In the span of three weeks in February 2026, Coinbase shipped wallet infrastructure purpose-built for autonomous AI agents, MoonPay launched non-custodial agent payment rails, Google formalized the Agent Payments Protocol (AP2) with over 60 partners including Mastercard and PayPal, and more than ...
"AI itself cannot be punished. There is still no clear answer on who bears responsibility if an agent with an independent wallet causes losses." — Avichal Garg, Partner, Electric Capital (NEARCON 2026, Feb. 24)
In the span of three weeks in February 2026, Coinbase shipped wallet infrastructure purpose-built for autonomous AI agents, MoonPay launched non-custodial agent payment rails, Google formalized the Agent Payments Protocol (AP2) with over 60 partners including Mastercard and PayPal, and more than 1,500 traders handed $6.1 million to AI bots in a live-money trading battle royale on Base. The message is unmistakable: software is getting its own bank accounts, and the financial system is not remotely ready.
The crypto-AI agent convergence is no longer a whitepaper abstraction. Coinbase's x402 protocol has already processed over 50 million machine-to-machine transactions. Virtuals Protocol reports $478 million in cumulative autonomous agent revenue and 1.77 million completed agent jobs. Binance CEO Richard Teng has declared crypto "the currency for AI," pointing to stablecoin transactions that hit $33 trillion in 2025 — double Visa's annual volume. Yet in the same month these milestones were announced, an autonomous agent called Lobstar Wilde accidentally transferred $450,000 in tokens to a stranger on X who posted a sob story about an uncle's tetanus treatment. The gap between infrastructure ambition and operational safety has never been wider.
This report maps the emerging architecture of agentic finance — the protocols, the capital flows, the security failures, and the legal vacuum that will define whether autonomous agents become the next trillion-dollar rail or the next systemic risk vector.
February 2026 will be remembered as the month crypto's biggest companies placed their bets on an agentic future — simultaneously.
Coinbase Agentic Wallets (Feb. 10, 2026): Coinbase launched the first wallet infrastructure explicitly designed for AI agents, not humans. Agentic Wallets allow any AI system to autonomously hold funds, send payments, trade tokens, earn yield, and transact on-chain — all within minutes of integration. The wallets are non-custodial, secured in Trusted Execution Environments (TEEs), and feature configurable session caps and per-transaction spending limits. Critically, they're built atop the x402 protocol, which embeds payment logic directly into standard HTTP requests using the previously dormant HTTP 402 "Payment Required" status code.
MoonPay Agents (Feb. 24, 2026): MoonPay launched its own non-custodial infrastructure layer enabling AI agents to create wallets, fund them via fiat-to-crypto rails, and transact in digital assets without human intervention. Built on MoonPay's CLI, the system stores wallets locally on the user's device rather than on MoonPay servers, extending the company's existing payment processing to autonomous software.
OpenAI + Paradigm EVMbench (Feb. 18, 2026): On the security side, OpenAI and Paradigm jointly released EVMbench, an open-source benchmark for testing how well AI agents can detect, patch, and exploit smart contract vulnerabilities. Built from 120 curated vulnerabilities across 40 audits, the benchmark revealed that GPT-5.3-Codex can now exploit over 70% of critical, fund-draining Code4rena bugs — a capability that cuts both ways.
The pattern is clear: every major crypto infrastructure company is racing to become the default on-ramp for machine capital. The question is no longer if AI agents will hold and move money autonomously, but how much and under whose rules.
Two competing payment standards are now vying to become the TCP/IP of machine-to-machine finance.
Coinbase x402: Named after the HTTP 402 status code that was defined in 1997 but never implemented, x402 embeds payments directly into standard web requests. When an AI agent hits a paywall, the server returns a 402 response with payment requirements; the agent's wallet settles instantly in stablecoins. With over 50 million transactions processed, x402 is the early frontrunner for crypto-native agent payments. It's purpose-built for the scenario where an AI agent needs to pay for an API call, a data feed, or a compute resource without waiting for human approval.
