VIP Signals · Elixir

Smarter Trading Starts Here

Get structured trading signals, weekly test sessions, and a transparent referral-based VIP access model.

Join Telegram

New MetaMask AI Wallet for DeFi Agents Changes the Approach to Security

0 Reading time: 14 min. okasks_editor

MetaMask has opened early access to Agent Wallet — a new non-custodial wallet for AI agents. The idea is simple: the user can delegate operations in DeFi to the agent without giving it full control over the funds.

The agent only gets access to actions that have been pre-approved. The wallet owner sets up limits, available protocols, and other restrictions before starting work.

Ranking
of the best traders
according to the opinion of the REAL USERS
“Trades Closed From +40% Profit”
“+1,300$/Month in Profit”
“Stable 500$–600$ Withdrawals”

Agent Wallet became available on June 8 as part of an early launch. MetaMask is targeting users who want to automate their work with DeFi instead of manually executing each operation.

Agents are allowed to perform a wide range of tasks. They can swap tokens, work with perpetual contracts, use prediction markets, manage liquidity, and interact with various EVM networks, including Hyperliquid.

The emergence of such tools raises a new question for the industry. While AI was previously limited to giving advice, the final decision was always made by a human during transaction signing. But when the agent is allowed to act independently, the approach to security must be reconsidered.

See Also: Ethereum Again Discusses Private Tokens

A regular crypto wallet protects the user at the moment of transaction confirmation. With an AI agent, the system must control its actions in advance, while the owner is away, during the execution of a chain of operations, and after interacting with smart contracts that the user may not even check manually.

At MetaMask they call their solution a kind of leash for the AI agent. The agent can act independently, but only within predefined limits.

There are plenty of settings here. The user can predefine limits, a list of allowed protocols and addresses, and also connect additional transaction verification mechanisms.

How well all this will work in practice is still hard to say. Autonomous agents are gaining more and more freedom, and with it, new points of risk are emerging. In this model, much depends not only on the wallet’s own protection but also on how carefully the owner has set the agent’s restrictions.

The Wallet Becomes a Security Policy Layer

The description of Agent Wallet states that it is a non-custodial wallet for AI agents that connects via a command-line interface. Before starting, the user sets the rules within which the agent can perform operations.

Private keys remain under the owner’s control. The agent itself gets a separate wallet and can act only within the restrictions that were set in advance.

According to the technical documentation of MetaMask, in Server Wallet mode, two main operating modes are available.

By default, Guard Mode is used. In this mode, there are limits on daily spending or the total volume of transfers over a certain period, lists of allowed addresses and protocols, as well as mandatory confirmation via two-factor authentication if the transaction looks suspicious, violates the set rules, or requires increasing limits.

See Also: Bitcoin Has Entered Capitulation Zone. What Will Happen to BTC Next

For more advanced users, there is Beast Mode. It reduces the number of such restrictions, but the MetaMask documentation clarifies that dangerous transactions and interactions with risky smart contracts will still require confirmation via 2FA.

The company also states that each Agent Wallet operation passes through several levels of verification. Before sending a transaction, it is simulated, threat analysis is performed by Blockaid and protection against MEV attacks is provided through the Smart Transactions mechanism where such a feature is supported.

In addition, for some operations, the Transaction Protection program may apply, providing additional user protection. However, its application depends on the specific conditions and requirements of the program.

 

Control What It Includes What Risks Remain
Spending and Transfer Limits Restrict the amount of funds the agent can manage without additional confirmation. An incorrectly set limit may still be too high for a specific task.
Lists of Allowed Protocols and Addresses Restrict the set of protocols and addresses the agent is allowed to interact with. Even approved platforms may contain risky contracts, unsafe routes, or changed operating conditions.
Transaction Simulation and Blockaid Verification Analyze transactions before execution and identify potentially malicious actions. The quality of threat detection becomes part of the overall security model and does not guarantee protection from all risks.
Escalation via 2FA Blocks suspicious or rule-breaking operations until confirmed by the user. Frequent confirmation requests may lead to the user becoming the weak link in the system.
Beast Mode Gives experienced users more autonomy and reduces the number of restrictions for the agent. The fewer the restrictions, the more trust must be placed in the agent’s preconfigured rules.

This approach seems logical because it considers autonomy not as a choice between allow or deny, but as a matter of distributing authority. An AI agent can be useful even with limited wallet access.

To complete a specific task, it only needs the rights that are truly necessary. This avoids situations where the user has to manually confirm every minor action.

In essence, the main question is no longer whether the agent can independently make transactions. What matters more is whether the wallet can maintain a balance between the convenience of automation and security. It’s about protection from errors in transaction routes, overly broad permission lists, or careless confirmation of operations by the user.

The Confirmation Level Becomes the Security Boundary

In March, analysts already noted a broader risk of autonomous agents. When a program starts searching for information, buying, coordinating actions, and performing tasks almost without human involvement, it needs wallets, access, budgets, payment tools, and clear operating rules.

Cryptocurrency infrastructure is well suited for such scenarios because it is programmable and operates around the clock. But for this very reason, the moment of confirmation becomes critically important.

