Authority stays outside the model.
Models can propose actions. Deterministic policy and customer-controlled systems decide what may execute.
About VulSight
VulSight secures the moment an AI agent becomes capable of moving value. We combine adversarial research with deterministic authorization controls so useful autonomy does not require unchecked authority.
Our mission
AI agents can reason about a task, choose a service, and prepare a transaction. They should not define their own financial limits or hold unchecked signing authority.
VulSight separates intent from permission. The model proposes one typed action. Policy evaluates it against live state. A customer controlled signer authorizes only the approved payload.
Why we built VulSight
Secure the rails
Research across blockchain clients, smart contracts, wallets, and financial infrastructure taught us how small control failures become system-wide impact.
Test the agent
Agent workflows add probabilistic decisions, external tools, identities, and delegated authority to an already consequential system.
Control execution
VulSight puts a deterministic policy boundary between an agent proposal and the signer that can move value.
Operating discipline
Models can propose actions. Deterministic policy and customer-controlled systems decide what may execute.
Recipient, asset, amount, rail, budget, expiry, and purpose become explicit before evaluation.
The signer accepts only the authorized bytes, within the approved scope and time window.
The proposal, decision, reason, approval, and result remain connected for review and safe recovery.
Demonstrated adversarial work
CVE-2026-26314
The advisory credits Waleed Ahmed from vulsight.com with reporting the issue to the Ethereum Foundation Bug Bounty Program.
Open the official advisoryBuild the boundary before value moves
Start with the agent, action, policy, signer, and rail. We will map the authority path and define a safe first scope.