Give your agent a USDT budget. Not your wallet.

Agents request economic actions. Spenda checks budget, risk, approval and policy on-chain before a single dollar moves.

How a Spenda payment flowsLive policy
  1. 01

    AI agent

    Wants to pay a vendor

    Holds zero funds

  2. 02

    SpendIntent

    Amount · target · expiry

    Single-use request

  3. 03

    Policy engine

    Caps · allowlists · risk

    Approve or block

  4. 04

    USDT vault

    Executes · emits receipt

    You keep custody

The agent asks for a payment it cannot execute itself.

Agents hold zero keys and zero tokensEvery decision lands on-chain as evidence
The problem

Hand an agent your wallet and one mistake can drain everything.

Prompt injection, a hallucinated action or a runaway loop: an unrestricted agent key exposes the entire balance, instantly and irreversibly.

Today: a raw agent wallet

  • The agent holds the private key
  • No spend cap, no expiry, no allowlist
  • One prompt injection can drain the full balance
  • Funds leave before a human can react

With Spenda: a policy vault

  • The agent holds nothing and signs nothing
  • Per-tx cap, daily cap and expiry enforced on-chain
  • Blocked requests emit evidence and move zero funds
  • Every decision becomes a public receipt
100%

of the wallet balance is exposed the moment one raw agent key leaks

$0

held by a Spenda agent. Caps, custody and every decision stay with the vault

Security model

Authorization fails closed at every layer.

The restricted account constrains what an agent can call. The vault independently decides whether value moves.

Boundary 1
Restricted ERC-4337 account

It cannot call around the vault

The account binds to one vault and one paymaster. It rejects direct owner execution, arbitrary targets, native value and every selector except the vault’s spend request.

Boundary 2
USDT vault policy

Every payment is independently checked

The vault checks agent status, expiry, token and target allowlists, per-transaction cap, daily cap and action replay before transferring USDT. Blocked requests emit evidence and move nothing.

How Spenda works

Give your agent autonomy.
Keep control of your money.

Spenda gives AI agents programmable identities, budgets, and permissions to act on your behalf while your funds remain secured inside a policy-controlled vault.

Flow running
Auto approveRisk 12

Low risk · Within policy

Human approval

Higher value / elevated risk

Block

Policy violation · Nothing moved

Spenda Vault

The vault holds user funds and enforces the policy boundary before any token moves.

Custody boundary

The agent never gets your wallet.

Your private key stays in the user wallet. The agent has an address and a request path, not custody of your money.

User wallet

Private key

×never shared

AI agent

Own address · $0

Spenda Vault

Policy-controlled execution

Recipient

Receipt on-chain

Technical layer

From identity to settlement.

Agent Identity: A dedicated account gives every autonomous actor a traceable on-chain identity.

Autonomous spending without autonomous custody.

Every transaction is evaluated, authorized, executed, and recorded on-chain. Agents get autonomy. Users keep custody. Spenda controls the boundary.

How it works

From economic intent to verifiable receipt.

01

Agent expresses intent

Purchase compute, renew a service, pay another agent or request an RWA transaction with a fixed amount and expiry.

02

Spenda decides

Independent budget, allowlists and deterministic risk produce approved, blocked or requires-approval outcomes.

03

Human signs when needed

High-risk requests bind the owner signature to one agent, token, recipient, amount, nonce and expiry. No blanket permission.

04

Vault executes and receipts

The restricted UserOperation reaches the vault. USDT moves only if on-chain policy passes, then chain events produce the receipt.

Built for USDT settlement on BOT Chain mainnet.

BOT funds gas and the paymaster. Official bridged USDT stays inside the policy vault. Restricted agents never custody either asset.

Deployment status

Deployed on mainnet · Aug 22, 2026

Spend asset

USDT · 6 decimals

0xaBabc7Ddc03e501d190C676BF3d92ef0e6e87a3C

Gas asset

BOT

Owner wallet + paymaster deposit

Mainnet network

Chain ID 677

rpc.botchain.ai

Live proof · on-chain

Policy outcomes you can inspect.

Real BOT Chain mainnet acceptance transactions show an approved restricted-account payment and a blocked policy request. Settlement is official bridged USDT; agents never custody it.

executeSpend
Event
Resultnothing moved
Transaction
vs
executeSpend
Event
Resultnothing moved
Transaction
Recent vault decisionsconnecting
Pilot procurement agentrestricted
0x13bb…F70E

Max 0.50 USDT per tx · 1 per day · active on mainnet

0 unauthorized spends

Track record

0 unauthorized moves

Across every deployed agent since the restricted stack went live. Blocked requests moved nothing.

Agents get autonomy. You keep custody.

Inspect intents, agent budgets, approvals, risk decisions and chain-derived receipts from the live restricted deployment.