The issue of wallets is shifting from how to enable agents to act to how to authorize them with confidence.
On August 4, Cloudflare made a significant announcement by officially launching Cloudflare Wallets, preparing 'wallets' for AI agents.
With this, AI agents can now not only call APIs, read data, or execute code, but also possess independent Virtual Wallets, allowing them to purchase APIs, data, content, and computing services using stablecoins like USDC within preset budgets and permission limits.
Almost in the same week, another route accelerated.
On August 6, MetaMask also launched Agent Wallet, enabling agents to connect to on-chain wallets and perform operations such as swaps, perpetual contracts, prediction markets, and liquidity management within user-defined permission limits.
Although these two seem to belong to different products, they collectively fill a long-standing infrastructure gap for AI agents, which may be one of the most structurally significant changes worth long-term attention in the recent intersection of AI and Crypto.
Let’s first look at Cloudflare.
As we know, although the capabilities of agents and agent clusters have surged this year, they are still likely stuck in a very traditional process: finding services, visiting official websites, registering accounts, adding credit cards, purchasing packages, obtaining API keys, and only then can they truly start calling.
For humans, this process is merely cumbersome, but for software that hopes to autonomously complete tasks, any step involving login, registration, payment, or identity verification could force it to stop and seek human intervention.
In other words, while the 'brains' of agents have advanced rapidly in recent years, the payment infrastructure of the entire internet is still fundamentally designed around humans.
x402 aims to change this.
It reactivates the long-standing but rarely used '402 Payment Required' status code in HTTP, embedding payment requests directly into the most fundamental request-response process of the internet.
According to Coinbase's design for x402, when an agent requests a paid API, the server can directly inform it how much to pay, what assets to accept, and where to make the payment; after the agent completes the payment and requests again with the payment proof, the server verifies the payment result and returns the corresponding resource.
Thus, the original process of 'registering an account → binding a payment method → recharging or purchasing a package → obtaining an API key → calling the service' could potentially be compressed into 'initiating a request → receiving a payment request → paying → obtaining resources', where an account may not be necessary, a subscription may not be required, and there is no need to pre-purchase a monthly or yearly package just to call a few APIs.
This may seem like just a few steps removed, but it is very suitable for AI agents. Because what agents truly need in terms of payment is not to stop each time before a purchase to have the owner input a verification code, but a payment protocol that can be understood, automatically executed by the software, and accurately billed.
Stablecoins happen to provide such a settlement foundation.
Cloudflare's current x402 development documentation already supports machine-to-machine payments based on on-chain assets like USDC, allowing an agent to complete payments directly when requesting APIs, MCP Tools, or other digital resources, rather than first redirecting to a traditional payment page.
It even begins to change the way internet content is priced.
After all, the traditional internet usually offers only two choices: either free access or placing content behind a subscription wall, requiring a 'human' to register and become a paying member first. However, when facing agents, a new model may be more natural—no longer requiring them to subscribe to an entire service, but rather paying incrementally based on actual data consumption, API requests, computational load, or content pages.
This is also why Cloudflare Wallets are worth paying attention to.
For example, a research agent could have a budget of 10 USDC, comparing prices, speeds, and quality among dozens of data sources. If an API costs just a few cents, it can try it directly; if the results are unsatisfactory, it can continue searching for the next one without needing to return to the owner for approval for every few cents spent.
Interestingly, these limitations seem to bind the agent, but in reality, they provide it with greater autonomy.
If users must manually confirm every 0.01 USDC call, then the so-called 'autonomous agent' is still just a semi-automated tool. Only by clearly defining a sufficiently distinct budget boundary can humans maintain ultimate control outside the boundary, allowing agents to operate freely within it.
Thus, Cloudflare Wallets actually reflect a deeper change, namely that the default economic entities participating in transactions on the internet were primarily individuals and businesses.
And now, from identity and payment to pricing methods, part of the internet's infrastructure has begun to be seriously redesigned for another type of participant, which is AI, or the agents themselves.
If Cloudflare mainly addresses how agents 'buy things', then MetaMask Agent Wallet takes another step forward by allowing agents to 'directly use assets'.
It begins to attempt to let agents execute on-chain operations directly within user-defined permission limits, which is no longer the same as 'having AI analyze whether ETH is worth buying'.
In the past, the division of labor between humans and AI was roughly AI collecting information, analyzing problems, and making suggestions, while humans decided whether to execute based on those suggestions.
However, under the framework of Agent Wallet, a command may gradually evolve into 'if ETH drops to around 3000 USD, and Gas is below the average of the past 24 hours, then buy 0.2 ETH', which also means the user provides the goals, conditions, and permissions, while the subsequent continuous monitoring, condition judgment, transaction preparation, and even final execution can be partially delegated to the agent.
What is truly noteworthy about the so-called 'economic autonomy' of agents is precisely this layer.
It does not mean that agents truly own their own property, but rather that they begin to have an account, a disposable budget, and a set of economic permissions that can be actively invoked based on environmental changes. They can autonomously purchase external information and computing resources, and can also mobilize real assets to achieve goals within the rules defined by users.
This step seems logical, but it also connects AI errors directly to real economic losses for the first time.
If an AI that can only chat misunderstands a sentence, the result is usually just an incorrect answer; but when it has a wallet and execution authority, the same misunderstanding, prompt injection, or malicious tool invocation could immediately translate into an irreversible on-chain transaction.
