The AI Agent Wallet's Harder Half | Elacity
An AI agent wallet can now move your money safely with a passkey tap. But a secure payment is not owned property. Here is the half MoonPay's PayBox leaves for you to solve.
The AI Agent Wallet Can Spend Safely Now. Owning What It Buys Is the Harder Half.
Your AI assistant can now spend your money on its own. The AI agent wallet finally works for a normal person. Everyone is asking whether the payment is safe, and that is the comfortable question. The one you will care about six months from now is whether you own what it bought.
On July 29, MoonPay launched PayBox, a payment vault that plugs directly into Claude and ChatGPT and turns a prompt into a real transaction. You register a passkey, fund a wallet, and your assistant can pay across several major chains. It is a genuine milestone, and it is worth being precise about what it solved and what it did not.
What the AI Agent Wallet Got Right
Start with the credit, because there is a lot of it. PayBox does not park your keys in one place. It uses multi-party computation to split the key across independent components, so a compromised phone, backend, or chat session does not hand over your funds by itself.
It also defaults to passkey approval instead of a seed phrase, and it lets you either confirm every payment or set limits the assistant works within. Those are the right instincts. We have argued for a while that keys should be used, not stored as a single secret, and PayBox is the market agreeing in production.
Where the Trust Boundary Actually Sits
Here is where the honesty has to start. Splitting a key is not the same as removing trust. The parties that hold the shares can, in principle, bring them back together. That is true of every multi-party scheme, including ours. Anyone selling you the word trustless is selling you a word, not a property.
So the useful question is not who could theoretically reassemble a key. It is what the split protects, and what it enforces at the moment of use. That is a trust and safety question, not a marketing one.
PayBox splits the key to protect the money. That secures the act of spending. It says nothing about the thing you spent on.
The Half a Payment Rail Cannot Reach
Watch what your agent actually buys: a dataset, a model output, a licensed clip, an hour of compute. The rail moves the money and the file arrives. You consumed it. In most cases you cannot resell it, and you hold no terms over how it gets used next.
Now flip the direction. When someone else's agent buys your work, the same open payment standard moves their money to you and hands over your file in the clear. The receipt proves a sale. It carries no rights, no royalty that follows the work, and no way to revoke access later. A payment rail is excellent at settling a transaction and structurally blind to ownership. We made this case when agents learned to pay for anything and still could not own it; PayBox is the most polished version of exactly that gap.
What Ownership Requires That Spending Does Not
Ownership needs the split to do more than guard funds. It has to gate the asset itself.
In Elacity's design, the key that unlocks what you bought is held as an owned quorum across independent machines, and no single one, Elacity included, can release the content alone. Before any machine releases its share, it re-checks your rights on-chain. The secret exists in the clear only for a sealed instant, welded to that one use, and is never handed to any app. That is what we mean by keys used, never owned.
That changes what a split can enforce. A payment split protects money. A rights-gated split protects property: revoke access, and the next attempt to use it fails closed, because the machines simply do not release their shares.
It also changes what you can sell. Through Elacity dDRM, a creator can wrap a song, a dataset, or a model into a sealed, programmable good with rights and royalties written in, so the work is never handed over in the clear and the terms travel with it. That is the piece a vault cannot add after the sale. The consumer Exchange for listing these goods is still being built out; the sealing and the rights gate that make it possible already run.
The autonomous agent layer, an agent that wields spending power it can use but never see, wrapped in an approval and kill loop, is what we are building toward on top of that primitive. We are not claiming it is finished. The hard part, a key an agent uses without ever holding, is the part that already exists.
The Harder Half
PayBox proved the payment can be safe, and that was the easier half. The harder half is turning what your agent touches into property you actually hold, and that is a question of architecture, not a feature you bolt onto a wallet. Follow Elacity on X for how the ownership layer gets built.