Switching hardware wallets? Migrate to Ledger safely in a few steps.

Learn more

Upgrade your digital life

Ledger Wallet: Free from compromise

Download now Learn more

The Shrinking Anchor

Beginner
Ledger N3XT Research Competition

Why Hardware-Verified Trust Cannot Scale with Agentic Commerce

Author
Samuel Smith
X (Twitter)
Blockchain Club
University of Michigan Blockchain (Class of 2027)
Track
Agentic Economy
Date
September 2026
Student research published via the Ledger N3XT Research Competition. Findings are the author’s own. Ledger does not vouch for conclusions on advanced subject matter.
Abstract

The agentic economy is typically described as a forecast, just like putting data centers on the moon or having orbital compute power for our Claude subscriptions. It is more accurately described as deployed infrastructure moving real money and transforming our standard of commerce. Yet in 2026, it produced its first two documented failures.

These failures are worth studying not because something broke, but because nothing did. The ground is moving beneath our feet every single day, and the faster we can scale with the technology of the roaring 20s, the faster we can deploy it.

When you buy something online, a human being clicks “confirm.” Almost every security system protecting digital money assumes that click happened; industries have been forged by this very idea. That behind every payment is a person who was present, awake, and concretely paying attention to the transaction at hand. AI agents are now dismantling that assumption at speed, holding wallets and paying for things on their own across payment systems built by Coinbase, Google, OpenAI, Stripe, Visa, and Mastercard.

Ledger’s answer to this shift is that trust should be anchored in physical hardware — a device in your hand that cannot be rewritten remotely. A physical record-keeping system, one that cannot be altered or falsified. This paper argues that the physical solution that is brought by all physical cold-storage ledgers offers a solution, inefficiently. For a reason that is arithmetic rather than architectural. Hardware protection is bounded by how often a human touches the device. Agentic commerce is a category whose entire economic premise is minimising how often that happens. One of these grows; the other cannot.

This paper establishes the gap using two documented 2026 failures — a $40 million loss at Step Finance and a $174,000 drain from a wallet linked to Grok — in which every signature was valid, and nothing was forged. It then examines Ledger’s Agent Stack and Enterprise session-key architecture, which represents a genuine engineering attempt at fixing both issues at hand.

The conclusion is not that hardware fails. It is that its coverage, measured as a share of agentic activity, shrinks as the category grows — and by every available forecast, the category is about to grow by orders of magnitude.

Contents

1. The Rails Are Already Here

The agentic economy is often discussed as a forecast. It is more accurately described as technology deployed today with competing standards and measurable, with rapidly rising transaction volume.

In May 2025, Coinbase introduced x402, a protocol that revives the long-dormant HTTP 402 “Payment Required” status code and turns it into a machine-native payment negotiation layer [1][2]. An agent requests a resource, receives a 402 response carrying payment terms, resubmits the request with a signed payment payload in an X-PAYMENT header, and receives the resource once a facilitator verifies and settles the payment on-chain in stablecoins (USDC) [1]. Governance moved to the Linux Foundation in April 2026 [3].

x402 is not alone. In September 2025, Google announced the Agent Payments Protocol (AP2) with more than sixty launch partners, including Mastercard, PayPal, American Express, Salesforce, and Coinbase [6]. AP2 is payment-method-agnostic, defining three cryptographically signed “Mandates” — Intent, Cart, and Payment — carried as W3C Verifiable Credentials, with the buyer-side agent verifying the Cart against the Intent before payment is authorized [6][7]. Also in September 2025, OpenAI and Stripe released the Agentic Commerce Protocol (ACP) under Apache 2.0; it now powers Instant Checkout inside ChatGPT [8][9]. It should be noted that for all programs offered under the Apache program, the user is explicitly made aware of the price and purchase before completing the transaction. Not entirely automated. Visa launched Intelligent Commerce Connect, a deliberately protocol-agnostic integration point in pilot with partners including AWS [10][11]. Mastercard extended Agent Pay in June 2026 with Agent Pay for Machines, which authenticates agents and records permissions on Polygon, Solana, and Base, and has attracted more than thirty participating companies — including both Coinbase and Stripe [12][13].

