BuildAWallet.xyz provides a secure framework for autonomous agents to interact with blockchain networks without exposing private keys. By utilizing unsigned transaction proposals and policy-controlled signing, developers can maintain full custody while enabling automated execution. This guide explores the architectural patterns required to safely integrate AI agents into the Base and Solana ecosystems.

Policy Controlled Signing

Policy controlled signing is a security mechanism where an agent's ability to execute transactions is governed by a predefined set of rules rather than direct key access. In the context of BuildAWallet, this approach ensures that even if an agent is compromised, it cannot perform actions outside the established policy boundaries. The agent acts, but the policy decides whether the action is valid.

Defining the Boundaries

Effective policies define limits on transaction value, allowed recipients, and specific network operations. For example, a policy might restrict an agent to sending no more than 10 USDC per transaction to a whitelist of addresses. This layer of abstraction separates the logic of the agent from the authority of the wallet.

Implementation in BuildAWallet

Hardware Wallet Integration

Hardware wallet integration is the process of connecting a physical secure element to a software interface to manage keys and sign transactions. This method is considered the gold standard for personal custody because the private key never leaves the isolated hardware environment. For human users, this provides a tangible layer of security that software-only wallets cannot match.

Safe AI Agent Crypto Transactions Without Private Keys

Why Hardware Matters for Agents

When integrating agents, hardware wallets serve as the final authority. The agent can prepare a transaction, but the hardware wallet must physically sign it. This ensures that a malicious agent cannot sign a transaction without human intervention or a specific hardware approval. The separation between the agent's logic and the hardware's signing capability is critical for safety.

Connectivity and Protocols

Unsigned Transaction Proposal

An unsigned transaction proposal is a fully constructed blockchain transaction that has not yet been signed with a private key. This object contains all the necessary data, such as the sender, recipient, amount, and gas parameters, but lacks the cryptographic proof of authorization. This is the primary mechanism for safe agent interaction.

The BuildAWallet Approach

BuildAWallet's machine API allows agents to prepare transactions without giving up custody. The service returns a wallet-signable transaction object. For Base, this is an EIP-1559 transaction with current nonce and gas estimates. For Solana, it is a serialized legacy transaction with a zeroed signature slot. The agent receives this proposal but cannot broadcast it until it is signed by the user's wallet.

Benefits of Proposals

Using unsigned proposals allows for human review before execution. The user can inspect the transaction details in their wallet interface before approving the signature. This mitigates the risk of prompt injection attacks where an agent might be tricked into sending funds to an unauthorized address. The proposal acts as a safe container for the agent's intent.

Unsigned Transaction Construction

Unsigned transaction construction is the technical process of assembling the specific data fields required by a blockchain network to form a valid transaction. This involves calculating the correct nonce, estimating gas fees, and encoding the payload in the network's specific format. Accurate construction is essential for the transaction to be accepted by the network.

Base and Solana Specifics

On Base, an EVM-compatible chain, the construction involves EIP-1559 fields such as maxFeePerGas and maxPriorityFeePerGas. BuildAWallet's API handles this complexity, returning a ready-to-sign object. On Solana, the construction involves a different serialization format, often using base64 encoding for the transaction body. The API abstracts these differences, providing a unified interface for agents.

Validation and Metering

Each successful preparation costs one API unit in the BuildAWallet system. This metering ensures that the service remains sustainable while providing developers with the tools they need. Failed validation or upstream RPC failures are not metered, which protects developers from paying for errors in their own logic or network issues.

Session Keys

Session keys are temporary cryptographic keys derived from a master key, allowing an application to sign transactions for a limited period or scope. This technique is often used in smart contract wallets to grant temporary authority to an application without exposing the master key. It provides a middle ground between full custody and no access.

Limitations and Risks

While session keys are useful, they still carry risk if the session is compromised. The key must be securely stored and rotated frequently. For high-value assets, session keys may not be sufficient. BuildAWallet's current focus on unsigned proposals and policy-controlled signing offers a safer alternative by ensuring the master key never leaves the user's control.

Use Cases

Session keys are ideal for low-risk, high-frequency operations, such as automated trading bots that execute small, frequent trades. They allow for seamless user experience by removing the need for constant hardware approval. However, they should be used in conjunction with other security measures, such as spending limits and address whitelisting.

