps, spot, and RWAs without ever gaining withdrawal rights.
  • Strategy engines running DCA, TWAP, and grid logic non-custodially, using signature-delegated agent wallets so the user keeps custody while the agent keeps working. (Early community projects such as Ember, a non-custodial trading terminal built on the Hotstuff broker system, are a preview of exactly this pattern.)
  • Payment agents that watch for an incoming stablecoin settlement and auto-route it into yield, or convert to local fiat across SEPA/PIX/SPEI rails.
  • Treasury agents for on-chain businesses that keep idle balances in vaults and pull liquidity only when needed.

None of these require the user to surrender custody. That single property — useful without being dangerous — is the whole game.

The honest caveats

Education means covering the downside, so here’s the part the hype cycle skips.

  • Delegation is only as safe as its scope. A poorly written permission is a poorly locked door. The security burden moves to how tightly authority is bounded and how easily it’s revoked.
  • Agents fail in new ways. A buggy strategy at machine speed can lose money faster than any human. Circuit breakers, position caps, and kill switches aren’t optional.
  • Throughput claims deserve scrutiny. Numbers like 200k TPS and 150ms finality are impressive on paper; the real test is sustained performance under adversarial mainnet load, which any reader should verify over time rather than take on faith.
  • Regulation is unsettled. Autonomous agents moving fiat across borders is exactly the kind of thing regulators will eventually have opinions about. “Non-US retail” is a design decision with a compliance shadow.

Agentic finance is promising precisely because it’s hard. The projects worth watching are the ones treating custody, determinism, and compliance as first-class problems instead of marketing bullet points.

Where this leaves us

The first era of DeFi asked, can we rebuild finance without intermediaries? The answer turned out to be yes — but it left a human doing all the work. The next era asks a different question: can we hand that work to software we don’t have to trust blindly?

That only becomes possible when the chain underneath does four things at once — leash the agent’s authority, settle its actions instantly and finally, prove its contact with the real world, and keep its compliance private. Hotstuff is one concrete attempt to make all four native, and its “Agentic Finance OS” framing is a useful way to think about where on-chain finance is heading, whoever ends up building it.

The agent economy won’t arrive because someone shipped a smarter model. It’ll arrive when the rails are safe enough that giving software a mandate feels less reckless than doing everything yourself. That’s an infrastructure problem. And infrastructure, unlike hype, either works or it doesn’t.

🔎Author’s note / disclosure: I write about ecosystem protocols and build tools in this space. This article is intended as an educational overview of agentic finance; it is not investment advice. Leveraged trading carries substantial risk of loss. Always do your own research.


Your Money Is About to Get an Agent: A Field Guide to Agentic Finance was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

How Blockchain + AI Could End Corruption

Weve always treated corruption as a problem of bad people. Its not, its a problem of bad situations. And for the first time, we have two tools that can fix the situation itself.

Naked Market breaks down macro finance, blockchain infrastructure, AI systems, and automated trading to help you understand the future of global finance before the mainstream catches up.

Picture this. Youre standing in a government office.

Youve got the right papers. Youve waited two hours. And the man behind the glass slides your form back across the counter without stamping it. “Hmm. This one could take a few weeks,” he says slowly. “Unless…”

He doesnt finish the sentence. He doesnt have to. You both know exactly how this goes a little cash slipped under the counter, and like magic, the stamp appears.

If youve lived just about anywhere on earth, you know this moment in your bones. Maybe it was a traffic cop. A hospital desk. A permit office. A border guard. And youre not imagining how common it is, either — roughly one in four people on the planet had a version of that exact moment in the last year. Paying a little extra, to a person with a little power, just to get something they were already owed.

Now, the normal reaction is to get angry at the guy behind the glass. What a crook. And fair enough — he is one. But heres the uncomfortable thing Ive slowly come to believe, and its the whole reason for this piece: the problem was never really him.

Put almost anyone behind that glass give them that much power, over something you badly need, with nobody watching — and youd get the same shakedown. Different face, same script. Which means corruption isnt mostly a problem of bad people at all. Its a problem of bad situations.

And that little shift changes everything. You cant fix human nature — good luck with that. But you can absolutely fix a situation. And two technologies youve heard a thousand overhyped things about blockchain and AI happen to be very good at quietly dismantling the exact situations corruption needs to survive.

Theres a twist coming, though. The same two tools, pointed the wrong way, could make all of it far worse. Both halves matter so stick with me.

Corruption always needs three ingredients

Heres the strange thing about corruption: for something so universal, its weirdly predictable. It almost always needs the same three ingredients sitting in the same room. Go back to our man behind the glass and youll spot all three.

One — hes the only game in town. You cant take your form to a competing clerk down the street. He is the one and only person who can stamp it. Youre stuck with him, and he knows it.

Two — he gets to decide, and the rules are fuzzy. Theres nothing forcing him to stamp your form today. He can drag his feet, misplace your file, discover a mysterious “problem.” The rules are just vague enough that hes got room to wiggle — room to make your life hard, or easy.