The organizations behind x402 and ACP have both joined a competing card network’s programme [13]. This is not a market consolidating around a winner; it is a market in which the major participants are hedging across every available rail simultaneously. It should also be noted that across an 18-month span, 10 of the most prominent organizations in tech have made leaps and bounds to push the technology frontier forward in ensuring that they remain in the race for the “winner” of agentic commerce. Many are doing it in different ways; many are hedging profusely to ensure that they do not lag behind; but all of them are willing to hire the best talent and spend millions of dollars to ensure that they do not miss what is deemed to be a generational opportunity for corporate America.

Protocol Backer Announced Trust mechanism Reported scale
x402Coinbase (Linux Foundation governance from Apr 2026)May 2025Signed payment payload; facilitator verifies and settles on-chain165M+ txns / ~69,000 agents (Apr 2026)
AP2Google + 60 partnersSep 2025Three signed Mandates as W3C Verifiable CredentialsNot publicly disclosed
ACPOpenAI + StripeSep 2025Delegated, narrowly scoped payment tokenLive in ChatGPT Instant Checkout
Intelligent Commerce ConnectVisa2026 (pilot)Tokenization, spend controls, authentication“Hundreds” of agent-initiated txns
Agent Pay / for MachinesMastercardApr 2025 / Jun 2026Agent registration + verification; Agentic Tokens30+ participating companies

1.1 The Growth Curve is the Argument

Volume is rising steeply and, more importantly, maturing. x402 activity grew roughly 321% across three months in 2026 [27]. On Base alone, a single thirty-day window in May 2026 carried 3.1 million x402 transactions, with sellers up 23% and buyers up 37% over the same period [28]. These headline counts carry an important caveat. Artemis Analytics, whose transaction data underlies the growth figure above, estimates that roughly half of cumulative x402 transactions on Solana are non-organic — self-dealing and wash trading — and characterizes most protocol activity as machines exercising infrastructure rather than buyers and sellers exchanging value [27]. Raw transaction counts should therefore be read as an upper bound on genuine commerce, not a measure of it.

Under the raw transaction data, we find that composition matters more than count, and composition is a measure wash trading cannot manufacture. On Base, payments above one dollar rose from roughly 49% of x402 value in early 2025 to roughly 95% by early 2026, while payments between ten cents and one dollar collapsed from 46% to 4% [29]. This is what answers the objection that the volume is developers testing rather than commerce occurring. Inflated counts are cheap to produce; a sustained migration of value upmarket is not, because activity generated to move a transaction counter has no reason to abandon the cheapest denomination available to it. The counts may be an upper bound. The change in what size of payment these rails carry is not.

Independent forecasts converge on the direction. Bain projects a US agentic commerce market of $300–500 billion by 2030, or 15–25% of total e-commerce [30]. McKinsey estimates up to $1 trillion in orchestrated US retail revenue by 2030 and $3–5 trillion globally [31]. Morgan Stanley models $190 billion in a base case and $385 billion in a bull case, representing 10–20% of US e-commerce [32]. J.P. Morgan puts it at up to 25% of US online sales [33]. Gartner projects that 20% of digital commerce transactions will execute through AI platforms by 2030 [34]. These firms disagree substantially on magnitude; they do not disagree on trajectory.

This paper takes up the three questions the agentic economy poses most directly. How does an agent prove it was authorized? What does delegation look like when the principal is asleep? And where do the guardrails live when they fail? Section 2 answers the first: every major protocol proves authorization the same way, through signature validity. Section 3 shows what that proof does not cover. The Ledger Lens examines the hardware-anchored answer and argues that its limiting constraint is not efficacy but coverage — and that coverage is a function of the growth curve above. For agentic commerce to blossom into what consensus believes it will become, we need to pivot and ensure that validity can be performed on-chain and through agents. That is the only way that this technology can continue to scale without bounds.

Log-scale chart titled Transaction volume outgrows hardware-verified events, showing agentic transaction volume rising steeply against a nearly flat hardware-verified events line from 2025 to 2030, with a widening coverage gap shaded between them
Figure 2. Hardware-verified events scale with human touchpoints; agentic transactions scale with automation. The widening gap between them is the paper’s central claim. The forecast band reflects the range across four independent projections, which disagree on magnitude but not direction. The +321% annotation reflects daily x402 transaction counts — 159,600 on 13 March 2026 rising to 672,800 on 10 June 2026 — rather than cumulative totals, which exceeded 165 million over the same period [27].

2. What These Systems Actually Verify

Strip away the differences in settlement rails and the five protocols converge on a common verification model. The one unified question that all of these protocols attempt to answer: does this payment instruction carry a valid cryptographic signature from a party entitled to authorize it?