Smart Account Policies

Smart account policies are rules embedded within a smart contract wallet that dictate how the wallet can be used. Unlike traditional external owned accounts, smart accounts can enforce complex logic, such as multi-signature requirements or time-locked withdrawals. This allows for a high degree of customization and security.

Policy Enforcement

Smart accounts can enforce policies that are impossible with standard wallets. For example, a policy might require two signatures for any transaction over a certain amount. This is particularly useful for business wallets where multiple stakeholders need to approve large transfers. BuildAWallet's design tools allow users to configure these policies as part of their wallet blueprint.

Integration with Agents

Agents can interact with smart accounts by submitting transactions that comply with the embedded policies. If a transaction violates a policy, the smart account will reject it at the network level. This provides a robust safety net that is independent of the agent's software. The policy is enforced by the blockchain, not by the agent's code.

Hardware Wallet Signing

Hardware wallet signing is the act of using a physical device to cryptographically sign a transaction. This process ensures that the private key remains secure within the device's secure element. The user must physically confirm the transaction on the device, providing a final layer of human oversight.

The Signing Workflow

The workflow typically involves the agent preparing an unsigned transaction, sending it to the hardware wallet, and the user reviewing and approving it on the device's screen. The device then signs the transaction and returns the signed object to the agent. The agent can then broadcast the signed transaction to the network. This workflow ensures that the user is always in the loop for critical actions.

Security Best Practices

Users should always verify the transaction details on the hardware wallet's screen before approving. This includes checking the recipient address and the amount. Phishing attacks can sometimes manipulate the software interface to display incorrect information, but the hardware wallet's screen is a trusted source of truth. BuildAWallet emphasizes this human-controlled aspect in its HUMAN mode.

MPC Wallets

MPC wallets are digital wallets that use Multi-Party Computation to split a private key into multiple shares. No single party holds the complete key, and a threshold of shares is required to sign a transaction. This provides a high level of security without the need for physical hardware.

Key Sharing and Recovery

In an MPC setup, the key shares can be distributed among different devices or parties. For example, one share might be on a user's phone, another on a server, and a third on a hardware device. This allows for flexible recovery options and enhanced security. If one share is compromised, the attacker still cannot sign transactions without the other shares.

Agent Integration

Agents can be integrated into MPC wallets by holding one of the key shares. However, this requires careful policy design to ensure that the agent's share cannot be used maliciously. BuildAWallet's platform is designed to support various custody models, including MPC, allowing users to choose the level of security and convenience that fits their needs.

Key Takeaways

  • Policy controlled signing ensures that agents can only execute actions within predefined boundaries.
  • Hardware wallet integration provides the highest level of security for personal custody.
  • Unsigned transaction proposals allow agents to prepare transactions without accessing private keys.
  • BuildAWallet's API supports transaction preparation for both Base and Solana networks.
  • Session keys offer a balance between security and convenience for low-risk operations.
  • Smart account policies enforce rules at the network level, providing a robust safety net.
  • MPC wallets distribute key shares to enhance security and enable flexible recovery.
  • Human oversight remains critical, even when using advanced cryptographic techniques.

Frequently Asked Questions

Does BuildAWallet store private keys?

No, BuildAWallet never accepts a seed phrase or private key. The platform is designed to work with existing wallets and provides tools for transaction preparation and data reading without custody.

Can agents sign transactions directly?

Currently, BuildAWallet's production service does not sign transactions for agents. It prepares unsigned transactions that must be signed by the user's wallet. Policy-controlled signing is in development for future agent capabilities.

Which networks are supported?

BuildAWallet supports Base and Solana mainnets for its machine API. It provides read-only data and transaction preparation for these networks.

How much does the API cost?

Is the HUMAN design tool free?

Yes, the HUMAN wallet design tool and detailed implementation plan are free after Cloudflare sign-in. No wallet payment or API subscription is required for the design phase.

How does the x402 payment work?

The x402 endpoints allow for pay-per-request access to wallet snapshots. The user pays $0.01 USDC per request via the x402 protocol on either Base or Solana. This is separate from the API subscription plans.

Conclusion

Securing AI agent interactions with blockchain networks requires a multi-layered approach. By combining unsigned transaction proposals, policy-controlled signing, and robust custody solutions like hardware wallets and MPC, developers can build safe and efficient agent systems. BuildAWallet provides the infrastructure to support these patterns, allowing both humans and agents to interact with the Base and Solana ecosystems securely. Explore the platform to design your own wallet blueprint and integrate agents with confidence.