AI agents are spending real money right now — autonomously

A hijacked AI agent can drain its wallet in under 2 minutes.

Agents now pay for APIs, data and compute on their own — hundreds of tiny stablecoin payments a minute, with no human clicking "confirm." Your bank flags a weird charge in seconds. Nobody does that for an agent that just got compromised. Burnwatch learns each agent's normal spend and alerts the instant the money starts leaving.

$600M+
Estimated settled through x402 rails
Industry estimates, early 2026
~500K
Estimated active autonomous agent wallets
x402 ecosystem data, 2026
100M+
Agentic payments on Base in ~3 quarters
On-chain data, Q1 2026
the gap

Spending caps aren't fraud detection.

The big platforms will sell you per-transaction limits — but only if your agent lives entirely inside their walled garden, and only if the attacker spends in obvious round numbers. A compromised agent doesn't. It bleeds you in thousands of "normal-looking" micro-payments.

What built-in spend limits do

  • Only work inside one cloud / one wallet — useless if you run agents across rails
  • Static caps an attacker simply stays just under
  • No concept of this agent's normal behavior
  • You find out when the wallet's already empty

What Burnwatch does

  • Works across any rail or wallet — x402, AgentCore, MPP, plain HTTP 402
  • Learns each agent's normal spend rate, counterparties and rhythm
  • Flags the anomaly — burn-rate spikes, unknown payees, drains
  • Alerts you in seconds, while the money's still in the wallet
setup

Watching your agents in under ten minutes.

No custody migration. No new wallet. It rides alongside the agent you already run.

01 / WRAP

Wrap your payment client

A thin SDK shim around your agent's x402 / payment client — pip install burnwatch. Outbound-only, fail-open, never in the money path.

02 / LEARN

It baselines normal

A short warm-up of real payments teaches it each agent's typical spend rate, counterparties, destinations and hours.

03 / WATCH

It catches the drain

Anomaly fires → you get a push / webhook / email with the agent, the suspicious payments and the evidence. Observe-only.

detections

The patterns that mean money is leaving.

Spend-velocity breach

An agent that normally spends cents a minute suddenly burning dollars a second — the classic hijacked-agent drain.

Unknown counterparty

Payments to a recipient or endpoint this agent has never paid before, appearing out of nowhere.

Off-pattern destination

Spend on a service category outside the agent's normal mix — a research bot suddenly buying compute it never touches.

Prompt-injection drain

A rapid burst of escalating payments right after a tool call — the signature of an agent that's been talked into spending.

Observe-only. It never touches your keys or your funds.

Burnwatch watches payment metadata — amount, recipient, frequency — and alerts. It never holds your money, never holds your private keys, never sits in the payment path. Think smoke detector, not a vault. That's the whole design, and the reason you can drop it in without trusting us with anything that matters.

pricing

Start free. Scale when you need to.

Every plan includes all 13 detection rules, explainable alerts, and the full dashboard. No black-box ML, no mystery flags.

Free
$0/mo
Forever free
  • 2 agents
  • 10,000 events / mo
  • All 13 detection rules
  • Email & JSON webhook alerts
  • Full dashboard
Get started free →
Team
$49/mo
Billed monthly, cancel anytime
  • Unlimited agents
  • Unlimited events
  • All 13 detection rules
  • Slack, Discord & Teams alerts
  • Full dashboard + audit log
Get Team →

Connect your first agent in five minutes.

Free plan, no credit card. Upgrade when your fleet grows.

Start for free → Sign in
No credit card. No key custody. Observe-only.
WORKS WITH x402 Coinbase AgentKit AgentCore MPP any HTTP 402 rail