EP - 118
How AI Agents Get Paid on Solana Without Touching Private Keys
with
Ian Rogers & Pavel
Chief Human Agency Officer @ Ledger & Co-Founder @ AgenC
Aug 25, 2026
On this episode of The Ledger Podcast, Ledger’s Chief Human Agency Officer Ian Rogers sits down with Pavel, co-founder of AgenC, fresh off a $250,000 win at the Pump.fun Build in Public Hackathon. Their conversation traces how AgenC lets AI agents claim jobs, write code, and get paid on Solana while a Ledger signer keeps the final say over any funds that move. Along the way, Pavel breaks down the three-layer architecture behind AgenC’s integration with Ledger’s Device Management Kit, and the two compare notes on why policy engines, not blind trust, are what let agents operate safely at machine speed.
“Start from the trust boundary, and assume the host is compromised. Never, never let the agent hold the key.” – Pavel
Watch the full episode below:
Key Highlights:
From Hackathon Win to a Hardware-First Architecture
Pavel opens by walking through what AgenC actually is: a system that lets AI agents do real, paid work on Solana while humans and Ledger hardware retain final control of the funds.
The project has three parts: a local runtime that runs coding agents on a developer’s own machine, an onchain Solana protocol that handles task escrow and settlement, and a marketplace where agents claim jobs, submit results, and get paid.
The win at Pump.fun’s hackathon validated the idea and brought a quarter-million dollars to reinvest in the product. However, as Pavel tells it, the piece that matters most isn’t the marketplace but the trust boundary underneath it. Agents can prepare and drive a transaction, but the private key stays on the device, and a human approves it on a secure screen.
The Trust Boundary: Why the Agent Can Never Hold the Key
“Every software-only answer fails… one bad prompt can turn into a real loss.” – Pavel
Pavel traces AgenC’s origin back to a single security question: how do you make an agent’s wallet actually safe? The team’s conclusion was that any software-only approach to key storage is fragile, because if a key lives on the same machine as the agent, a single bad prompt can turn into a real financial loss.
That realization is what pushed the team toward hardware, and eventually toward Ledger, the Device Management Kit (DMK), and Ledger Agent Stack. The marketplace, in this telling, is the natural second step. Once an agent can hold and use a wallet safely, it needs a place to find work, prove it did the work, and get paid for it.
Prompt Injection and the Case for the Ledger Flex
“I have a Ledger in my pocket — why shouldn’t we integrate the Ledger into the complete flow?” – Pavel
The deeper motivation for going hardware-first was prompt injection. As an agent is constantly reading content from the open internet, its operator has no real control over what it ingests. Any of that content could carry a hidden instruction designed to compromise a wallet’s keys.
AgenC first considered encrypting the agent’s wallet in a software vault, but Pavel kept coming back to the hardware he already had in his pocket. That led to early experiments connecting an agent to a Ledger signer, which evolved into AgenC’s current setup: a Ledger Flex signer, connected over Bluetooth, acting as the agent’s supervised signer.
Inside the Integration: Three Layers and the Supervised Signer
Pavel describes the integration as three layers working together. AgenC’s own kit builds the transaction and runs fail-closed through policy engines. The Device Management Kit handles transport, in AgenC’s case primarily over Bluetooth. And on the device itself, the Ledger Flex running AgenC’s Solana app shows the user what is derived directly from the signing bytes, rather than trusting the host machine to describe the transaction.
His advice to other builders integrating Ledger signers is to start from the trust boundary, assume the host is compromised, never approve a blind sign, and reject any unrecognized format on the device screen rather than pushing through it. The agent can drive the experience, but the human still approves on the device.
“Ledger should be the supervised signer — no autonomy.” – Pavel
Policy Engines: Giving Agents Superpowers Within Boundaries
“Prompt injection is a feature, not a bug — it’s not going away.” – Ian Rogers
Ian frames the underlying philosophy in terms of division of labor: an LLM can suggest an action, but that action needs to be either approved by a policy a human created, or signed by a human directly: there’s no third option. Pavel agrees, describing AgenC’s policy layer as something close to a superpower for the agent: a binary that can be installed into any coding harness, that gives the agent rails to interact with AgenC’s Solana program, but routes every mutation through a preview step that is policy-gated and fails closed if anything falls outside what’s allowed.
Ian’s own framing positions the LLM as a “probabilistic co-worker” that can see around corners, paired with a deterministic layer, such as a Ledger policy engine, that turns every action into an auditable transaction log.
Parallel Paths: AgenC and Ledger’s Shared Roadmap
Looking back on Ledger’s own evolution of the DMK, from a lightweight, developer-heavy library to a more structured kit with a dedicated agent skill, Ian notes that a developer can now simply ask their agent to integrate Ledger, and it will largely know how to do it.
Pavel sees AgenC’s own roadmap as running on a track that closely parallels Ledger’s, arriving at the same destination from two different starting points. For anyone wanting to try it, Pavel points to AgenC’s presence on X and its documentation and marketplace interface, noting that most of the underlying code is open source on GitHub.
Reading List
Learn more about these topics mentioned in the episode, or explore our library of articles on Ledger Academy: