Video wird geladen...
Video konnte nicht geladen werden
Unlimited agent access is a security problem. Scoped credentials are the fix. James Lawton, Head of DevRel at Polygon, on onchain mandates that cap what an agent can spend, where, and for how long, issued by banks and fintechs, and verified cryptographically to block prompt injection and other attacks.... show more
11,218 Aufrufe • vor 22 Tagen •via X (Twitter)
9 Kommentare

@jameslawton @0xPolygon Time, spend, and destination limits are the right defaults for agent credentials.

@jameslawton @0xPolygon Scoped credentials turn agent autonomy into a bounded financial and operational capability.

@jameslawton @0xPolygon lol imagine giving an AI unlimited access to your finances and just hoping it behaves 💀 scoped credentials really said not today

@jameslawton @0xPolygon Scoped credentials help, but they don't block prompt injection — that's two layers. A spend cap limits blast radius; it doesn't stop the injection. An injected agent still spends within its cap, on the attacker's target. Scoping bounds the damage. It can't prevent the hijack.

@jameslawton @0xPolygon the last line hits different. you dont have to trust the reasoning if you can verify the limits. thats such a clean way to think about agent security

Verify the limits rather than trust the reasoning is the right frame, and cryptographic mandates are a strong version of it. Worth naming the layer underneath too. Spend caps stop the expensive failure. The quieter one is an agent with read access wide enough to pull data it should never have seen, which costs nothing and trips no limit. So scope both directions: what it can spend, and what it can see. The second is usually the one nobody wrote down.

@jameslawton @0xPolygon 🍿

@jameslawton @0xPolygon onchain mandates verified cryptographically is wild to me in the best way. prompt injection has been such a headache and this feels like a real path forward

@jameslawton @0xPolygon so basically the bank issues the mandate and the agent cant go outside those bounds no matter what it thinks is right? that actually makes a lot of sense for fintech use cases

