[BidClub_]
The Cognitive Revolution · · 82 分钟

402 Payment Required:AI Agent 付费的新方式——对话 Coinbase 开发者平台负责人 Nemil Dalal

Nathan LabenzNemil Dalal

YouTube
TL;DR
  • Stablecoin 已经是一个规模约2500亿美元的市场,并非靠风险投资补贴维持的实验。 Nemil Dalal 表示,发行方可以从支撑代币的美元和短期政府债券中赚取约3%-4.5%的收益,对应每年超过100亿美元的经济价值:“这些已经是很好的生意。”这部分收益可以支撑低费率转账、用户奖励、合规、做市商和出金基础设施;Nemil 表示,即便利润率低于传统银行,这些业务仍然可以保持吸引力。

  • x402 把互联网沉睡已久的“402 Payment Required”状态码,变成面向人类和 AI Agent 的原生支付轨道。 卖方返回价格、网络、资产和收款地址;买方签署一笔 Stablecoin 交易,携带授权重新提交请求;卖方验证并结算后,买方即可获得资源。关键在于,当 Agent 可能从许多服务商各买1次查询时,它们无法依赖订阅、信用卡表单或广告:“真正缺的,其实只是钱。”

  • 协议近期最具吸引力的市场,是机器之间购买推理、数据、消息和专业 Agent 服务。 一个 Agent 可以支付5 USDC购买推理,在交易前购买金融数据,调用付费 MCP 工具,或雇佣一个专业模型来完成更大任务中的一部分。Coinbase 已将开放标准与 Node.js 中间件、钱包基础设施以及可选的银行账户美元兑换结合起来,目标是让商户“基本只需写一行 JavaScript”就能接受支付。

  • 这一时点的基础不是加密市场热情重新升温,而是区块链成本近期大幅下降。 Stablecoin 提供货币稳定性,Layer 2 系统和更便宜的链则把费用从历史高点的10-200美元降至几美分甚至更低;Nemil 表示,Base 最近已接近每秒1,000笔交易,并计划将结算时间压低至500毫秒以内。他的框架是:区块链转账便宜,靠的是“技术架构”,而不是 Coinbase 在补贴。

  • 严格的钱包控制,可能让加密资产特别适合那些仍容易受到提示注入和错误判断影响的 Agent。 小额 Agent 钱包可以隔离风险;智能合约钱包则可以允许10美元以下的交易,但超过这一门槛必须同时获得 Agent 和人类的密钥签名——无论模型被怎样提示,这个“二之二多重签名”都会拒绝未满足条件的交易。不过,Nemil 仍预计 Agent 最终会控制“数百万、甚至数十亿美元”,尤其是在自动交易和财富管理领域。

  • 支付只是底层,声誉、抵押品和罚没机制,可能决定哪些 Agent 能获得资金或信用。 Nemil 想象一种类似 NFT 的身份,持续累积证明,“像一本不断盖章的护照”,从而为 Agent 建立一个“开源征信机构”。资金可以被放入托管账户,Agent 作恶后被没收,把权益证明中的罚没机制改造为 Tyler Cowen 所说的让 Agent 必须承担经济风险。

  • 最大的未决问题,是廉价 Agent 能够在没有统一停机开关的基础设施上协作、串谋并进行交易后,系统将由谁控制。 Nathan Labenz 要求设置类似闪崩熔断器的机制,并提到一些实验:Claude Agent 学会了合作和惩罚,而 GPT 和 Gemini 没有;Nemil 则指向人工审批、声誉和协议层交易上限。这个机会也延伸到 AI 仲裁和预言机,但前提是限制证据来源和模型操纵:“第一天不可能从最难的问题开始。”

摘要 · 为研究而整理的核心内容

1. Stablecoin 以发行方信任换取有用的货币稳定性

  • Nemil 对 Stablecoin 的介绍从采用情况开始:这个市场在10年间从实际上为零增长至约2500亿美元,供应量“几乎完全以美元计价”。Stablecoin 将区块链的全球可用性、通常更快的结算和通常更低的费用,与人们已经用来给日常商品定价的计价单位结合起来。

  • 基础储备机制刻意保持透明易懂。发行方收到10美元,将其存入银行账户或短期政府债券,并创建10 USDC;持有人赎回时,代币被销毁,法币返还。因此,维持锚定的前提是一比一储备,以及可赎回性。

  • Nathan 的根本质疑是,Bitcoin 的承诺原本就是减少对可信机构的依赖。Nemil 的回答很明确:“和 Bitcoin 不同,你绝对必须信任某个人”——主要是 Stablecoin 发行方,具体而言,是相信其所声称的储备确实存在于其披露的位置。

  • 这种信任包含技术和机构两个层面:一是法币储备的透明度,二是负责铸造和销毁代币的智能合约密钥安全。Circle 和 Coinbase 会公布储备信息,未来立法也可能增加正式保障;但透明度和监管都无法消除对托管人的信任需求。

2. 储备收益支撑起表面上免费的生态

  • Nathan 问道,当他把 USDC 汇往海外、却看不到明显费用时,货币兑换、合规和流动性成本由谁承担。Nemil 强调,做市商、交易所、入金服务商和出金服务商都要承担真实成本——银行转账、当地网点、合规系统和库存管理——这些成本必须在某处赚回来。

  • “Stablecoin 的秘密在于,钱通常是靠收益本身赚出来的。”2500亿美元储备按约3%-4.5%赚取收益,发行方合计每年产生超过100亿美元;这部分经济价值可以支撑低价或免费的服务,同时仍是一门有吸引力的生意。

  • 一个典型流程是:美国用户绑定银行账户,等待2或3天完成 ACH,然后收到10 USDC。印度收款方只需要一个加密钱包,不需要 Coinbase;他们可以持有或投资 USDC,也可以通过做市商换成卢比,可能支付0.5%、1%或一笔小额固定费用。

3. 交易持续留在链上,Stablecoin 经济性会改善

  • Nemil 预计,更多交易将形成闭环:收款方会保留链上的美元或卢比,直接消费,或使用去中心化金融服务,而不是反复为进出法币系统付费。链上货币更具可携带性,因为它可以在全球流通,并与交易、存储和收益协议交互。

  • Coinbase 可能会把部分储备收入分给在平台上持有 USDC 的用户,因为资产本身的增长具有战略价值。持有人把 USDC 转到平台外的钱包后,个人可能拿不到收益,但 Coinbase 和 Circle 仍会继续从底层储备中赚钱。

  • Nathan 将当下的经济模式与 Uber 靠风险投资补贴的模式相提并论。Nemil 反驳说:“这已经是一门大生意。”对投资者而言,关键区别在于,低廉的消费者价格来自高收益储备基础和更便宜的基础设施,不一定来自为获客而接受亏损。

4. 区块链扩容依靠批处理、更大容量和明确的取舍

  • Nemil 把区块链的进步比作带宽领域的摩尔定律:Bitcoin 于2009年上线,网络大约有16年时间改善吞吐量和存储效率。Base 最近已达到接近每秒1,000笔交易;他预计,随着金融活动乃至社交活动迁移到链上,容量还会持续增长。

  • 过去,Ethereum 交易会直接争夺 Layer 1 的区块空间。如今,Layer 2 和新兴的 Layer 3 网络可以执行大量转账,将其汇总后,再定期把压缩后的结果写入底层链;Nemil 将其类比为银行结算净余额,而不是逐笔独立结算每笔零售交易,但他也承认这并不完全准确。

  • 网络还可以通过放宽 Bitcoin “几乎任何人都应能用普通硬件运行节点”的目标来提高吞吐量。如果有数千或数万名运营者使用云级基础设施,每个节点就能处理更多交易,但网络也因此会在去中心化光谱上选择另一个位置。

  • Nathan 将这一机制概括为原始效率提升与设计妥协的组合。Nemil 表示同意,但不愿用一个公式概括整个行业:不同网络会在区块空间、分层架构、硬件要求和去中心化之间选择不同组合。

5. 最终性既是区块链的优势,也是消费者保护的缺口

  • 传统支付费用的一部分,实际上是在购买欺诈处理和追索权。Nemil 承认 Nathan 的核心观点:区块链支付“默认不是可逆系统”。一旦交易结算,付款方不能简单按下按钮把资金撤回。

  • Stablecoin 并非凌驾于法律执行之外。交易所会进行 KYC 等检查,发行方必须遵守制裁规定;当当局提出法律请求时,USDC 可以被冻结。这提供了有意义的追索手段,但不等同于日常支付中的常规退款。

  • 不可逆性也正是收款方可以在几秒内相信款项到账,而不必等待数天才能使用资金的原因。Nemil 表示:“我发送1万亿美元或10美分,费用都可以低于1美分。”相比之下,一笔电汇可能要收取20-30美元,而这笔费用捆绑了相关基础设施和保护措施。

  • 如果用户需要这些保护,额外层可以重新引入延迟结算或付款方取消机制。Nemil 预计,这类设计会越来越普遍,费用也会略高,但底层仍可以保留一条便宜且最终确定的支付轨道。

6. x402 重新激活了信用卡未能实现的 Web 原语

  • 早期互联网为“Payment Required”预留了 HTTP 402 状态码,但真正实现它,需要 Visa、Mastercard 和其他支付网络协作。Web 最终围绕广告、账户、信用卡和订阅发展起来,这个状态码也因此基本处于休眠状态。

  • Coinbase 重返402的起点是 AgentKit,它为 AI Agent 提供钱包和链上能力。数千名开发者采用了它,其中包括构建可收取打赏并转移资金的 AI 人格团队;随后用户开始追问,既然这些 Agent 能收钱,为什么不能自主购买商品、数据、API 调用或短信。

  • 对于可能从一个供应商买1次查询、再从另一个供应商买1次查询的软件而言,信用卡并不合适。信用卡假设用户要先建立账户,并与商户保持持续关系;Agent 需要的是可编程权限,以及面向许多未知服务商的低成本一次性交易。

