AI Agent Self-Custody: Where the Rule Lives | Elacity
Tether's new AI agent wallet keeps the seed away from the agent. But once unlocked, the spending rule is an instruction. Self-custody for agents needs the rule at the key.
AI Agent Self-Custody Hid the Key. Now Decide Where the Rule Lives.
Hand an AI agent your wallet and the question that decides whether you lose money is not whether it can see your seed phrase. It is what the agent can do once the wallet is unlocked, and who, exactly, enforces the limit. That is the real test of AI agent self-custody.
On September 27, Tether added a command-line wallet and a Model Context Protocol server to its Wallet Development Kit, so the same local wallet can be driven by a person at a terminal or by an AI agent. It is serious engineering, and it sharpens the self-custody question better than most launches this year.
What Tether Got Right
According to the project's README, a background daemon holds the unlocked wallet while the CLI and the MCP server act as thin clients: private keys and seeds never leave the daemon process. Seeds are encrypted at rest with AES-256-GCM under a scrypt-derived key. The agent calls structured tools such as getbalance and sendtoken; it cannot read the key.
That is the right instinct. An agent that can read a seed phrase can leak it through one poisoned web page or one careless log line. And because Tether open-sourced the kit, anyone can check the claim instead of trusting it.
The ambition is explicit. Tether CEO Paolo Ardoino has predicted that every AI agent will have a wallet, and Tether now joins Coinbase, which launched Agentic Wallets in February, in shipping the plumbing.
The Failure of the Unlocked Session
Hiding the key prevents theft of the key. It does not prevent misuse of the key, and misuse is the failure agents are prone to.
The same README recommends a time-to-live of zero, meaning an unlimited session, as ideal for AI agent environments. Once unlocked, the daemon signs what it is asked to sign for as long as the session lasts. The safeguard it describes is procedural: agents must show the user a preview and wait for confirmation. That is a rule the agent is told to follow, and CryptoSlate reported that developers are left on the hook for overspending.
This is ambient authority in miniature. The agent sits next to the full power of an unlocked wallet, and the only thing narrowing that power is the agent's own behaviour. We have explained why one poisoned file is enough to hijack an agent in exactly that position.
The IMF named the underlying tension in April: agentic AI behaves probabilistically, while payment infrastructure demands deterministic outcomes. An instruction to an agent is probabilistic. A lock is deterministic.
Custodial designs answer differently. Coinbase's Agentic Wallets add session caps and per-transaction limits, which is genuine enforcement, but it runs on infrastructure Coinbase operates. So the market offers a trade: self-custody with the rule left to the agent, or enforcement with the rule held by a provider. Neither puts the key and the rule in your hands at once.
The Paradigm Shift: Put the Rule at the Key
The fix is not a better prompt or a friendlier provider. It is making the permission itself the thing that unlocks the key, so an agent cannot act beyond its grant even when it tries.
That is the design of ElastOS, the open-source runtime beneath Elacity. Three mechanisms carry it.
1. Keys are used, never held
A key can sign or pay for you while the secret exists in the clear for a split second inside a sealed sandbox, welded to that one transaction, then wiped. There is no unlocked session waiting in memory for an agent, a script, or an attacker to lean on.
2. Permission is narrow, expiring, and revocable
Nothing touches your money until you grant a specific capability: this amount, this counterparty, this window. The grant expires on its own. Revoke it and the action stops mid-flight. With no grant, the answer is no: the system fails closed.
3. Humans and agents pass the same gate
Tether lets a person and an agent drive the same wallet. ElastOS makes the stronger promise: humans and AI share the same capability model, so an agent can never hold more authority than the narrow grant you gave it, however persuasive its instructions or its attacker.
What Is Built, and What Is Not
The hard primitive, a key an agent can use but never see, bounded by a revocable capability, exists in ElastOS today. The agent product around it, dedicated agent wallets and an autonomous approval and kill loop, is what Elacity is building toward.
The stakes run past payments. Elacity exists to turn data into capital: your work, data, or IP packaged as a Wealth Capsule that humans and agents pay to use on terms you set. That market only holds if agents transact inside boundaries they cannot talk their way out of. Spending safely is also only half of the agent problem; owning what it buys is the harder half. More on where custody meets markets lives in our DeFi & Market Strategy hub.
Tether showed an agent can transact without seeing the key. The next step is an agent that cannot exceed the rule. Follow Elacity on X as we build it.