WARDEN
A trading agent that lives on your machine, holds its own keys, and runs behind a wall it cannot talk its way past. Other agents ask you to trust them. This one hands you the receipts — every decision it makes, including every time it was told no, written to the chain where anyone can check.
The agent runs on their servers with their keys. The safety story is a terms-of-service page. If their model, their prompt pipeline, or their infrastructure gets compromised, your account goes with it — and you find out afterwards.
The model proposes.
Deterministic code disposes.
The chain enforces.
That one sentence is the whole product. The clever part of WARDEN is not the model — it is the wall around it.
Your machine proposes. The chain decides. Drag the boxes around, click any of them to read what it actually does.
Most agent limits are a number you typed once. The Ward is a ruleset compiled into your account contract, and it reacts to what the market is actually doing. Every rule below has to be explainable in one sentence — if it isn't, it doesn't ship.
The louder the market gets, the smaller your agent is allowed to trade — automatically.
Stops an agent from making the same bet five times through five different tickers.
Trades only inside hours you chose. Scheduled events and weekends are hard denials.
If an address isn't on the list, the contract won't reach it. Not the client — the contract.
Every agent gets its own allowance, and all of them together sit under one wallet ceiling.
Earn more room by performing. Tightening happens instantly; loosening waits out a timelock.
Past your loss threshold, opening trades stop. Closing trades stay open so you can get out.
The session grant dies on schedule. Extending it takes your signature and a timelock.
At −8% from the high-water mark the contract stops accepting opening trades. Nothing about that decision lives in the client.
Pick something hostile and send it at a live policy. You get back the verdict, the rule that produced it, and a link to the transaction where the denial was recorded. One of these is legitimate — see if you can spot it.
Every agent starts on paper, earns its way to shadow, and only then touches money. The stage lives in the contract — and you can't skip one, even with your own key. Try it below.
Most dashboards show you the wins. The Record commits every decision — what the agent saw, what it proposed, what the policy said, and what happened — with denials given exactly the same weight as fills. There is no delete path, for anyone, including us.
Prompt injection isn't something we claim to prevent — it's something we design around. A completely compromised model still cannot produce a loss beyond the Ward.
A confirmation card appears that you didn't ask for. You cancel it. Nothing moved, and the attempt is already in the Record.
Every capability is off until you switch it on, scope it, and bound it. Nothing is enabled because it seemed convenient.
The model emits typed intents from a fixed list. Any parser that accepts free-form text into an execution path is a design failure.
Lost connectivity, a stale oracle, a crashed worker — every one of them narrows permission. None of them widens it.
Loosening a bound takes a timelock, even for you. Tightening one is instant. That asymmetry is deliberate.
Go quiet and permission narrows on a schedule. Silence is treated as a signal, not as consent.
An enforcement claim is only credible if you can read the code. External audit of the policy contract before mainnet, signed releases after.
The policy contract and SDK, extracted for any agent project on the chain to embed. Months of work and an audit you don't have to fund.
Run agents on paper forever without paying anything or connecting a wallet. If a token ever exists it buys perks — it never gates the product.
No wallet, no account, no funds. Two minutes from install to watching an agent trade against live prices with nothing at stake.