惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Secure Thoughts
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
月光博客
月光博客
博客园 - 【当耐特】
Jina AI
Jina AI
雷峰网
雷峰网
J
Java Code Geeks
腾讯CDC
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 叶小钗
aimingoo的专栏
aimingoo的专栏
Martin Fowler
Martin Fowler
The Register - Security
The Register - Security
罗磊的独立博客
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Security Latest
Security Latest
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cyber Attacks, Cyber Crime and Cyber Security
有赞技术团队
有赞技术团队
The Hacker News
The Hacker News
Scott Helme
Scott Helme
T
The Blog of Author Tim Ferriss
Spread Privacy
Spread Privacy
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
Cisco Talos Blog
Cisco Talos Blog
美团技术团队
B
Blog RSS Feed
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
SecWiki News
SecWiki News
Webroot Blog
Webroot Blog
N
News | PayPal Newsroom
D
Docker
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
W
WeLiveSecurity
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
T
Tenable Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
阮一峰的网络日志
阮一峰的网络日志
I
Intezer
Hugging Face - Blog
Hugging Face - Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
From Symbol to Contract: Asset Resolution APIs for Multi-Chain Trading Bots
Wallet Guy · 2026-06-24 · via DEV Community

From Symbol to Contract: Asset Resolution APIs for Multi-Chain Trading Bots

Your trading bot spotted the arbitrage window — SOL/USDC spread across Jupiter and a CEX, closing in seconds. The alpha is there. But before a single swap executes, your bot needs to resolve token addresses, verify it has the right session token, check gas conditions, and route the transaction through policy controls that won't silently reject a $500 move. Most of that infrastructure doesn't exist in your codebase yet. That's the problem this post solves.

Why Infrastructure Debt Kills Good Strategies

Algorithmic trading bots fail in two ways: bad strategy and bad plumbing. Bad strategy is hard to fix. Bad plumbing is just engineering work you haven't done yet.

The plumbing problem for multi-chain bots is specific: you're operating across Solana and EVM chains simultaneously, hitting 15+ DeFi protocols, managing gas costs, and maintaining risk controls that prevent your bot from blowing up a wallet on a bad trade. If you bolt all of that together yourself — custom signing logic, manual address lookups, ad hoc rate limiting, hand-rolled session management — you'll spend more time maintaining infrastructure than improving your edge. WAIaaS is a self-hosted Wallet-as-a-Service that provides that infrastructure as a local API, so you can focus on the strategy layer.

The Asset Resolution Problem

Multi-chain trading bots constantly need to answer a deceptively annoying question: what is the contract address for this token on this chain?

Hardcoding token addresses is fragile. Token lists go stale. New tokens get listed. Wrapped versions differ across chains. And when you're working across Solana (where tokens are identified by mint addresses like So11111111111111111111111111111111111111112) and EVM chains (where they're checksummed hex addresses), your address management code gets messy fast.

WAIaaS exposes a resolve-asset MCP tool and token resolution via the REST API that handles this lookup layer for you. But more importantly, it normalizes the entire execution path — from asset resolution through policy check through on-chain execution — so your bot doesn't have to think about chain-specific quirks at each step.

What WAIaaS Gives a Trading Bot

WAIaaS runs locally (default: 127.0.0.1:3100) and exposes a REST API with 39 route modules. For a trading bot, the relevant surface area is:

  • Wallet management — create isolated wallets per strategy, per chain
  • Session tokens — scoped credentials for bot processes
  • Transaction execution — 7 transaction types including Batch for atomic multi-step trades
  • 15 DeFi protocol integrations — Jupiter, Drift, Hyperliquid, Aave v3, LI.FI, Across, and more
  • Gas conditional execution — transactions only fire when gas price meets your threshold
  • Policy engine — 21 policy types with 4 security tiers to bound your bot's risk
  • Dry-run simulation — test a trade path before committing gas

Let's walk through how a real trading bot interacts with each layer.

Step 1: Create an Isolated Wallet Per Strategy

Good bot architecture isolates capital per strategy. A Solana arb bot shouldn't share a wallet with your Drift perpetuals position manager. Create a wallet for each:

curl -X POST http://127.0.0.1:3100/v1/wallets \
  -H "Content-Type: application/json" \
  -H "X-Master-Password: my-secret-password" \
  -d '{"name": "trading-wallet", "chain": "solana", "environment": "mainnet"}'

Then create a session token scoped to that wallet — this is what your bot process uses at runtime:

curl -X POST http://127.0.0.1:3100/v1/sessions \
  -H "Content-Type: application/json" \
  -H "X-Master-Password: my-secret-password" \
  -d '{"walletId": "<wallet-uuid>"}'

The session token (wai_sess_...) is all your bot needs for transaction execution. The master password stays out of the hot path entirely.

