MetaMask has introduced Agent Wallet, a command-line wallet framework designed to let AI agents transfer assets, execute swaps and interact with on-chain financial applications programmatically. The system gives agents transaction authority while placing security checks between an AI-generated instruction and the final blockchain signature. MetaMask positions the product as self-custodial infrastructure for autonomous agents operating across multiple EVM networks.
According to the official MetaMask Agent Wallet documentation, the framework is built around the mm command-line interface and an agent skills package that translates natural-language requests into wallet commands. The current quickstart requires Node.js 22.18 or later and an AI agent capable of using skills, with MetaMask listing environments including Claude Code, Codex, Cursor, OpenClaw and Hermes Agent.
Agent Wallet Separates Wallet Control From AI Instructions
Setup begins by installing the CLI and adding MetaMask’s agent skills before choosing a sign-in method. Users can authenticate through Google, passwordless email or MetaMask Mobile QR, but each method resolves to a different wallet address. The user then chooses between a server wallet and a bring-your-own-wallet configuration, creating materially different key-management models.
In server-wallet mode, keys are secured server-side inside a trusted execution environment and the agent operates a dedicated wallet rather than gaining access to the user’s primary wallet. The alternative accepts a BIP-39 mnemonic and keeps key control on the user’s machine. MetaMask describes both models as self-custodial, but their security boundaries differ because one relies on server-side TEE key management while the other stores the signing material locally.
Guard Mode and Beast Mode apply only to the server-wallet configuration. Guard Mode enforces network, address and token-recipient allowlists alongside a rolling 24-hour outflow limit, while Beast Mode removes those restrictions to reduce interruptions. Both modes continue to screen for malicious or risky transactions, with flagged operations requiring user approval. In Guard Mode, transactions outside established policies can also trigger 2FA.
That architecture reflects a broader race to define financial boundaries for autonomous software. Coinbase has already introduced Agentic Wallets for autonomous crypto agents, while MoonPay’s Open Wallet Standard uses policy controls and key isolation to address a similar problem. The emerging competitive question is increasingly how much authority an agent receives and where enforcement occurs, rather than simply whether an AI can submit blockchain transactions.
MetaMask Extends Agents Into Trading and Payments
Once configured and funded, Agent Wallet exposes commands for token transfers, swaps, cross-chain bridges, Hyperliquid perpetuals, Polymarket prediction markets, yield vaults and x402 payments. It currently supports numerous EVM mainnets, although individual features and MetaMask’s Transaction Shield coverage vary by network. Users are instructed to check the CLI’s current network list rather than assuming every capability works uniformly across every supported chain.
Every supported transaction follows a security pipeline that includes transaction simulation and threat scanning, while Smart Transactions can add MEV protection and execution optimization on eligible networks. Server-wallet requests may also enter an AWAITING_MFA state until the user approves them through MetaMask Mobile or email. Agent autonomy is therefore conditional: software can initiate and execute permitted activity automatically, but policy violations and detected risks can reintroduce human authorization.
That distinction matters as autonomous agents become capable of browsing external systems and moving funds. Research into malicious webpages manipulating autonomous agents has highlighted how valid wallet permissions can become dangerous when an agent follows hostile instructions. MetaMask’s approach attempts to move part of that defense into the wallet execution layer itself.
Agent Wallet is operational developer infrastructure rather than evidence of large-scale autonomous trading adoption. MetaMask documents the available commands, supported networks and security architecture, but does not provide transaction volume, active-agent counts or recurring usage metrics demonstrating production-scale demand. The product’s significance currently lies in giving developers a concrete controlled execution layer for AI agents, while real-world adoption remains a separate metric.