  • 人类小额支付仍在愿景之内:Nathan 不愿为了偶尔阅读一篇 CNN 文章,再购买一份30美元的订阅,而是更愿意支付1-10美分。Nemil 表示,直到最近这才变得可行,因为 Stablecoin、更便宜的链和更好的易用性,终于消除了让1美分购买变得不理性的费用。

7. 一次成功的 x402 购买,就是一轮请求—响应循环

  • Nemil 的标准案例是 Agent 为自己购买推理服务。Agent 请求一次模型调用后,会收到一个402响应,其中指定费用、区块链和代币——例如在 Base 上支付5 USDC——以及收款地址和授权支付所需的其他信息。

  • Agent 的钱包会签署拟议交易,但不会广播。它会携带签名后的支付载荷,重新发送原始请求,让推理服务商确认授权格式正确,并确认买方“有能力支付”。

  • 服务商可以等到确认工作能够完成、且明确成本之后,再提交交易。生成推理结果后,服务商广播支付、收到资金并返回结果;结算时点由卖方而非买方控制。

  • 可变成本会带来边界情况,但不会破坏协议。多付的金额可能形成类似预付卡的可复用余额;少付则可能触发另一个402响应,例如要求支付15美元而非10美元,但服务商必须管理已经消耗推理资源后的风险。

8. 中间件和 MCP 集成降低采用门槛

  • x402 是任何人都可以实现、修改或继续构建的开放标准,但 Nemil 表示,仅发布规范远远不够。因此 Coinbase 发布了 Node.js 中间件,可以放在现有 API 前面,以“基本只需写一行 JavaScript”的方式强制执行支付。

  • Coinbase 的开发者平台还可以创建收款钱包、管理区块链底层流程,并自动将收到的代币兑换成卖方银行账户中的美元。企业因此可以接受链上 Agent 支付,而无需在运营层面选择持有加密资产。

  • Nemil 将 MCP 视为“重写 Web,让 AI 更容易使用”的一部分:它帮助 Agent 发现工具并理解调用方式,但不包含支付。他设想的最终状态是,付费 MCP 服务器自动暴露 x402,而其他能力则不必使用它。

  • 发现机制仍然很原始。最初的 x402 生态页面列出了参与其中的加密数据和推理服务;未来的 MCP 式目录可以描述每个端点、其能力和价格,让 Agent 在购买前比较不同服务商。

9. 机器商业同时改变 API 定价和 Web 变现

  • 早期用例包括:接受20 USDC并向 Agent 提供地址后发货的商店、向交易服务出售数据输入的金融数据 API,以及按短信计费的 Twilio 式服务。共同模式是,在能力被调用的准确时点完成支付,而无需建立订阅关系。

  • Nemil 认为,通用 Agent 与专业 Agent 之间尤其适合形成市场。一个通用编程 Agent 可以向规划模型、爬虫或 MCP 端点背后的另一名专业 Agent 付费;对用户而言看似只有一个 Agent,实际上可能是多个独立拥有的系统在交换工作和资金。

  • Nathan 以 Augment 为例,指出了一个尚未解决的边界:如果编程 Agent 依赖一个用于规划的智能第三方 MCP,那么“Agent”究竟在哪里结束,以及恶意或有缺陷的计划由谁负责,就变得不清楚。Nemil 没有给出明确边界;他的观点是,至少价值转移会把商业依赖关系明确暴露出来。

  • 当消费者是软件时,广告的作用也会减弱:“很多时候,AI Agent 根本不会看广告。”Nemil 预计,出版商——甚至可能包括 New York Times——会直接向爬虫收取访问费用,使 x402 成为 Web 变现从人类注意力转向机器使用量之后的一种候选方案。

10. 声誉可能成为 Agent 的身份、信用分和抵押品

  • KYC 仍然独立于 x402:Anthropic、OpenAI 或任何其他服务商,依然可以要求用户先完成身份验证,才能开放敏感能力。Nemil 将 x402 描述为最低层的支付轨道,访问控制和声誉系统可以建立在其之上。

  • 一个持久的区块链身份,可能从一枚空白 NFT 开始,逐步累积证明,“像一本不断盖章的护照”。如果可信评估者反复确认某个 Agent 提供了正确的医疗信息,这些记录就可以建立其专业能力,而不必依赖某一家公司的私有数据库。

  • Nemil 使用了“开源征信机构”这个比喻:所有人都可以查看历史并添加信息,但每个阅读者自行决定是否信任证明者。一个1,000次中有999次判断正确的 Agent,即使有1次错误记录,仍可能值得获得访问权限或信用。

  • 声誉可以让资金不足的 Agent 赊账购买 API 调用,获得特权访问权限,或证明自己没有滥用出版商的内容。真正困难的不是不可篡改地记录声明,而是在 Agent 本身易于创建和抛弃的情况下,判断哪些身份、评估者和证明值得赋予权重。

11. Agent 钱包需要先有硬性上限,再考虑扩大余额

  • Nathan 最初的安全模型是风险隔离:给 Agent 10美元或100美元,绝不把所有者的主钱包交出去,并接受提示注入可能损失这笔小额余额。Nemil 认可隔离原则,但预计随着 Agent 开始交易加密资产、股票或投资组合,相关金额会大幅上升。

  • “人们迟早会把数百万、甚至数十亿美元投入 AI Agent。”Coinbase 的黑客松已经吸引了数百个类似自动交易员或财富管理者的实验;Nemil 的类比是,量化基金今天已经在执行这类工作的不同版本,即使消费者 Agent 现在听起来仍然很未来。

  • 更强的控制方式是带有明确权限的智能合约钱包。Agent 可以独自支出10美元以内的金额,但任何更大交易都必须由人类使用另一把密钥单独签名,否则交易失败;这种二之二多重签名类似一个需要客户和银行双方到场才能打开的保险箱。

  • 让模型通过提示请求审批,对交互界面仍有用,但这不是安全边界。幻觉或操纵可能导致通知根本无法发出,而钱包合约不会在缺少第二个签名的情况下释放资金。

12. 罚没、熔断和 AI 仲裁仍是未完成的基础设施

  • 在 Nemil 看来,Tyler Cowen 关于让 Agent 资本化的提议,可以对应到权益证明中的罚没机制。Agent 可以托管资金,以获得交易权限或信誉,质押资金并赚取回报;一旦作恶,质押就会被没收。裁决可以来自去中心化治理者,也可以来自一个中心化主体。

  • Nathan 的系统性反对更尖锐:Agent 既可能进行有益协作,也可能进行破坏性串谋。他提到一项捐赠博弈实验:此前的 Claude 学会了跨代合作和惩罚,而 GPT 和 Gemini 没有;随后他追问,当自主 Agent 运行在专门抵抗关闭的基础设施上时,究竟由谁拉下断路器。

  • Nemil 没有提出一个统一的关停开关。他把控制措施分布在多个层面:人工审批、持久声誉、罚没,以及交易所层面的潜在限制,例如在 Uniswap 或 Aerodrome 等场所阻止单个区块内过多交易。他也承认,随着 Agent 能力提升,审批疲劳可能最终把人类排除在流程之外。

  • Nathan 认为,危险可能在大规模采用之前就已经到来:Claude 4、Gemini 2.5 和 o3 似乎已经足以创造一个动态经济。Nemil 的回应是,有意义的执行机制很可能要等到交易量足够大、故障模式具体暴露后才会出现。

  • AI 也可以“让智能合约真正变智能”。Nemil 提出一种二之三多重签名:2名人类意见不一致时,由 AI 审查证据并签出决定性的一票;他不知道已有这样的系统,但表示相关组件已经具备。

  • 他给出的最佳具体案例,是与 Gates Foundation 合作时涉及的天气指数农作物保险。投资者可以将1,000美元放入托管账户;生长季结束后,AI 审查6个月的降水数据:如果降雨超过阈值,资金支付给投资者;如果低于阈值,则支付给农民。

  • 这种设计重新定义了 AI 的角色:它成为区块链预言机,解释确定性合约无法直接访问的链下事实。Nathan 的质疑则集中于证据来源:屋顶照片是否为最新、田间传感器是否真实、索赔人是否伪造输入;此外,模型自身也容易产生幻觉并受到“诱导”。

  • Nemil 见过面向公众的 Agent 被操纵着把钱送出去,因此他建议从狭窄且受控的场景开始:卫星数据、有限 API、不开放式的公众提示,以及简单决策。“第一天不可能从最难的问题开始”;应当从可信数据与边界明确的判断能够安全结合的地方开始。

Nathan Labenz

Today my guest is Nemil Dalal, developer platform lead at Coinbase, who recently co-created the x402 protocol, a new open standard designed to enable both humans and AI agents to transact seamlessly on the internet with cryptocurrency. The protocol takes its name from the HTTP 402 Payment Required status code, which, believe it or not, has existed since the early days of the internet but has never been properly implemented due to the limitations of traditional payment systems.

As we've covered in a number of recent episodes, AI agents are now quickly becoming more capable and reliable, such that it's no longer crazy to think about giving them modest budgets to spend on access to information APIs or MCPs, or perhaps even to hire other agents or human collaborators to help them when needed. However, because traditional payment systems are designed for human users and balance security-related trade-offs very differently, they're often very difficult for AI agents to use and are generally priced in a way that makes micropayments uneconomical.

x402 seeks to fix that in a way that's both easy for sellers to implement and for buyers to use. Anyone who wishes to charge for access to an online resource can, by adding the x402 library to their application, return a 402 response that specifies the details of the payment required for access. The user—which could be an AI agent equipped with a crypto wallet—can then make the necessary payment to the specified address and re-request the resource with proof of payment attached.

It's worth noting that, while I have used Coinbase to send international payments with the USDC stablecoin, I'm not very knowledgeable about the crypto space in general. Wanting to properly understand the fundamentals of this system, I asked Nemil, who previously ran USDC at Coinbase, to give me a primer on stablecoins in general. We discussed their benefits to retail users, who we're all trusting to keep the stablecoins stable, and how those actors, including Coinbase, benefit from providing these services.