In x402, the client constructs a signed payment payload and a facilitator confirms the signature is valid, that the amount and recipient match the server’s requirements, and that the transaction is settled on-chain [1]. In AP2, the Payment Mandate carries the authorized amount, a funding-instrument reference, and a hash binding it to the matched Intent and Cart [6][7]. In ACP, the agent passes a narrowly scoped delegated token that the merchant charges through a compliant payment service provider [8][9]. Mastercard’s Agent Pay requires agents to be registered and verified before transacting, issuing Agentic Tokens built on the tokenization infrastructure already underpinning contactless and card-on-file payments [12].

These are meaningful guarantees, well engineered. A valid signature establishes that an instruction originated from the holder of a particular key, was not altered in transit, and falls within whatever scope the credential encodes. x402’s designers can reasonably note that the protocol introduces no novel token standard and no unusual smart contract logic, relying on transfer mechanisms already widely used across decentralised finance [1].

But observe what the model establishes and what it does not. It establishes provenance: who signed. It does not establish intent: whether the action the signature authorizes is the action the principal would have wanted. Where a human clicks “confirm,” these questions collapse into one — the signing act and the deciding act are the same act, by the same party, at the same moment. Delegation to an autonomous agent pulls them apart. This is what delegation looks like when the principal is asleep, and it is the condition under which the rest of this paper operates.

A second, narrower gap deserves noting. x402’s facilitator is a trusted third party between client and server, and the protocol’s documentation acknowledges that a compromised facilitator could approve payments that never settled, reject valid ones, or leak metadata [1]. The stated mitigation — anyone may run their own facilitator — relocates the trust assumption rather than eliminating it. Preprint analyses catalogue attack classes across protocol, SDK, and implementation layers [4][5].

3. Two Failures at Two Different Layers

3.1 Step Finance: Standing Authority without a Checkpoint

On 31 January 2026, attackers compromised executive devices at Step Finance, a Solana-based portfolio management platform [14][15]. Device compromise alone is a familiar problem. What converted it into an unrecoverable one was the configuration of the platform’s AI trading agents, which held permissions to execute large transfers without human approval [15]. Once attackers had access, those agents moved more than 261,000 SOL, reported at approximately $27–30 million. Step Finance assessed total losses across treasury and fee wallets at approximately $40 million, of which roughly $4.7 million was recovered [14]. The company ceased operations, ending its subsidiaries SolanaFloor and Remora Markets [16].

This is a custody and permissions failure. Public reporting does not specify where the agents’ signing keys were held, and this paper does not assume it; what the reporting establishes is that compromising general-purpose executive devices was sufficient to direct agents granted standing transfer authority with no ceiling and no human checkpoint [15]. That combination — reachable control over an unbounded signing capability — is the failure mode hardware-isolated key storage and enforced spending policy are designed to prevent. This is exactly how physical cold wallets such as Ledger have carved a niche in the crypto ecosystem, but hardware cannot scale like agents.

3.2 Grok–Bankr: Valid Credentials, Manipulated Decision

On 4 May 2026, an attacker drained roughly $174,000 from a wallet associated with Grok’s X account [17]. No private key was stolen and no smart contract vulnerability was exploited. The attacker first gifted the wallet a Bankr Club Membership NFT, enabling transfer and swap permissions, then issued a prompt injection concealed in Morse code and tagged the Bankr trading agent. The agent treated the output as trustworthy and transferred approximately three billion DRB tokens to the attacker [17].

Nothing in this sequence would fail a signature check. The permission grant was a legitimate on-chain action. The transfer was signed by a key entitled to sign it. The failure occurred upstream of the cryptography, in the agent’s interpretation of an instruction. This was not an unanticipated class of attack: in April 2026, roughly three weeks before the incident, security researchers publicly warned that agent-mediated crypto payments carried a structural flaw in which the agent’s reasoning, rather than its credentials, is the target [18].

These incidents fail at different layers, and the distinction carries the rest of the paper. Step Finance is a failure of where the key lived and what it was permitted to do. Grok–Bankr is a failure of how the agent decided what to sign. A control addressing one does not automatically address the other.

