OpenServ SERV Hackathon · RWA Vaults · IXS Finance

An AI agent that has to earn its limits.

It proposes. Fixed rules decide. Only its own on-chain record can raise its limits.

Unaudited · local BNB fork · no real funds

same request, two agents
$ deposit(200)
Agent AALLOWED
tier T1 · earned · cap 300
Agent BREVERTED
tier T0 · brand new · cap 120
OverMaxTx, rejected before it was mined
89/89
contract tests
144/144
engine cases, TS = Python
21/21
adversarial evals held
0
limit breaks under fuzzing
How it works

The model can't move money. Full stop.

01

The agent proposes

Deposit, redeem or hold. No addresses, no calldata, no limits to touch.

02

The engine decides

Mandate, tier, vault health. Same inputs, same verdict.

03

The contract enforces

Re-checks on-chain and stamps a receipt. No receipt, no action.

See the engine react live

In your browser. No wallet.

Earned authority

Trust is a ladder. Every rung is on-chain.

Time served, risk carried, receipts logged, no incidents. Anyone can call the promotion; it only passes if the record holds. One incident drops a tier.

Reads the demo run's chain. No wallet.

T3
1200
up to 1000 per deposit · earned, never granted
T2
800
up to 600 per deposit
T1
400
up to 300 per deposit
T0
150
up to 120 per deposit · every agent starts here
Max held in the vault. Demo-speed schedule.
Measured, not promised

“A defined window.” We measured it.

The docs give no number. The chain does. 7 settled, in 17 s to 12.7 days. 2 are still open after 76 days and 120 days.

Time to get money out
LIVE
settledstill open
#1
3.8 min
#2
120 days · still open
#3
15 min
#4
17 s
#5
2.8 h
#6
76 days · still open
#7
45 h
#8
12.7 days
#9
35 h
1 min
1 hour
1 day
100 days

Read live from BNB Chain, block 126,299,217, 2026-10-07 18:22 UTC. Refreshes every 5 minutes. Log scale. Small sample (9 requests). One open request is under 1 share. Why they're open isn't on-chain. The health feed counts settled requests only, so it misses them.

Honeypot

Try to talk it into something.

Write a notice built to fool the agent. Scores come from what it actually did on-chain.

Not run publicly yet. No prize pot; no live model reads notices.

0
limit breaks across 256 fuzz runs per invariant.
The fuzzer, not public attackers.

Run an account

Capacity, decisions, and every owner, agent and guardian control.

Read-only here. Wallet controls run on a local copy.

Check it without trusting us

Replays the on-chain record and flags any tier change the rules didn't allow.

Opens on the demo run's Agent A. Any account address works.

See it end to end.

Five minutes. Mostly no wallet.