ETHOnline 2026 — ENSv2 · Ledger · Chainlink CRE

Give your AI agenta key it can't misuse.

Hardware-backed spending limits. A kill switch that fires in milliseconds. Only your Ledger device can bring it back.

Architecture

One request. Every sponsor's piece of the stack.

The agent never holds a key. Every transaction is verified live against ENSv2 permission state inside a Chainlink CRE Nitro enclave, then executed — or killed — onchain.

AI

Agent

TEE

Chainlink CRE

ENS

ENSv2

V

AgentVault

L

Ledger

How it works

01

Create on Ledger

Set daily cap, whitelist, and speed limits. Your Ledger device shows every field — hardware button = consent.

02

Agent transacts

Your AI calls Chainlink CRE with a JWT. The TEE verifies limits and executes via DON-signed report — no private key on any server.

03

Kill switch fires

Unauthorized recipient or exceeded cap → instant suspension. ENSv2 status flips to suspended. Only Ledger can reinstate.

GREEN

Within limits

Auto-execute

YELLOW

Over daily cap

Ledger approval

RED

Unauthorized recipient

Instant suspend

Ready to give your agent a bounded key?

Set the limits on your Ledger. Everything after that is enforced by hardware and code, not trust.

Create agent key →