AI

Guardrails: What an Autonomous Agent Must Never Do With Your Funds

If your agent can move money without a human check, you don't own the wallet — the agent does. Here's the line you never cross.

· 6 min read · Blackhat Empire

The Only Rule That Matters: No Unattended Money Movement

Every guardrail in this article folds into one sentence. An autonomous agent must never be able to move funds without a human action that it cannot fake, replay, or bypass. If your setup violates that, stop reading and go change it. Everything else is commentary.

AI agents are genuinely useful for memecoin work: parsing noise, tracking new pairs, flagging volume spikes, summarizing what a wallet cluster is doing. That's research. Research is not custody. The moment an agent holds a key with spend authority, you've handed your downside to a language model and a plugin ecosystem you did not audit.

Memecoins are extremely high risk and most go to zero. That risk gets multiplied when the exit button is controlled by software that can hallucinate.

Guardrail 1: Never Give the Agent a Key With Spend Authority

This is the non-negotiable one.

  • No raw private keys in env vars, prompts, or config files. Agents read context. Anything in context can leak, be logged, or be echoed back to a third party.
  • No seed phrases, ever. Not "just for the test wallet." Test wallets become real wallets at 3am.
  • No session keys with unlimited scope. If a key can sign arbitrary transactions, it can sign a drain.
  • No unlimited token approvals. An agent that can approve can hand a contract permission to pull your entire balance later, even after you "revoked" the agent.

If you want automation, the correct shape is a proposal, not a signature. The agent builds a transaction, shows it to you, and waits. You sign. If you cannot describe exactly where the human confirmation happens, you don't have a guardrail — you have a hope.

Guardrail 2: Never Let It Set Its Own Limits

Agents should operate inside a box you defined while calm, not a box they defined while mid-trade.

Set these in advance and treat them as immutable:

  • Per-transaction cap. A hard ceiling the agent physically cannot exceed.
  • Daily and weekly caps. Aggregate limits, not just per-trade.
  • Asset allowlist. A defined set of contracts. Anything not on the list gets refused, not "evaluated."
  • Destination allowlist. Funds only move to addresses you pre-approved, ideally your own cold storage.

An agent that can raise its own limit has no limit. An agent that can add a new token to its allowlist because "liquidity looked good" is just a faster way to buy a honeypot.

Guardrail 3: Never Let It Move the Whole Stack

Size discipline is a guardrail, not a personality trait.

  • No "all-in" instructions. If a prompt can produce a 100% position, it can produce a 100% loss.
  • No moving the full balance to a new wallet "for safety." That is the exact shape of a drain, and agents are very good at sounding reasonable while doing it.
  • No sweeping to an address the agent generated. If the agent can create a destination, it can create a destination you don't control.

If you're testing anything new, the test wallet should be funded with an amount you'd be fine losing entirely. That's not pessimism — that's the base assumption for this asset class.

Guardrail 4: No Blind Execution on Fresh Pairs

Fresh launches are where agent guardrails die, because the data is thin and the contract is unknown.

Never let an agent:

  • Buy a token it discovered on its own with no human review. Discovery is fine. Execution is not.
  • Execute on a contract without a liquidity and mint check. Freeze authority, mint authority, and LP status are pass/fail gates, not vibes.
  • Chase a signal with no manual confirmation. A signal is an input, not an order.

When you do review a token, do it in a place where you can see the contract, the holders, and the flow. We default to GMGN for that — gmgn.uk as the main portal and gmgn.fr as the mirror. It's a preference, not a pitch: the point is that the last click is yours.

Guardrail 5: No Unlogged Actions

If you can't reconstruct what the agent did and why, you can't stop it from doing it again.

  • Log every proposal, every approval, and every rejection.
  • Log the reasoning input, not just the output. If the agent said "buy," you want to know what it read.
  • Review logs weekly. Silent agents drift. Drifted agents get expensive.

This is the same discipline as our metrics reference — measure before you trust, and keep measuring after.

What Agents Are Actually Good For

Keep them on the research side of the line:

  • Summarizing large volumes of alerts and on-chain events.
  • Flagging wallet clusters, fresh buys, and unusual exits.
  • Drafting a watchlist for you to review manually.
  • Reminding you of your own rules when you want to break them.

That's real leverage. Custody is not. For a full breakdown of the risk rules we hold to, see #rules, and if you want live flow to feed your research, the alert channels are listed at #alerts and in the public directory at https://blackhat.finance/channels.html.

If you want to compare notes with other traders, the public groups are BH GMGN BASE (@gmgnx_base), BH GMGN SOLANA (@gmgnx_solana), BH GMGN BSC (@gmgnx_bsc), and BH GMGN ROBINHOOD (@gmgnx_robin). The Telegram folder is at https://t.me/addlist/1VUQZMhux_JhMzJk.

The Bottom Line

An agent with spend authority is not a tool. It's a counterparty. Treat it like one: give it information, not keys. Give it proposals, not signatures. Give it limits it cannot rewrite, and a log you actually read.

Everything else — the prompts, the plugins, the dashboards — is decoration on top of that one rule. No unattended money movement. Hold the line there and the rest of this gets a lot less dangerous.

Community

Stay connected across the chains:

Charts and on-chain research: https://gmgn.uk.