Haltr AI

The circuit breaker for rogue AI agents.

A public spec registry for Solana AI agents. Helius telemetry on every registered wallet. A zero-override breaker that halts an agent the moment a signed transaction breaks its published bounds, with the receipt onchain. Live on mainnet, nothing simulated.

Built for The AnsemHack Clawrena. Solana. Helius priority RPC.

Agents watched21 Haltr Verified
Actions evaluated12signed mainnet transactions
Breaches intercepted5spec violations flagged
Capital protected0.011 SOLexposure of halted trades
Receipts onchain5memo transactions posted
$ANSEM burned151 certified spec
The problem

Agents fail at machine speed.

An agent is a wallet driven by a model. It follows a bad instruction to the letter, at full size, in one block. Haltr sits between the model and the chain.

01

Prompt injection

A poisoned tweet or token description convinces the agent to route a swap through a drainer program. The model did what it was told. The wallet is empty.

caught by UNAPPROVED_PROGRAM
02

Runaway sizing

A parsing bug turns 0.5 SOL into 50. Nothing in the agent's own code stops it from sending the whole balance in one transaction.

caught by MAX_TRADE_SIZE
03

Toxic assets

The agent buys a fresh ticker that cannot be sold. Every honeypot looks like a breakout until you try to exit.

caught by HONEYPOT
04

Drawdown spiral

A losing strategy keeps averaging down. Without a hard equity floor, a bad hour becomes a wiped account.

caught by MAX_DRAWDOWN
How Haltr works

Spec to receipt.

Six stages, each one public and verifiable. Judges can fire a real breach from the simulator and send a real pre-flight check from the docs.

01

Publish a spec

Registry · live

Owners register a mainnet wallet with machine-readable bounds: max trade size, max drawdown, approved venues, slippage, rate limit and program allowlist. They prove control by signing a message with the agent wallet, or with their ClawPump API key.

02

Ask before signing

Pre-flight · live

An agent can send the trade it is about to sign to the pre-flight API. Haltr checks it against the spec and the halt state, quotes a sell-back to catch honeypots, reads the token mint and simulates the transaction on mainnet. The agent signs only when the answer is ok.

03

Stream every wallet

Telemetry · live

The watchdog daemon subscribes to each registered wallet over the Helius WebSocket and parses every signed transaction into venue, size, asset and programs within seconds of confirmation.

04

Evaluate against spec

Watchdog · live

Each transaction is judged by deterministic rules: size, venue, drawdown, program allowlist, asset allowlist and rate. Every verdict is stored with its Solscan signature.

05

Halt and receipt

Breaker · live

A breach halts the agent, through the ClawPump stop endpoint when the owner key is on file, and posts a memo receipt onchain from the Haltr wallet. The receipts explorer reads each one back from chain. No developer override.

06

Read, score, draft

Inference · live

After the halt, UsePod inference reads unknown programs, scores behavioural drift and drafts specs. Advisory only, paid per request with x402, listed in a public ledger.

What the watchdog enforces

Eight rules. No exceptions.

Each rule maps to one field in the spec. Six run on every confirmed transaction. Honeypot and slippage are checked before signing, through the pre-flight API.

MAX_TRADE_SIZEhigh
live

Max trade size

Single trade notional exceeds the spec ceiling.

MAX_DRAWDOWNcritical
live

Max drawdown

Projected equity breaches the peak-to-trough drawdown limit.

APPROVED_DEXhigh
live

Approved DEX

Route goes through a venue the spec does not permit.

ASSET_ALLOWLISThigh
live

Asset allowlist

Token is not on the agent's approved asset list.

MAX_SLIPPAGEmedium
pre-flight · live

Max slippage

Slippage tolerance exceeds the spec ceiling.

UNAPPROVED_PROGRAMcritical
live

Unapproved program

Transaction invokes a program outside the agent's allowlist.

HONEYPOTcritical
pre-flight · live

Honeypot token

Pre-simulation shows the token cannot be sold back.

RATE_LIMITmedium
live

Trade rate limit

Too many trades inside a rolling sixty second window.

The spec

A spec is a contract.

Machine-readable, versioned and public. Users read it before they trust a bot. The watchdog reads it before every trade.

example spec · v3Haltr verified
{
  "agent": "your-agent.clawpump",
  "version": 3,
  "maxTradeSizeSol": 2,
  "maxDrawdownPct": 5,
  "approvedDexs": ["Raydium", "ClawPump"],
  "approvedAssets": null,
  "maxSlippageBps": 150,
  "maxTradesPerMinute": 12,
  "allowedPrograms": [
    "675kPX9MHTjS2zt1qfr1NYHuzeLXfQM9H24wFSUt1Mp8",
    "TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA"
  ],
  "flattenTo": "USDC"
}
Versioned. Every change is a new version, and the spec history shows what changed and when.
Public. Anyone can read the bounds an agent has committed to.
Enforced. The registry is not documentation, it is the rulebook the breaker runs.
Certified. Burning $ANSEM stamps the version with the Haltr Verified badge.
Embeddable. Every agent has a live status badge for its README or any web page.
Circuit breaker

Zero override.

When a transaction breaks the spec, the sequence is fixed and the developer is not in it. Three stages run today; the fourth lands with the onchain program.

