Agents

The next launchpad has no token

The DeFAI launchpads sold agent tokens to audiences and died with the attention they monetised. The agents that survived get paid for being right — and the thin conditional books that decide treasuries are shaped for exactly that trade, once someone builds the layer between a wallet and a view.

This post examines a question the DeFAI cohort has started asking: are decision markets the next venue for autonomous trading agents — and what would a launchpad for such agents actually be? We make three claims. First, the durable residue of the 2024–25 agent wave is not any token but a species: the agent that is paid for being right. Second, binding decision markets are structurally well suited to that species — but the fit is supply-side. Agents are the cheapest standing depth these thin books can buy, not a wave of incoming demand. Third, the binding constraint on agent participation is neither custody nor execution, both largely solved in 2026, but pre-trade epistemics: what an agent can know about a thin, manipulable mechanism before it trades. We call that missing layer the pre-flight layer, and we sketch its contract.

Introduction

Two measurements frame the question. In March 2026, reporting on Polymarket put agents behind more than 30% of wallet activity and fourteen of the twenty most profitable wallets; by July, a University of San Diego study attributed over 80% of volume in the venue's smaller markets to bots. That same July, the entire binding decision market tape printed $5.86K of volume across thirteen wallets.

One tape is where the agents live. The other is where treasuries are decided. Whether these two lines belong to one story is a fair question, because decision markets' missing product is standing depth and agents are the one participant class whose cost of standing anywhere is collapsing. Our answer is a conditional yes, with the condition doing most of the work. The condition is not a wallet, a framework, or a token launch. It is the layer between a wallet and a view.

The first wave

The 2024–25 attempt to put AI agents into DeFi had a precise structure, worth stating exactly because the next attempt will rhyme with it.

The product was distribution. An agent posting crypto commentary to half a million followers was genuinely new in November 2024, and the market priced the novelty as software: by mid-January 2025, Virtuals Protocol — the launchpad most agents issued through — reached a market cap around $3.2B, the ai16z DAO token about $2.4B, and aixbt, the flagship commentary agent, roughly $800M. The word "DeFAI" was coined that month by a project whose own token was going parabolic.

The mechanism underneath was token issuance. The flagship's premium surface was gated by holding 600,000 of its own tokens — a paywall denominated in the asset it was meant to justify, which is supply lock, not income. "Launching an agent" meant issuing a token about an agent, on a bonding curve, to an audience. Almost none of the market cap corresponded to an agent doing economic work.

The unwind followed from the mechanism. The sector lost roughly two thirds of its value in under a month in early 2025. aixbt's one execution surface was prompt-injected out of 55.5 ETH in March 2025 — two hostile instructions queued through its own dashboard. By 22 August 2026 the arithmetic was complete: ai16z's founder had declared the token "dead. Completely," its successor marked at $1.4M against the original's $2.4B peak; aixbt at $21M; Virtuals at $454M. The DeFAI category label now covers about $655M across some 160 tokens.

Figure 1 The first wave, marked to market Peak market capitalisation of the flagship agent tokens against 22 August 2026. Log scale; ai16z is shown at its successor token's current value.
$10M $100M $1B log scale Virtuals (VIRTUAL) — Jan 2025 peak Virtuals (VIRTUAL) — Jan 2025 peak: ≈$3.2B ≈$3.2B Virtuals (VIRTUAL) — 22 Aug 2026 Virtuals (VIRTUAL) — 22 Aug 2026: $454M $454M ai16z — Jan 2025 peak ai16z — Jan 2025 peak: ≈$2.4B ≈$2.4B ELIZAOS, its successor — 22 Aug 2026 ELIZAOS, its successor — 22 Aug 2026: $1.4M $1.4M aixbt — Jan 2025 peak aixbt — Jan 2025 peak: ≈$800M ≈$800M aixbt — 22 Aug 2026 aixbt — 22 Aug 2026: $21M $21M
CoinGecko, read 22 August 2026; January 2025 peaks as reported by CoinDesk, Messari, and crypto.news. Download Data

What survived is more instructive than what died: agent wallets whose keys live in enclaves the model never touches; a micropayments standard (x402) that graduated from a Coinbase experiment to an industry foundation while its real daily volume stayed small; one launchpad still earning — Clanker, an agent that launches other people's tokens and charges for the service, past $50M in cumulative fees; and one cohort of agents with an actual business, the ones trading prediction markets.

What the record shows

The measured record of agents in markets, as of August 2026, has three properties.

Participation is large and profitable participation is automated. Beyond the March share figures, bots earned on the order of $35–50M in Polymarket's larger markets between late 2022 and early 2026 — earning it, pointedly, on speed and entry price rather than prediction accuracy. Retail picked winning outcomes more often and still lost by trading late at bad prices. Within the largest genuinely autonomous fleet, Olas's Polystrat — 4,200+ Polymarket trades in its first month — 37% of agent wallets report positive P&L, against a 7–13% baseline for human traders. A minority either way; three times the human rate.