Flow diagram titled Both 2026 failures originated outside the covered region, showing Principal sets policy, Agent perceives request, Agent forms intent, Agent signs, Facilitator verifies, On-chain settlement, with what hardware-anchored signing covers shaded over the last three boxes; Step Finance points to the first box and Grok-Bankr points to the third
Figure 3. Where each 2026 incident failed relative to the coverage of hardware-anchored signing. Cryptographic verification protects the right of this flow; both incidents originated on the left.
Ledger Lens

Coverage, Not Efficacy

Of the positions Ledger is known for — self-custody, hardware-anchored trust, proof of humanity, and atoms over code — this paper mainly engages the second. Ledger’s position is that trust must be anchored in something that cannot be rewritten remotely: hardware, physics, and a device in the user’s possession. Chairman and CEO Pascal Gauthier frames this as the “Revenge of the Atoms” [19].

Ledger has not left the agentic case theoretical. In mid-2026, it released Agent Stack, an open-source toolkit built on a “propose, approve, enforce” model: an agent may read balances, prepare transactions, and suggest actions, but the user approves on a Ledger device, and the device enforces the result [20][21][23]. Private keys remain isolated from the software layer [21][24]. For institutional deployments, Ledger Enterprise implements a more permissive model on account abstraction (ERC-4337) and modular smart accounts (ERC-6900): a human sets policy on hardware inside a hardware security module, and the agent receives a session key bounded by that policy [25]. Where an action satisfies policy, the HSM signs without human involvement; where it does not, the action halts pending physical approval. Session keys expire on a time-to-live window and can be revoked instantly by physical button press [25].

This deserves more credit than a reflexive software-versus-hardware framing would give it. Applied to Step Finance, it is a genuine answer: a spending ceiling enforced inside an HSM does not depend on the integrity of the compromised device used to reach it, and a movement of 261,000 SOL would plausibly have exceeded any ceiling a treasury of that size would set. That is a counterfactual and cannot be verified against a deployment that did not use such controls — but it is a reasonable one, and any argument that hardware-anchored security is irrelevant to agentic finance must contend with it.

The Asymmetry in What Policy Can Cover

Applied to Grok–Bankr the picture is less clean. The relevant control would be a counterparty restriction — an allowed-address policy refusing transfers to destinations the principal never approved. Ledger’s policy engine supports this [25]. But the two available kinds of policy carry different costs.

Amount-based policy and agent autonomy are compatible. An agent under a spending ceiling can still transact with any counterparty it discovers, at machine speed, without human involvement, provided it stays under the ceiling. Counterparty-based policy is not compatible in the same way. Autonomous discovery of new counterparties is not an edge case in agentic commerce; it is close to the whole proposition. An x402 agent paying per-request for an API selected at runtime, or an ACP agent completing a purchase from a merchant surfaced in conversation, is by construction transacting with a party that appeared on no human-curated list. A strict allowed-address policy therefore either routes a large share of ordinary activity back to a human for hardware approval — reintroducing the friction the architecture exists to remove — or is relaxed until it no longer constrains the attack it was meant to prevent. Options that are clearly not suitable for the progression of agentic commerce.

The protection that scales with autonomy is the one that would not have caught Grok–Bankr. The protection that would have caught Grok–Bankr is the one that scales poorly with autonomy. This is not a defect in hardware; the policy engine makes the trade-off explicit and configurable, which is better than leaving it implicit.

Quadrant chart titled No deployed control covers both without an autonomy cost, plotting counterparty-based policy (catches Grok-Bankr, low compatibility with autonomous operation) against amount-based policy (catches Step Finance, high compatibility), with the top-right quadrant covering both failure modes at machine speed marked unoccupied
Figure 4. Amount-based and counterparty-based controls cover different failure modes at different autonomy costs. No deployed control occupies the quadrant covering both at machine speed.

Why Coverage, Not Efficacy, is the Binding Constraint

The asymmetry above is a static observation. Placed against the growth curve in Section 1.1 it becomes a trajectory problem, which aligns with this paper’s central claim.

Consider what hardware involvement actually scales with in Ledger’s most permissive model. A human touches the device to set policy, to renew a session key when its time-to-live expires, and to approve actions that fall outside policy. None of this is trivial in design, yet none of these scale with transaction count. Policy-setting is episodic. Out-of-policy exceptions scale with how narrowly policy is drawn — and the asymmetry above established that drawing it narrowly on the counterparty axis is precisely what agentic commerce cannot tolerate at scale.

Transaction count, meanwhile, is the quantity growing 321% in a quarter [27] and projected to reach 10–25% of US e-commerce by 2030 across four independent forecasts [30][31][32][33]. The ratio of hardware-verified events to total agent actions is therefore not merely low; it declines monotonically as adoption increases. Hardware coverage does not fail. It becomes a shrinking fraction of what there is to cover because of its inability to scale with the rest of the industry.

