VERSE PRESS

Crypto News, Global First.

Ledger Launches Open-Source Agent Stack to Put Hardware Between AI and Your Crypto

Ledger went public today with its Agent Stack, a suite of open-source tools designed to stop AI agents from executing crypto transactions without explicit human sign-off, enforced by the company's hardware security chips.

|

The Paris-based hardware wallet maker made the toolkit available on July 16, 2026, following a private preview that involved more than 1,000 agents. The release arrives as losses from rogue or compromised AI agents in crypto surpassed $340 million in the first quarter of 2026 alone, according to KuCoin research. The company's stated design principle is blunt: "Agents propose. Humans approve. Hardware enforces."


What the Stack Actually Does

The Agent Stack bundles four open-source command-line tools: Device Management Kit Skills, Ledger Wallet CLI, Ledger Enterprise CLI, and Ledger Enterprise Multisig CLI. Taken together, they allow AI agents to read balances, prepare swaps, suggest transactions, and draft multi-signature operations, but they cannot push any of those actions on-chain without a physical confirmation from a connected Ledger device. The hardware itself runs on a Secure Element chip certified to CC EAL6+ or CC EAL5+ under the Common Criteria international standard, indicating the chip has passed rigorous independent security testing. Keys never leave the device. The screen that shows transaction details renders directly from the Secure Element rather than from the host computer, which blocks a category of attack where malicious software overlays fake transaction data on screen.

The stack is compatible with Claude Code, Codex, Cursor, and other shell-capable agents. Documentation is available at developers.ledger.com/docs/ai-tools/overview.

MoonPay became the first production integration in March 2026, embedding the Device Management Kit into its AI agent CLI wallet. "Autonomy without security is reckless. We built MoonPay Agents with Ledger so intelligence can scale without surrendering control," said Ivan Soto-Wright, MoonPay's CEO and Founder. Ledger has sold over 8 million hardware devices and secures more than 20 percent of the world's on-chain crypto market cap, a foundation that positions it as a credible provider of AI security infrastructure.


Developer Incentives

To encourage adoption, Ledger has attached financial incentives to the launch. Developers can earn a $5,000 bounty through College.xyz, and a $10,000 prize pool across five categories is available through ETHGlobal New York. A June 2026 student competition called N3XT Build and Show drew 50 project submissions from 38 universities across eight countries, generating 46 public GitHub repositories in the process.


The Problem This Is Designed to Solve

AI agent activity in crypto has grown sharply. A May 2026 research report tracked 176 million agent transactions between May 2025 and April 2026, with more than $73 million in total settlement value. On Coinbase's Base network, cumulative agentic payments crossed 100 million by Q1 2026. The share of agent transactions exceeding $1 in value rose from 49 percent to 95 percent in roughly a year, indicating the activity has moved well beyond test payments. McKinsey projects that AI agents could mediate $3 to $5 trillion in global consumer commerce by 2030, a trajectory that raises the stakes on every unresolved security gap in the space.

The security record has not kept pace. In January 2026, memory poisoning and indirect prompt injection drained more than 261,000 SOL, worth approximately $27 to $30 million at the time, from Step Finance on Solana. The platform subsequently shut down and its native token fell 97 percent. University of California researchers, working alongside blockchain security researcher Chaofan Shou of Fuzzland, identified 26 LLM routers (intermediary services that sit between users and AI models) that were covertly injecting malicious tool calls into agent workflows. One incident alone drained $500,000 from a client wallet.

The systemic exposure runs deeper. According to KuCoin research, 45.6 percent of AI agent teams relied on shared API keys, making rogue agents nearly impossible to trace or stop, and 88 percent of organizations using AI agents faced confirmed or suspected security incidents.

Ledger's Ian Rogers, Chief Human Agency Officer (formerly Chief Experience Officer), described the core risk in the company's April 2026 security roadmap as a "lethal trifecta": prompt injection combined with autonomous execution and direct access to real financial resources. "A compromised agent can ask your signer to sign something," Rogers wrote. "It cannot make your signer sign without you."


Regional Barriers Are Real

The hardware-confirmation model works well for developers and enterprise users who already own Ledger devices. For the majority of crypto users in high-growth markets, the picture is more complicated.

India ranked first in the Chainalysis 2025 Global Crypto Adoption Index with an estimated 93 million retail users, but hardware wallet penetration sits below 2 percent. South Asian DeFi developers have a genuine on-ramp through the Agent Stack's open-source tools and prize incentives, but end users who would need a physical Ledger device to benefit from the human-in-the-loop model face both price and availability barriers. India's AI agent use cases are also skewing mobile-first and high-volume, with voice agents handling NBFC (Non-Banking Financial Company) loan servicing, KYC, and collections in more than a dozen languages. A model that requires a physical device confirmation on every transaction may need significant UX adaptation before it fits that context.

In Africa, the security threat is present but the solution remains out of reach for most users. Sub-Saharan Africa received $205 billion in on-chain value between July 2024 and June 2025, a 52 percent year-on-year increase. Nigeria alone accounted for $92.1 billion of that. Yet the Middle East and Africa region sold roughly 380,000 hardware wallet units in all of 2024. Nigeria and Kenya's dominant crypto activity runs through mobile wallets and peer-to-peer markets, not hardware signers. South Africa leads the continent in AI adoption according to Microsoft data, underscoring that demand for agentic financial tools is real even as hardware wallet infrastructure lags. Oluwatobi Ajayi, CEO of Ivorypay, has argued that as AI agents become Africa's next class of digital customers, the region needs machine-readable pricing infrastructure and accessible payment rails. Emerging standards such as the X402 payment protocol are beginning to address that gap within the African developer community, but they remain outside the scope of the current Agent Stack.


What Comes Next

Ledger's published roadmap schedules two additions for later this year. A Q3 2026 update is expected to introduce Agent Intents and Policies, a feature set that would let developers define rule sets restricting agent behavior, such as capping spending at no more than $500 per day. A Q4 2026 feature called Proof of Human would use hardware-level attestation to verify that a real person is present, targeting bot farms and multi-accounting.

No formal regulatory framework currently governs autonomous machine-to-machine transactions. Three active frameworks address adjacent concerns: MiCA in Europe, the US GENIUS Act, and the EU AI Act. None of them directly resolves liability for unauthorized agent actions, leaving that question legally open. That gap makes the technical controls Ledger is building more consequential than they might otherwise be.