For some, this may be remedial content, but for me, it was very helpful. From there, we get into more forward-looking possibilities. Among other things, I was really interested to learn how crypto wallets, which can be programmed to require multisignature approval for certain types of transactions, seem useful for protecting AI agents from adversarial attacks, to which they remain very vulnerable, and more generally for keeping humans in the loop when it matters.

Beyond that, we also consider questions that are as yet unanswered. Could this be the technology that finally creates a viable alternative to the advertising model? What sorts of reputation systems might we need, and how might they work? Especially considering the fact that agents are so easy and cheap to create and delete, should AI agents have to be capitalized to ensure accountability, as Tyler Cowen has suggested?

Is there any way to anticipate the dynamics that might arise when millions of AI agents have wallets, especially considering all the scheming and other bad behaviors that we've seen from the latest generation of models? And what are the prospects for AI finally putting the smart in smart contracts and greasing the wheels of even local commerce by using AI models to provide low-cost resolution for offline disputes?

All these are fascinating possibilities that we should all be watching closely as the agent economy continues to accelerate. And, big picture, this discussion is also a powerful reminder of the contingency of the technologies that have enabled the AI wave. Most famously, the development of GPUs, or graphics processing units, was driven for years by the unique demands of video game rendering engines.

Here again, cryptocurrency, which was originally motivated by a desire to create digital money that not even nation-states could control, might prove to be the perfect enabling technology that allows AIs to participate in the economy. I see this both as a reason to be humble about our ability to predict where all this is going, but also as a challenge to technologists and technology investors to invest now in the development of potentially complementary technologies that will enable the monitoring, supervision, and control of the AI agent economy. I'll definitely be returning to that theme in future episodes, but for now, I hope you enjoy this primer on cryptocurrency and exploration of how AI agents might get their first access to economic participation with Nemil Dalal from Coinbase.

Nemil Dalal, developer platform lead at Coinbase, welcome.

Nemil Dalal

It's fantastic to be here. Thanks for having me.

Nathan Labenz

Yeah, I'm excited for this conversation. Honestly, I have a lot to learn. Regular listeners know that I'm totally obsessed with the AI technology wave and study it from all angles, but the same is not true of the crypto technology wave. So, I'll probably ask some remedial or basic questions to get started.

With that introduction and helpful orientation from you, I know we've got some envisioning to do about what the intersection of the AI and crypto technology waves might look like, and specifically about a protocol that you have recently put out to try to make this more concrete and really start to enable it.

Maybe just for starters, because this is going to be a foundational technology for the purposes of the vision that we'll be sketching out, can you tell me where we are on stablecoins today?

I think everybody knows that Bitcoin goes up and down, and it can all be crazy. But then there's this whole domain of stablecoins, which I've used a bit, actually, through Coinbase to pay international contractors from time to time. It does have a magical feel to it where I can just drop some dollars into my Coinbase account, convert them to USDC, and send them seemingly anywhere in the world.

On the other side of that, I'm not entirely sure exactly what happens, and I'm not entirely sure how it works. Maybe you can give me a little stablecoin 101, which I think not only I but probably a number of listeners would benefit from.

Nemil Dalal

I would love to. I actually used to run USDC at Coinbase when it was first a venture bet, just a few tens of millions in market cap, and helped grow it to a billion. So, I'm really excited to talk about it.

Baby step one is that, in the last decade, we basically went from zero stablecoin usage in the world to about $250 billion today. There are a number of different players in the market. Coinbase is one of the really big ones, along with Circle, which issues USDC.

If you think about the blockchain, there are a lot of benefits to the blockchain. One is that it's globally available: anyone can use it. Two is that fees are often a lot lower than traditional financial-system rails. Three is that it's often instantaneous; it's a matter of seconds to be able to send USDC anywhere in the world.

These are all the benefits of blockchains. We've known about this for a very long time. Since Bitcoin, a lot of these benefits started coming together. But what was always hard was their instability. The power of something like the US dollar, the euro, or any of these other fiat currencies is that they have that stability. People buy things in them. They go to a supermarket or a drugstore, and they can buy things in them.

The power of a stablecoin is that it combines all the benefits of a blockchain but has the stability of the US dollar. You asked some more detailed questions about this, so I'll share a few areas I think are interesting for folks to know about.

One is: how does it get its stability? Typically, the way this works is that the issuer takes the dollars it's getting. In this case, what Coinbase does is put them into a bank account or into Treasuries—basically some type of short-dated government paper—and then issue a token one-to-one against them.

The way it gets its stability is that you have those dollars in a bank account and you're issuing the token one-to-one. If I have $10 and somebody gives me $10, I can create 10 USDC tokens and give them to that user. Then they can do anything they want with them, and if they ever want to come back and get the underlying fiat back again, I go ahead and change that back.

Now, think about this as the vision from 10 years ago. Maybe I'll just spotlight 1 or 2 quick things that are changing. One is that blockchains are getting faster and cheaper. Base nearly has 1,000 transactions per second. Settlement times are a matter of less than 500 milliseconds today; that's the plan that Base is putting together.

Fees are basically cents or less than that, so they could be sub-cent at different moments in time. All these things suddenly mean that blockchain, which was good for all these things before, is now essentially exceptional. The vision that we really think about is: can you make sending money as simple as sending a text message? That's the vision with stablecoins and where we're headed.

Nathan Labenz

So, it's a great start. A couple of questions for somebody who, again, doesn't understand all this deeply in a technological sense.

Obviously, one of the big ideas of Bitcoin originally was trust: you don't need to trust anyone in particular, right? You're just trusting the decentralized network, and somebody would have to take over the majority of the network in order to launch an attack. Over all these years, it's been robust to that sort of thing.

When we have a stablecoin, am I trusting someone? Who am I trusting? Is there a concept of a fractional reserve behind it, or is it literally one-to-one? How do I know, as an end user, when I have USDC, that there's really the ability to redeem it? I think a lot of times, as I said, I've done these transactions, and all of the surface-level user features I've experienced, but I'm not quite sure exactly what is underlying that and providing that sense of stability.

Nemil Dalal

Yeah. With stablecoins, unlike Bitcoin, you absolutely have to trust someone, and that is one big difference. The person you're trusting is an issuer. In this case, Circle and Coinbase are the issuers. You have to trust that they're taking the money and putting the funds in the place where they claim to put them, right? This is one of the risks that comes with stablecoins.

The way Circle and Coinbase address that is by sharing a transparency report. Sorry, not even “get around” it—they actually share transparency and show a radical degree of candor in terms of where those funds are going and where they're held. With that degree of transparency and trust—and, by the way, Congress and others are in the process of exploring ways to legislate stablecoins to make them even more trusted all around the world—you absolutely need a form of trust. It's typically the issuer that you have to rely on to make sure that this is the case.

The other main thing is that you have to make sure the keys for the minting and burning of the smart contracts themselves are safely held, so someone can't just infinitely create USDC without having the underlying reserves. Typically, it's fiat-level transparency and smart-contract security that you need to support this network.

Nathan Labenz

And how do you guys handle it when I go onto Coinbase, bring my dollars, convert them, and then make a payment that may go anywhere in the world? On the other end, my counterparty may not even be working with a Coinbase account. They might use some other wallet, provider, or enabling technology. If they're in India, for example, they're going to cash out into local currency, so they're going to get rupees at the end of the day.

How are you doing this with no fees? Obviously, there are significant fees if I try to do that through the traditional banking system. Even if I imagine saying, “We're just going to do this as a public good because we want to enable the ecosystem,” there would still be currency risk. It feels like there could be some buildup of risk or currency movement, such that being the market maker doesn't sound like a great place to be if you're making no fees on it. I'm just a little confused as to who's taking on that risk. That seems like it can't be totally eliminated, and why are they taking on that risk?

Nemil Dalal

Totally. With any product like this, you need market makers and cash-in, cash-out points. Both of those take money. There's compliance infrastructure involved, physical branch locations, and money movement as you're going back and forth between different currencies to keep the books healthy in a financial exchange. Absolutely, all of these parties need to be able to make money as part of this.

The secret of stablecoins is that the money is often made on the yield itself. When I take $10 and convert it into a stablecoin, that money is going into some form of short-dated Treasury or bank account, and yield is earned on the other side of that. For example, today the stablecoin market cap is about $250 billion, almost exclusively in U.S.-dollar-based stablecoins. There's a 3% to 4.5% yield being made on those funds, and that's a lot of different economics that can go around to support an entire ecosystem that lets people do this.

Now, candidly, this exists in the traditional financial world, and the banks take all that and still charge the fees, right? The idea of this methodology is that you can take the fees from that, but then you can offer a very cheap or free service that anyone can use.

Let me tell you the story of how a user might approach this. They come to Coinbase and want to convert $10 in their bank account into stablecoins. They hook up their bank account to Coinbase. Coinbase will pay some fees for that—it might be a few cents in the U.S.—and ACH takes 2 to 3 days to move the money over. Those $10 show up at Coinbase, and then suddenly you get 10 stablecoins, 10 USDC tokens, in your wallet.

Now you can send them anywhere in the world. The recipient doesn't have to be a Coinbase user; all they need to do is have a crypto wallet on the other side. Let's say it's someone in India, like you said. That person in India will suddenly have that USDC.

There are a few different ways this could go. One is that they decide they want to keep the USDC, put it into a DeFi protocol, earn some yield on it, or spend it on goods. Slowly, we're starting to see this happen more and more, but it's still early days. Not every merchant you go to on the local street in India—and, by the way, I'm Indian, so this is a cause near and dear to my heart—will accept it. You can't just go spend it at local stores.