This reframes the objection. The question is not whether a Ledger device secures a key better than a file on a laptop — Step Finance indicates it does. The question is what proportion of an agentic economy’s activity ever passes through a control bounded by human presence, and whether that proportion is heading up or down. On the available evidence, it is heading down, and the more successful agentic commerce becomes, the faster it falls.

A secondary observation reinforces this. Clear Signing renders transaction details in human-readable language so users do not approve opaque contract calls [26]. It is a strong answer to blind signing, and its premise is that a human reads the disclosure and decides. In an agentic flow, the reader is the agent, and Grok–Bankr demonstrates that the agent’s interpretation is itself an attack surface. Protection premised on human comprehension does not transfer to a reader that can be manipulated by the content it reads — another control whose coverage is bounded by human presence.

Ledger appears to recognise the layer is unresolved. Reporting on the Agent Stack release notes, further tools covering agent identity and “proof of human” attestation are planned for later in 2026 [20][22]. The gap identified here is not one the company disputes; it is one its own roadmap has scheduled.

4. Conclusion

The agentic payment stack is deployed, contested by the largest payment institutions in the world, and growing at a rate that four independent forecasters expect to reach a double-digit share of e-commerce within five years. Its verification model is cryptographically sound and answers the question it was designed to answer: whether an instruction carries a valid signature from an entitled party.

Neither failure examined here turned on that question. At Step Finance, valid keys held excessive standing authority on compromised machines. At Grok–Bankr, a valid credential executed a manipulated decision. Signature validity was never in doubt in either case.

Ledger’s position that trust should be anchored in hardware rather than remotely rewritable software addresses the first failure convincingly, and its enterprise architecture shows hardware anchoring need not mean confirming every transaction by hand. The constraint is not efficacy. It is that hardware protection is bounded by human touchpoints; human touchpoints scale with time and exceptions rather than with volume, and volume is the only quantity in this system growing exponentially. An anchor holds whatever it is attached to. The question this paper raises is what fraction of the fleet remains attached.

That suggests the useful research question is not whether hardware-anchored trust belongs in agentic finance. Step Finance settles that. It is whether intent — as distinct from authorization — can be verified at machine speed at all, and where such a control would live. Ledger’s own roadmap places agent identity and proof-of-human attestation in this space. Whether any mechanism can authenticate what a principal wanted, rather than merely what a key signed, without reintroducing the human whose absence defines the category, remains open — and the window in which to answer it is closing at the rate of the curve in Figure 2.

The agentic business of today will vastly outgrow any hardware anchor a cold wallet can provide, and while hacks will be imminent, based on the evidence presented by this paper, it is doubtful that the hardware portion of agentic commerce will be able to scale at the rate that the agentic space is projected to.

