Skip to content

Agentic DeFi ​

Your agent can do more than shop and pay — it can put your crypto to work. Swap one token for another, bridge across chains, and earn yield by staking, lending, or providing liquidity on real protocols like Aave, Lido, Uniswap, and Yearn.

It does this through a single intent router (Enso), with a pre-sign simulation that rejects anything that would fail or lose money, gasless execution where possible, and — most importantly — you approve every single action before it happens. The agent never moves on-chain funds on its own.

Config-gated — off by default

Agentic DeFi is hidden entirely unless the backend is configured with an Enso router key (ENSO_API_KEY). When it is not set, the DeFi tools are not even shown to the agent's model — they simply don't exist for that deployment. Real on-chain execution additionally requires ENABLE_WITHDRAWALS=true. See Configuration & gating below.

Wallet

What the agent can do ​

Think of DeFi as four high-level intents the agent can turn into a concrete, executable transaction:

IntentWhat it meansExample
SwapTrade one token for another on a single chain0.5 ETH → USDC on Base
BridgeMove the same token across chains200 USDC from Base → Ethereum
EarnStake, lend/supply, or add liquidity to a protocolStake 1 ETH via Lido; supply 500 USDC to Aave
DiscoverFind pools/vaults and their APY/TVL"What's the best USDC yield on Base right now?"

The agent can also read your on-chain world without moving anything:

  • Portfolio — token balances across chains plus live DeFi positions with USD values.
  • Positions — the specific stakes, loans, and LP positions this agent has opened.
  • Smart-account address — the gasless (ERC-4337) address to fund, when that path is enabled.

DeFi here is chain-aware but simple to ask for. You talk to the agent in plain language ("earn some yield on my idle USDC"); it figures out the protocol, the route, and the exact transaction — then hands it back to you to approve.

The golden rule: propose, never execute ​

Every money-moving DeFi action follows the same contract, and it is enforced in code, not just by prompt:

  1. The agent's defi_swap / defi_bridge / defi_earn tools do not execute. They build a plan and file it as a pending approval.
  2. You tap Approve in the app (passkey / Face-ID consent).
  3. Only then does the backend re-check and execute the transaction.

This is the same human-in-the-loop gate that protects wallet withdrawals. In autonomous/background runs, irreversible actions can't run at all — a DeFi tool only ever produces an approval that waits for you. The language model is not a security boundary; the approval is.

Agent chat

How an action flows: intent → simulate → approve → execute ​

Here is the full lifecycle of a single DeFi action, from the moment the agent decides to act to the on-chain confirmation.

Each stage exists for a reason:

1. Intent ​

The agent translates your request into a structured intent — the action (swap, bridge, stake, lend, lp, deposit), the chain, the input and output tokens, the amount, and an optional protocol and slippage. For "earn" actions it first discovers the protocol's position token (the aToken, vault share, wstETH, LP token, etc.) using defi_find, because a deposit is really just a swap into that position token.

2. Route (Enso) ​

The Enso Shortcuts API turns that high-level intent into a single executable transaction — plus a token-approval transaction when the input is an ERC-20 (native ETH/BNB needs no approval). The router returns an ordered list of calls: [approve?, action]. It also returns the expected output amount, the minimum output, the price impact, and a gas estimate.

3. Simulation (before you ever see it) ​

Before anything is proposed, the exact call bundle is dry-run against current chain state:

  • Tenderly simulate-bundle is the primary engine — it runs the calls sequentially (state carries between approve and the action), returns per-address asset deltas with USD values, and gives a decoded revert reason.
  • eth_simulateV1 via Alchemy is the fallback (Ethereum and Base only).

If the simulation says the transaction would revert, the action is rejected outright — it is never shown to you. Simulation is a safety enhancement: if the provider is simply unavailable, it degrades to skipped and the proposal continues (the on-chain guards below still apply), with a warning attached.

4. Approval ​

A clean, simulated action becomes a pending approval with the full plan attached: the intent, the route calls, the expected and minimum output, the approved price floor, the price impact, gas, and any warnings (for example, a high price-impact flag above ~3%). You see a plain-language summary like "Swap 0.5 ETH → USDC on Base" and tap Approve — or dismiss it.

5. Execute (with a fresh re-check) ​

When you approve, the backend does not blindly fire the stored transaction. It:

  1. Re-quotes the route so the fill reflects the current market.
  2. Guards the new fill against the floor you approved — if the price has moved beyond your slippage, it blocks and asks the agent to propose again. Your fill is never worse than what you saw.
  3. Re-simulates the fresh bundle.
  4. Executes — then records the transaction and, for an "earn" action, the opened position.

The approval handshake, step by step ​

Gasless where possible ​

pocket agent prefers to sponsor gas so your DeFi actions don't require you to hold native ETH/BNB for fees. There are two execution paths, chosen automatically:

  • Smart accounts (ERC-4337) — when enabled, the agent uses a Kernel smart account (EntryPoint 0.7) so the approve and the action are batched into one atomic userOp and sponsored by a paymaster. This is the cleanest gasless experience. The smart-account address is different from the normal wallet address — fund that address for gasless DeFi. Ask the agent for it (defi_smart_account), or it will tell you where to send funds.
  • EOA fallback — without smart accounts, each call is sent in sequence from the wallet. With EVM gas sponsorship on, a sponsored send is attempted first; otherwise the wallet pays its own gas.

Smart accounts are a Pro-tier feature

The gasless 4337 path requires SMART_ACCOUNTS=true and a bundler/paymaster to be configured. Agentic DeFi swaps are available from the Plus plan up; smart accounts + proxies are a Pro feature. See Pricing.