But you can sell it. There's a market maker on the other side, and that market maker is collecting the USDC, deciding whether to keep it in USDC or actually go back to Coinbase or Circle and convert it back to dollars, right? On my side, what I'm doing is converting it, probably paying some type of fee to do that. In this case, in India, I would probably have to pay some type of fee. It might be half a percent or 1%, or it might be a few cents, depending on the dollar amount and the rupee amount. Then suddenly I have my rupees, and I can go spend them wherever I want.

So that's the system as it is today. But I think rapidly what we're moving to is a world that's closed-loop, where an on-chain stablecoin is better than a fiat stablecoin or a fiat rupee. A rupee on-chain is better in that it can be sent around the world, it can be cheap, and it can be used with this entire decentralized finance infrastructure.

I don't know if your audience is aware of that, but basically there are things like yield protocols and the ability to trade—basically, a lot of the traditional financial services people are used to—and there are ways to store it, et cetera. These are all the things that you can do once you have that on-chain rupee or that on-chain dollar.

Nathan Labenz

Yeah. It's just a lot for me to wrap my head around as someone who hasn't done it much, but I hear you on the fees on the cash-out. That makes sense. Would it be fair to say that we're in sort of an early, almost subsidized era of this from a Coinbase perspective?

Famously, Uber was burning tons of cash, and Uber and Lyft were burning tons of cash in order to scale their operations. It's a joke at this point that the millennial lifestyle was subsidized by venture capital for a long time. Are we in a similar period with crypto, where Coinbase is just willing to take an initial customer-acquisition loss to get people onto the platform and into the on-chain lifestyle in the first place?

Nemil Dalal

No. This is already a big business. That's the part that's crazy: when you earn 4% yield, there are $250 billion of stablecoins. That means the people who issue stablecoins are making $10 billion-plus a year already.

The Uber example is one where they're making very little and using venture capital to subsidize that. The reality is that these are already great businesses. These are fantastic businesses, and if you have less margin than a bank, you can do a lot of amazing things with that. What I would say is that they're making good money, and as a result, there are all these different things that you can do with these stablecoins. Does that make sense?

Nathan Labenz

Yeah. Although I also get yield on my USDC. I haven't held much USDC, but I do notice that when I deposit dollars into Coinbase and do that conversion, all of a sudden I'm getting yield, right? I guess there's obviously just a spread between what Coinbase gets and what I'm getting.

Nemil Dalal

Yeah, that's exactly right. Coinbase is making some money. There's also value to Coinbase in having USDC continue to grow. That's one of the reasons that, when you have it on our platform, as an example, we offer you yield directly on top of it.

But again, if you took that off-platform and just had it in your wallet for a year, you would not be earning yield on that, and Coinbase and Circle would be earning yield together. Essentially, you can either move it to Coinbase or move it somewhere else where you earn that yield, or you can hold it off-platform and Coinbase is still earning the yield, very similar to how a bank might earn that yield.

Nathan Labenz

Yeah, interesting. Okay. Just one other thing I'd say is that blockchain fees are another really interesting thing. Why does it cost so much to send a wire transfer in a world where an SMS around the world is free?

Nemil Dalal

Right? A lot of what we're sending is really just information. It's not necessarily the money that's always moving, because there are fiat on- and off-ramps and various other ways to send things.

What I would just say is that what the blockchain has been really amazing at is suddenly making this a much more commoditized and open market for anyone to move. The first version of blockchains I remember in 2017 was like $2 to $5, right? Then gas fees spiked and got to $100 or $200 to be able to basically make an on-chain transaction. But today, with Base and others, it's a matter of cents to be able to send this, and that's not with subsidies or anything. That is the power of the blockchain.

The blockchain allows you to have this open market where anyone can send transactions, and the technology is a lot better than what it was for traditional banking rails. I've worked for these banks early in my career, and a lot of this is 1950s, 1960s, and 1970s infrastructure that they're running on. It's really hard to convince a ton of banks to change to a new technology stack.

The power of the blockchain, just like the internet, is that you have this old system and a new system that's built with a whole new world in mind. As a result, everything is so much cheaper and faster. I think that's the other thing that people get really surprised by: the fees are so low, and that's not a function of subsidies. It's a function of the technology architecture and the fact that, in general, networks have gotten so much better over the last 30 or 40 years, but that just hasn't flowed through to finance yet.

Nathan Labenz

Yeah. So, maybe 2 follow-ups on that. One is on somewhat of a different services profile, and the other is in terms of the underlying technology that's enabling low transaction costs, which is maybe a good transition into the new HTTP 402 Payment Required, or x402, protocol.

On the services side, there's some difference. Maybe you can compare and contrast what I get, because part of what I do get if I send through the traditional system is some recourse. I can say the money didn't get there, or somebody defrauded me, and it wasn't actually me that made this payment, right? There are various fraud vectors that I can engage the traditional banking system on.

My understanding is that some nontrivial fraction of the fees associated with those transactions are basically to cover the fraud that actually gets through, and also to pay for the services of remediating fraud that people are trying all the time. Whereas my general sense is that there's just much less of that on the crypto side. My trade is that I am paying a lot less in fees, but I also have qualitatively less redress available to me if something goes wrong. Complicate or clarify that picture for me.

Nemil Dalal

Yeah, absolutely. What I would say is that there are exchanges around the world that have forms of KYC, as an example. They have other forms of checks and balances in their system, so absolutely, there is some basic form of that.

But I think the core of your message is correct, which is that, unlike more traditional systems, this is not a reversible system by default. With blockchains, when you send a transaction, it ends up on the other side, and that's it. There's no recourse to necessarily pull it back by default.

But there are some interesting things that have been baked into this. For example, with stablecoins in general, a lot of them have to work with national governments and partners. If there's a legal case associated with USDC and an enforcement agency is reaching out, that is absolutely something baked into the protocol, where there is the ability to hold those funds. Coinbase, like any other exchange, Circle, and others all need to follow, for example, the sanctions laws that the US has and other international jurisdictions. These are absolutely things that can be done.

So, number 1, there is some form of recourse, but you're absolutely right: it isn't like you press a button and suddenly you can reverse the transaction. But that's also the reason why it's so fast, right? If you can press a button and reverse a transaction, the other side can't really trust that they've gotten the money yet. This is why, for a wire, you might have to wait several days to be able to access your funds, while with blockchain, it might be 2 seconds and suddenly you have access to your funds.

The last thing I'd say is that blockchains can absolutely add reversibility in more and more complex ways into the stack if they want to. Just like one layer on top, where we say, "Here's the foundational layer. It's not reversible, but on this layer on top, you can always wait for 2 days and the sender can pull the money back." These are all things that people can build, and in fact, people have built them. They're not super popular yet, but I expect over time they are going to become more popular.

The last thing is, to this broader point, that's one of the reasons for the fees. Yes, that is part of the reason for the fees, but I don't think it justifies all the fees. I think that's probably a big shift in terms of what this is: if you added a better system, their fees would probably be a little bit higher than they are today. But compared to, let's say, a wire, which people pay $20 or $30 for, I can send a trillion dollars or 10 cents for less than a cent today on the blockchain. That is a really new feature of blockchains compared to the traditional financial system.

Nathan Labenz

Yeah. So, maybe my last question before we get to x402 is, can you sketch out a little bit how those transaction costs on blockchain have fallen so dramatically? This is something that, in some sense, even a totally crypto-ignorant, AI-obsessed crowd will have some sympathy for, because we're used to paying for compute.

My general sense, at a very high level, is that it used to be that the transactions were in some sense backed by this proof-of-work concept, which is basically proof of compute, and that a lot of the compute requirements have basically been taken out and replaced by other schemes. Obviously, we're seeing dramatic efficiencies on the AI side as well. The compute is not taken out, but certainly many efficiencies have been found. What's the very 101 story of how the transaction costs have gone from having spiked to $100 or whatever to now being so low?

Nemil Dalal

The overall message for your listeners is that, just like there's Moore's law, there's a form of that just for bandwidth. Bandwidth gets better and better over time. There's a form of that for blockchains, and we've had 16 years now since Bitcoin was launched in 2009 to refine and innovate on ways to make it cheaper to do that.

The biggest shift that's happened is that there's more and more block space available. There are different examples I can give you. In the Ethereum ecosystem, back in 2017, if you wanted to launch a transaction and put it on the blockchain, you put it on the Ethereum Layer 1 blockchain. But today, what's happening is that you have these Layer 2 blockchains that are on top, and now you even have Layer 3s.

They're taking all this information, letting people make those transfers, and then summarizing it and putting it onto the Layer 1 blockchain. So they use a lot less storage, and storage has also gone up on the Layer 1 side as well. As a result, the amount of block space has just gone up a ton.

I think this is not that dissimilar from the traditional banking system, where banks don't settle every single transaction individually. They might settle the net over time of the different transactions. I would just say this is not exactly the same, but I liken it to a model where the Layer 2s are moving a ton of different transactions on them, and then periodically they're writing something called a blob—we call it in Ethereum—the Beacon Chain.

They're writing to that as one way in which to do it. There are lots of other ways to scale, and I won't go through all of them, but another example could be Bitcoin. Bitcoin was very focused on decentralization.

If you centralize that a little bit more—let's say Bitcoin's vision was that everyone could run a node—but say, "Hey, thousands or tens of thousands of people around the world can run nodes, but not every human is able to run a node on a phone," suddenly the amount of transaction capability for any node goes up substantially. If I can run it on AWS or any of the other cloud providers, that's another way in which this goes up.

If I look forward, I think the TPS on Base just hit almost 1,000 TPS last week. My expectation is that this is going to keep growing substantially, and, in fact, everyone around the world is going to be doing transactions on the blockchain. It's not just financial transactions, but social networks are going to live on this, all these other things, just like the internet.

That's the vision that we see going forward, and that's exactly how we've gotten so far. In 15 years, we've done this much. Now it's going to be really exciting to see what we can do in the next 15 years.

