Sato Hub
← Back to blogMetaMask Ships Agent Wallet — With an Off Switch

MetaMask Ships Agent Wallet — With an Off Switch

Guard Mode and Beast Mode give AI agents onchain spending power, but the permission layer is the actual product.

2026-08-08 · 3 min read

MetaMask opened early access to Agent Wallet on Thursday, August 6 — a self-custodial wallet built so an AI agent, not a human, holds the keys and executes transactions on your behalf. Not a wrapper prompt bolted onto a browser extension. A wallet product with its own permission model, and that permission model is the actual story.

What an agent can do with it

Inside an Agent Wallet, an AI agent can swap tokens, open perpetuals positions, participate in prediction markets, and interact with DeFi protocols — across every EVM chain MetaMask supports, plus Hyperliquid. It plugs into agent frameworks including Claude Code, Codex, Cursor, OpenClaw, Hermes, and OpenCode, so the wallet sits as the execution layer underneath whatever's doing the reasoning.

General access is slated for later this summer; for now it's early access only.

The permission layer is where the design happens

Two modes, and the gap between them is the product:

  • Guard Mode — any transaction outside the rules you set requires your manual approval. Slower, but a human stays in the loop on everything.
  • Beast Mode — cuts down on approval interruptions so the agent can act with less friction. Flagged or suspicious transactions still force two-factor authentication regardless of mode.

Before an agent gets turned loose, a user sets daily spending limits and a protocol whitelist. That's the actual constraint surface: not "trust the agent," but "bound the agent."

The security stack underneath

MetaMask layered three checks on top of the permission model: transaction simulation for supported EVM transactions (see the outcome before it executes), Blockaid-powered threat scanning, and MEV protection that's fixed — the agent cannot override those checks, even in Beast Mode. That last detail matters more than it sounds: the fastest way to break a "safe" autonomous system is letting the autonomous part switch off its own safety rail. Here it can't.

The take

This is the part of the agent economy that gets skipped in the demos. Everyone wants to show an agent trading; nobody wants to show the spending-limit dialog. MetaMask shipping Guard Mode / Beast Mode as a first-class wallet feature, not an afterthought, is the tell that "AI agent with a wallet" is graduating from party trick to product category. If an agent can move funds, "trust me bro" isn't a security model — a whitelist and a spending cap are. That's the same principle behind any serious onchain-agent build: the wallet isn't a detail, it's the risk surface.

Worth separating claimed from shown: this is early access, not a public GA release, and "later this summer" is MetaMask's own timeline, not an independently confirmed one. The security stack — simulation, Blockaid scanning, fixed MEV protection — is MetaMask's own description of the product; no independent third party has put it through public stress-testing yet. That's not a knock on the design, it's just the gap that matters before an agent with real spending authority gets pointed at your funds.

What to watch

Whether Beast Mode's lower-friction default becomes the norm once general access ships, and whether the two-factor backstop on flagged transactions holds up once agents — and attackers — start probing it at scale. Any wallet-permission product's real test isn't the demo, it's the first exploit attempt against the whitelist.

Sources

  • [MetaMask Launches Agent Wallets](https://www.bankless.com/read/news/metamask-launches-agent-wallets) — Bankless

Sources

Join the Sato Hub Briefing

One email a week — the agents, tools, and infrastructure that actually shipped, and why they matter.