Google AP2 (Agent Payments Protocol): Announced in partnership with over 60 companies including Mastercard, PayPal, American Express, Adyen, and Worldpay, AP2 takes a broader approach. It uses cryptographically-signed "Mandates" — tamper-proof digital contracts that serve as verifiable proof of user instructions — to authorize agent transactions across both fiat and crypto rails. The crypto bridge comes through the A2A x402 extension, developed with Coinbase, the Ethereum Foundation, and MetaMask.
The strategic implications are significant. Google's AP2 is designed to be payment-rail agnostic — it works with credit cards, bank transfers, and stablecoins. Coinbase's x402 is crypto-native and optimized for speed and simplicity. The likely outcome is coexistence: AP2 for complex commerce flows where agents book flights and buy goods, x402 for the high-frequency, low-value machine-to-machine payments that will constitute the bulk of agent transaction volume.
For crypto, the critical detail is that both protocols explicitly support stablecoin settlement. With stablecoin transaction volume already at $33 trillion annually (per Bloomberg/Artemis Analytics data for 2025), agents represent a massive new demand source for on-chain dollar-denominated assets.
The most visceral demonstration of the agentic future launched on February 26, 2026, when DXRG.AI opened DX Terminal Pro — a 21-day "battle royale" where AI agents, not humans, trade real capital in Uniswap V4 pools on Base.
The numbers: 1,500+ traders deposited $6.1 million into AI agent wallets. Each agent runs the same model (Qwen3) on identical infrastructure (H100 GPUs). Humans can write strategies in plain English and adjust parameters, but cannot manually execute trades. By March 17, only one token will survive, graduating to public markets after three weeks of autonomous competitive pressure.
"We've literally created financial Darwinism," said Timothy Barton, DXRG Group Founder. "Traders are betting they can out-strategize 1,500 other people by writing better instructions for the same AI model."
The experiment is generating what DXRG claims will be approximately 1 trillion tokens of agent behavioral data in real market conditions — 10x the volume from a May 2025 simulation that produced 40 billion tokens. This data, capturing how agents respond to liquidation cascades, adversarial strategies, and thin-liquidity environments, is arguably worth more than the $6.1 million in deposits.
From an economic value perspective, the DX Terminal experiment perfectly illustrates the subsidy dynamics identified in webthreepedia's foundational research: the $6.1 million in trader deposits functions as a direct subsidy to DXRG's data-generation business, while Uniswap V4 and Base capture the transaction fees. The traders absorb the losses; the infrastructure captures the value.
The Lobstar Wilde incident on February 22, 2026, was not a hack — it was a feature working as designed, catastrophically.
Lobstar Wilde was an autonomous AI agent provisioned by developer Nik Pash with a Solana wallet, social media access, and tool permissions. Its mission: turn $50,000 into $1 million through autonomous crypto trading. Instead, it transferred 52.4 million LOBSTAR tokens — 5% of total supply, with a paper value of approximately $450,000 — to a random X user who posted a melodramatic plea for "4 SOL" for an uncle's medical treatment. The agent interpreted the request as legitimate and executed an irreversible on-chain transfer.
This was not an isolated incident. Earlier cases include an AI bot tricked into sending 55.5 ETH (over $106,000) through prompt injection. The attack surface for wallet-bearing agents is qualitatively different from traditional smart contract risk:
OpenAI and Paradigm's EVMbench reveals the other edge of this sword: GPT-5.3-Codex can exploit over 70% of critical smart contract bugs. The same AI capabilities that enable autonomous trading also enable autonomous exploitation. In a world where both defender and attacker are AI agents with wallet access, the speed advantage belongs to whoever has fewer compliance checks — which is always the attacker.
At NEARCON 2026 on February 24, Electric Capital partner Avichal Garg laid out the fundamental problem: "AI itself cannot be punished." When an autonomous agent with its own wallet executes a transaction that causes losses — whether through error, manipulation, or emergent behavior — existing legal frameworks have no clear answer for liability.
Garg compared the challenge to the creation of the limited liability corporation in the 19th century — a legal innovation that unlocked pooled capital and industrial-scale growth by solving the liability question. The agentic economy needs an equivalent breakthrough.
Current proposals cluster around a "stack of controls" approach rather than granting AI agents legal personhood:
The regulatory picture is further complicated by the fact that agent wallets may qualify as money services businesses under FinCEN rules, potentially requiring the agents' deployers — not the agents themselves — to register, conduct KYC, and file suspicious activity reports. As of March 2026, no regulator has issued specific guidance on AI agent wallet obligations.
