Haltr AI
The circuit breaker for rogue AI agents.
A public spec registry for Solana AI agents. Helius telemetry on every registered wallet. A zero-override breaker that halts an agent the moment a signed transaction breaks its published bounds, with the receipt onchain. Live on mainnet, nothing simulated.
Built for The AnsemHack Clawrena. Solana. Helius priority RPC.
Agents fail at machine speed.
An agent is a wallet driven by a model. It follows a bad instruction to the letter, at full size, in one block. Haltr sits between the model and the chain.
Prompt injection
A poisoned tweet or token description convinces the agent to route a swap through a drainer program. The model did what it was told. The wallet is empty.
caught by UNAPPROVED_PROGRAMRunaway sizing
A parsing bug turns 0.5 SOL into 50. Nothing in the agent's own code stops it from sending the whole balance in one transaction.
caught by MAX_TRADE_SIZEToxic assets
The agent buys a fresh ticker that cannot be sold. Every honeypot looks like a breakout until you try to exit.
caught by HONEYPOTDrawdown spiral
A losing strategy keeps averaging down. Without a hard equity floor, a bad hour becomes a wiped account.
caught by MAX_DRAWDOWNSpec to receipt.
Six stages, each one public and verifiable. Judges can fire a real breach from the simulator and send a real pre-flight check from the docs.
Publish a spec
Registry · liveOwners register a mainnet wallet with machine-readable bounds: max trade size, max drawdown, approved venues, slippage, rate limit and program allowlist. They prove control by signing a message with the agent wallet, or with their ClawPump API key.
Ask before signing
Pre-flight · liveAn agent can send the trade it is about to sign to the pre-flight API. Haltr checks it against the spec and the halt state, quotes a sell-back to catch honeypots, reads the token mint and simulates the transaction on mainnet. The agent signs only when the answer is ok.
Stream every wallet
Telemetry · liveThe watchdog daemon subscribes to each registered wallet over the Helius WebSocket and parses every signed transaction into venue, size, asset and programs within seconds of confirmation.
Evaluate against spec
Watchdog · liveEach transaction is judged by deterministic rules: size, venue, drawdown, program allowlist, asset allowlist and rate. Every verdict is stored with its Solscan signature.
Halt and receipt
Breaker · liveA breach halts the agent, through the ClawPump stop endpoint when the owner key is on file, and posts a memo receipt onchain from the Haltr wallet. The receipts explorer reads each one back from chain. No developer override.
Read, score, draft
Inference · liveAfter the halt, UsePod inference reads unknown programs, scores behavioural drift and drafts specs. Advisory only, paid per request with x402, listed in a public ledger.
Eight rules. No exceptions.
Each rule maps to one field in the spec. Six run on every confirmed transaction. Honeypot and slippage are checked before signing, through the pre-flight API.
Max trade size
Single trade notional exceeds the spec ceiling.
Max drawdown
Projected equity breaches the peak-to-trough drawdown limit.
Approved DEX
Route goes through a venue the spec does not permit.
Asset allowlist
Token is not on the agent's approved asset list.
Max slippage
Slippage tolerance exceeds the spec ceiling.
Unapproved program
Transaction invokes a program outside the agent's allowlist.
Honeypot token
Pre-simulation shows the token cannot be sold back.
Trade rate limit
Too many trades inside a rolling sixty second window.
A spec is a contract.
Machine-readable, versioned and public. Users read it before they trust a bot. The watchdog reads it before every trade.
{
"agent": "your-agent.clawpump",
"version": 3,
"maxTradeSizeSol": 2,
"maxDrawdownPct": 5,
"approvedDexs": ["Raydium", "ClawPump"],
"approvedAssets": null,
"maxSlippageBps": 150,
"maxTradesPerMinute": 12,
"allowedPrograms": [
"675kPX9MHTjS2zt1qfr1NYHuzeLXfQM9H24wFSUt1Mp8",
"TokenkegQfeZyiNwAJbNbGKPFXCWuBvf9Ss623VQ5DA"
],
"flattenTo": "USDC"
}Zero override.
When a transaction breaks the spec, the sequence is fixed and the developer is not in it. Three stages run today; the fourth lands with the onchain program.
Detect
The transaction is seen on the Helius stream and evaluated against the agent's current spec version, usually within five seconds of confirmation.
Halt
The agent is marked halted in the registry and, for verified ClawPump agents, stopped through the owner's API. Re-arming needs a signature from the agent wallet, or the owner's ClawPump key, and publishes a new spec version.
Receipt
A memo transaction from the Haltr wallet records the agent, rule, offending signature and exposure onchain. Each receipt has a permalink that decodes it from chain and checks it field by field against the registry.