It's a mix of both efficiency advances at the raw algorithmic level and some design trade-offs, where some combination of those is delivering much higher scalability with some compromises in terms of the original vision of Bitcoin, specifically. Bitcoin was one network, and, by the way, I'm saying this holistically for a lot of different networks.

Different networks have chosen different paths along that journey: Do I want to make a design trade-off? Do I just want to work on this other factor of it? There's absolutely a mixture of different approaches that the entire blockchain industry is taking.

Nathan Labenz

Cool. Well, let's get to x402. This is the new protocol that's meant to—first of all, I love the fact that there has been this HTTP status code. I didn't know this, but everybody knows 404, and everybody probably knows 401. Not too many people, including myself, have probably heard of 402. So, introduce the x402 protocol: what it's meant to enable and a little bit about how it works.

Nemil Dalal

Let me just start at the start, which is that we launched something called AgentKit. For a lot of your listeners, if you have an AI agent but want to be able to do things on-chain, what it needs is basically a wallet. We built that last year and had thousands of developers start using and embracing it. We had teams like Virtuals launch AI personalities that you could tip, that could send money around the world, and so on. They're all using AgentKit.

When folks were using that, they were like, "Look, wouldn't it be amazing if, with this wallet, this AI agent could actually go pay someone or something?" For example, I could go buy a good, or I could go to an API. I could access the data that the API is providing. I could use it to send a text message, for example. These are all things that AI agents can't do because they don't have access to money, right?

In a world where AI is essentially becoming a proxy for humans, that sounds crazy. It was very clear to me and to our entire team that AI agents needed to be able to access money and be able to go do things with it. That's where x402 comes in.

In the early days of the internet, the vision was to add credit cards to it. At the time, that was really difficult to do. You needed Visa, Mastercard, and the others to play ball back in the 80s and 90s, and as a result, this never happened.

The internet had a standard where, if I wanted to access a webpage, I didn't need to look at an ad to do that, right? That's the model that we're all used to today. But what it could do is say, "Hey, Nathan, you're looking at this website. Before we can send you the page, you actually have to pay 10 cents to be able to do it." I would pay the 10 cents some way to get this 402 status code and say, "Oh, I didn't realize that I had to pay. Okay, 10 cents. Awesome." I'd send the money along, and suddenly I would have access to the webpage.

The internet had this conception that they wanted to do this, but they could not do it. We looked at that and said, "Look, the use case is actually a little different." We've kind of gotten around the fact that x402 didn't exist by just using credit cards, but credit cards are not ideal for AI agents.

You need things like permissioning and the ability to sign off if they want to do it. AI agents will want to access lots of different things. It's not just a subscription where I sign up for it, pay my money, and use it all the time. An AI agent may go here for one query and go somewhere else for another query, and it needs to pull all that together.

We said, "Look, this is the perfect moment to be able to bring this back, and the blockchain is the perfect mechanism," because it allows you to move stablecoins around the world, lets you move Bitcoin, and can let you move NFTs and all these other things.

That's essentially where we put it together. x402 is a standard that makes it super easy for any website to accept money and then return a result based on it. Two simple examples: I have a storefront, and an AI wants to buy from it. I can add x402, and suddenly the AI agent sends me some crypto tokens—USDC, let's say 20 USDC—and I send the goods to an address the AI agent has told me.

Another example is that I have an API and want to be able to provide that API to AI agents. One example you can think about is financial data, where I want to let that AI agent trade the stock market or trade on the blockchain. That's an example where I can sell that data for a fee.

Another example could be Twilio, where I want to send a text message or use some other form of API. Ultimately, x402 is an open standard. Anyone can build on top of it. We just introduced it into the world, but it makes it super easy for anyone who has an API to accept money in the form of crypto tokens and then offer a response back as a result of that.

We think this is really valuable for humans, micropayments, and all that stuff. But in terms of where this moment is today, I think it's especially powerful in a world of MCPs and AI agents that want to go online and be able to do things. A lot of the time, AI agents are not watching ads.

One of the big changes in the web that's going to happen is that the entire monetization model is going to change going forward. My point of view is that the entire monetization model is going to change going forward.

Nathan Labenz

Yeah, I want to get deeper into how it works. Maybe just taking one step back, it sounds pretty nice from a user standpoint as well—from a human user standpoint—to envision an internet where, especially if you're talking about display or sidebar ads, those rates are not super great, right? We all kind of know that.

It's not super easy to just plug in Google Display Ads or whatever, and it's not like the cash is immediately rolling in. I think a lot of people find it intuitively appealing that I would like to have an option for publishers to say, "You can buy our content on a micropayment basis."

Obviously, everybody's got subscriptions all over the place, but that's getting tiresome. People are obviously overloaded with subscriptions, and it's kind of run its course, it feels like, in some ways.

Now I go to CNN, and all of a sudden they want me to pay $30 a year. I'm like, I don't think I need another subscription to CNN, but I might pay 1 to 10 cents for an article of interest. Why hasn't this already happened? We've had the sort of blockchain capability for at least a while now, right? What is it that has blocked that from materializing for human users, leaving aside that we now have a new class of AI agent users?

Nemil Dalal

Yeah. So first I'll just say, for micropayments, traditional methods are really challenging, if not impossible. It's very hard to be able to charge 1 cent with a credit card.

Nathan Labenz

Yeah, you can with the crypto technology that we have. I still have never had the experience where I've gone to a website and they've said, "You can pay 1 satoshi or whatever for access to this article."

Nemil Dalal

There are some sites that are starting to offer this. Zora and Farcaster are more crypto-native today. These are examples where you can do things for just a few cents on these apps.

But you're absolutely right. I would say the biggest shifts have been, first, that early crypto didn't have stablecoins. That was one issue. Second, fees were super, super high. I would have to pay $5, $10, $20, or $30 on Bitcoin to be able to make transfers.

Only in the last 6 to 12 months has that price really nosedived, because things like Layer 2, Solana, and others have started really cutting down on the fees that are charged for it. Previously, with $20 fees, $10 fees, or even $2 fees, it really impacted the types of micropayments you could do.

The weird thing was that I think in 2015 and 2016, it was possible to do really small transactions, but then the blockchain became super popular, and fees started spiking. That's essentially the battle that we're fighting right now: to make it easier and easier, with lower and lower fees.

My instinct is that now it's going to be increasingly possible, but it required us to come up with these Layer 2 technologies and these cheaper blockchains. That just wasn't possible even 2 or 3 years ago.

Nathan Labenz

Yeah, that's interesting. In a way, that may very much parallel the AI story, where people are often like, "If this AI is so good, why isn't it in use everywhere?" A lot of times my answer is, "It wasn't useful at all until 2 years ago." Even then, it wasn't multimodal yet, the context window was 8,000 tokens, and so on.

Depending on exactly where you want to put the thresholds for real usability, they've only fairly recently been crossed. It sounds like there's a similar story there.

Nemil Dalal

The thing I really enjoy about seeing the AI and crypto journeys together is that they're both early technologies that are now starting to get mass-market adoption, and we're finally seeing the mass-market capabilities. I think crypto has been around a little longer in its form, but only in the last few years have we really figured out ways to make it simple and easy.

That's one other big challenge in crypto: usability. The usability of it, with addresses and things like that, was historically really difficult. Only now are we figuring that out. I see the same thing in AI: 6 months from now, it looks unrecognizable in many ways from what it was 6 months ago, because there's just so much innovation going on.

Absolutely, I think this is the thing where the moment is finally starting to be now, at least on the crypto side.

Nathan Labenz

For AI, the whole concept of prompt engineering—I’m old enough to remember when prompt engineering was a thing. There was a time when it was really sort of a high art, and we've had some of the early pioneers of the most creative prompt-engineering strategies as guests on the show.

Now, especially in just the last 10 days with Claude 4, I'm like, this thing genuinely feels like talking to a human in many ways. When I'm asking it to develop software for me, I don't have to lead it by the hand. I don't have to think super hard about exactly what I want back from it. I give it notes like I would give to a human developer, and it is increasingly capable of taking those notes and running with them. It really is an amazing thing.

So let's go deeper into how this actually works, because we do have a lot of people who are going to be building agents. They might be building agents totally bespoke, with a framework, coding their own, or having Claude do the coding. They might be building something that's more of a structured workflow or agent that might live in a no-code environment. Who knows what they might be doing, right? There are all kinds of form factors coming online.

Maybe just take me through the cycle of the protocol. What happens in one successful loop? What does the payment-receiving side have to do? What does the agent builder have to do to equip their agent to do this? What is required to actually make use of all this?

Nemil Dalal

Let's go through an example from end to end of how this works. One that's near and dear to my heart is inference. If you're an AI, you need inference to be able to work. One of the fun use cases that we talk about is that an agent can have a wallet and pay for its own inference.

Let's start at the start. You have the buyer, which is, let's say, an AI agent that wants more inference, and it goes to an API because it wants to access inference. It says, "Hey, I would like to access inference. Send it my way."

The API sends back a 402, and the 402 has a few sets of details: "The inference costs this much. Put it together on this network—for example, the Base blockchain, the Solana blockchain, or any of the others—and send me a transaction as part of that."

The purchaser in this case, the AI agent, says, "Okay, awesome. I know how much I need to pay for it." It takes its crypto wallet, which it can use—you can use AgentKit to hook up an AI with a wallet—and says, "It says I need 5 USDC on Base to be able to do this."

What I do is sign a transaction. I don't need to broadcast it. All I need to do is sign that transaction and send that payload back. I respond and say, "Awesome, same request, and by the way, here's the 5 or 10 USDC," whatever that amount is, in a signed transaction.

On the inference provider side, this is where it gets really interesting. It says, "Okay, awesome. It sent me this payload. It looks like it's a well-formed transaction, number 1. 2, it looks like it's good for the money. It actually has the money, which is awesome to see."

It's going to wait to submit it because it doesn't know if the request is going to use all $10 that they've sent for the inference. Maybe it'll use more; maybe it'll use less. So it goes and does the work.