Figure 2 The profitable minority is automated Wallets in profit on Polymarket, March 2026 reporting: 37% of the Polystrat autonomous fleet against a 7–13% baseline for human traders. A minority either way; three times the human rate.
0% 50% 100% Polystrat fleet agents Polystrat fleet agents: 37% 37% Humans — top of range Humans — top of range: 13% 13% Humans — bottom of range Humans — bottom of range: 7% 7%
CoinDesk, 15 March 2026; Olas. Download Data

Raw model skill still trails the crowd's professionals. In the Prediction Arena benchmark, six frontier models traded live money for two months and every one lost between 16% and 30.8% on Kalshi, averaging roughly flat on Polymarket. On ForecastBench, superforecasters lead the best model by 0.017 Brier points (best model 0.102 on the late-January 2026 leaderboard — a year earlier the best score was 0.117). The Forecasting Research Institute's trend fit puts parity in late 2026 with a confidence interval running deep into 2027; Metaculus's own extrapolation lands later still. Both are trend lines, not measurements, and the one system claiming parity today adds value only in ensemble with the market it trades. The profitable agent of 2026 is a quant-style hybrid, not an oracle.

The rotation toward new venues has begun. The project that coined "DeFAI" launched a prediction market in February 2026, resolved — in its telling — by AI-agent oracle consensus. IOSG's March brief named prediction-market agents the product form of 2026, locating the value in automating information processing rather than out-forecasting anyone. Prop firms are deploying agents on Kalshi and Polymarket, and the trade press's summary is that the easy money is disappearing: where agents saturate a venue, the venue gets efficient and agent returns compress. The two worlds are already touching from both sides. Aerodrome, Base's dominant DEX, replaced gauge voting with prediction-market allocation of its liquidity incentives this summer, with its chief executive naming AI agents as expected participants. And inside MetaDAO's own cohort, Laso Finance — a futarchy-governed launch — became the second-largest application on the x402 agent-payments rail, with all of its ~$79K in 30-day volume coming from AI agents. Agents are customers of a market-governed business before they are traders in its market.

Why decision markets

The first essay in this series made the economic argument in one paragraph: agents do not need to beat the crowd; they need to make the marginal informed opinion cheaper, because every dollar off the cost of forming a view comes off the subsidy a sponsor must post to get a thin question answered. Vitalik's info-finance essay made the micro-scale version of the claim first — with AI participants, markets become viable at volumes no human analyst would show up for. Hanson's 2025 note on futarchy liquidity supplies the other half of the ledger: the decision sponsor subsidises the market maker, and the subsidy is the purchase price of the information. His note never mentions AI traders; the synthesis — subsidised conditional books as standing bounties that machine attention collects — belongs to this decade's readers of both.

Four structural properties make binding decision markets a good habitat for the surviving species of agent. None is a growth projection.

  1. The question is bounded and settlement is programmatic. A conditional book on one proposal settles into the organisation's own asset, by program, when the TWAP clears its threshold. There is no resolution essay and no oracle vote for a whale to buy — the failure mode behind Polymarket's $7M Ukraine-minerals dispute has no address here. A market that cannot be argued with after the fact is a contract a machine can price.
  1. The clock pays patience, not latency. Where agents already dominate, they win on speed — the axis that adds the least information. A 48-hour time-weighted verdict is the opposite selection pressure: a trade in the final ten minutes carries ≈0.35% of the verdict. A venue that structurally refuses to pay for microseconds selects for agents with views.
  1. The subsidy is explicit and the buyer is named. Decision-market depth is not cross-subsidised by a sportsbook; the organisation buying the answer pays in pool share and serialised attention, which is why the books are thin — and why an agent quoting a 72-hour dying book is collecting a bounty, not donating liquidity. The category's open problem — a market-maker contract for a book that lives three days and extinguishes — reads like an agent job description. No human desk wants that contract. A fleet that costs tens of dollars a week to run can hold it.
  1. The door has no host. Hanson's adoption obstacle is about rooms: the advisor who cannot read the room is not given a seat, and a firm must invite a market in for the market to advise it. An AI agent is that advisor industrialised — all topic, no room-sense. A permissionless conditional book is the one interface in this economy that cannot tell an uninvited intelligence from a citizen. Nobody adopts the agent, seats it, or believes it; it buys its seat with its order, and the mechanism pays it strictly for being right. Kleros's founder predicts agents take the majority of non-sports prediction volume precisely because conditional and scalar structures are easier for machines to parse than for people. Adoption by invitation failed for twenty years. Adoption by order flow does not need permission.