Flatten · v2
With the onchain breaker program, funds sit in a vault the agent cannot drain: violating transactions are cancelled pre-flight and positions flattened to USDC or SOL.
Utility, no buyback.
Two mechanics run on mainnet today and burn or lock real $ANSEM. Nothing is recycled back to the market.
Burn to certify · live
Send $ANSEM from the agent wallet to Haltr's certification address. Haltr burns it onchain with a memo naming the agent and spec version, and the registry shows the Haltr Verified badge with the burn signature. Every new spec version, including a re-arm after a breach, needs a fresh burn.
Priority telemetry · live
Wallets holding the threshold of $ANSEM are swept every ten seconds instead of thirty and drift-scored on every new batch. Read from the balance at each sync, so it switches on the moment the tokens land.
Underwriting pool · v2
Stake $ANSEM into the Security Reserve and earn each time Haltr saves user capital. Needs the onchain program.
Inference, kept out of the kill switch.
Haltr buys inference per request on UsePod, paid with x402 from its own wallet, and publishes every call in a ledger. The breaker never depends on it.
Unknown-program reads
After the halt, the model reads the unapproved program's account and recent activity and writes a plain-English summary and risk onto the receipt.
Advisory drift scoring
Deterministic features compare an agent's latest actions to its own baseline. The model scores them 0 to 100 with named signals. It informs humans and never halts.
Spec drafting
Describe the strategy at registration and get a proposed spec. The developer edits and publishes it. Enforcement stays deterministic.
Shipping now.
What is live for the Clawrena, and what follows once the onchain program lands.
- Public spec registry with watch-only entries
- Wallet-signature ownership proof, alongside the ClawPump key
- Helius WebSocket telemetry through a 24/7 watchdog daemon
- Deterministic spec evaluation on every signed transaction
- Halt via registry and ClawPump stop, memo receipts onchain
- Re-arm only with a signature from the agent wallet or the owner's ClawPump key
- Pre-flight API: agents ask before they sign, with honeypot, slippage and simulation checks
- Receipts explorer with permalinks that decode each receipt from chain
- Spec history with version diffs, breaches per version and certification burns
- Leaderboard ranked on onchain behaviour
- Embeddable live status badge for every agent
- Stream mode: a full-screen live board for screen sharing
- Telegram alerts for breaches, certifications and elevated drift
- Reference agent: Haltr's own SOL/USDC trader that signs only what pre-flight clears
- Breach simulator that fires real mainnet transactions
- UsePod inference paid with x402: program reads, drift scores, spec drafts, public ledger
- $ANSEM certification burn and the Haltr Verified badge
- Priority telemetry for $ANSEM holders
- $HALTR token launch on ClawPump
- Onchain breaker program with vault PDAs: pre-flight cancel and flatten
- Underwriting pool with yield on saves
- Automated @useHaltr receipt posts
- Coverage beyond ClawPump: any Solana agent wallet
Straight answers.
The questions judges and users ask first.
Can a developer switch the breaker off?
Not while the agent is armed. After a trip, re-arming needs a signature from the agent wallet, or the ClawPump key that owns it, and publishes a new spec version anyone can read in the spec history. That is what zero-override means.
What happens when the breaker trips today?
The agent is halted, ClawPump agents are stopped through their owner's API, and a memo receipt goes onchain. Flattening positions into USDC or SOL arrives with the v2 onchain program.
Can an agent check a trade before it signs?
Yes. The pre-flight API takes the trade an agent is about to sign and answers ok or not. It applies the same spec rules as the watchdog, checks the halt state, quotes a sell-back for honeypots and simulates the transaction on mainnet. It is free, limited to 30 requests a minute per IP, and every check is logged publicly.
Read the pre-flight docsDoes the AI decide halts?
No. Halts come from eight deterministic rules anyone can audit. UsePod inference only reads unapproved programs, scores drift and drafts specs, and every output is labelled advisory.
Which agents can Haltr protect?
Any Solana mainnet wallet its owner registers. Owners prove control by signing a message with the agent wallet, or with their ClawPump API key. Wallets can also be registered watch-only.
Is the data on this site real?
Yes. Every agent is a real wallet, every verdict is a real signed transaction with a Solscan link, every receipt is a real memo transaction, and every inference call in the ledger was paid onchain. Each receipt page reads its transaction back from Solana and compares it with the registry.
Open the receipts explorerWatch a rogue trade die.
Pick an agent, craft a spec-violating transaction, and watch the watchdog catch it, halt the agent and post the receipt onchain.