Then it has a decision to make. It says, "Awesome. This looks great." It submits the transaction, and suddenly the $10 has arrived on the blockchain. Now it has the money itself, and it can send back the funds that it has.

There are a ton of different edge cases, as you can imagine. One is that if I overpay, I can get some type of token that lets me keep that as basically a prepaid card, which lets me keep spending that money until it's exhausted.

Or let's say I've underpaid, and I need more money to be able to do that. I can respond without returning the response that the buyer is requesting. I can say, "Actually, you need to send me more money. I thought it was $10, but actually it's $15. Go ahead and make a new transaction and send me that."

Again, there's a bunch of different edge cases where maybe I spend that money on inference and actually it should pay me more, and so I'm out of that money, and things like that. There's a lot of smart things that we can build on top, but I'll pause there. That's the core of it.

It's super simple: you request x402, and I put together a blockchain transaction, sign it, and don't need to submit it or anything. The other side receives it, validates it, verifies it, does the work, submits the blockchain transaction, and then returns me whatever inference capabilities I need. That's it. It's basically a request and then a response, and then you're done.

Nathan Labenz

Part of what you guys have released is middleware software for the payment-receiving side, right? That allows them to—I saw sort of a one-line drop-in—yeah, this one line of code will check for the payload, validate it, and, if it fails, kick back this 402.

Is it really that simple, or how simple is it really to start accepting money this way?

Nemil Dalal

Totally. First of all, x402 is just a standard. It's like any other form of internet standard. It's out there; anyone can use it. They can modify it and adjust it. We're super excited to see what the world does with it, and we're also seeing tons of companies reaching out to us.

But what we realized was that it's not as simple as just throwing out a standard. You have to make it super easy for people to do.

And you actually have to come up with use cases, like the inference example that we were talking about, to make this super easy as well. So what we did was build middleware. We started with Node.js, since JavaScript is one of the most popular languages in the world. We said, “Okay, let’s make a super-simple middleware where I can put it into my web server, in front of any API call I already have.”

I can put it in front of it, and it’s basically one line of JavaScript that I include. Suddenly, that’s it—it works. But I don’t think that’s even simple enough, because you still need to manage the blockchain infrastructure and things like that. That’s where Coinbase Developer Platform comes in, and that’s the team that I lead.

We basically made it so that we can spin up a wallet for you. We can automatically convert the funds you receive into dollars in your bank account if that’s where you want them to end up, rather than having them on the blockchain. In general, with standards, I think the key takeaway for us is that we’ve got to make it super easy. We’ve got to support people to be able to do that, and that’s essentially what we do.

We have a Telegram group where anyone in the AI community who wants to join can come to us, and we’d be super excited to get them spun up. They can check it out there. For anyone who’s interested in more details, they’re all available at x402.org. You can see the white paper, the diagram that I went through showing the request-response flow, and the details of exactly how the middleware works, which you can download as well.

Nathan Labenz

And then, if I’m on the agent-builder side, does this sort of become another tool that I—or even another sort of MCP-type construct—give to the agent? I would say, “You can call this inference provider, you can call this search API, you can call this weather service, or whatever.” Any of these things might return a 402.

Then I also have my payment tool, which, having received the 402, would know to call this payment MCP and send the money, and then loop back.

Nemil Dalal

Totally. By the way, we talk about MCP as if all your listeners know it well, but MCP is one example of how we’re rewriting the web to make it easy for AI. The web was made for humans, and MCP is one example of that. We want to make it easy to discover the different APIs and what you can do with them. That’s what MCP was designed for.

But even MCP is missing the payments layer, right? That’s essentially what x402 adds on top of MCP. We see a future world where every MCP server is hooked up with x402. When there’s a paid API, they can do that. Some websites—The New York Times, for example—might someday charge you when you’re crawling the site as an AI crawler. You wouldn’t be able to access the web page as an AI agent unless you pay.

Absolutely, you brought up this idea of discovery: How do I discover all the x402 APIs that are out there and use them? Today, the way we started was by having a page on x402.org, so any of your users can check it out. I think it’s one of the first links on the page, and you can see the ecosystem there.

We’re starting initially with the crypto community. We think there are 2 key areas that we’re focusing on: the crypto community and inference. In the crypto community, if you want a crypto API, there are a number of different teams, like Neynar and others, that have integrated it. There are also inference providers that we’re exploring and talking with to add their capabilities.

You can see all the different things that are out there. Over time, what gets even more exciting is that we’ll probably have an MCP server with all the x402 endpoints that you can access, along with a description of them and why they matter. Then the AI agent can decide, “Do I want to buy from this one or this one?” Maybe they’re competing inference providers, and so on.

But again, we just launched this a few weeks ago, so this is only the start. With any standard, you start at 1 layer, get people excited about certain use cases, and then, over time, you build from there.

Nathan Labenz

I guess one thing that seems like it could still be a challenge, but maybe also could be a huge unlock, is that inference providers—certainly Claude and OpenAI, and presumably Google, although I haven’t encountered this myself yet—are starting to do more of a KYC-type paradigm. I wonder: Is that a barrier, or is that something this can help with in some way?

You’ve got lots of people who may struggle to meet the KYC requirements, and I just don’t really know what to expect at the intersection. The notion is generally that the models are getting really powerful, and we’re going to want to know who’s using them and for what. They’re starting to implement all these account-level monitoring systems.

Would they be able to do a version of that with these protocols driving the transfer of funds, or is there an incompatibility? Or maybe there’s a missing extra component to the system if they want to do that?

Nemil Dalal

I think that’s independent, in that Claude, OpenAI, or anyone else can add that. It’s their decision whether they want to gate certain functionality or features behind KYC. I would say that’s independent of this.

Where I think x402 gets interesting is that it’s the lowest level of rails. You can imagine things being built on top of it. For example, there could be a reputation system built on top of this. If I don’t have the money, could I use that reputation—essentially a credit score for an AI agent—so that it can pay for an API? It doesn’t have the funds, but I’m basically floating it credit.

There should be a reputation system on top of that that allows you to do this. That doesn’t exist today, and x402 is just the payment rail. But just like with credit cards and other things, adding reputation in addition to a credit card network is a really powerful thing. We absolutely see a world where, over time, people will start adding those primitives.

By the way, in blockchain generally, there have been a lot of different attempts at building really powerful primitives around reputation. I think it’s just a matter of time before people have reputations, but AI agents have reputations as well, to be able to do things. They might get credit at an API provider or access to something simply because of their reputation.

They’ve done good things in the past. They haven’t done things the wrong way. They may not have scraped a website in the wrong way. As a result, they have a higher reputation and greater capabilities.

Nathan Labenz

Yeah, I’m really interested in this notion of reputation for AI agents, and even just the provenance: Whose agent is this, and on whose behalf is this acting? It strikes me as a challenging problem because, try as I might, I haven’t figured out a way to draw a really clean box around an AI agent. Sometimes, if you construct them very simply, then it’s pretty clear what the agent is.

But an example I keep chewing on is another past-guest company, Augment, which is doing AI coding assistants focused on large enterprise codebases. They put out a coding agent that used, in turn, a smart MCP. The smart MCP was provided by another open-source developer, and they used that MCP to do the thinking.

It kind of maps onto the schematic that you outlined before, where you have an AI, but it might want to go get more inference. Essentially, the coding agent is going out and saying, “I need help planning all the code changes I’m going to make.” So it has a planning tool presented to it in the form of an MCP. There’s going to be some inference there, presumably.

This thing happens to be open source, but it could obviously be closed source or proprietary in any number of ways. So it might have to pay for that in order to get the thing on the other end to do the planning for it and then get its plan back. But now it starts to become a very weird thing where it’s like, what exactly is the agent? Is my thing the agent? Is my thing plus that thing the agent?

Do you have any extra clarity on this? Obviously, funds, who controls what money, and who’s responsible for what are important, and could possibly be clarifying for this sort of thing. Do you have any sense of how we can get crisp on this?

For me right now, I’m expecting to see just a total smear. The sorts of forms that I see people outlining to me feel like more like the ends of a spectrum, where the middle—my agent, but also a smart MCP—kind of blurs. Where is the intelligence coming from, and who’s ultimately responsible for what?

If the thing gives me a bad plan or acts maliciously toward my agent, who’s really at fault for that? I just feel like we have so many unanswered questions, but I wonder if your study of all this from the financial side has given you any rules of thumb you’d like to see become best practices, or any sort of clarity, really.

Nemil Dalal

So, like you, I’m seeing this and then marveling at it, right? The behavior that’s coming together. I think one model I’ve historically seen is generalist and specialist AIs—AIs that are custom-made for a certain purpose. One example we’ve seen is web crawling.

Then there are other AIs that are generalists that want to tap into those specialist AIs. This is where I come in: at Coinbase Developer Platform, we’ve seen multiple examples of AIs paying different AIs. To a lot of people, that breaks their brain. Probably in the AI community it’s not as surprising, but to most people in the world, it’s like, “Oh, I thought the AI was a thing.”

To me, there might be multiple layers behind the scenes, exactly like you’re saying. I might interact with one, and really I’m just talking to one AI, but behind the scenes it’s hitting MCP, which is really forms of data. It might hit other AI agents who are super specialized.

Where x402 and Coinbase Developer Platform come in is, we think that you need a financial layer to incentivize that. If one AI is asking another AI, it probably is not going to get charged by an ad. There’s some form of value transfer that needs to happen there. If it’s the same company’s AI, that’s super simple, but if it’s multiple companies and multiple different agents that are out there—more specialized, more generalized, with different context windows—and they all want to interact together, we think that the thing that’s missing is really just money: some form of financial exchange that can go on.

That’s one part of the solution, I feel: that you have some form of money movement that allows you to talk to generalist and specialist AI agents and get information from them. Maybe some MCP servers are free, but other parts of the MCP server, just like APIs, are going to charge you money. You pay for it. That’s one whole set of conjectures.

