惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
IT之家
IT之家
H
Heimdal Security Blog
Jina AI
Jina AI
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
WordPress大学
WordPress大学
AWS News Blog
AWS News Blog
C
Cisco Blogs
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Hacker News
The Hacker News
The Cloudflare Blog
Hugging Face - Blog
Hugging Face - Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Threatpost
S
Securelist
P
Privacy International News Feed
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 聂微东
博客园 - 叶小钗
J
Java Code Geeks
V
V2EX
博客园 - Franky
Spread Privacy
Spread Privacy
K
Kaspersky official blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Simon Willison's Weblog
Simon Willison's Weblog
Project Zero
Project Zero
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
C
Cybersecurity and Infrastructure Security Agency CISA
C
CERT Recently Published Vulnerability Notes
Latest news
Latest news
NISL@THU
NISL@THU
罗磊的独立博客
W
WeLiveSecurity
Google DeepMind News
Google DeepMind News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园_首页
V
Visual Studio Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
The agent economy solved 'how to pay.' It still hasn't solved 'who to trust.'
Baris Sozen · 2026-06-21 · via DEV Community

Baris Sozen

PayPal's real innovation in 1999 wasn't moving money. Banks already moved money. What PayPal did was make it safe to transact with a stranger — someone you'd never met, on the other end of an auction, who had your payment before you had your goods. Buyer protection, dispute resolution, a reputation trail. The money rail was the easy half. The trust rail was the product.

A quarter century later, the agent economy is rebuilding the easy half at high speed and mostly skipping the hard one. This week was a clean illustration, so as the weekly wrap-up, I want to pull on the one thread that ties it together rather than re-list the news.

The week, in one sentence

More ways to pay shipped; no new way to know who you're paying. Mastercard's agent-payment program kept rolling and is now recording agent authorizations to Polygon — a TradFi network writing agent-spend permissions on-chain. Coinbase's x402 kept spreading behind mainstream web infrastructure, even as its standalone transaction volume cooled hard from the November peak. Eco extended cross-chain stablecoin orchestration across roughly fifteen chains. And ERC-8004, the "Trustless Agents" identity-and-reputation standard, kept maturing with a v2 direction that leans into MCP.

Line them up and three are answers to the same question — how does an agent move value? — and exactly one points at the question the others leave open.

Why "who" is a different problem than "how"

A payment is one-directional and to a known party. Your agent buys compute from a provider it already chose; value goes one way, one asset, one hop. The hard parts are authorization and delivery, and the rails above genuinely nail them.

A trade is not that. My asset for yours, possibly across two ledgers that don't share a clock, where the other side is not pre-selected. That introduces two problems no payment rail touches:

  1. Atomicity — both legs clear together or both refund. A one-way rail can't express "all-or-nothing across two transfers." The usual patch is an escrow that holds both sides, which doesn't remove the risk so much as relocate it into a custodian you now have to trust to be solvent and honest.
  2. Counterparty — who is the other side, and why should my agent trust them enough to lock funds at all?

Atomicity is a settlement problem, and it has a known answer. Hash-time-lock contracts (HTLCs) let both parties lock funds against a single hash preimage on a timelock: reveal the secret and the whole trade clears; stay silent and the whole trade refunds. No half-settled state, no intermediary holding the bag. That part exists and is live on Ethereum mainnet today.

The counterparty problem is the one almost nobody is building for agents, and it's why ERC-8004 is the most interesting item on the week's list.

Discovery solved tools. It didn't solve counterparties.

Think about how fast tool discovery became. With MCP an agent finds a capability, OAuths in, and starts calling it in seconds. Discovery of what an agent can do is nearly a solved problem.

Discovery of who an agent should trade with is not. Today it's manual — a human vets the counterparty, or the agent simply doesn't trade with strangers. That's fine when the payee is a merchant you picked. It falls apart the instant you want open, agent-to-agent markets where the other side isn't chosen in advance. The stranger is the whole point, and the stranger is exactly what we have no automated way to assess.

ERC-8004 is the ecosystem finally treating that as first-class: identity and reputation as on-chain primitives instead of an off-chain allowlist, with MCP in the v2 picture. It's complementary to settlement, not competitive — identity tells you who, settlement guarantees the trade clears. You need both.

The part most people miss: identity has to be coupled to settlement

Here's the design trap. It's tempting to picture agent reputation as a score that lives somewhere — a registry an agent can look up before trading. But a reputation number floating beside the settlement path is weak in both directions. Read it as advisory and it gets skipped under time pressure. Read it as authoritative and it becomes a sybil target the moment it gates value, because now faking identity is worth exactly as much as whatever it unlocks.

The interesting designs bind the attestation to the action being authorized, and make identity expensive to fake in proportion to what it unlocks. Trust stops being one KYC gate everyone passes through and becomes a dial: anonymous, small swaps stay permissionless; larger or regulated flows opt into higher assurance. The check isn't a lookup you can route around — it's wired into the clearing mechanism itself.

That coupling is the piece we're building toward, and the design we'd call a Verified Counterparty Directory:

  • Attestation, not gatekeeping. A counterparty carries verifiable claims — identity, track record, tier — that an agent reads before quoting, not after settling.
  • Settlement-coupled. The directory isn't a standalone score in the void; it plugs into the same HTLC settlement path, so "find a counterparty" and "clear the trade trustlessly" are one flow rather than two systems bolted together.
  • No custodian in the loop. Identity raises confidence; the contract still guarantees the outcome. You trust neither the counterparty nor an intermediary with your funds — the timelock does the enforcing.

Put plainly: the rails move the money, identity tells you who the stranger is, and atomic settlement makes sure the trade can't half-complete. The Verified Counterparty Directory is the seam that joins the second and third so an agent can act on them at the same instant. That's the layer this week's announcements kept circling without landing on.

Status, stated precisely

Because precision is the brand: atomic HTLC settlement is live on Ethereum mainnet today. Sui contracts are deployed and CLI-tested with gateway wiring in progress; Bitcoin is signet-validated with mainnet pending. The Verified Counterparty Directory is a primitive on the roadmap — described here as a design, not a shipped feature. Rails ready, trains coming. (For the curious: the MCP server is hashlock-tech/mcp (scoped) on npm, now also listed on the awesome-mcp-servers directory, and the protocol is listed on DefiLlama.)

The honest tradeoffs of the HTLC approach still hold — capital is locked for the timelock window, and you take on timeout/refund handling. That's the price of removing the intermediary entirely, and reasonable builders weigh it differently by trade size and latency tolerance. Reputation has its own hard parts — sybil resistance and cold-start chief among them — which is exactly why coupling attestation to settlement, rather than trusting a free-floating score, matters.

The preview

Next week the thing worth watching is whether ERC-8004's v2 makes agent identity readable at quote time rather than after the fact — because that's the difference between a reputation score and a usable counterparty signal. If the identity layer becomes settlement-adjacent, the directory pattern gets a lot more concrete.

Question for the builders reading: if your agent could settle atomically with any stranger, what would you actually need to know about the counterparty first — verified identity, on-chain track record, or nothing at all? Where's the line for you?