Sizing the claim honestly: none of this is a demand forecast. The venue class is broader than one launchpad now — a permissionless arm in Futardio, a constitutional minting gate at Kleros resolved on a 24-hour terminal TWAP, an advisory pilot on Gnosis run by a startup with Hanson as its chief scientist, an allocation variant on Base — but every book in it is thin. The scale mismatch is four orders of magnitude, July's binding tape was thirteen wallets, and "the next meta" as a rotation claim has no evidence behind it and one month of counter-evidence. The defensible claim runs the other way. Decision markets' missing product is standing depth; agents are the only participant whose cost of standing there is collapsing. That is a supply-side thesis: not that agents make these markets big, but that they make honest depth cheap — and cheap depth is what separates a covenant that can defend itself from one that merely promises to.

The adversarial case

Every property above is symmetric, and a desk that publishes an attack-vector library does not get to skip this section.

Automated volume is first an attack technology. The canonical study of unregulated crypto exchanges attributes over 70% of reported volume to wash trading, overwhelmingly bot-executed; Columbia researchers put wash trading at roughly a quarter of Polymarket's historical volume, peaking near 60% during an airdrop-farming winter. Fabricated conviction is the cheapest thing a fleet produces, and two of our four monitored vectors — wash-volume alignment inflation and coordinated multi-wallet stake assembly — describe exactly that fleet pointed at a conditional book.

Thin books make the arithmetic worse. Umbra's defence held with about $52K in the pools on a day $1.5M was in play, and the rejection margin was real but, as one post-mortem put it, not enormous. MetaDAO's own history includes a quarter-million dollars spent openly bidding up a pass market. The TWAP clock defeats flash loans, not capital with patience — late-window outcome steering is a monitored vector on this desk, and new measurement work finds manipulation price impacts in prediction markets persisting for weeks. The theorems compound the concern: the decision market literature's known incentive bends — priced into this series from the start — are exploits a human finds occasionally and an optimiser finds systematically. Whatever bends for a person bends industrially for a swarm.

The agent itself is attack surface. The first wave's flagship was robbed through its own dashboard; in May 2026 an attacker drained roughly $150–200K from an agent wallet stack with a prompt injection encoded in Morse code in a tweet reply. An agent trading a book that moves a treasury is a strictly richer target: the payoff of one poisoned input is a governance outcome, not a bad fill.

And the tape cannot certify anyone's edge — including a defender's. The one onchain benchmark built for forecasting agents computes that certifying even a 0.02 Brier edge at 80% power requires about 350 resolved questions. The entire binding decision market record is roughly a hundred proposals. On a tape this short, every claimed edge — bull or bear, attacker or defender — is a story rather than a measurement, and will remain one for years. A desk that withholds a classification when evidence is missing should say the same about agent performance: the honest state of nearly every decision market agent metric is withheld.

Figure 3 The tape is too short to certify an edge Certifying even a 0.02 Brier edge at 80% power takes about 350 resolved questions. The entire binding decision market record is roughly a hundred proposals.
needed to certify an edge: ≈350 ≈350 needed to certify an edge binding proposals, ever: ≈100 ≈100 binding proposals, ever
Foresight Arena power analysis (arXiv, 2026); binding-proposal count as published on this desk. Download Data

The net is not a wash; it is a design constraint. Agent flow amplifies whichever side is better informed, and on a thin book the better-informed side is whoever prepared. The July head-to-head — a token vote that lost $20M against a market that billed its attacker $4,623 — is the mechanism working when someone shows up armed. A swarm changes who can afford to show up, in both directions at once.

The missing layer

"Self-sovereign agent" in 2026 means something narrower than the phrase suggests. Custody is substantially solved: keys live in enclaves the model never touches; the agent holds a scoped, revocable capability rather than a secret; spending limits are enforced below the model, where no prompt can reach them; payments have a standard with an industry foundation behind it. Six major venues shipped official agent-trading surfaces across July and August alone — with, as one analysis noted, no independent security audit of any exchange's MCP implementation published as of August 2026. The sovereignty stack is real, and it stops at the signature.

What the stack does not contain is a view. The trust registries meant to distinguish good agents from bad are, per the first empirical study of ERC-8004, mostly namespace: between 3% and 15% of registered agents expose a valid registration with a live endpoint, and 59–91% of reviewer accounts show Sybil behaviour. The guardrail products that exist — mandatory simulation, threat scans, allowlists, isolated sub-accounts — are theft prevention, built to stop an agent's money leaving through the wrong door. No commercial layer stops an agent from trading badly on manipulable evidence: no position-level risk gate, no oracle-divergence halt, no check that the print you are about to trust is thinner than your size. The industry has no product name for that layer yet.