Step 2: Check Balances Before You Trade

Before your bot enters a position, it needs to know what it's working with. The balance check is a single authenticated call:

curl http://127.0.0.1:3100/v1/wallet/balance \
  -H "Authorization: Bearer wai_sess_eyJhbGciOiJIUzI1NiJ9..."

In the TypeScript SDK, the same call looks like:

import { WAIaaSClient } from '@waiaas/sdk';

const client = new WAIaaSClient({
  baseUrl: 'http://127.0.0.1:3100',
  sessionToken: process.env.WAIAAS_SESSION_TOKEN,
});

const balance = await client.getBalance();
console.log(`${balance.balance} ${balance.symbol} (${balance.chain}/${balance.network})`);

Use getAssets() if you need the full picture — all token balances across the wallet, not just the native token. That's your pre-flight check before sizing a position.

Step 3: Execute a Swap via Jupiter

Once your bot resolves that the Jupiter SOL/USDC spread is worth hitting, execution is a single API call:

curl -X POST http://127.0.0.1:3100/v1/actions/jupiter-swap/swap \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer wai_sess_<token>" \
  -d '{
    "inputMint": "So11111111111111111111111111111111111111112",
    "outputMint": "EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v",
    "amount": "1000000000"
  }'

Notice the token addresses here — So111...112 is the native SOL mint, EPjFW...t1v is USDC on Solana. WAIaaS handles the Jupiter routing, quote fetching, and transaction construction. Your bot just specifies the economic intent.

The same pattern works across all 15 integrated DeFi protocols. For Hyperliquid perpetuals, for Drift, for Aave v3 on EVM — the action provider pattern is consistent. Your bot doesn't need protocol-specific SDKs; it needs one authenticated HTTP client.

Step 4: Simulate Before You Execute

Sending a transaction without knowing if it'll succeed is expensive. WAIaaS has a dry-run mode that simulates the full transaction pipeline — including policy checks — without touching the chain:

curl -X POST http://127.0.0.1:3100/v1/transactions/send \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer wai_sess_<token>" \
  -d '{
    "type": "TRANSFER",
    "to": "recipient-address",
    "amount": "0.1",
    "dryRun": true
  }'

For a trading bot, this is valuable before executing large positions or testing a new strategy path. If a policy would block the trade, you find out before paying gas. If your balance is insufficient, you find out before the swap fails on-chain.

Step 5: Build Risk Controls with the Policy Engine

This is where WAIaaS earns its place in a serious trading setup. Bots go wrong. A bug in your sizing logic can drain a wallet. A policy engine that's always running gives you a hard floor on how badly things can go.

The policy engine has 21 policy types and 4 security tiers. For a trading bot, the relevant ones are:

SPENDING_LIMIT — the primary guardrail. Define how much your bot can move instantly, how much triggers a notification, how much requires a delay, and how much requires your explicit approval:

curl -X POST http://127.0.0.1:3100/v1/policies \
  -H "Content-Type: application/json" \
  -H "X-Master-Password: my-secret-password" \
  -d '{
    "walletId": "<wallet-uuid>",
    "type": "SPENDING_LIMIT",
    "rules": {
      "instant_max_usd": 100,
      "notify_max_usd": 500,
      "delay_max_usd": 2000,
      "delay_seconds": 900,
      "daily_limit_usd": 5000
    }
  }'

With this policy: trades under $100 execute immediately. Trades $100–$500 execute and notify you. Trades $500–$2000 wait 15 minutes (cancellable). Anything above $2000 requires manual approval. A runaway position-sizing bug can't drain more than $5000 in a day.

ALLOWED_TOKENS — default-deny whitelist. If your bot should only ever touch SOL and USDC, configure exactly that. Any attempt to approve or transfer an unknown token gets blocked at the policy layer, before signing.

CONTRACT_WHITELIST — only allows calls to contracts you've explicitly approved. If your bot is a Jupiter-only strategy, it should only be able to call the Jupiter router contract. Full stop.

PERP_MAX_LEVERAGE and PERP_MAX_POSITION_USD — for bots running on Hyperliquid or Drift, these policies enforce position sizing limits at the infrastructure layer, independent of your strategy code.

The critical detail: WAIaaS uses default-deny enforcement. A transaction is blocked unless it's explicitly permitted. You're not writing code that says "block this" — you're writing code that says "allow this, and deny everything else."