See Also: The EU Wants to Ban Operations on 11 Crypto Platforms

This is already evident in the case of agent payments. In a May analysis of x402-payments, it was noted that micropayments from machines are poorly compatible with manual confirmation of each operation. If the payments are less than a dollar for API, data, or computing resources, the user may spend more time confirming than the payment itself takes.

With large DeFi operations, it’s different. There, the same confirmation is not an obstacle but an important protection.

Agent Wallet sits right on this boundary. It allows the agent to spend funds but predefines where the user has already given enough permissions and where the transaction must return for manual review.

The risk of an AI wallet is not always about stealing the private key. Sometimes the problem arises earlier when an instruction turns into permission to spend funds.

A similar scenario was shown in the incident with Bankrbot, related to Grok. There, another system interpreted the public output of the model as an executable command. In essence, ordinary text turned into the right to spend funds, without directly hacking the private key.

In such an architecture, the attack surface is not just the wallet. Risks appear at the level of the parser, social triggers, permission system, and execution rules.

The MetaMask model should block some of these scenarios. If a transaction leads to a contract outside the allowed list, exceeds the limit, involves a suspicious address, or is identified as malicious, the agent must stop and request confirmation.

But the reliability of such a scheme depends on how precisely the user has set the rules. It’s also important whether the moment of confirmation remains truly conscious when the agent acts quickly and generates many operations in a row.

Even such a “leash” can fail if attackers start targeting the restrictions themselves. Injections into prompts or content can push the agent to unwanted actions even before the wallet sees the transaction.

A malicious contract may be inside a route that looked safe at the instruction level. An overly broad list of allowed protocols can turn a restricted agent into an almost free one. An inflated daily limit makes control a formality. And a stream of routine confirmation requests can train the user to click “approve” even when it shouldn’t be done.

These problems can arise even before a specific product hack. When a user delegates financial authority to a program, attackers have more targets than just the seed phrase or private key.

See Also: Bitcoin Miners’ Revenues Drop to Record Low: Will BTC Stay Above $60,000?

In a May warning, Gartner on managing autonomous agents, it was said that such systems need restrictions corresponding to their level of independence. The more access, the stricter the control and rules should be.

At the maximum level of autonomy, agents need constant monitoring, strict restrictions, rollback mechanisms, emergency switches, and clear accountability for system behavior.

In DeFi all this boils down to practical questions about wallets. Can the agent’s rules be set narrowly enough for it to do the job but not gain too much freedom? Does the 2FA screen show enough details for the user to recognize a dangerous route? Are policy templates updated when markets, routes, or smart contracts change?

There’s another important question: how quickly can the user stop the agent if it is formally following the rules but clearly not acting as expected?

The risk increases because of speed. In the description, MetaMask states that a trading agent can monitor markets, respond to commands, build routes, and send transactions faster than a person at the keyboard.

This is the product’s value. But for the same reason, the rules must be set correctly before the agent starts acting.

The Next Test Will Be Default Settings

Currently, MetaMask has opened access to Agent Wallet only to a limited group of users. This gives the company an opportunity to see how traders and developers will configure agents when it comes to real money, not just tests.

The main question is not so much about the technology itself as about user behavior.

If the first participants use strict restrictions, create targeted lists of allowed addresses and protocols, set small limits, and enable Beast Mode only in scenarios they understand, Agent Wallet could become a working model for safer use of autonomous agents in DeFi.

But another scenario is possible. Many users traditionally try to remove unnecessary confirmations and restrictions for convenience. In this case, the same infrastructure can turn automation into an additional source of risk.

See Also: Traders Are Watching the Bank of Japan’s Decision: Will Bitcoin Get a New Impulse?

The problem becomes even more relevant against the backdrop of the AI agent economy’s development. It’s not just about payments and trading, but also about digital identity, responsibility, and control over program actions.

In January, the World Economic Forum drew attention to this. The organization cited forecasts that the AI agent market could grow from $5.4 billion in 2024 to $236 billion by 2034.

Exact figures may still change, but the overall trend seems obvious. More and more tasks will be performed by programs acting on behalf of people and organizations.

Much now depends on the first users. They will show whether traders are ready to work with strict restrictions or prefer to sacrifice some security for convenience.

The answer to this question will largely determine the future of Agent Wallet. If most start disabling protective mechanisms, the risks will not disappear. Some will simply move to the automation level.

For MetaMask the task seems quite simple only at first glance. The company needs to ensure that safe settings do not become an obstacle in daily product use.

Ranking
of the best traders
according to the opinion of the REAL USERS
“Trades Closed From +40% Profit”
“+1,300$/Month in Profit”
“Stable 500$–600$ Withdrawals”
Comments (0)

News about digital currencies, fintech trends and financial innovations

CoinSpot.io - the largest Runet resource about digital currencies, fintech trends and financial innovations. We talk about technologies, startups and entrepreneurs shaping the face of the financial world. Venture investments, p2p and digital technologies, cryptocurrencies, analytics and reviews - everything you need to know to stay in trend and earn.

Full or partial use of site materials is allowed only with the written permission of the editorial office, and a link to the source is mandatory!

Subscribe to email updates about new articles and important news from Coinspot.io