The core issue: the agent had the master key. Session keys fix this at the account level: the agent gets a scoped credential (spending cap, expiry, function restrictions) that is enforced onchain If it leaks, you revoke it. Damage is bounded by the cap, not the whole treasury We've implemented this for Starknet agents (ERC-8004 + account abstraction): github.com/keep-starknet-stran...… Would be happy to chat about the design if useful cc @austingriffith who has raised this issue before

From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments