MetaMask launched a self-custodial wallet built for AI agents on June 8, 2026, giving autonomous software the ability to trade across decentralized finance while users keep control through spending limits, protocol allowlists, and two-factor approval on risky transactions. The Consensys-owned wallet, the most widely used in crypto, opened the product to roughly 200 traders and developers through an early-access program, with a public release planned for later this summer. The Agent Wallet covers swaps, perpetual futures, prediction markets, and liquidity provisioning across Ethereum and eight other compatible chains.
An AI agent is software that can take actions on its own, such as placing trades or moving funds, without a person approving each step. Letting that software hold and spend crypto has been the missing piece for autonomous on-chain finance, and it is also the part most likely to go wrong.
- MetaMask’s Agent Wallet lets AI agents trade DeFi autonomously under user-set spending limits and allowlists.
- Every agent transaction runs through simulation, threat scanning, and MEV protection, with up to $10,000 in loss coverage on safe trades.
- Private keys sit inside a hardware-isolated enclave using Cubist technology, so MetaMask and Consensys cannot access them.
- Access is limited to about 200 users now, with a wider rollout expected later in summer 2026.
Published: June 8, 2026, 16:00 UTC
Why a wallet for bots is a hard problem
Handing an autonomous agent the keys to real money invites two failure modes: the agent makes a costly mistake, or an attacker hijacks it. MetaMask’s answer is to wrap every agent action in checks before it reaches the chain. Each transaction is simulated, scanned for malicious addresses, and routed through MEV protection ahead of execution. MEV, or maximal extractable value, is profit that bots capture by reordering or inserting transactions in a block, often at a regular trader’s expense.
Transactions the system flags as malicious are paused until a human clears them through two-factor authentication. Trades judged safe fall under MetaMask’s Transaction Protection program, which covers up to $10,000 in losses. The design assumes agents will err and tries to make those errors survivable rather than catastrophic.
The wallet offers two operating modes. Guard Mode requires users to pre-approve the protocols and addresses an agent can touch, and anything off that list triggers 2FA. Beast Mode drops the upfront allowlist and instead scans addresses in real time, prompting for approval only when something looks dangerous. Guard Mode favors oversight; Beast Mode favors hands-off automation.
How the keys stay locked down
Security rests on Cubist’s trusted execution environment, hardware that isolates sensitive computation from the rest of a system. Private keys stay inside that enclave during signing, which means neither MetaMask nor Consensys can reach the underlying key material. A trusted execution environment is a protected area of a processor that runs code and stores data where other software, including the operating system, cannot see it.
The wallet supports Ethereum Virtual Machine chains plus Hyperliquid, and connects to agent frameworks including OpenAI Codex, Anthropic’s Claude Code, Cursor, OpenClaw, and Hermes Agent. Protections span Ethereum, Linea, Arbitrum, Avalanche, Optimism, Base, Polygon, BNB Chain, and Sei. That reach matters because perpetual futures and prediction markets, two of the supported activities, draw heavy volume on networks like Hyperliquid, which has seen its own token supply debates in recent weeks.
What it signals for the market
Consensys CEO and Ethereum co-founder Joe Lubin framed the launch as a structural shift. “The next great expansion of the onchain economy won’t be driven by humans alone,” he said. “Agents will manage real capital and make real financial decisions, and the infrastructure underneath has to be worthy of that.”
The bet is that autonomous agents become a meaningful share of on-chain activity, and that whoever controls the safest rails for them captures the flow. Researchers have warned through 2026 that AI agents transacting on-chain open a security gap, since a compromised agent can drain funds faster than a human can react. MetaMask is positioning its allowlists, simulation, and loss coverage as the guardrails that make agent-driven finance usable for businesses rather than just experiments.
For now the product is gated to a small group, and the $10,000 coverage cap signals caution about how much MetaMask is willing to backstop. The wider summer rollout will test whether agent wallets attract real capital or stay a developer curiosity. What comes next is competition: rival wallets and custody providers are likely to ship their own agent controls as institutions weigh handing trading decisions to software.
Frequently asked questions
What is the MetaMask Agent Wallet?
It is a self-custodial wallet from MetaMask that lets AI agents trade and interact with DeFi protocols on their own, while users set spending limits, approved protocols, and two-factor checks on risky transactions. It launched in early access on June 8, 2026.
How does it protect against losses?
Every agent transaction is simulated, scanned for malicious addresses, and run through MEV protection. Flagged transactions need human approval via 2FA, and trades deemed safe carry up to $10,000 in coverage through MetaMask’s Transaction Protection program.
Who can use it right now?
Access is limited to roughly 200 traders and developers through an early-access program. MetaMask plans a broader public release later in the summer of 2026.








