A humanoid AI agent — the thing HumanPay keeps bounded
agent #9836 · ERC-8004 42220 · Celo mainnet tag celo_131f6e57e5b5
Celo · Agents at Work 2026

Your AI agent can hold money.
It just can't be drained.

An agent that holds real money is an agent that can be robbed. HumanPay puts agentic payments on a leash — real USAT, moved only inside limits a human set once, only after proof-of-human, with every decision on a tamper-evident receipt.

Self custodyERC-8021 taggedFee abstracted

Agents getting robbed is the story of 2026.

Prompt injection drained ~$150K from an agent wallet in May. Over-permissioned agents amplified a $40M breach in January. The accountability layer doesn't exist yet — HumanPay builds it.

  • Real incidents, not hypotheticals — Forbes: "Rogue AI agents are turning crypto risk into a financial-control issue."
  • The leak is the architecture — agents holding keys with no defined bounds.
  • Recently possible — TEE wallets, MetaMask Agent Wallet, Ledger Agent Stack all launched this year.
A controlled robotic hand — the anti-drain leash, brought to life

Three steps. Self-custody end to end.

Fund your own Celo wallet, sign each tip in your own app, and settle peer-to-peer over gasless x402. The bot never consolidates funds and never sees a private key.

  • 1Connect your wallet — your lab binds to you; the peer roster becomes the payTo allowlist.
  • 2Set your limits — one-time per-tx, daily, and lifetime caps it can never exceed.
  • 3Move money, provably — USAT sender → recipient, ERC-8021-tagged, on a tamper-evident receipt.
Sending money from a phone — HumanPay's peer-to-peer payments

Three promises that make an agent worth trusting.

The same guarantees that stop a breach are what make the agent usable by real people.

🛡️

Can't exceed its bounds

Per-tx, daily, and lifetime caps in integer micro-units. A prompt-injected agent simply can't overspend.

🧠

Can't self-authorize

The agent never holds the master seed. Every payment needs a signature from you.

🔗

Every decision is provable

Allows and blocks are hash-chained receipts. Recompute the whole audit trail in one call.

Six gates. One breach-proof whole.

A payment is ALLOWED only if every one holds. Otherwise it's blocked — and blocked decisions are still receipted.

Proof-of-human

Self verifies a person is in control.

Operator authorization

You sign each request; agent can't self-authorize.

Bounded spend

Per-tx + daily + lifetime integer caps.

payTo allowlist

Funds only reach declared addresses.

ERC-8021 attribution

Every settlement carries the on-chain tag.

Tamper-evident receipts

A hash-chained ledger recomputable in one call.

Self-custody peer-to-peer — value moves between people, not through a middleman

Set your limits once. It respects them forever.

Connect your wallet to launch your HumanPay lab — peer-to-peer, fee-abstracted, and provably bounded.

Launch the app →