18M+
x402 payments audited on-chain. Payer, payee, amount and timing are public for every one.
Deep First Search ·
AI agents are starting to pay for things, and anyone can talk them into paying the wrong party. We keep every payment inside limits you signed, and expose less of your business.
The problem
Your agent reads untrusted content all day, and it can move money. One poisoned page is enough to make it pay the wrong party. And every payment it makes is public: who, how much, when. Attackers read your balance. Competitors read your suppliers.
18M+
x402 payments audited on-chain. Payer, payee, amount and timing are public for every one.
$150K+
drained from one AI agent's wallet by a single prompt injection. The same trick worked again a year later.
77%
of employees paste company data into AI tools that keep logs.
Exposure control
Each merchant sees a fresh payer with no history, and what your agent bought is shared with that merchant only, never with facilitators or the chain. Amounts and payees remain on-chain. Funding payers through a regulated exchange breaks the public link to you, while you can still prove any payment to an auditor.
The product
01
An on-chain vault that assumes your agent will be tricked. You sign a budget per merchant; the agent's key can spend inside it and never widen it. Revoke or pause instantly.
02
An x402 client that treats every payment request as hostile. Payee, asset, network and price must match what you approved before anything is signed. The model proposes; code decides.
03
Expose less of your business. Each merchant sees its own payer, nothing extra leaves your machine, and payers can be funded through a regulated exchange so the public can't trace them back to you.
Built to survive
We never hold funds or run relayers. Immutable contracts with no admin keys, open source.
A tamper-evident payment log lets owners prove any payment to an auditor or tax authority, on their terms. Sanctioned addresses are screened before any payment.
Privacy lives in the app, not in the token. stays exchange-listable after EU AMLR 2027.
No master key, no admin, no upgrade path. Enclaves are defense in depth, never the only lock.
1,000,000,000
total supply, minted once
Tokenomics
One billion , minted once at genesis. The contract has no mint function at all, so the number can only shrink.
| Allocation | Share | Terms |
|---|
Usage burns supply
Agent Safe
0.1% fee in USDC
Fee jar
50% of fees, immutable
Anyone
burns to claim the jar
Burned
supply goes down
No swaps, no oracle, no admin, nothing to front-run. The price to claim the jar doubles after every claim and halves every three days. Only Agent Safe, SDK and inference fees feed the jar. No transfer taxes, no reflections, no hidden market-maker deals.
0%
to venture capital
0
new tokens, ever
0%
of fees to the burn jar
0y
founder lock, on-chain
No token until there is revenue to burn.
Roadmap
Phase 0 · Done
Market pain, 30+ launches and failures studied, legal and security assessments, tokenomics.
Phase 1 · Live on testnet
x402 client with a policy engine outside the model, Agent Safe vaults, per-merchant payers. Verified contracts and the first live x402 payment.
Phase 2
Capped beta, independent review, bug bounty, real USDC fees. Exchange-funded payers.
Phase 3
Wallet-only airdrop to real users, one-price public auction, liquidity burned, no mint function at all.
Phase 4
Integration with a compliant, third-party privacy pool. Later: private inference paid through the same rails.
npm install @deepfirstsearch/agent-pay