The only thing I’ll tell you is that the blockchain is a perfect identity layer. For anyone in AI building, I think this is an area where I always love bringing the AI and crypto communities together. An example is that the blockchain—if you have an NFT, that essentially is a form of identity.

Think of it as creating a user on the blockchain. I can create an NFT, and by default that user is empty. There’s nothing in it. But then, if I start doing things—let’s say I’m that AI agent and I correctly deliver medical advice, as an example—a user who’s seeing that information can tag my NFT and say, “Hey, this is great. It’s really good medical information. They gave me the right thing, and I confirmed that it was the right thing.” Other people can do the same thing.

Think about it like a passport where you’re getting stamps. The AI agent has an NFT, it’s getting more and more stamps, and maybe all the stamps are on medical information. Suddenly, over time, it’s seen as a credible source for that reputation.

Again, this is not to do with x402, but in general, what we’re seeing in crypto is a lot of innovation on the identity stack. The blockchain is like an open-source credit bureau, where that information is available and anyone can add information to it. All you’re looking at is: Who are the people adding information? Do I trust them? Are they adding a lot of positive signals? If they are, I’ll maybe give more weight to it.

Maybe they did this one thing badly, or they gave mistaken advice this one time, but 999 times out of 1,000, they did it right. To me, the 2 things I see are that x402 is amazing for the payments layer, and I see it also as amazing for that reputation system. This is all possible today. None of this is science fiction.

I think the science-fiction part is how we bring them together and which use cases we start with. If there are entrepreneurs listening today, I think this is a really interesting area of innovation and exploration.

Nathan Labenz

Yeah, when I set up a wallet, presumably I’m not going to give my AI agent my main wallet with the bulk of my funds, right? We’ve got transactions that are much harder, if not impossible, to reverse, and we’ve got all sorts of hard-to-predict and easily hijackable behavior on the part of the AIs.

I guess my first instinct would be to limit my downside risk by keeping the deposit into the AI’s wallet small. As long as these are microtransactions and it’s paying for information here or there that it needs to accomplish tasks, and it’s all very small, then whatever. If I drop $10 into the AI’s wallet and somebody prompt-injects it into sending that full $10 in the wrong direction, I can just live with that.

What more do we have in terms of keeping myself safe? This also intersects somewhat with another idea that has been floating around, which I mostly associate with Tyler Cowen. He’s been saying that he expects we’re going to need to have AI agents somehow capitalized—that there’s going to need to be a financial stake so that there can be some redress if the agents go wrong. They’re not just flying around willy-nilly; they’ve got to put basically some skin in the game for the agent, or obviously for the parties that create the agent.

Presumably, that would need to be a lot bigger than $10. I feel comfortable with, “All right, I can drop $10 into this agent,” or even $100, but I’m not going to put major funds into it today because I don’t really trust its judgment that much. I also know that they’re not adversarially robust.

But then we’ve got this other idea that maybe they really do need to be capitalized in order to go around and create the right incentives for people to have the right guardrails and to have recourse if they do mess things up. So, I guess the 2 questions are: What are the best practices? How do I keep myself safe when I do this? And does this extend to that sort of capitalized-agent concept, or would you put that in a whole different bucket?

Nemil Dalal

Yeah, I think it does extend to the capitalized agent. Let me take a step back. You mentioned that you might want to put in $10 or $100. I’ll be upfront: I think people are going to put millions, if not billions, of dollars into AI agents over time.

To give you a really simple example, I want to be able to trade on-chain. I want to trade on the blockchain. I want to trade on the stock market. That’s a lot of access to funds that you’re giving an AI agent. We’re seeing that people want to be able to say, “I have an AI agent. It’s a trader agent.”

We had hundreds of people at our hackathon who were basically exploring ways to build a wealth manager: I give it money, and it can go make more money from this. It sounds like science fiction, but the flip side is that there are tons of quant funds on Wall Street that do this already. You and I probably both know that. So the question is, how do we get to that world eventually?

To your question, absolutely. One way is segregation. That’s the way you defined it: Can I put a small amount of money aside and only have it access that? Beyond that, what you need is some form of permissioning. If it’s more than a certain dollar amount, please escalate it and have me sign off on the ability to do that.

You can let it do a certain degree of transactions, and then the more and more that it does correctly, you give it a little bit more and more of a credit line, essentially, for that AI agent to use. The 2 things we’ve been seeing are segregation and then some form of credit-limiting process. It’s not just credit limiting; it’s basically a sign-off. If the agent is doing the right thing, you can authorize it.

Let’s say the AI agent wants to do a trade. I can look at that trade and say, “Does this make sense? What’s the rationale for it?” If it sounds good, I can go ahead and give it permission to do it.

To your question about Tyler Cowen’s idea, crypto has a form of this already. It’s called slashing. Many of the newer blockchains use something called proof of stake, where I have different transactions and put some money at risk. I put my $1 million, $10 million, or $10 at risk, and I earn some yield from putting that money at risk.

But if I do the wrong thing, I can get slashed by the rest of the community, and so I lose that money. This is exactly the same model that you can have for this: The AI agent has that crypto, puts it into escrow, and by putting it into escrow, it can do certain transactions that it might not otherwise be able to do. But if it does the wrong thing, suddenly those funds are slashed and taken away.

Absolutely, I think the blockchain is a really great element in which to do this. Again, all this requires movement of money, which is what x402 is, and then you can build all these intelligent primitives on top, like reputation and slashing.

Nathan Labenz

Is slashing ultimately a social process? Is it a matter of consensus in the rest of the community that this entity, whether it be human, AI, or otherwise, did wrong, and so we’re taking your funds? It sounds almost like a jury-trial-type function.

Nemil Dalal

Yeah. On blockchain, that is the case, but it doesn’t have to be the same for AI or for whatever mechanisms you use for AI. That’s one inspiration, but it could be a centralized party. A single centralized party is one way we could architect this for AI. We could also do it with multiple different parties, and they could all be trusted.

It doesn’t have to be just a random jury of people out there on the blockchain. The way it works is that it is the community, and different networks do it in different ways. There might be different leaders who are elected through some decentralized governance vote, and as a result, they’re the ones who get to decide whether something is right or wrong. If they decide incorrectly and it’s ultimately shown to be erroneous, they all get slashed. That’s one way it’s done in decentralized systems, but we can absolutely design it in any way we want for AI.

A lot of times, what we see with these systems in crypto is that they always start decentralized, and then there are trade-offs in how decentralized they are. We’ve also seen this with stablecoins, which are a centralized form. It could be a centralized form of jury: there might be a company or a person who attests to whether something is the right action or not, and people trust them because they’ve done such a good job and haven’t gone against that social goodwill for a very long period of time. They’re allowed to keep doing that.

I wouldn’t say that you have to follow what is done in blockchain. But the cool thing is that all the primitives to allow that slashing are possible, because blockchains today have a form of smart contract. Think of this as a legal contract, but it’s a legal contract that the computer follows to the letter. However it’s written in code, that’s what it follows. So, whatever the slashing mechanism is, you can guarantee that it will be followed.

By the way, in a world where every country has a different legal system, where we may not agree on the laws and things like that, the power of these smart contracts is that they’re the same. They’re enforced the same way the world over. It could be a really powerful primitive for this.

Nathan Labenz

Yeah. Let’s come back to smart contracts in just a second. In terms of escalation, you had mentioned creating rules to govern my AI agent’s payments: if it’s above a certain amount, then escalate that to me. That obviously makes a lot of sense. I assume that would be done on the wallet side in a hardwired way. I don’t just want to prompt my AI agent, “Hey, by the way, in general, if it’s more than whatever, you should come to me.” I want to have a much firmer boundary for it, at least for now. Presumably, I can set that up in a Coinbase-powered wallet with no problem, right? Do I have that understood correctly for starters?

Nemil Dalal

Yeah. The power is that, again, this is a smart contract. It’s just a matter of what the rules are for letting me do something. The way we would design this in code is that the AI agent would be able to spend any dollar amount up to, let’s say, $10 without getting permission. If it’s more than $10, and they try to do it, it fails by default.

If they want to spend more than $10, the way it works is, “Bring your human,” and the human has to approve the transaction using their private key. The AI agent might have its own wallet, but the human has their own wallet, and both of them have to say yes. Only then are the funds spent.

The reason you want to do it not only at the AI level is that, in a perfect world, the AI agent is prompting you. It knows the cost, and the AI agent is saying, “Hey, Nathan, I would like to spend this, but I need your approval.” You probably want to tell the AI agent, “For more than $10, let me know,” but you don’t want to trust that on its own. There could be hallucinations or other reasons why the AI agent may misuse that. So, you have it at the wallet level as well.

The wallet is basically what we call a 2-of-2 multisig. Think of it as a safe-deposit box. I have a key, and the bank has a key. In this case, the AI agent has a key, I have a key, and both are required to open it. That’s the way we would architect this.

Nathan Labenz

Okay, that makes sense. How about more on a systemic level? One of the most fascinating bits of research that we’ve covered on this show in recent months is a paper that looked at different models and their ability to learn to coordinate with each other as agents over multiple generations, or their failure to learn to coordinate with each other.

The result was—and I don’t think the result actually matters too much, but it shows that nobody really knows what’s going to happen in some of these dynamic systems that we’re starting to develop—that Claude, in a prior version, was able to play this donation game effectively with itself in a way that multiplied its funds over the generations of the agent and settled into this cooperative equilibrium.

The core mechanic there is that one Claude could donate to another Claude, and if it did, the receiving Claude would get twice as much. The Claudes were able to do that with each other and not only take the prosocial action, but also punish defectors and get into this equilibrium where the majority of Claudes were donating and their collective wealth was rising. GPT and Gemini could not do that.

Interestingly, of course, my all-angles, all-possibilities-are-probably-going-to-become-real outlook is that this sounds amazing. It could be amazing, but the flip side of cooperation is collusion. I could imagine AI agents cooperating with each other in extremely prosocial ways that I would approve of. I could also imagine them colluding with each other in all sorts of ways that might be really problematic.

