{"data":{"slug":"agent-wallet-threat-model","title":"Agent Wallet Threat Model: Keys, Sessions, Budgets, and Receipts","tags":["AI Privacy","Wallets","OPSEC"],"desc":"A practical threat model for AI-agent wallets: key custody, prompt injection, sessions, budgets, receipts, approval policies, wallet reuse, and privacy logs.","time":"~5 min read","date":"2026-07-05","lastReviewed":"2026-07-13","contentKind":"brief","editorialStatus":"ok","url":"https://cunicula.com/en/articles/agent-wallet-threat-model","answer":"A practical threat model for AI-agent wallets: key custody, prompt injection, sessions, budgets, receipts, approval policies, wallet reuse, and privacy logs.","sources":[{"label":"AP2 v0.2 specification","url":"https://ap2-protocol.org/ap2/specification/"},{"label":"Coinbase x402 docs","url":"https://docs.cdp.coinbase.com/x402/welcome"},{"label":"Stripe machine payments docs","url":"https://docs.stripe.com/payments/machine"},{"label":"Ethereum privacy documentation","url":"https://ethereum.org/en/privacy/"},{"label":"OWASP prompt injection guidance","url":"https://genai.owasp.org/llmrisk/llm01-prompt-injection/"}],"section_headings":["Main assets","Main failure modes","Safer architecture","Minimum controls"],"related_articles":[{"slug":"score-agent-payment-rail","title":"Evaluating AI-Agent Payment Methods","tags":["AI Privacy","Payments","OPSEC"],"desc":"A practical scoring rubric for AI-agent payment rails: identity exposure, authorization, settlement, custody, autonomy, revocation, logs, and privacy fit.","time":"~5 min read","date":"2026-07-05","lastReviewed":"2026-07-13","contentKind":"brief","editorialStatus":"ok","url":"https://cunicula.com/en/articles/score-agent-payment-rail","answer":"A practical scoring rubric for AI-agent payment rails: identity exposure, authorization, settlement, custody, autonomy, revocation, logs, and privacy fit.","sources":[{"label":"Privacy AI agent cards page","url":"https://agents.privacy.com/"},{"label":"AP2 protocol docs","url":"https://ap2-protocol.org/"},{"label":"Coinbase x402 docs","url":"https://docs.cdp.coinbase.com/x402/welcome"},{"label":"Stripe machine payments docs","url":"https://docs.stripe.com/payments/machine"}],"section_headings":["The seven fields that matter","Autonomy is a risk score","How to use the score","Scoring rubric"]},{"slug":"unbroker-ai-data-broker-removal-agent","title":"Local-First Data Broker Removal: Extraction, Deletion, and Rechecks","tags":["AI Privacy","OPSEC","Data Brokers"],"desc":"A local-first workflow for finding data-broker records, approving least-disclosure opt-outs, tracking proof, escalating to a human, and rechecking for reappearance.","time":"~10 min read","date":"2026-07-05","lastReviewed":"2026-08-05","contentKind":"guide","editorialStatus":"ok","url":"https://cunicula.com/en/articles/unbroker-ai-data-broker-removal-agent","answer":"A local-first workflow for finding data-broker records, approving least-disclosure opt-outs, tracking proof, escalating to a human, and rechecking for reappearance.","sources":[{"label":"California Data Broker Registry","url":"https://cppa.ca.gov/data_broker_registry/"},{"label":"unbroker README on GitHub","url":"https://github.com/NousResearch/hermes-agent/tree/main/optional-skills/security/unbroker"},{"label":"BADBOOL broker opt-out list","url":"https://github.com/yaelwrites/Big-Ass-Data-Broker-Opt-Out-List"},{"label":"Hermes Agent unbroker skill docs","url":"https://hermes-agent.nousresearch.com/docs/user-guide/skills/optional/security/security-unbroker"},{"label":"California DROP official page","url":"https://privacy.ca.gov/drop/"},{"label":"EFF digital-footprint guide","url":"https://ssd.eff.org/module/how-to-manage-your-digital-footprint"}],"section_headings":["What it is","What to check","What matters operationally","How DROP changes removal work in California","Separate extraction from removal","Self-hosting and fallback boundaries","Limits","Before using a removal agent"]},{"slug":"virtual-cards-vs-stablecoin-wallets-ai-agents","title":"Virtual Cards vs Stablecoin Wallets for AI Agents","tags":["AI Privacy","Payments","Wallets"],"desc":"A privacy-first comparison of virtual cards and stablecoin wallets for AI-agent spending: KYC, issuer logs, onchain history, revocation, budgets, and merchant fit.","time":"~4 min read","date":"2026-07-05","lastReviewed":"2026-07-05","contentKind":"brief","editorialStatus":"ok","url":"https://cunicula.com/en/articles/virtual-cards-vs-stablecoin-wallets-ai-agents","answer":"A