How It Works
Full technical flow · 9 steps
Limit-aware draining
9 transactions just under the cap, different recipients, rapid succession. Every one passes. Static limits never notice.
Gradual behavioral drift
Agent slowly manipulated via prompt injection over days. Each action is small. The cumulative shift is massive. No alert fires.
Hallucination burst
Model fires payments to nonsensical targets at irregular intervals. Nothing exceeds the daily cap. Wallet drains slowly.
Agent registers on-chain
Owner calls register() on AttractorGuard.sol. A unique agentId is derived on-chain. AgentRegistered event emitted and indexed by Goldsky within one block.
register("alice-expense-agent", wallet)
→ agentId: 0x4a3b...f9c2
→ AgentRegistered eventTakens' Embedding Theorem (1981)
A scalar time series — transaction amounts — can reconstruct the full attractor geometry of the underlying system via delay embedding. v(t) = [x(t), x(t+τ), ..., x(t+(m-1)τ)]
Grassberger-Procaccia Correlation Dimension (1983)
D₂ is the slope of log C(r) vs log r, where C(r) is the correlation integral. Stable agents: consistent D₂ ∈ [1.5, 3.5]. Compromised agents: D₂ shifts outside this range.
Sample Entropy (early-stage)
For <200 transactions, SampEn measures payment rhythm irregularity. Low SampEn = predictable. High SampEn = irregular. A sudden spike signals unexpected behavior change.
On-chain baseline hash
Baseline parameters (mean, stdDev, threshold) are hashed and committed to AttractorGuard.sol via logDecision(). Any quiet alteration produces a new on-chain transaction — auditable forever.
AttractorGuard.sol
ExplorerAgent registration, gate decision logging, freeze/revoke lifecycle
AgentPaymentSimulator.sol
ExplorerDemo payment simulation, normal pattern seeding, attack injection