Security
What's enforced on-chain
- An agent key can only call
AgentVault.execute. executeonly reaches an allowlisted Hartii contract (see Contracts).transfer/transferFromare forbidden on every token — an agent key cannot move assets out of the vault through any call it's allowed to make.approveis only allowed against a token this vault can actually trade, must carry zero QUAI value, and its spender must be the router or that token's own registered curve — an agent cannot disguise a payment as an approval.- Per-transaction and rolling-24h QUAI caps are enforced by the contract, not by the API, the MCP server, or the page.
- The owner can
pause,revoke, or withdraw everything at any time, independent of the agent.
What isn't guaranteed
- Caps limit blast radius, not loss. An agent can still lose everything within its caps — a bad trade, a buggy strategy, a launched token going to zero.
- The Agent API's builders and the MCP server's simulation reduce the chance of a failed or unintended transaction, but a simulation can still miss a revert that only happens under different chain state a block later.
- This is beta software. Start with low caps, and fund a vault with only what you can afford to lose.
The agent key must be ground in-zone
Quai Network is sharded into zones; a vault's agent key must resolve to a Cyprus-1 address,
the zone AgentVault deploys in. A plain random private key lands in Cyprus-1 only about 1 in 512
tries. The vault wizard grinds a fresh key client-side until quais.isQuaiAddress(address) and
quais.getZoneForAddress(address) === quais.Zone.Cyprus1 are both true, shows it to you once, and
never stores or transmits it. See MCP setup for the same requirement from the agent
runtime's side.
Revoking access
From hartiilabs.com/agent, "Revoke" clears the vault's agent address and pauses it in one on-chain transaction — the agent loses all ability to act immediately, independent of whatever MCP server or key it was using.
Reporting an issue
Treat a suspected vulnerability the same as any other Hartii contract issue — see the main FAQ for the current contact channel.