privacy-first comparison of virtual cards and stablecoin wallets for AI-agent spending: KYC, issuer logs, onchain history, revocation, budgets, and merchant fit.","sources":[{"label":"Privacy AI agent cards page","url":"https://agents.privacy.com/"},{"label":"Coinbase x402 docs","url":"https://docs.cdp.coinbase.com/x402/welcome"},{"label":"Stripe machine payments docs","url":"https://docs.stripe.com/payments/machine"}],"section_headings":["Virtual-card strengths","Stablecoin-wallet strengths","How to choose","Comparison checklist"]},{"slug":"qwen38-obliterated-local-model","title":"Qwen3.8-27B OBLITERATED: Why the Same Model Gives Different Answers","tags":["AI Privacy","Local AI","Guide"],"desc":"What Qwen is, what the unofficial OBLITERATED version changed, why local AI apps can produce different answers, and the developer's 23 August 2026 GGUF redownload notice.","time":"~6 min read","date":"2026-08-22","lastReviewed":"2026-08-23","contentKind":"brief","editorialStatus":"ok","url":"https://cunicula.com/en/articles/qwen38-obliterated-local-model","answer":"What Qwen is, what the unofficial OBLITERATED version changed, why local AI apps can produce different answers, and the developer's 23 August 2026 GGUF redownload notice.","sources":[{"label":"OBLITERATUS project","url":"https://github.com/elder-plinius/OBLITERATUS"},{"label":"Current OBLITERATUS Qwen3.8-27B download page","url":"https://huggingface.co/OBLITERATUS/Qwen3.8-27B-OBLITERATED"},{"label":"Second OBLITERATUS release for Apple computers, since removed","url":"https://huggingface.co/OBLITERATUS/Qwen3.8-27B-OBLITERATED/commit/ed77303604d422221952f9f10f3d876ee9603acd"},{"label":"OBLITERATUS Qwen3.8-27B model card, saved copy used for the comparison","url":"https://huggingface.co/OBLITERATUS/Qwen3.8-27B-OBLITERATED/raw/08a7ab67298e9ffab4b55612d946cc96e1e34c6f/README.md"},{"label":"Official Qwen3.8-27B model","url":"https://huggingface.co/Qwen/Qwen3.8-27B"},{"label":"Developer's 23 August 2026 announcement about the GGUF conversion error","url":"https://x.com/elder_plinius/status/2091339694303068467"}],"section_headings":["What the unofficial version changed","Why the same download gave two answers","What the local comparison did","What to check before you download or compare it"]},{"slug":"ap2-x402-mpp-agent-payment-privacy","title":"AI Agent Payment Protocols Compared","tags":["AI Privacy","Payments","Agent Money"],"desc":"A privacy-first comparison of AP2, x402, and MPP for AI-agent payments: authorization, HTTP 402 challenges, settlement rails, logs, wallets, and metadata exposure.","time":"~5 min read","date":"2026-07-05","lastReviewed":"2026-07-05","contentKind":"brief","editorialStatus":"ok","url":"https://cunicula.com/en/articles/ap2-x402-mpp-agent-payment-privacy","answer":"A privacy-first comparison of AP2, x402, and MPP for AI-agent payments: authorization, HTTP 402 challenges, settlement rails, logs, wallets, and metadata exposure.","sources":[{"label":"AP2 protocol docs","url":"https://ap2-protocol.org/"},{"label":"Google AP2 announcement","url":"https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol"},{"label":"Cloudflare MPP compatibility note","url":"https://developers.cloudflare.com/agents/tools/payments/mpp/"},{"label":"Coinbase x402 docs","url":"https://docs.cdp.coinbase.com/x402/welcome"},{"label":"Stripe Machine Payments Protocol","url":"https://stripe.com/blog/machine-payments-protocol"}],"section_headings":["What each layer does","The privacy split","Privacy guidance","Before letting an agent pay"]}],"content":{"slug":"agent-wallet-threat-model","answer":"A practical threat model for AI-agent wallets: key custody, prompt injection, sessions, budgets, receipts, approval policies, wallet reuse, and privacy logs.","publishedAt":"2026-07-05","reviewedAt":"2026-07-13","sections":[{"heading":"Main assets","paragraphs":["Money is only one asset. An agent payment can expose account identity, purchase intent, wallet history, receipts, API keys, merchant sessions, and the prompts that explain why the payment happened.","Separate payment intent from signing authority. AP2 does this with checkout and payment mandates that other roles verify. The same boundary can be simpler: let the agent prepare a request, then let deterministic code or a person approve it."],"bullets":[]},{"heading":"Main