Blog
Notes from the build.
Short essays on AI evals, agent products, and the cryptography under them. Every one ends in something you can check: a repo, a demo, or a number.
01 Essays
The cluster is the result. xAI is the exception.
In a 22-model T=0.1 political-questionnaire cohort, all 20 non-xAI models across nine US- and China-headquartered providers answered from the same equality–liberty region. Release drift was family-level, temperature had no common direction, and the country comparison depended on one provider.
An image is not a sentence
From an analytical-philosophy obsession to VSON: a notation where every claim about an image declares every argument it takes, viewpoint included.
Trick the agent all you want. The vault does not care.
Assume prompt injection will happen. Maestro puts ten on-chain checks between a hijacked agent and the money, and is honest about what an attacker still gets.
Three agents, one signature, none holds the key
How Chorus runs an AI-agent committee on FROST threshold signatures and ERC-7710 delegation: no key to steal, no authority that was not explicitly given.
App islands: an edge you can rent is not an edge
AI collapsed the cost of building your own internal tools. Notes on skipping the CRM in San Francisco, and why the next moat is the internal codebase.
Why we ship products from cryptography papers
There is a long gap between a zero-knowledge paper and something a person can click. Notes on how we close it.
Hiding zero-knowledge latency is a UX problem
Proofs take seconds. Players will not wait seconds. What designing Mina Mastermind taught me about masking compute.
AI agents need wallets. They also need a kill switch.
Off-chain guardrails are bypassable middleware. The case for putting agent spending policy on-chain.
02 Thoughts
@yamancan →Thinking in public: threads and theses on agents, cryptography, and where this is all going.
Agents are about to become first-class citizens
When agents move funds, make decisions, and hire each other directly, the Fat Protocol thesis needs updating: coordination becomes cryptographic, and boundaries have to be human-defined.
Three agents sign one transaction. None holds the key.
FROST threshold signatures plus ERC-7710 delegation, coordinated over XMTP. How Chorus splits authority across an agent committee on Base.
Your inbox is an identity you never claimed
DKIM-signed emails can become private, verifiable credentials: proving the email is real without revealing its contents.
A CAPTCHA that proves you are NOT a human
Reverse the test: can you tap a button at 200 Hz? Notes on proving agent-ness in an internet that has to tell agents, humans, and human-piloted agents apart.
Give an AI agent a real phone number
World ID for sybil resistance, x402 for payment, XMTP + Twilio for the line. One verified number per human, for their agent.
Best DevX or deepest liquidity wins the chain
On agent-first IDEs, agentic tooling, and what actually decides chain competition in the agent era.