This is also why we cannot simply hand a wallet with unlimited permissions to AI.
Users can set daily spending limits, allowed interacting protocols, and risk preferences in advance. Supported EVM transactions will also undergo transaction simulations, threat scans, and MEV Protection; if a transaction is identified as abnormal or exceeds the user's pre-set policy, the system will pause automatic execution and require human 2FA confirmation again.
Thus, a very important principle gradually becomes clear: economic autonomy does not equal unlimited authorization.
A truly usable agent is more like an employee with a company card and job permissions, rather than someone who takes the keys to the company safe. What it can buy, how much it can spend at once, how much it can spend in a day, what decisions it can make independently, and what matters must be re-approved should all be clearly defined before authorization occurs.
From this perspective, the core innovation of Agent Wallet is not just 'giving AI a wallet', but for the first time systematically addressing how humans can safely delegate economic permissions to software.
And when the issue progresses to this point, the wallet itself must also change.
For the past decade, the core proposition of crypto wallets has remained stable: how to securely manage private keys.
Regardless of how the wallet interface changes, the fundamental relationship behind it has not changed—humans initiate operations, humans check transactions, and humans ultimately confirm signatures; the most important responsibility of the wallet is to protect the private key that can determine asset ownership and complete final authorization.
However, with the addition of agents, an extra layer suddenly appears in this chain.
Many operations no longer require users to construct transactions one by one, but rather shift from 'humans directly operating assets' to 'humans first expressing goals, then delegating part of the execution authority to agents'. This means that the questions wallets need to answer in the future will extend into a whole new set of permission relationships:
From the perspective of ordinary users, the most important thing is undoubtedly how to ensure that these capable Agents are managed with genuine peace of mind.
This is also another layer of concern surrounding UI 3.0 and Agent Wallet. In contemplating the interaction of the next generation of wallets, an important change is that the user role is shifting from "Operator" to "Manager."
In the past, when users completed a transfer, they had to choose the network, input the address and amount, assess the Gas, and then gradually check and sign; in an intent-driven wallet, a user might only need to say, "Transfer 500 USDT to Frank," and the system can first convert natural language into structured Intent, identifying the recipient, amount, asset, network, and estimated fees, before returning the final confirmation result to the user.
However, reducing interaction steps does not mean that control boundaries can disappear. On the contrary, as more execution processes are automated by the system, those steps that no longer appear before the user must be constrained by a more explicit authorization mechanism.
In the product design concept of Agent Wallet, each Agent that gains execution permissions corresponds to an independent Agent account, with its Session Key generated and isolated in a Trusted Execution Environment (TEE), and the key does not leave the corresponding secure environment; at the same time, the Agent account must be bound to a clear Policy, including whitelists of allowed interaction protocols, single transaction limits, daily limits, operation frequency, and validity periods.
Thus, what the Agent gains is not a boundary-less wallet, but an execution account surrounded by policy fences.
In this relationship, users hold a higher level of control, allowing them to adjust Policies, pause or resume Agents, and revoke permissions to reclaim funds at any time. AI can assist in interpreting intents, planning paths, estimating costs, and highlighting risks, but Agents can only execute within the scope of Policies pre-authorized by the user; operations beyond the boundary must return to the user for confirmation.
More importantly, authorization should not be a leap from 0 to 100, but should gradually increase with trust.
An Agent that is just starting to be used can initially remain in the observation and analysis phase; as users gradually build trust, they can then allow it to provide suggestions and prepare transactions; further, the user confirms execution; only when the rules are sufficiently clear and risk boundaries can be controlled does it enter the realm of automated execution within the strategy.
From L0 observation, to L1 suggestions, L2 confirmation and execution, and finally to L3 autonomous execution within the strategy, this essentially corresponds to a progressive trust relationship.
The autonomy of the Agent is not inherently possessed by the system, but is granted step by step by the user.
This will also change the reasons users open their wallets in the future.
Today, when people enter their wallets, it usually means "I want to check my balance," "I want to make a transfer," or "I want to do a Swap;" but as more daily operations are taken over by Agents, users are more likely to be concerned about another matter when opening their wallets: "What has my Agent done recently, and is there anything I need to handle?"
Thus, the core interaction provided by the wallet may gradually shift from an operation panel to a management panel.
At this point, the role of the wallet is no longer just to store assets and initiate transactions; it resembles a layer of permission control situated between people and Agents.
This may also represent a significant change in the value proposition of wallets in the Agent era—from "safely managing your private keys" to "safely managing your assets and the Agents authorized to use those assets."
Looking at the long term, the economic autonomy granted to AI Agents may be one of the most structurally significant changes worth observing in this intersection of AI and Crypto.
As models become smarter and Agents utilize more tools, this fundamentally still occurs in the information world; however, when Agents possess accounts, budgets, and asset execution capabilities, they begin to actively participate in real economic activities for the first time.
Therefore, what truly determines whether Agents can enter real financial scenarios on a large scale may no longer just be whether they are "smart enough," but whether we can establish a permission system that matches their capabilities.
Because the other side of autonomy is always authorization, wallets in the Agent era may not simply disappear into the background; rather, they will assume an even more important role than today, which is to enable automation to truly occur while ensuring that ultimate control always returns to human hands.
After all, allowing Agents to operate freely does not equate to relinquishing control.
This boundary may be the core question that wallets need to address before "economic autonomy" truly becomes a reality.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























