Menu
The task finished. The overspend didn't.
Inspect the verified mainnet outcome without signing or spending: a deterministic workflow bought the two inputs needed for an ETH risk brief. Then an injected test instruction requested an unnecessary export, and the signed card contained it before settlement.
Research Agent Expense Card
Verified replayThe resource payloads and brief are deterministic demo fixtures. The two USDC settlements and revoke are mined mainnet evidence from the verified live run. The adversarial instruction is a deterministic fixture, not LLM reasoning; its refusal was observed live during preflight against the deployed policy and can be reproduced below.
- Mission
- Prepare an ETH risk brief
- Signed boundary
- 0.10 USDC / tool
- Daily budget
- 2.00 USDC
Outcome
Task complete · policy heldTask completed safely
Software bought 2 required inputs, produced the brief, and could not move funds for the unexpected over-cap request.
- Useful spend
- 0.13 USDC
- Blocked request
- 0.20 USDC
- Budget left
- 1.87 USDC
2 inputs
1 refused
Still controlled
Particle Network proof
FINISHEDExecuted by Particle Universal Account
EIP-7702 · Particle verified the cross-chain card funding before this task; the tool purchases settled separately on Arbitrum
Useful result
ETH market-risk brief ready
ETH momentum neutral-to-positive; stablecoin flows rising on L2s. Sentiment is mildly bullish across 1,284 sources.
- L2 stablecoin inflow: rising (71% confidence)
- ETH funding: neutral (60% confidence)
Unexpected over-cap request
Refused before broadcastOver-cap charge blocked
SpendPolicy rejected the request in preflight. No transaction was broadcast and nothing left the account.
0.00 USDC moved
zero gas on the blocked attempt
- Attempted
- 0.20 USDC
- Signed limit
- 0.10 USDC
- Rule
- Per-charge limit enforced
Proof trail
Linked receipts prove money movement; the blocked attempt records the observed preflight verdict.
Tool purchase settlements
Budget revoked
The mined revoke disarmed this permission on-chain.
The receipt is the separate canonical Particle UA checkout proof; the tool purchases and funding evidence above remain linked to this agent run.
Reproduce the refusal yourself
No login or wallet. Simulate an over-cap request against the live Arbitrum policy; nothing is broadcast.
Base funded. Arbitrum settled.
Inspect the real 2 USDC Universal Account payment, its Base debit, Arbitrum merchant settlement, and the anchored InvoicePaid proof.
The three moments that build trust
Earlier checkout replay
PAID · proof recorded- Amount
- 0.1 USDC
- Merchant
- 0x8C54783849A2C042544efc37c4657Ee98a411Fb7
- Payer smart account (legacy mode)
- 0xeE1FB8b1d24d658F39D1AFEc50a82D0c306c0246
- Invoice ID
- 0xa804ede9c169e3e9ae6003c5e1a3fa5531bd0d1955ea3e6466d434f6b8a94ee1
- Payment mode
- Legacy smart-account checkout (pre-7702)
This early checkout ran in the SDK's legacy smart-account mode, so the payer is a separate contract address. The current product path is EIP-7702 — the Universal Account is the owner's own EOA (same address); see the cross-chain receipt above.
On-chain proof
Payment transaction0xfb480ac9…615eb357Payment transaction: 0xfb480ac9357e88d6a98f8e08fdf8a6a686cbcd8ee5e46aff20a56893615eb357 (opens block explorer in a new tab)Proof transaction0xb65cdcf3…9428788bProof transaction: 0xb65cdcf3e7a6973c801b0f0da8a50c03f19fd99dee4693ba7e8861609428788b (opens block explorer in a new tab)Honest scope: the Research Agent resources are deterministic fixtures; its two payments, policy block, and revoke evidence are real Arbitrum results. The checkout card uses a separate real same-chain payment, while the main-track receipt is a separate real Base-to-Arbitrum Universal Account settlement. No transaction is created by this replay.