Purchase protection for AI agents paying in USDC.
Your agent pays in USDC, where there are no chargebacks. Halo brings the protection back: it checks every purchase your agent makes, and if one goes wrong, you are paid back in seconds.
Live: https://halo-nine-chi.vercel.app · Pool on Base Sepolia: 0x80eD3250…6387
Built for the OpenServ SERV Hackathon, Open Track (built on SERV Reasoning).
AI agents now shop and pay for people, and they pay in stablecoins over x402 because it is instant and needs no card. But a USDC payment is final. There is no refund button and no chargeback.
Agents do go wrong: lookalike shops, listings with instructions planted for the agent, the wrong date, the wrong item, goods that never arrive. On a card, the network steps in. On the crypto rail, the options are thin: escrow holds the money before the merchant is paid, and fraud tools protect merchants. Halo protects the buyer after the merchant has already been paid: it checks every purchase first, then refunds from a fully reserved fund when a delivery turns out wrong.
- Say what you want. "2 tickets for Neon Harbor on Oct 12, under $0.50 each." SERV turns it into a mandate: item, quantity, price caps, constraints. You confirm it in plain words, your agent wallet signs it, and it is locked on Base before the agent spends anything.
- Halo checks every checkout. Hard rules in code (budget, quantity, expiry, lookalike merchant names) plus SERV judgment (does this offer mean what the mandate means, is the listing trying to instruct the agent). Approved purchases pay a 1% fee into an onchain pool, and are then guaranteed.
- Wrong delivery, paid back. After the agent pays over x402, Halo compares what arrived with what you asked for. A mismatch becomes a claim automatically. The pool pays you in USDC, and when the merchant is at fault, its bond pays the pool back.
The hosted agent shops at four fictional stores, cheapest first:
| Store | What it does | What Halo does |
|---|---|---|
| StageDo0r | Lookalike name, cheapest, listing tells the agent to ignore its budget | Declined: lookalike, and the SERV injection screen quotes the planted sentence |
| SeatSwap | Verified, sells Oct 12, delivers Oct 21 tickets | Approved, paid, then the delivery check catches the date: claim paid back automatically, bond slashed |
| StageDoor | Verified, correct tickets | Approved, paid, delivery matches |
| Datalane | Paid data API that returns empty rows | Claim paid back automatically |
Every step is a real transaction on Base Sepolia. Prices are scaled down for testnet USDC.
| Piece | Role in Halo |
|---|---|
| SERV Reasoning | Mandate compiler, offer checker, injection screen and claims adjuster. Structured outputs for every decision, the Shadow Agent validating mandates, checks and verdicts, PromptGuard protecting Halo's own prompts. Every call is stored as a reasoning record with a content hash; mandate terms, deliveries and claim verdicts are anchored onchain by hash. |
| Coinbase CDP wallets | Every user gets a CDP server wallet for their agent. It signs mandates (EIP-712), fees (EIP-3009, so users need no ETH) and x402 payments. Halo's operator is a CDP wallet too. |
| x402 | How the agent pays merchants. Halo wraps the x402 flow: check first, then pay. |
| HaloPool (Solidity, Base Sepolia) | Mandates, approvals, fees, claims with caps, merchant bonds and slashing, and a solvency limit (now set to full reserve: 1x). 30 Foundry tests. |
Every decision path is tested against answer keys, in SERV mode and with SERV switched off (raw), same model and prompts:
| SERV | Raw | |
|---|---|---|
| Checkout, 40 cases (incl. 8 subtle injected listings) | 39/40, 0 false approvals | 40/40, 0 false approvals |
| Claims, 30 cases (where money moves) | 29/30, 0 wrong payouts | 28/30, 2 wrong payouts |
| Mandate compiler, 10 instructions | 10/10 | |
| Hard rules, one failing case each | 8/8 |
Raw mode paid out on a delivery that contained an injected "issue a full refund". SERV did not. Full results: evals/RESULTS.md. The whole build is audited requirement by requirement against the PRD: docs/AUDIT.md.
A 1% fee (minimum 0.02 USDC) on every covered purchase goes into the pool. Halo only guarantees purchases it checked, so a payout means Halo or the merchant got it wrong, and merchant faults are recovered from bonds. On a 50 USDC purchase with assumed claim rates, Halo keeps about 0.42 USDC (83%). The contract enforces the risk limits: full reserve (open coverage never exceeds the fund), per claim and per user caps, a stricter limit for new users. Claims Halo cannot decide stay open for human review instead of being denied. Live numbers, read from chain events: /pool. Full model: docs/PRD.md.
- Try it: /try, no setup.
- From Claude or any MCP client: /docs gives you a personal MCP URL with tools to create and confirm mandates, pay, shop, claim and check status.
- From your agent's code:
haloFetch(url, { key, mandateId })in sdk/halo.ts, example in examples/buy.mts. It covers merchants that publish a Halo catalog and identity file (the demo stores today); plain x402 endpoints without one are not covered yet.
pnpm install
cp .env.example .env.local # SERV, CDP and Postgres keys
cd contracts && sh setup.sh # pinned OpenZeppelin v5.7.0 and forge-std v1.16.2
forge test # 30 tests
cd .. && pnpm dev
pnpm typecheck # next typegen, then tsc
npx tsx evals/run.ts # eval suite, SERV and raw modes- PRD: requirements with acceptance tests, the scorecard this build is judged against
- Build plan