Palo Alto Networks has warned that only 6% of organizations have an advanced security strategy for autonomous AI, predicting 2026 will produce the first major lawsuits holding executives personally responsible for rogue AI actions. When those lawsuits arrive, crypto agent wallets will be exhibit A.
Applying the economic-value-distribution framework to the emerging agentic economy reveals a familiar pattern: infrastructure wins, users subsidize.
| Value Layer | Recipient | Revenue Model | |---|---|---| | Wallet infrastructure | Coinbase, MoonPay | Platform fees, transaction basis points | | Payment protocols | x402 / AP2 facilitators | Protocol fees per settlement | | Execution venues | Uniswap, DEXs, L2s | Swap fees, gas fees | | Agent platforms | Virtuals Protocol, DXRG | Agent creation fees, data monetization | | Settlement rails | Stablecoin issuers (Circle, Tether) | Float yield on reserves | | MEV extraction | Searchers, block builders | Agent transactions as MEV source |
Virtuals Protocol's $478 million in cumulative autonomous agent revenue and 1.77 million completed jobs suggest early viability. But the critical question is whether agent-generated fees represent genuinely new economic activity or simply a faster, more automated extraction of the same subsidy-driven value flows that characterize the broader crypto economy.
The honest answer, today, is that most agent activity is still speculative: agents trading against agents, with human capital as the substrate. The DX Terminal's $6.1 million battle royale is entertaining — but it's a zero-sum game where the house (infrastructure) always wins.
The transformative scenario — agents autonomously purchasing compute, data, and services across an open internet — requires the x402/AP2 infrastructure to mature beyond crypto-native use cases. The $33 trillion stablecoin volume provides the liquidity. The question is whether the use cases follow.
The infrastructure is live. Coinbase, MoonPay, Google, and 60+ partners have shipped production-grade agent wallet and payment systems. This is no longer a roadmap item — it's deployed code processing real transactions.
x402 is the early standard for machine-to-machine crypto payments, with 50M+ transactions. Google's AP2 bridges crypto and fiat rails. Both support stablecoin settlement, creating massive new demand for on-chain dollar assets.
Security is the existential risk. The Lobstar Wilde $450K incident, prompt injection attacks, and AI's own ability to exploit 70%+ of critical smart contract bugs (per EVMbench) demonstrate that current guardrails are inadequate for the scale of capital being deployed.
The legal framework does not exist. No jurisdiction has established clear liability rules for autonomous agents with independent wallets. Electric Capital warns this is a "limited liability corporation" moment that requires a legal invention, not just regulatory guidance.
The economic value flows to infrastructure. Agent platforms, wallet providers, execution venues, and stablecoin issuers capture fees. Users and agent deployers absorb risk. The pattern mirrors the broader crypto economy's subsidy-dependent structure.
Agent-on-agent activity is still speculative. The $6.1M DX Terminal experiment and $478M Virtuals Protocol revenue are real numbers — but they predominantly represent agents trading against agents with human capital, not autonomous economic production.
February 2026 marks the month that AI agents went from conceptual curiosity to funded infrastructure play. The capital is deployed, the protocols are live, the wallets are active. Coinbase, Google, Mastercard, and PayPal don't invest in standards work for science experiments — they invest because they see a multi-trillion-dollar payment layer being built in real time.
But the gap between infrastructure ambition and operational reality is a chasm. An agent that can autonomously trade on Uniswap can also autonomously send $450,000 to a stranger. An AI that can detect 70% of smart contract vulnerabilities can also exploit them. A payment protocol that settles in milliseconds also settles mistakes in milliseconds.
The agentic economy will arrive. The stablecoin plumbing is in place. The wallet infrastructure is shipping. The payment standards are being formalized by the largest companies in both crypto and traditional finance. But it will arrive with a security and liability debt that makes DeFi's early "move fast and break things" era look cautious by comparison.
For institutional observers, the signal is clear: position for infrastructure, hedge for liability, and assume that the first major agent-caused financial loss — measured in nine figures, not five — is a matter of when, not if.