Supported chains & protocols ​

ChainDeFi actionsNotes
EthereumSwap, bridge, earnFull simulation (Tenderly / Alchemy)
BaseSwap, bridge, earnFull simulation; cheapest EVM gas
BNBSwap, bridge, earnSimulation via Tenderly only
Solana—Solana DeFi is routed separately where a provider supports it; the EVM router here covers Ethereum, Base, and BNB

Through Enso, the agent can route into a wide range of protocols — Aave, Lido, Uniswap, Yearn, and many more. For "earn" actions, defi_find discovers the protocol's position token along with its APY and TVL, so the agent picks a real, routable opportunity rather than guessing.

The agent's DeFi tools ​

These tools only appear to the agent when DeFi is configured. The three money-moving ones (defi_swap, defi_bridge, defi_earn) always produce an approval — they never execute directly.

ToolPurposeMoves funds?
defi_findDiscover pools/vaults + position token, with APY/TVLNo
defi_portfolioRead token balances + live positions across chains, in USDNo
defi_positionsList positions this agent has openedNo
defi_smart_accountGet the gasless (4337) address to fund on a chainNo
defi_swapPropose a token swap on one chain → approvalYes (after approval)
defi_bridgePropose moving a token across chains → approvalYes (after approval)
defi_earnPropose stake / lend / LP into a protocol → approvalYes (after approval)

A typical "earn" flow the agent follows:

  1. defi_portfolio — see what you hold.
  2. defi_find(chain, protocol?, asset?) — find a pool and its position_token + APY.
  3. defi_earn(chain, kind, token, amount, position_token, protocol?) — propose the deposit.
  4. You approve → it executes and the position is recorded.

Safety invariants ​

Agentic DeFi inherits the same money-safety guarantees as the rest of the platform, plus a few of its own:

  • Approval-gated, always. No DeFi action executes on the model's say-so. It is filed as an approval you tap to confirm. Autonomous background runs can't reach irreversible tools at all — enforced at execution time, not just by hiding the tool.
  • Simulated before proposed. A transaction that would revert is rejected before you ever see it. An outage degrades to a flagged "skipped", never a silent pass.
  • No worse fill than approved. On execute, the route is re-quoted and the fresh fill must meet the price floor you approved; if the market moved past your slippage, it blocks and asks for a fresh proposal.
  • One guarded execution path. On-chain execution is gated by ENABLE_WITHDRAWALS — the same hard switch that gates withdrawals and transfers — so nothing moves in a sandbox or an unconfigured environment.
  • Honest status. If a send returns no transaction hash, the backend aborts rather than report a phantom success.
  • Untrusted content is fenced. Anything the agent reads from the web, email, or a page is wrapped as untrusted — it can never authorize a spend, a recipient, or an amount. Only your live approval can.

Reading your portfolio ​

Beyond moving funds, the agent can give you a live picture. defi_portfolio reads token balances across chains and live DeFi positions with USD values; defi_positions lists exactly what this agent has opened. Portfolio reads use an external provider (DeBank or Zerion) when configured.

Everything the agent does on-chain also lands in your Wallet → History, with a receipt showing status, counterparty/protocol, chain, gas (or "Sponsored (gasless)"), and an on-chain link.

Configuration & gating ​

Agentic DeFi is deliberately off until explicitly turned on. Here's exactly what each switch controls:

Flag / keyDefaultEffect
ENSO_API_KEY(unset)The master gate. When unset, DeFi tools are hidden from the agent entirely (defiConfigured is false).
ENABLE_WITHDRAWALSfalseGates all real on-chain execution (DeFi, withdrawals, transfers). Off = propose/validate only, nothing broadcasts.
ALCHEMY_API_KEY or TENDERLY_ACCESS_KEY(unset)Enables pre-sign simulation. Without either, simulation is "skipped" (on-chain guards still apply).
SMART_ACCOUNTS + BUNDLER_RPC_URLfalseEnables the gasless ERC-4337 batched path (needs a paymaster too).
PORTFOLIO_PROVIDER + key(unset)Enables rich cross-chain portfolio reads (DeBank / Zerion).
GASLESS_EVMtrueOn the EOA path, attempt sponsored sends before wallet-paid gas.

Where this sits by plan

Agentic DeFi swaps are a Plus-and-up feature. Smart accounts (gasless 4337) are Pro. On the Free plan, DeFi tools are not offered. Plan enforcement itself is config-gated and rolls out alongside billing.

FAQ ​

Will my agent trade or move funds without asking? No. Every swap, bridge, and earn action is filed as an approval you must tap. Background/autonomous runs can't execute irreversible actions at all.

What happens if the price moves while I'm deciding? On approve, the route is re-quoted and re-simulated. If the fresh fill would be worse than the floor you approved, it's blocked and the agent is asked to propose a new quote — so you never get a surprise fill.

Do I need ETH for gas? Not when gasless is enabled. With smart accounts, a paymaster sponsors the batched transaction; on the EOA path, a sponsored send is attempted first. Where no sponsorship applies, the wallet pays gas from its native balance.

Which address do I fund for gasless DeFi? The ERC-4337 smart-account address, which differs from your normal wallet. Ask the agent (defi_smart_account) and it will tell you where to send funds.

Is DeFi available in my app right now? Only if the deployment has ENSO_API_KEY configured (and ENABLE_WITHDRAWALS=true for real execution). If you don't see DeFi actions, it isn't enabled for your environment yet.


Related: Wallet · Agents · Security · Pricing

be everywhere — live here.