Protocol Rating · Sixth in the Index

MetaMask Agent Wallet

Agentic Custody Readiness · Scored August 20, 2026 · ACR v1.0

At a Glance

MODERATE RISK
ACR — Agentic Custody Readiness
5.1
MODERATE RISK
/ 10.0 · higher = higher risk
Primary Failure Mode
Plausible Error
Confidence: HIGH

MetaMask Agent Wallet scores 5.1 (MODERATE), the lowest risk of the six agentic protocols assessed. It carries the strongest programmable guardrails in the index alongside three categories where no control is documented. The scale is inverted: a higher number means higher risk.

Category Breakdown

CategoryScoreRisk
Session Key Support2.1
Programmable Guardrails1.9
Audit Log Generation8.4
Multi Party Approval7.8
Protocol Compatibility2.2
Quantum Resistance Readiness8.5

Category breakdown reflects several structural risk properties assessed under the ACR framework. Weights and methodology are proprietary.

Risk Flags
  • No audit log generation or machine-readable transaction history
  • No quantum-resistance planning or post-quantum cryptography roadmap
  • Single-approver 2FA model without threshold or multi-party support
  • Beast Mode removes allowlist and spend-limit guardrails entirely
  • Early GA maturity (launched 2026-08-06) with limited production exposure
  • Developer-first CLI interface may have usability gaps for non-technical operators
Mitigating Factors
  • TEE-based signing architecture isolates keys from agent process
  • Onchain enforcement of spend limits and allowlists prevents single-actor override
  • Mandatory threat-scanning pipeline on every transaction in both modes catches malicious patterns
  • Transaction Protection programme provides up to 10,000 USD coverage for verified-safe transactions

Analyst Notes

MetaMask's own Beast Mode guidance isolates the real risk surface: 'Beast Mode doesn't weaken malicious-transaction detection specifically; it removes the allowlist and spend-limit layer that would otherwise catch a legitimate-looking transaction the agent shouldn't have attempted in the first place.' The characteristic failure mode is not hostile attack but plausible error—an agent manipulated or mistaken into executing a transaction that appears entirely legitimate but violates intent. MetaMask's programmable guardrails are materially stronger than any scored comparator: onchain spend limits, two-tier permission model, and mandatory per-transaction threat scanning outperform Visa TAP (7.2, sole key directory), Mastercard AP4M (6.6, opacity), Google AP2 (6.4, documented prompt injection), Ripple XRPL (6.2, Phase 1 immaturity), and Coinbase AgentKit (6.0, delegation risk). TEE-based signing with request-only agent credentials is architecturally superior to direct key custody. However, complete absence of audit logging, no quantum-resistance posture, and single-approver 2FA (not threshold or multisig) represent material control gaps that elevate risk above the LOW tier. At 5.1 MODERATE, MetaMask Agent Wallet scores as the strongest agentic custody protocol assessed to date while acknowledging governance and long-term cryptographic vulnerabilities.

All Protocol Scores Methodology

Not financial advice. Based on publicly available information as of August 20, 2026, drawn from MetaMask's own product documentation and published security guidance.