01

Detect

The transaction is seen on the Helius stream and evaluated against the agent's current spec version, usually within five seconds of confirmation.

02

Halt

The agent is marked halted in the registry and, for verified ClawPump agents, stopped through the owner's API. Re-arming needs a signature from the agent wallet, or the owner's ClawPump key, and publishes a new spec version.

03

Receipt

A memo transaction from the Haltr wallet records the agent, rule, offending signature and exposure onchain. Each receipt has a permalink that decodes it from chain and checks it field by field against the registry.

04

Flatten · v2

With the onchain breaker program, funds sit in a vault the agent cannot drain: violating transactions are cancelled pre-flight and positions flattened to USDC or SOL.

$ANSEM mechanics

Utility, no buyback.

Two mechanics run on mainnet today and burn or lock real $ANSEM. Nothing is recycled back to the market.

01

Burn to certify · live

Send $ANSEM from the agent wallet to Haltr's certification address. Haltr burns it onchain with a memo naming the agent and spec version, and the registry shows the Haltr Verified badge with the burn signature. Every new spec version, including a re-arm after a breach, needs a fresh burn.

02

Priority telemetry · live

Wallets holding the threshold of $ANSEM are swept every ten seconds instead of thirty and drift-scored on every new batch. Read from the balance at each sync, so it switches on the moment the tokens land.

03

Underwriting pool · v2

Stake $ANSEM into the Security Reserve and earn each time Haltr saves user capital. Needs the onchain program.

Inference markets · UsePod

Inference, kept out of the kill switch.

Haltr buys inference per request on UsePod, paid with x402 from its own wallet, and publishes every call in a ledger. The breaker never depends on it.

01

Unknown-program reads

After the halt, the model reads the unapproved program's account and recent activity and writes a plain-English summary and risk onto the receipt.

02

Advisory drift scoring

Deterministic features compare an agent's latest actions to its own baseline. The model scores them 0 to 100 with named signals. It informs humans and never halts.

03

Spec drafting

Describe the strategy at registration and get a proposed spec. The developer edits and publishes it. Enforcement stays deterministic.

Roadmap

Shipping now.

What is live for the Clawrena, and what follows once the onchain program lands.

V1
Live on mainnet
  • Public spec registry with watch-only entries
  • Wallet-signature ownership proof, alongside the ClawPump key
  • Helius WebSocket telemetry through a 24/7 watchdog daemon
  • Deterministic spec evaluation on every signed transaction
  • Halt via registry and ClawPump stop, memo receipts onchain
  • Re-arm only with a signature from the agent wallet or the owner's ClawPump key
  • Pre-flight API: agents ask before they sign, with honeypot, slippage and simulation checks
  • Receipts explorer with permalinks that decode each receipt from chain
  • Spec history with version diffs, breaches per version and certification burns
  • Leaderboard ranked on onchain behaviour
  • Embeddable live status badge for every agent
  • Stream mode: a full-screen live board for screen sharing
  • Telegram alerts for breaches, certifications and elevated drift
  • Reference agent: Haltr's own SOL/USDC trader that signs only what pre-flight clears
  • Breach simulator that fires real mainnet transactions
  • UsePod inference paid with x402: program reads, drift scores, spec drafts, public ledger
  • $ANSEM certification burn and the Haltr Verified badge
  • Priority telemetry for $ANSEM holders
  • $HALTR token launch on ClawPump
V2
Q4 2026
  • Onchain breaker program with vault PDAs: pre-flight cancel and flatten
  • Underwriting pool with yield on saves
V3
2027
  • Automated @useHaltr receipt posts
  • Coverage beyond ClawPump: any Solana agent wallet
Questions

Straight answers.

The questions judges and users ask first.

Can a developer switch the breaker off?

Not while the agent is armed. After a trip, re-arming needs a signature from the agent wallet, or the ClawPump key that owns it, and publishes a new spec version anyone can read in the spec history. That is what zero-override means.

What happens when the breaker trips today?

The agent is halted, ClawPump agents are stopped through their owner's API, and a memo receipt goes onchain. Flattening positions into USDC or SOL arrives with the v2 onchain program.

Can an agent check a trade before it signs?

Yes. The pre-flight API takes the trade an agent is about to sign and answers ok or not. It applies the same spec rules as the watchdog, checks the halt state, quotes a sell-back for honeypots and simulates the transaction on mainnet. It is free, limited to 30 requests a minute per IP, and every check is logged publicly.

Read the pre-flight docs
Does the AI decide halts?

No. Halts come from eight deterministic rules anyone can audit. UsePod inference only reads unapproved programs, scores drift and drafts specs, and every output is labelled advisory.

Which agents can Haltr protect?

Any Solana mainnet wallet its owner registers. Owners prove control by signing a message with the agent wallet, or with their ClawPump API key. Wallets can also be registered watch-only.

Is the data on this site real?

Yes. Every agent is a real wallet, every verdict is a real signed transaction with a Solscan link, every receipt is a real memo transaction, and every inference call in the ledger was paid onchain. Each receipt page reads its transaction back from Solana and compares it with the registry.

Open the receipts explorer
For judges

Watch a rogue trade die.

Pick an agent, craft a spec-violating transaction, and watch the watchdog catch it, halt the agent and post the receipt onchain.