Three — nobodys watching. No one is looking over his shoulder. Theres no record of what he does that he cant quietly fix later. If he squeezes you for a bribe, who on earth would ever find out?

Put those three together — the only option, free to decide, and unwatched and you get a bribe. Every single time. In every country. No matter how kind or nasty the person behind the glass happens to be. An economist called Robert Klitgaard actually squeezed this into a little formula so tidy it belongs on a poster in every government building on earth:

And heres why that formula is secretly full of hope. If corruption came from evil hearts, wed be stuck forever — youd have to make people good, one soul at a time. But if it comes from those three ingredients, you dont need better people at all. You just need to quietly remove one ingredient from the room. Take away his monopoly, or his wiggle room, or his darkness, and the whole thing falls apart.

So lets remove some ingredients. One tool takes away the darkness. The other takes away the gatekeeper. Watch.

Blockchain switches on the lights

Start with the easiest ingredient to attack: nobodys watching.

Corruption is a creature of the dark. It lives in the file only one official can open, the record that gets quietly changed at midnight, the money that slips between two desks and simply vanishes. Take away the dark, and a huge amount of it just… cant happen anymore.

This is the one thing blockchain is genuinely, boringly great at. Forget coin prices and Twitter hype for a second. Strip all that away and a blockchain is really just a shared notebook. Everybody holds the same copy. Everybody can see whats written in it. And here is the magic part — nobody can secretly rip out a page or change something thats already written. If you try, everyone elses copy still shows the original, and youre caught red-handed.

Now imagine every government contract, every payment, every land title, written in a notebook like that. Suddenly our clerk cant “lose” your file, because copies of it exist everywhere. He cant quietly hand your neighbours land to his cousin, because the real record is still sitting there for the whole world to see. And anyone can follow the money from the second it leaves the treasury to the second its spent. The shadows just got a whole lot smaller.

And this is not some far-off daydream. Its already running, in places where it genuinely matters.

The country of Georgia — long haunted by property disputes and quietly rewritten land records — moved its land titles onto a blockchain, so ownership can no longer be fudged by whoever controls the database. Colombia ran school-lunch contracts on one, so every bid was out in the open and impossible to erase. The United Nations World Food Programme sends aid to refugees over a blockchain it calls Building Blocks, so the help reaches hungry people instead of leaking to middlemen on the way. The move underneath all of them is the same: take the ledger out of one officials private drawer, and put it in a shared notebook nobody can secretly edit.

AI removes the man behind the glass

Blockchain handles the watching. But what about the other two ingredients — the guy whos your only option, and his wiggle room to say no? Thats AIs job, and it does two very different things.

Job one: the watchdog that never sleeps. A human auditor can only check a handful of files. He samples a few, crosses his fingers, and prays the fraud happened to land in the pile he grabbed. An AI doesnt sample. It reads every single contract, invoice, and payment — millions of them — and it never gets tired, never looks away, and cant be taken out to a nice lunch. It catches the things no human ever could: the supplier who doesnt actually exist, the bill split neatly in two to sneak under a limit, the one company that somehow wins every contract.

This is already live. Colombia built a system that flags suspicious contracts before the money even goes out the door. Brazil and Portugal are running their own versions. And just like that, the one thing every crook is quietly counting on — that no one will notice — stops being a safe bet.

Job two: the vending machine. This one is sneakier, in the best way. Think about our clerk again. The reason he can squeeze you is that he decides. But what if he didnt? What if getting your permit worked like a vending machine — you feed in the right documents, and out pops the stamp, automatically, with no human in the middle to haggle with?

Thats exactly what these systems can do: take a decision thats currently “whatever the official feels like today” and turn it into a fixed, automatic rule. If the aid money is set to send itself the moment you qualify, theres nobody standing in the doorway with their hand out. It turns out you cant bribe a vending machine. (This is the same quiet machinery I wrote about when AI agents got their own bank accounts and started paying for things with no human in the loop — just pointed at a government office instead of a shop.)

Put them together, and the trap closes

Now line the two up, and you can see why people get excited.

Blockchain flips on the lights, so nobody can hide. AI plays two roles at once — the watchdog that never blinks, and the vending machine that deletes the middleman. One takes away the darkness. The other takes away the gatekeeper. Do both at the same time, and youve pulled every ingredient out of the room at once. No monopoly, no wiggle room, no shadows. On paper, thats the most powerful anti-corruption machine anyone has ever dreamed up.

Which is precisely the moment you should get suspicious. Because Ive only shown you the shiny half.

Here comes the twist

Nobody selling you “blockchain will save the world” wants to say this part out loud, so I will: our corrupt friend is not stupid. When you slam his old doors shut, he doesnt quit and go home. He goes looking for new doors. And these shiny new tools quietly hand him a few.

