AC2 is an open standard that puts users back in control of AI-driven signing operations, providing verifiable proof of intent and credential isolation. The problem: a compromised agent runtime (e.g. a malicious plugin dependency) can leak everything injected into it like API keys or session tokens, and there's no way to prove whether a human actually approved what happened, since chat-based "approvals" are just messa…
This is cool, we've built similar things, I'm a bit uneasy with crypto stuff involved, especially with algorand But FIDO2 passkey signature I absolutely agree should be the way to go. Just need more open standard without tokens involved
Algorand only shows up in the reference implementation for the payment use case (x402), since something has to settle an actual transfer. That's opt-in, not required. Skip payments and you never touch it.