AI agents are spending real money right now — autonomously

A hijacked AI agent can drain its wallet in under 2 minutes.

Agents now pay for APIs, data and compute on their own — hundreds of tiny stablecoin payments a minute, with no human clicking "confirm." Your bank flags a weird charge in seconds. Nobody does that for an agent that just got compromised. Burnwatch learns each agent's normal spend and alerts the instant the money starts leaving.

how it works →
$600M+
Settled through x402 agent payments
Chainalysis / x402, early 2026
~500K
Active autonomous agent wallets
x402 protocol data, 2026
100M+
Agentic payments on Base in ~3 quarters
Chainalysis, Q1 2026
the gap

Spending caps aren't fraud detection.

The big platforms will sell you per-transaction limits — but only if your agent lives entirely inside their walled garden, and only if the attacker spends in obvious round numbers. A compromised agent doesn't. It bleeds you in thousands of "normal-looking" micro-payments.

What built-in spend limits do

  • Only work inside one cloud / one wallet — useless if you run agents across rails
  • Static caps an attacker simply stays just under
  • No concept of this agent's normal behavior
  • You find out when the wallet's already empty

What Burnwatch does

  • Works across any rail or wallet — x402, AgentCore, MPP, plain HTTP 402
  • Learns each agent's normal spend rate, counterparties and rhythm
  • Flags the anomaly — burn-rate spikes, unknown payees, drains
  • Alerts you in seconds, while the money's still in the wallet
setup

Watching your agents in under ten minutes.

No custody migration. No new wallet. It rides alongside the agent you already run.

01 / WRAP

Wrap your payment client

A thin SDK shim around your agent's x402 / payment client — pip install burnwatch. Outbound-only, fail-open, never in the money path.

02 / LEARN

It baselines normal

A short warm-up of real payments teaches it each agent's typical spend rate, counterparties, destinations and hours.

03 / WATCH

It catches the drain

Anomaly fires → you get a push / webhook / email with the agent, the suspicious payments and the evidence. Observe-only.

detections

The patterns that mean money is leaving.

Spend-velocity breach

An agent that normally spends cents a minute suddenly burning dollars a second — the classic hijacked-agent drain.

Unknown counterparty

Payments to a recipient or endpoint this agent has never paid before, appearing out of nowhere.

Off-pattern destination

Spend on a service category outside the agent's normal mix — a research bot suddenly buying compute it never touches.

Prompt-injection drain

A rapid burst of escalating payments right after a tool call — the signature of an agent that's been talked into spending.

Observe-only. It never touches your keys or your funds.

Burnwatch watches payment metadata — amount, recipient, frequency — and alerts. It never holds your money, never holds your private keys, never sits in the payment path. Think smoke detector, not a vault. That's the whole design, and the reason you can drop it in without trusting us with anything that matters.

Get it before your agent needs it.

Burnwatch is in early access. Drop your email to claim a founding spot — and tell us what your agents are running so we build for your stack first.

✓ You're on the list. We'll be in touch.
No spam. One launch email, plus a couple of questions about your setup.
WORKS WITH x402 Coinbase AgentKit AgentCore MPP any HTTP 402 rail