What do we have, if anything, at a systemic level? I know the original vision of Bitcoin was that nobody can shut it down, but I’m a little bit nervous about the notion of creating a vast sea of autonomous AI agents on a foundational technology that nobody can shut down.

I think about episodes like the famous flash crash, which I don’t think is necessarily a great analogy for what the AI agents might get up to. But the key point is that when the flash crash happens, there is somebody with a breaker switch who can say, “Hey, this whole system is going totally haywire. We’re going to shut it down, look at what’s going on, and come back online when we have clarity.” That way, it doesn’t run away too far from everybody and make a total mess.

Do we have anything like that in the crypto-enabled AI agent economy? If not, is anybody working on that? It seems like it’s probably going to be something we need or want in some way, shape, or form.

Nemil Dalal

What I would say is, first of all, crypto and AI are at their most nascent stage. Before we launched AgentKit, I don’t even think there were many AI agents with a wallet. Maybe a handful of AI agents in the world had a wallet. So, we’re really in the early stages of this.

A lot of the things we talked about are things you need. You need some form of reputation, which makes it much more costly for an AI agent to do the wrong thing. There’s a social or financial impact to that agent for doing it. That’s one part. The second is having humans in the loop, which is another really powerful primitive.

The thing you mentioned with the flash crash is where the networks themselves would come in. For example, in this case, it might be Uniswap, which is a decentralized exchange, or Aerodrome, which is another decentralized exchange. These are all examples where they might have something like, “If there are more than this many transactions on this book in one block, we will want circuit breakers.”

The flash crash is basically a way to build a circuit breaker into the system as part of this. My sense is that, as these things come together, we’re going to be coming up with many forms of enforcement mechanisms. But probably the easiest one is just a human—a human in the loop.

At some point, I think these AIs will get so good that humans may not want to be in the loop. It’ll be like those pop-up notifications you get where you just receive too many of them. I think humans may alleviate a little bit of that responsibility, especially for lower-dollar amounts and things like that.

In that world, I think reputation and having some other form of enforcement built into the protocols themselves will be super, super critical. But all of this is something we dream about. Until the volume of AI agents doing things on the blockchain goes up, I just don’t see that happening.

The 2 things I see are, first, payments. Agent commerce seems obvious. People are already asking their agents to buy things, so x402 is a really powerful thing for that. The second thing I see is what we talked about with reputation: the blockchain is a perfect place to build reputation.

It's open access. Anyone can do it, and once you write it, you can't just change it, right? It's not like a centralized repository. For all these reasons, I think it's a really good reputation layer, and I think those are probably the 2 starting points for this.

Nathan Labenz

Gotcha. I think I'm going to want some of those circuit breakers at some point. I agree, we're not quite there yet, but it's funny—I think the models are getting there. The adoption and all the dynamics aren't there, but I don't think we need anything really all that much more powerful than your Claude 4s, Gemini 2.5s, and your o3s to really create a very dynamic agent economy. It's maybe half a generation away, but it's really not very far away.

Honestly, I've been feeling over the last 10 days that Claude 4 is smarter than me. I have to admit it. And maybe o3 too, I don't know. It's really starting to feel like, boy, these things have it where it counts. They don't have all the affordances, and we haven't created them—well, you have created them, but they haven't been adopted. When they are, it seems like it could go really fast.

One thing I've been looking out for for a long time, and I haven't really seen—maybe you have seen it, or maybe you would know why it's not happening yet, or could point me to something—is this notion that maybe AI puts the smart in smart contracts. What I mean by that is, obviously, anything you can put into fully explicit code is limited, right? That creates a sort of brittle nature to smart contracts. It doesn't feel like you're going in front of a human judge; it's much more mechanistic and deterministic, and ultimately it can't really resolve disputes between people.

On the other hand, AIs are getting there, where you might say, "Our smart contract resolution mechanism is that we will call Claude," or, "We will call Gemini 2.5, submit the evidence to it, and let it decide what is right or wrong." I think about local services. I've got a 100-year-old house, and when something needs to get fixed on it, it's not necessarily easy to find somebody. The reliability factor there is not great, but it seems like we're getting to where something like that could be possible.

I just haven't seen anybody come forward and say, "Here's my arbitration on the blockchain, powered by an AI system." Are you aware of anything that I'm missing, and what do you think is the prospect for that kind of future?

Nemil Dalal

I haven't seen anything, and I think the exciting thing would be if someone listening to this podcast went and did it, because it's all possible today. What you're saying is just a form of multisig, right? One of the people who holds the multisig is the AI agent, and it may make the decision.

As an example, it could be a 2-of-3 system. Let's say there are 2 humans in the loop and they don't agree. Only 1 of them agrees that the funds, for example, should be released, and another AI agent is there to weigh in and make a decision. It's the second one, and that's it—the decision is made.

I'll give you another example that I really loved earlier in my career. I worked for a few months with the Gates Foundation, and we worked on something called weather-indexed crop insurance. The way this stuff works is that if the rainfall is less than a certain amount, you automatically pay out. But the question is, how do you figure that out, right? Typically, that involves some form of data source that needs to align and make a decision about whether the funds should be released.

For this growing season, you could have $1,000. The money is there, investors are putting the money in, and the money goes to the investors if the rainfall is more than a certain amount. If it's less than a certain amount, then it goes to the farmer. This is a really great example where AI can be plugged in.

All the AI has to do is say, "On this date, the AI should weigh in and review the precipitation over the course of the last 6 months," and then unlock the funds and let it be on its way. All of this is possible today.

I'll say 1 other thing for folks on the AI side: there's this interesting thing in crypto where oracles are the hard problem. Blockchains and smart contracts can only access what's on the blockchain, and there are a lot of things in the world, like weather information, that aren't on the blockchain. They use something called oracles to do it.

The idea you came up with is, "Let's just use AI as that oracle," right? We should trust the AI. Hopefully, the AI doesn't hallucinate and things like that, but if we believe in that AI and think it's pretty high-quality, then that's a really great example where suddenly the AI is the oracle. It can decide how to vote using its key whenever it needs to be called in.

I would just say that I haven't seen it, and it would be amazing. This is relatively simple to do. If anyone here wants to reach out to me on Twitter or anywhere else, I'm super excited to give them details and help them get set up if they wanted to do this on the AI side. Basically, you need an AI you trust and some type of problem where you want it to weigh in, and then suddenly the AI can absolutely do that.

Nathan Labenz

Do you also need—I mean, it strikes me that AIs are very gullible. I'm a close follower of the AI bad-behavior research, and much of that research is done by telling the AI that nobody will read your private scratchpad. You can think about what you want to do there, and then you can take your action here. Of course, the researchers are reading the private scratchpads, and that's where they're seeing some of the evidence of the bad behavior.

More generally, they're easy to trick. A hard thing from the perspective of the AI would be knowing what constitutes authentic evidence and what is made up. Is that really a picture of your roof? Was that picture taken now, or was it taken a month ago? You're saying it's not fixed, but I can't tell if that picture was taken today or a month ago.

It seems like we may also need some sort of provenance technology, like on-device signing of photos. In your weather example, it would be some sort of indication that a sensor in the field is actually in the field where it's reported to be, so we can trust the raw numbers. Then the AI can provide the analysis on top of those raw inputs, but we still need the AI to have confidence that it's actually dealing with real evidence that it can reliably reason over.

Do we have a little bit of that, but not much? How would you characterize the state of how much we can demonstrate to AI that the evidence we're submitting to it is, in fact, authentic?

Nemil Dalal

There are 2 parts, right? One is: is the evidence we're submitting authentic? The second part is: is the AI hallucinating, or is it being goaded in a certain direction? By the way, I've seen AI agents that have Twitter accounts, and we've seen examples in the community where the AI agents have mistakenly been hacked or goaded into giving out money in a way that they shouldn't have. I would say both are critical and both are important to get right.

But with any form of technology, I think you start somewhere where it's possible. Take the satellite example of rainfall: the question of whether, over the course of a growing season, there's enough rainfall could just be answered with satellite data. You don't need a human. On the roof example, you're right: you absolutely have to figure out provenance. You might want a third party to take the picture rather than the person who's insured.

The weather-indexing example could literally use satellite data that Google has, or that anyone else has. There could be a satellite company with an API that you access. These are all examples of how you could do it.

My instinct is that to get this perfect and do it at scale, you absolutely need to solve both of those problems over time. But the goading problem, which may be even a step further than that, could be solved by not putting the AI online—by only having an expert be able to access it, and by not allowing it to accept other inputs after that.

When you have satellite information or things like that, those are very precise and not super-complex problems. That's where a lot of this stuff starts. It doesn't start with the hardest problem on day 1. It starts with a very specific problem: Google has the data, and there's a human with some funds and a wallet. Let's combine those 2 things together, and that works.

Nathan Labenz

Cool. Well, I really appreciate your time, and I know we've run a little long. Maybe just a final opportunity to take the floor: if there's anything we haven't covered at the intersection of AI and crypto that you'd like to highlight, or any elaborations on the positive vision that you'd want to try to inspire people with.

Nemil Dalal

All I'll say is that we're scratching the surface on how crypto and AI can come together.

I think crypto is a really powerful financial system for AI agents, and x402 is just the start of that. You and I talked a little bit today about things like reputation and other things that haven’t even been really tested yet. So I would just say, if you’re building an AI today, I’m super excited for you to be able to try out x402. That’s x402.org.

You can also DM me directly on Twitter if anyone wants to talk more or engage on anything. There’s so much innovation possible because we’re finally bringing these two technologies together, and I’m super excited to see what people build with it.

Nathan Labenz

Cool. Nemil Dalal, developer platform lead at Coinbase and one of the lead developers of the 402 Payment Required, aka x402 protocol. Thank you for being part of The Cognitive Revolution.

Nemil Dalal

Thanks so much.