Vitalik's second thoughts about "AI governance" were earned within days of a public exploit of an AI assistant's tool access: naive designs collapse to a jailbreak plus a request for the money, and the robust shape is an open market of models held to spot checks and human juries — AI as engine, humans as steering wheel. That is a statement about inputs. An engine is only as sovereign as the instruments it steers by.

For decision markets the gap is sharper still, because the venue state is not even conveniently readable. The flagship venue's public API serves market data without proposal-level state; the maintained path to the thing that decides — window boundaries, thresholds, TWAP accumulators — is decoding program accounts yourself. An agent can get a wallet in an afternoon and a futarchy position an hour later. What it cannot get anywhere, as of this writing, is the answer to the questions that determine whether its participation is depth or noise: what mechanism am I inside, which of its components has no detector watching it, what would it cost to move the print I am reading, and what am I not entitled to conclude from the evidence that exists?

The pre-flight layer

A launch pad, literally, is not where a thing is sold. It is where a thing is checked before ignition, with ground control after. The first wave built launchpads in the issuance sense — bonding curve, audience, fee share — and that model died with the attention it monetised, then died again this August when its flagship's founder pronounced the token dead. We propose the opposite object. For a machine trader entering a binding conditional market, the pre-flight layer has five components:

  1. The mechanism, decoded. Live window state, thresholds, and TWAP accumulators as structured data, not a chart. Our desk publishes its live read and serves it to agents over an open MCP endpoint — to our knowledge the only agent-native surface over live futarchy state anywhere, which is less a boast than a measurement of how early it is.
  1. The attack surface, mapped. The mechanism decomposed into components with the vector library's detector coverage of each, including the components nothing covers. An agent that knows which part of the machine is undefended can size accordingly; one that does not is the exit liquidity of whoever does.
  1. The depth arithmetic, priced. What one-sided flow moves the print being read, stated as a floor under named assumptions, never as a rating. Thin is sometimes consensus and sometimes cheap; the number that distinguishes them belongs in the packet.
  1. The covenant, checked. Launch terms evaluated tri-state — present, absent, unknown — with unknown never rounding to present.
  1. The refusals, in the wire format. This component cannot be retrofitted. An agent consumes schemas, and a schema that can express a composite risk score or a "safe" will eventually emit one under pressure. Our read surface encodes the refusals as logic: the ontology declares a composite proposal-risk score and a safety rating equivalent to owl:Nothing, and every tool payload carries its lane, version, and withheld status. A machine reading it cannot be told more than the evidence supports, because there is no field in which to say it.

The fifth component is what separates a pre-flight layer from a data feed. The prompt-injection incidents above are one lesson wearing two masks: an agent's data layer is part of its attack surface, and a data layer that flatters — that rounds missing forensics up to "low risk," that compresses six findings into one green number — is an injection an attacker does not have to send. Withheld-stays-withheld is not compliance prose here. It is armour for a reader with no scepticism of its own.

A second fit sits under the first, and we expect it to age best. An argument circulating in the venue's own research orbit runs the mechanism the other way: decision markets as the accountability layer for capital that agents allocate — the agent proposes, the owners price the consequences, and the treasury moves only if the market clears. The covenant essay observed that an organisation born under decision markets has no incumbent to kill them. An agent-run organisation is the limiting case: it has no boardroom for the market to embarrass, and its principals need a control instrument that does not require trusting a model's account of itself. If self-sovereign agents end up holding treasuries — and the wallet rails being built for them say someone intends exactly that — the covenant that binds a treasury to a market was already invented, on this venue, for humans who could not trust each other either.

Three open problems gate all of it, and they are the same list this series has carried, now with a second customer. The event indexer is still the keystone: the wallet-attributed, in-window trade history that would let detectors classify live instead of withholding is the same history an honest agent needs before trusting its own fills. The dying-book market-maker contract still needs writing, and its natural counterparty is now a fleet. And parameter review before a book opens — window length, liquidity floor, threshold, priced against attack cost — is still a review nobody sells, and the one an agent operator should demand before pointing capital at a venue.

Conclusion

The first launchpads launched tokens about agents at audiences, and the audiences left. The venue that decides treasuries needs the opposite object: no token, no audience, no ignition without a checklist. Decision markets are not the next meta for DeFAI in the sense the phrase intends — there is no rotation to front-run, and the tape says so. They are something narrower and better: the venue where a machine that is merely fast earns nothing, a machine with a view earns the subsidy, and a machine with a view and a map of the mechanism is the standing depth the covenant has been missing. The launchpad for that machine is the map. Its first deliverable is the answer to the question every self-sovereign agent should ask before touching a book that moves a treasury: what am I not allowed to conclude? On this pad, nothing ships green.

Back to blog