hackquest logo

Flying Money

Give a budget. Not your wallet. Let AI agents and people spend capped USDC at one seller: checked instantly, collected in batches on Arbitrum, and impossible to overspend.

视频

技术栈

Solidity
Next
React
Web3
Node
Foundry
viem
MCP

描述

Give a budget. Not your wallet.

To let Claude pay for an API today, you hand it a card or a hot wallet. One prompt injection or one leaked key, and everything is exposed. Flying Money replaces that with a budget: USDC locked on Arbitrum for one seller, one spending key, a maximum, an end date. A stolen key can't pay anyone else or spend past the limit. Enforced by the contract, not by the prompt.

Try it in 60 seconds: useflyingmoney.vercel.app/demo → Run it for real. An agent buys 20 API calls from a 0.30 USDC budget: 20 purchases, 3 Arbitrum transactions, each with an explorer link. Tick Steal the agent key and watch a thief get refused three ways: by the seller, by the contract, and by a different seller.

What's different

  • Sellers don't watch the chain. Payment channels let the payer withdraw after a delay, so the seller must monitor and react. A Flying Money budget can't be cancelled before its end date, so a seller that has checked it can serve instantly, even through an internet outage at the till, and collect later.

  • Agents ask; humans approve. With one message, an assistant (Claude, Cursor, any MCP client) sets itself up and requests a budget. The owner sees who asks, which seller, how much and for how long, then funds it from their own wallet. An agent can never approve or raise its own budget.

  • One budget, two worlds. The same contract pays an API per request over HTTP 402, and a café by QR code at the counter. The customer needs no crypto wallet and pays no fees.

Why Arbitrum: purchases happen off-chain as signed slips, and only collection touches the chain. Batches are cheap: collecting 10 slips costs about 328k gas. Arbitrum's low fees make micro-payments from API calls, allowances and café tabs economical to settle.

What's built (open source, MIT)

  • FlyingMoney.sol, verified on Arbitrum Sepolia: 0xb9ae3158f9cA841d9Da3C3725014D8352ca967F2. No owner, admin, pause, fee or upgrade path. Seven invariants are tested by fuzzing in Foundry.

  • TypeScript SDK with a crash-safe outbox (a retry never charges twice), seller middleware, and an MCP server with six tools.

  • Account app (requests inbox, approvals, budgets, collection), a phone wallet and an offline-capable shop till.

Business: the protocol is free and open. The plan is a hosted service for sellers (payment records, collection, recovery), starting with paid API and data sellers whose customers are agents, then pilots with known shops.

本次黑客松进展

We rebuilt Flying Money from scratch starting 23 September: 73 commits in 11 days, by one founder working with AI coding agents. What's live today: the escrow contract on Arbitrum Sepolia (verified, with batched collection), buyer and seller SDKs, an MCP server that sets itself up, an inbox where owners approve or decline their agents' budget requests, a phone wallet for people who receive a budget, a shop till that keeps working offline, guided onboarding for owners, assistants and shops, and a live demo that runs real Arbitrum transactions. It is tested, not just demoed. 369 automated tests pass with no cached results. They include 41 contract tests with fuzzed invariants (256 runs at depth 50), 148 seller tests covering concurrency, replay attacks and crash recovery, and 10 browser end-to-end tests that also check accessibility (WCAG 2.2 AA) in light and dark mode. We ran our own adversarial security review and fixed every high- and medium-severity finding before submitting. Next: an independent security audit, then one pilot with a paid API seller and one with a known shop, then mainnet with built-in caps of 100 USDC per budget.

融资状态

Not raised yet; self-funded. Open to pre-seed conversations after the first paid-API and shop pilots.
队长
HHerald Bayoca
项目链接
赛道
DeFiAIInfra