Step 6: Handle Policy Denials Gracefully

When a policy blocks a trade, your bot gets a structured error response:

{
  "error": {
    "code": "POLICY_DENIED",
    "message": "Transaction denied by SPENDING_LIMIT policy",
    "domain": "POLICY",
    "retryable": false
  }
}

The retryable field matters for bot logic. A POLICY_DENIED with retryable: false means you need human intervention — don't hammer the endpoint in a retry loop. A different error class might be retryable. Build your bot's error handling around these structured codes, not string matching on error messages.

In TypeScript:

import { WAIaaSClient, WAIaaSError } from '@waiaas/sdk';

try {
  const tx = await client.sendToken({ to: '...', amount: '1.0' });
} catch (error) {
  if (error instanceof WAIaaSError) {
    console.error(`API Error: [${error.code}] ${error.message}`);
    // error.code examples: INSUFFICIENT_BALANCE, POLICY_DENIED, TOKEN_EXPIRED
  }
}

Step 7: Multi-Step Execution with Batch Transactions

Real trading strategies often involve more than one step. Approve a token, then deposit into a lending protocol. Swap on Jupiter, then stake the output. WAIaaS supports a Batch transaction type as one of its 7 transaction types, letting you compose atomic multi-step operations into a single transaction submission.

This matters for MEV protection: if your strategy requires two actions, bundling them prevents another actor from sandwiching the intermediate state.

Connecting to Claude or an LLM Orchestrator via MCP

If your trading bot is LLM-orchestrated — using Claude or another model to interpret market signals and decide on trades — WAIaaS has a 45-tool MCP server that gives the model direct access to wallet operations without you building a custom tool layer.

Setup is a single command:

waiaas mcp setup --all

That auto-registers all your wallets with Claude Desktop. The MCP server exposes tools including get_balance, send_token, get_defi_positions, simulate_transaction, hyperliquid, polymarket, and get_assets — the full trading surface area, all authenticated and policy-gated.

For a multi-strategy setup where different LLM agents manage different wallets, you can run one MCP server per wallet:

{
  "mcpServers": {
    "waiaas-trading": {
      "command": "npx",
      "args": ["-y", "@waiaas/mcp"],
      "env": {
        "WAIAAS_BASE_URL": "http://127.0.0.1:3100",
        "WAIAAS_AGENT_ID": "019c47d6-51ef-7f43-a76b-d50e875d95f4",
        "WAIAAS_AGENT_NAME": "trading-agent",
        "WAIAAS_DATA_DIR": "~/.waiaas"
      }
    },
    "waiaas-solana": {
      "command": "npx",
      "args": ["-y", "@waiaas/mcp"],
      "env": {
        "WAIAAS_BASE_URL": "http://127.0.0.1:3100",
        "WAIAAS_AGENT_ID": "019c4cd2-86e8-758f-a61e-9c560307c788",
        "WAIAAS_AGENT_NAME": "solana-wallet",
        "WAIAAS_DATA_DIR": "~/.waiaas"
      }
    }
  }
}

Each agent gets its own session scope, its own policies, its own position limits. They can't interfere with each other's capital.

Quick Start: Bot Infrastructure in 5 Minutes

# 1. Install the CLI
npm install -g @waiaas/cli

# 2. Initialize and start the daemon
waiaas init
waiaas start

# 3. Create wallets and sessions in one command
waiaas quickset --mode mainnet

# 4. Connect your bot using the session token printed by quickset
# Set WAIAAS_SESSION_TOKEN in your bot's environment

# 5. (Optional) Register with Claude Desktop
waiaas mcp setup --all

For production deployments, Docker is the better path:

git clone https://github.com/minhoyoo-iotrust/WAIaaS.git
cd WAIaaS
docker compose up -d

The daemon runs on 127.0.0.1:3100 by default — local-only by design. Your API keys and session tokens never leave the host.

The OpenAPI Spec Is Your Friend

WAIaaS auto-generates an OpenAPI 3.0 spec and serves an interactive API reference:

# Download the spec for your bot's HTTP client generation
curl http://127.0.0.1:3100/doc -o openapi.json

# Browse the interactive reference
open http://127.0.0.1:3100/reference

If you're generating a typed HTTP client for your bot (which you should be), point your generator at /doc and get a fully typed interface to all 39 API route modules.

What's Next

WAIaaS is open-source and self-hosted — your keys stay on your infrastructure, your trades stay private, and you're not dependent on a third-party service staying online when your bot needs to execute. The full codebase, including the 15 DeFi protocol integrations and policy engine, is on GitHub.

Star the repo and read the full documentation to go deeper on policy configuration, account abstraction with ERC-4337, and the incoming transaction monitoring that lets your bot react to deposits in real time.