New door one: just lie at the start. Remember the magic notebook nobody can change? It has a loophole. It perfectly protects whatevers written in it — but it has no clue whether what got written was actually true. So the clerk stops trying to change the record. Instead, he simply writes the lie in the first place. He registers the wrong owner. He types “shipment arrived” for a shipment that never showed up. Now his lie is locked in — permanent, tamper-proof, and protected forever by the very system built to stop him. The notebook guards the record beautifully. It just cant tell whether the human holding the pen was honest — and the human at that entry point is always the weak spot.

New door two: bribe the person who built the vending machine. You cant bribe the machine, true — but somebody built it. Somebody wrote the rules deciding who gets a yes and who gets a no. So the bribe simply climbs one level up, to that person. And it gets worse. When a normal corrupt clerk gets caught, the corruption stops. But when the favouritism is baked quietly into the code, it keeps running long after anyones been arrested — rigging the game while looking perfectly fair and neutral. The crook stops being a person you can catch, and becomes a line of code nobody can even see.

And new door three — the one that should genuinely give you pause. That all-seeing eye we pointed at the corrupt minister? It can just as easily be spun around to watch you. The same money that can be programmed to reach a refugee in seconds can be programmed to expire, to freeze, or to punish. Pointed at the powerful, this technology sets ordinary people free. Pointed at ordinary people, the very same technology becomes a cage — the exact double-edge sitting underneath every government digital-money project being built right now. Nothing in the code decides which way it faces. Only the person holding it does.

So can it actually end corruption?

After all that, lets just answer the question in the title honestly. Can blockchain and AI end corruption?

No. Truthfully, no. Nothing ends it, because you cant delete the part of human nature that reaches into the jar when it thinks no ones looking. But heres the thing — that was always the wrong target.

What these tools can do is almost as good: they can drain the swamp corruption grows in. Make it far riskier, far more visible, and far more of a headache to pull off. Shrink its hiding spots from “basically everywhere” down to a few tight corners you can actually guard. Thats not a perfect world. Its just a much fairer fight — one where the crook has to work ten times as hard for a tenth of the reward. And that, honestly, would change the lives of billions.

Which leaves the real question — the one this whole piece has been sneaking up on. Its not “does the technology work?” Its “who gets to hold it?”

Because the very same machine either starves corruption or supercharges it, and it all comes down to one thing: is that all-seeing eye pointed at the powerful, or at the people? Are the rails open and shared by everyone — or owned by one hand that can flip the switch whenever it likes?

And that is why the thing this newsletter keeps circling back to actually matters. Corruptions favourite hiding place in the modern world is the gap between countries — the cracks between 180 separate national money systems, where more than a trillion dollars a year quietly disappears simply because nobody can see across the seams. A shared, neutral, open money layer closes those cracks and drags all of it into daylight — but only if it belongs to everyone and no one, not to whoever grabs it first. One Earth, One Currency was never really about paying faster. Its about building something transparent enough to starve the rot, without handing any single government the master switch. Thats the whole system were tracing here — and corruption is the sharpest test of whether we build the version that frees people, or the version that watches them.

Four things worth remembering

If you forget everything else, keep these four. Theyll quietly change how you read every corruption story from now on.

1. Its the situation, not the person. Corruption is just what happens when someones the only option, free to decide, and unwatched. So stop asking “is he a good guy?” and start asking “could he get away with it?” That second question actually predicts things.

2. Watch the new doors. These tools dont delete corruption — they move it. To the moment someone types the data in, and to the people who write the code. Thats where the next fight quietly goes.

3. Always ask which way the eye is pointing. Aimed at the powerful, its accountability. Aimed at you, its surveillance. Same exact technology — the direction is a choice a human is making, not a fact of the machine.

4. Open beats owned. A system no single person can switch off is the only kind that actually fights corruption, instead of just moving it upstairs to whoever owns the switch.

Where are you looking?

One last thought, because its the whole reason to read a newsletter like this instead of the daily noise.

When a corruption scandal hits the news, most people feel a jolt of anger, shake their heads, and scroll on. Totally understandable. But the people who really get where the world is heading arent watching the scandal at all. Theyre watching the machine underneath it — whos quietly building these new systems, and who is going to control them — because thats where the next hundred years of power, honest or crooked, is actually being decided. And this one reaches every single person reading this, in every country: one in four of us paid that hidden tax last year, and its almost always the people who can least afford it who pay the most.

We cant vote corruption out of the human heart. But for the first time in five thousand years, we can start taking apart the situations it needs to survive. Whether we end up building the version that frees people or the version that watches them is still — for a little while longer — genuinely up to us.

Thats the difference this whole newsletter is about, really. The rich react to the headline. The wealthy understand the machine.

If you want to keep reading finance this way — the structure under the headlines, before it gets obvious — subscribe. One clear breakdown at a time, for readers all over the world.
Subscribe to Naked Market →

Keep going

-More soon


How Blockchain + AI Could End Corruption was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

❌