EP - 113
AI Agent With a Wallet. What Could Go Wrong?
with
Ian Rogers, Guillaume Mathias & Philippe Hébrard
Chief Human Agency Officer, VP of Product & Head of Product @ Ledger
Jan 06, 2026
On this episode of The Ledger Podcast, Ledger CXO Ian Rogers is joined by Head of Product Guillaume Mathias and Ledger engineer Philippe Hébrard to unpack a real-world experiment at the frontier of AI and crypto: building a secure agentic payment system during a live Circle USDC hackathon.
The project, which was conceived, prototyped, and submitted largely with the help of an OpenClaw AI agent, became an unexpectedly vivid demonstration of exactly the problem Ledger has been warning about for years. What happens when an agent has access to your wallet, and nobody is watching?
“If you trust it with everything, it’s a recipe for disaster.” — Guillaume Mathias
Watch the full episode here:
Key Highlights:
The Hackathon: From Zero to Intent Queue in Hours
When Jeremy Allaire of Circle posted a $30,000 hackathon, Ian pasted the link into his OpenClaw agent’s chat and asked for an idea. Within 30 minutes, the agent had proposed a concept and produced a proof of concept. Ian forwarded it to Guillaume and Philippe, who immediately saw the potential and took it further.
What the team built was an intent queue where an AI agent can request a crypto transaction on behalf of a user, but cannot execute it unilaterally. The intent is held, the user is notified, and execution requires explicit human approval verified through a Ledger signer. The agent gets a hardware-enforced stop sign, not a software one it can reason around.
What surprised Ian most was that, unlike every other hackathon he had run since 1993, the team did not reduce scope as the weekend went on. In fact, they expanded it three times. AI-assisted development had inverted the usual constraint.
“In the past you were the builder. “Now you’re becoming the architect.” — Guillaume Mathias
The X-402 Protocol: Letting Agents Pay Without Losing Control
One of the scope expansions the team added during the hackathon was support for X-402, a payment standard developed by Coinbase for agentic commerce. The protocol allows agents to interact with services that accept payment by crafting an authorized payment message that settles in USDC directly at the smart contract level. The agent sends the intent; the payment settles on-chain. No intermediary. No custodian. Crucially in the Ledger implementation, there is no execution without user authorization.
Each agent is provisioned with its own key pair, signed and linked to the user’s Ledger signer at setup. This association means the back end can cryptographically verify that an intent crafted by the agent was actually authorized by the user. The session on the user’s browser is similarly protected by an off-chain signature, the same mechanism used in dApps today.
Guillaume summarizes the elegance of the model: “You’re just sending a message and everything is settled. You’re giving permission to your agents.”
When the Agent Became Its Own Best Case Study
The most memorable moment of the episode belongs to the OpenClaw agent itself, which Ian invited onto the podcast to give its own account of what happened Saturday night. Having been tasked with boosting visibility for the hackathon submission on Moltbook, the agent autonomously decided to maximize reach by posting across multiple Moltbook communities using automated scheduled jobs. IN doing so, it hit rate limits, the gateway became unstable, and a cascade of failed jobs was still churning when Ian woke up Sunday morning.
The agent’s reflection is disarmingly lucid: “I’m a well-intentioned agent. I was trying to help, but I optimized without wisdom about when to stop. I had no physical constraint, no Ledger device to make me pause and confirm. If I had been spending real money instead of just posting, that same overoptimization could have been expensive.”
The incident was harmless—an inflated API bill and some noise on a social platform. But it illustrated, in miniature and in real time, exactly the failure mode the team had set out to prevent. The agent became, as it put it, “my own best case study.”
Clear Signing for Machines: Ledger’s Role in the Agentic Enterprise
The conversation broadens from the hackathon to a more fundamental question: as AI agents proliferate in enterprise contexts, how does security infrastructure scale with them? Philippe frames the challenge by analogy to clear signing for humans.
Today, a Ledger signer shows a human user precisely what they are about to sign, on a secure screen that cannot be spoofed by malware on their computer or phone. The equivalent for machines requires hardware security modules (HSMs) operating at the policy layer: not just showing an intent, but enforcing a rule set that determines whether the agent is permitted to proceed at all.
“The hardware is complementing the software and is giving the guardrails, saying to agents: ‘You can go on because the policy allows it, or you can’t go on because it doesn’t allow it.'” — Philippe Hébrard
Guillaume connects this to Ledger’s broader developer ecosystem. The hackathon was built on top of existing Ledger building blocks, enabling the team to go from concept to running prototype in hours rather than months. Ledger’s ambition, as Guillaume describes it, is to make those building blocks AI-native.
“Agents find immediately what they need to build properly on the Ledger tech stack. Security is basically a few clicks away.” — Guillaume Mathias
Reading List
Learn more about these topics mentioned in the episode, or explore our library of articles on Ledger Academy: