On August 6th, the MetaMask team opened general access to the non-custodial Agent Wallet, which allows AI agents to independently conduct on-chain operations within user-defined rules.
Your agent finally gets its own wallet.
— MetaMask 🦊 (@MetaMask) August 6, 2026
MetaMask Agent Wallet is now live for everyone. pic.twitter.com/F81PZ7etxv
Agent Wallet operates via a command-line interface (CLI) and is compatible with Claude Code, Codex, OpenClaw, Hermes, OpenCode, and Cursor. The user pre-defines spending limits, a list of allowed protocols, and other rules. After that, the AI agent can independently conduct operations within the established limits.
In Guard Mode, which is enabled by default, allowlists for networks, addresses, and token recipients are active, along with a 24-hour outbound fund limit. Representatives of the Web3 wallet have called this mechanism 2FA.
If an operation falls outside these boundaries or the security system deems it suspicious, execution is paused. The user can approve or reject the transaction via MetaMask Mobile or a link in an email. After five minutes without a response, the request is automatically canceled.
In Beast Mode, allowlists and the outbound fund limit are not applied. However, threat checking is preserved, and operations that the system considers malicious or risky still require user confirmation.
"The agent can act, but it acts within the user's boundaries," stated MetaMask.
Keys Isolated from the AI Agent
In server mode, private keys are stored in a trusted execution environment to which the AI agent's process should not have direct access.
The agent sends an operation request, and a separate infrastructure checks the policies and signs the transaction. The user can export the secret recovery phrase. On this basis, MetaMask calls Agent Wallet non-custodial. However, during day-to-day operation of server mode, the user relies on the infrastructure running the isolated signing module.
A separate mode with its own BIP-39 mnemonic phrase is provided for developers. MetaMask's documentation warns against passing it through command-line arguments, as they may remain in history or be displayed among running processes.
Agent Wallet supports EVM-compatible networks, Hyperliquid, and Solana. Through it, AI agents can perform swaps, trade perpetual contracts and on prediction markets, provide liquidity, and interact with lending protocols.
Coverage for Specific Losses
MetaMask also introduced Transaction Protection for eligible operations. If the system deemed a transaction safe, but it still led to a covered loss, the user can receive compensation of up to $10,000 per month.
In the program description, the company specifies that reimbursement is made in mUSD — MetaMask's US dollar-pegged stablecoin. The asset is issued by Bridge, a Stripe-owned company, on the M0 protocol infrastructure.
Coverage does not apply to all losses. Among the exclusions listed by the team are compromise of the private key or seed phrase, ordinary market losses, P2P transfers, and protocol-level exploits.
Risks
Granting AI the ability to independently manage assets creates threats that are not present with a standard wallet requiring manual confirmation of each operation. MetaMask includes "prompt injection" among them. Such a command could be found, for example, on a web page, in a token description, an email, or an API response.
If a single system simultaneously reads external data and has the right to initiate financial operations, a malicious instruction could turn into an irreversible on-chain transaction. MetaMask attempted to separate these functions: the AI proposes an action, while the wallet rules, the isolated signing module, and transaction checks operate independently of the model's decision.
This does not eliminate the risk completely. For example, in Beast Mode, the agent is not limited by allowlists for addresses, networks, and protocols or a daily spending limit. The system continues to block known malicious operations, but a correctly looking transaction triggered by an erroneous or manipulative instruction may pass the checks.
Digital Cyborgs and Their Rights. On the Legal Side of AI Agents
In February, Coinbase introduced Agentic Wallets for autonomous AI agents, and in June presented Coinbase for Agents. The service allows an agent to trade and make payments via MCP or a command-line interface within the user's permissions.
In May, Base launched the Base MCP system, which allows AI assistants to initiate real on-chain operations in the network. Transactions can be formed through Claude, ChatGPT, Codex, Cursor, and other models.
Recall that on June 8th, the MetaMask team opened early access to Agent Wallet for approximately 200 users.
end-content







