On-chain, the mistake is final.
A transfer cannot be charged back or reversed, so a control that runs after it is only a report. Digital assets and crypto get the largest rule pack we ship.
What is in the pack
| Rule | What it stops |
|---|---|
| Sanctions screening | a transfer to a listed address, against the lists you subscribe to |
| KYC tiers | a wallet doing more than its verification level allows |
| Daily volume caps and cooldown | a wallet drained by many small transfers, each under the single-transfer limit, with a 24-hour cooldown after a breach |
| First-time destination | the first transfer to an address this wallet has never used, held for review |
| New-wallet drain | a large transfer out of a wallet created days ago |
| Bridge whitelist and token security | funds leaving through a bridge you never approved, or a swap into a token that cannot be sold back |
| Token approvals | an unlimited approval to an unknown contract, the usual way a phishing site drains a wallet later, and a burst of approvals from one wallet within an hour |
| Geo restriction | activity from a jurisdiction you do not serve |
| Recovery | a wallet taken over through recovery: a seed-phrase restore after repeated failed sign-ins, too few guardian signatures, or a request from an unfamiliar IP address |
These are declarations you read and edit. Change a tier limit and it goes through candidate, backtest and promote like any other rule.
When an agent is the one signing
The signed transaction passes through a gateway on its way to your node, and a rule checks the asset, the recipient and the amount in the signed bytes before the network sees it. Your signing key stays where you keep it.
An agent moves faster than a person, acts on text it read somewhere, and repeats the same mistake until something stops it. Two controls matter most: authorization, which catches a sequence that is not allowed even when each action in it is, and a counter with a stop, because a loop turns one bad decision into an incident.
A harmful instruction can also arrive inside the data. Injection detection checks what comes in, including what a tool sends back.