failure modes","paragraphs":["The worst design puts seed material, browser automation, untrusted web content, and open-ended spending authority in one runtime. OWASP warns that indirect prompt injection can arrive through websites or files and trigger unauthorized tool use or commands.","A second failure is receipt sprawl. If receipts, prompts, files, and identity documents land in one store, the payment trail becomes a map of the user."],"bullets":["Prompt injection asks the agent to pay the wrong party.","A merchant session leaks identity across unrelated tasks.","Wallet address reuse links agent tasks on a public ledger.","A broad API key lets the agent create spend surfaces without review."]},{"heading":"Safer architecture","paragraphs":["Use a separate wallet, card, or balance for each task compartment. Keep signing authority outside the browsing and prompt runtime. Put a deterministic policy check between the agent request and the payment tool.","Require human approval for high-risk payments. For repeat low-value work, enforce amount, merchant, frequency, instrument, and expiry limits. AP2 autonomous mandates use signed constraints; x402 instead lets a client construct and send payment data during an HTTP request. Neither protocol removes the need to limit the wallet that the client can use."],"bullets":[]},{"heading":"Minimum controls","paragraphs":[],"bullets":["No seed phrases in the agent runtime.","One wallet, card, or balance per task compartment.","Hard maximum amount before the workflow starts.","Human approval above a tiny threshold.","Receipt logs without prompts, private files, or secrets."]}],"faq":[{"question":"Should an AI agent hold wallet keys?","answer":"Usually no. The safer pattern is for the agent to draft a payment request and for a separate wallet, policy engine, or human to approve and sign."},{"question":"What should an agent payment wallet log?","answer":"Log merchant, amount, task, instrument, approval result, and receipt reference. Avoid storing prompts, private files, seed material, bank data, or unrelated identity data in the same log."}],"sources":[{"label":"AP2 v0.2 specification","url":"https://ap2-protocol.org/ap2/specification/"},{"label":"Coinbase x402 docs","url":"https://docs.cdp.coinbase.com/x402/welcome"},{"label":"Stripe machine payments docs","url":"https://docs.stripe.com/payments/machine"},{"label":"Ethereum privacy documentation","url":"https://ethereum.org/en/privacy/"},{"label":"OWASP prompt injection guidance","url":"https://genai.owasp.org/llmrisk/llm01-prompt-injection/"}],"hasDedicatedSourceLedger":true,"figure":{"id":"agent-wallet-approval","figId":"FIG.05","title":"The agent drafts. It never signs.","alt":"Approval path from agent-drafted payment request through policy check, human approval, and an external signer, with four failure modes and where each is caught.","caption":"The safer architecture from the article: intent and signing authority are separated, with limits enforced before payment.","image":"https://cunicula.com/article-figures/agent-wallet-threat-model/agent-wallet-approval--article-desktop.png","width":1200,"height":475,"sources":["https://ap2-protocol.org/ap2/specification/","https://docs.cdp.coinbase.com/x402/welcome","https://genai.owasp.org/llmrisk/llm01-prompt-injection/"],"semanticData":{"caption":"The safer architecture from the article: intent and signing authority are separated, with limits enforced before payment.","headers":["Failure","Effect","Caught by"],"rows":[["PROMPT INJECTION","asks the agent to pay the wrong party","policy check + approval"],["MERCHANT SESSION LEAK","identity crosses unrelated tasks","one wallet per task compartment"],["WALLET ADDRESS REUSE","links agent tasks on a public ledger","one wallet per task compartment"],["BROAD API KEY","creates spend surfaces without review","hard maximum before the workflow starts"]]}}}},"meta":{"total":1,"api_version":"1.2","powered_by":"cunicula.com","documentation_url":"https://cunicula.com/en/api-docs","machine_index_url":"https://cunicula.com/llms.txt","license":"LicenseRef-Cunicula-Attribution-1.0","license_url":"https://cunicula.com/en/cite","attribution":"Cunicula, \"{name}\", cunicula.com, reviewed {reviewed}, retrieved {retrieved}, {url}","cite_guide_url":"https://cunicula.com/en/cite","dataset_url":"https://cunicula.com/api/v1/dataset","schema_version":"1.1.0","related_total":5,"has_content":true}}