Smart Stables - The next stablecoin primitive
Wrap existing stablecoins and create new app and use specific smart stablecoins linked to key metrics and events in your app while accessing DeFi yield on the underlying stablecoin 🧵
Circle has been shipping out primitives for the @Arc ecosystem.
We've cooked up a demo showcasing how @Circle Nanopayments + x402 power the agentic economy and why it depends on sub-cent settlement. ↓
Too many @GoogleChrome tabs open? Try vertical tabs, rolling out now.
Just right-click any Chrome window and select “Show Tabs Vertically” to move your tabs to the side of the browser window, making it easier to read page titles and manage tab groups.
Agentic payments are a pricing model innovation for SaaS
We've started doing simulations on how agents behave as multiple parties change pricing over time. Retention is soo different for agents vs humans
API pricing will look a lot more like ad auctions in an agent-first future.
Instead of fixed pricing with tiers, APIs will sell a number of calls per unit of time, agents will bid.
It will look like HFT but for agents paying for getting API calls fulfilled faster.
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
We've been thinking about AI agent payments wrong
You don't need to trust them with money. Or audit every transaction
Just program the money itself
Token-level rules are like physics. An agent can't violate them for the same reason a ball can't fall upward
Congrats on the release! Looking fwd to giving this a spin
I remember some of the stuff you did with ithaca and wallet ux with passkeys was pretty cool too, how much of those learnings did you take into tempo's native features? What is your go to auth provider/method when starting a new project on tempo?
Gotta give huge credit to @tempo on how well they've designed batch txns, gas sponsorship natively at the chain lvl and a great block explorer
Surely raised the industry's dev UX bar
We’re Based Labs. We build programmable stablecoin infrastructure. Stablecoins with rules. Spend controls, compliance logic, agentic payments, treasury automation. We’re turning stablecoins into application-aware financial infra for payments, treasury, and agentic commerce.
@jinglingcookies Wallets are also only programmable up to a point. Agents creating stablecoin with rules baked into them will do things beyond programmable cards and wallets
Wallets are mainly for the vendor lock-in you get as you scale
📢 Solidity JSON Writer v2
1/
A complete overhaul of the only on-chain, gas-efficient JSON builder library for smart contracts
Wanting on-chain metadata (NFTs, agents, etc.) or need structured JSON in Solidity? Read on.
👇
ERC20 was never designed for agentic commerce
x402 should be designed to support tokens having custom rules. Agent to agent commerce should have tokens designed for agent to agent commerce, not ERC20!
Downside of x402:
It basically enshrines USDC as the only payment token.
x402 on the EVM uses ERC-3009, which is basically just supported by USDC.
Not possible to use ETH, USDT, Dai, BOLD, etc
Having some AI follow you into your zoom meetings or google meet for taking notes is the digital equivalent of showing up to a meeting with your fly down