Every move your agent makes is public. Permanently.
AI can't transact over email or Slack. Blockchains are the first rails it can actually use, agents that hold value, sign contracts, and pay each other directly. But every one of those actions happens in the open, and the ledger never forgets.
Agents finally coordinate on-chain
Contracts, payments, and messages between agents settle on the chain, the only neutral rail machines can transact on without a human in the loop.
All of it happens in the open
Every interaction is broadcast to a public forum and recorded forever. Who an agent talks to, what it pays, and how it decides are readable by anyone.
The AI web needs both
Machines need data that stays private but still proves true. Shield47 keeps it immutable and verifiable, without putting it on display.
Shield in. Unshield out.
No link between the two.
Shield: deposit into the pool
Your agent deposits funds into the unified privacy pool and receives a private note.
Blend: break the link
Zero-knowledge proofs sever the connection to your deposit inside one shared anonymity set.
Unshield: withdraw clean
Funds arrive at a fresh wallet with no traceable connection to the source. Gasless via x402.
Infrastructure-grade by design
Unified privacy pool
One anonymity set. Every shield deepens the same pool, so withdrawals blend into the crowd.
Non-custodial
The protocol never touches your funds. You hold the note, only you can unshield.
Audited Groth16 proofs
The live stack runs on Groth16 zero-knowledge proofs, independently audited, with the audit complete.
Gasless withdrawals
A relayer pays gas via x402, so a fresh wallet needs no prior funding.
Compliance-capable
KYT/KYP screening keeps flows compliance-capable, so institutions stay auditable, not exposed.
Post-quantum, on the roadmap
A WHIR hash-based stack, formally verified in Lean, with no trusted setup, the credibility moat coming next.
Secure today. Quantum-ready next.
We never present a roadmap item as already shipped. Here is exactly where the protocol stands.
Pre-quantum privacy · Live
LIVE NOWLink-breaking shielded transfers, running today on Base with battle-tested zero-knowledge cryptography.
Post-quantum · On its way
~95% COMPLETEA quantum computer could one day break the elliptic-curve cryptography securing today's chains, and adversaries can harvest encrypted data now to decrypt later. We're moving to a WHIR hash-based stack that stays secure even then. Not yet deployed.
Built to be used by software, not just people.
The first agent-native privacy protocol. Full MCP support and an OpenClaw SKILL.md let AI agents transact privately, no frontend required.
- ✓ Native MCP server, drop into Claude, Cursor, and ACP
- ✓ Shield and unshield from a few lines of agent code
- ✓ Gasless withdrawals, relayer pays gas via x402
- ✓ KYT/KYP screening keeps automated flows compliance-capable
Most privacy hides amounts. We break the link.
A fair frame for where Shield47 sits, not a takedown of anyone.
Hides values, but the payer↔payee link stays visible, so the graph is still reconstructable.
Private, but walled off from DeFi liquidity and from the agents now transacting on-chain.
Breaks the link, on Base, with full DeFi and agent reach, and stays compliance-capable for institutions.
Give your agents the privacy any
serious operation requires.
Shield your first transaction on Base, or drop the MCP server into your agent stack today.