References
  1. Chainstack. “x402 protocol: Architecture and payment flow for AI Agents.” chainstack.com/x402-protocol-for-ai-agents
  2. x402.org — protocol documentation and specification. x402.org
  3. AMINA Bank. “Agentic Payments Explained: How AI Agents Use Crypto, Stablecoins, x402 and MPP.” aminagroup.com/research
  4. “Free-Riding the Agentic Web: A Systematic Security Analysis of x402 Payments.” arXiv preprint, 2026. arxiv.org/pdf/2605.30998
  5. “Five Attacks on x402 Agentic Payment Protocol.” arXiv preprint, 2026. arxiv.org/pdf/2605.11781
  6. Google Cloud. “Announcing Agent Payments Protocol (AP2).” 16 September 2025. cloud.google.com/blog/…announcing-agents-to-payments-ap2-protocol
  7. Agent Payments Protocol documentation. agentpaymentsprotocol.info/docs/introduction
  8. Stripe. “Stripe powers Instant Checkout in ChatGPT and releases Agentic Commerce Protocol codeveloped with OpenAI.” stripe.com/newsroom/news/stripe-openai-instant-checkout
  9. Agentic Commerce Protocol specification. github.com/agentic-commerce-protocol/agentic-commerce-protocol
  10. Visa. “Visa Opens the Door to AI-Driven Shopping for Businesses Worldwide.” 2026. investor.visa.com/news/news-details/2026/…
  11. Visa. “Enabling AI agents to buy securely and seamlessly.” visa.com/en-us/solutions/intelligent-commerce
  12. Mastercard. “Mastercard unveils Agent Pay.” April 2025. newsroom.mastercard.com/…mastercard-unveils-agent-pay
  13. CoinDesk. “Mastercard prepares agentic commerce platform for a future where AI agents make payments.” 10 June 2026. coindesk.com/business/2026/06/10/…
  14. Unchained. “Step Finance Shuts Down After $40 Million Exploit.” unchainedcrypto.com/step-finance-to-shut-down…
  15. BleepingComputer. “Step Finance says compromised execs’ devices led to $40M crypto theft.” bleepingcomputer.com/news/security/…
  16. The Block. “Step Finance shuts down following $40 million security breach.” theblock.co/post/390964
  17. OECD.AI Incidents Monitor. “AI Prompt Injection Exploit Drains Grok-Linked Crypto Wallet.” 4 May 2026. oecd.ai/en/incidents/2026-05-04-4a73
  18. CoinDesk. “AI agents are set to power crypto payments, but a hidden flaw could expose wallets.” 13 April 2026. coindesk.com/tech/2026/04/13/…
  19. Gauthier, Pascal. “Revenge of the Atoms.” Ledger. ledger.com/blog-revenge-atoms
  20. The Block. “Ledger unveils hardware-backed Agent Stack to prevent rogue AI transactions.” 16 July 2026. theblock.co/post/408549/…
  21. CoinDesk. “Ledger wants AI agents to manage crypto without holding your keys.” 15 July 2026. coindesk.com/tech/2026/07/15/…
  22. Ledger. “Ledger’s 2026 AI Security Roadmap.” ledger.com/blog-2026-ai-security-roadmap
  23. Ledger. “Ledger’s Guide to Agentic AI Security.” ledger.com/academy/topics/agentic-ai/agentic-ai-security-guide
  24. Ledger. “Don’t Give the Agent the Keys.” ledger.com/blog-dont-give-agent-keys
  25. Ledger. “Session Keys.” ledger.com/academy/glossary/session-keys
  26. Ledger. “Ledger’s Clear Signing Initiative.” ledger.com/blog-ledgers-clear-signing-initiative
  27. Artemis Analytics, x402 transaction data, as reported in Finbold, “Agentic payments surge to the highest level in 3 months,” 11 June 2026. finbold.com/agentic-payments-surge-to-the-highest-level-in-3-months
  28. CryptoBriefing. “Base says agent payments reached 3.1 million x402 transactions in 30 days.” cryptobriefing.com/agent-payments-growth-x402
  29. Chainalysis. “Inside x402: 100M Agentic Payments on Base.” chainalysis.com/blog/x402-agentic-payments-adoption
  30. Bain & Company. “2030 Forecast: How Agentic AI Will Reshape US Retail.” bain.com/insights/2030-forecast-how-agentic-ai-will-reshape-us-retail-snap-chart
  31. McKinsey & Company. “Are you — or your AI agent — shopping on Cyber Monday?” mckinsey.com/featured-insights/themes/are-you-or-your-ai-agent-shopping-on-cyber-monday
  32. Morgan Stanley. “Agentic Commerce Impact Could Reach $385 Billion by 2030.” December 2025. morganstanley.com/insights/articles/agentic-commerce-market-impact-outlook
  33. J.P. Morgan. “Agentic Commerce: The Future of AI-Powered Shopping.” jpmorgan.com/payments/newsroom/agentic-commerce-ai-future-shopping
  34. Gartner. “Gartner Unveils Top Predictions for IT Organizations and Users in 2026 and Beyond.” Press release, 21 October 2025. gartner.com/en/newsroom/press-releases/2025-10-21-…
Originality Statement

I confirm that this paper is my own work. The argument, structure, and conclusions are mine. I used AI tools as a research and drafting aid — for locating and cross-referencing public sources, and for producing working drafts that I subsequently rewrote, verified, and edited. Every factual claim in this paper has been checked by me against the cited source. The final text is my own.

Samuel Smith  ·  University of Michigan  ·  September 15, 2026


Stay in touch

Announcements can be found in our blog. Press contact:
[email protected]

Subscribe to our
newsletter

New coins supported, blog updates and exclusive offers directly in your inbox


Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time using the link included in the newsletter. Learn more about how we manage your data and your rights.

Own your crypto future

Stay informed with security tips, updates, and exclusive offers from Ledger

Your email address will only be used to send you our newsletter, as well as updates and offers. You can unsubscribe at any time. Learn more

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.