
Close-up of logo on facade at headquarters of cyber security company Cloudflare in the South of Market (SoMA) neighborhood of San Francisco, California, June 10, 2019. (Photo by Smith Collection/Gado/Getty Images)
Getty Images
Cloudflare said on August 4 it will give AI agents their own wallets and a permanent identity, letting software hold stablecoins and shop online within limits set by its owner.
“A lot of the websites use Cloudflare as the gate for bot traffic,” Kenneth Shek, chief executive of the Animoca Brands identity project Moca Network, said in an interview. “Now they’re saying, instead of gating bots, we’re welcoming bots. We just want to identify whether that’s a good bot or a bad bot.”
Shek’s read is that cloudflare.pay, the optional address that tells merchants whose agent has come calling, stops one layer short of what they will eventually need. “They would know that the 10 agents actually belong to, like, 0012345 user ID,” he said. “What we’re doing is actually deepening that data about that user ID.”
‘The human behind the agent’
“Agent identity, for the agent themselves, is important,” Shek said. “But our point of view is what’s even more important is the human behind the agent.”
Erika Maslauskaite, chief executive and co-founder of the European digital-identity startup AlongID, works on the verification side of that gap. “Behind every agent you would need to verify who’s acting,” she said in an interview. “With AI currently, you can fake everything. You can literally fake everything.”
Moca’s answer, in Shek’s words, is “the W3C verifiable credential standard,” signed attestations a user carries from site to site. “We took a very opinionated view of how that should be, and the broader internet has agreed with that standard actually from a very long time ago,” he said.
‘At least 500 agents’
The traffic he is planning for does not exist yet at scale. “A human probably visits 100 to 150 web pages a day,” Shek said. “With agents, one agent could easily visit thousands of pages.” He counts current chatbot users in that future. “Some might assume that if you use Claude or ChatGPT, you are not using an agent. Technically you are.”
“I have two hundred and eighty agents now doing all sorts of stuff,” Yat Siu, Animoca Brands’ co-founder and executive chairman, said on the On The Margin podcast, projecting “anywhere from 50 to 100 billion agents minimum” as the rest of the internet catches up. “If you ask him, he would basically say that everyone would have at least, like, 500 agents in the future,” Shek said.
Banks have mostly answered by blocking AI agents from customer money, and Varun Kabra, chief growth officer at the blockchain firm Concordium, says the reflex has a reason. “The counterparty on the other side, the airline in this case, or the ticketing platform, whatever it is, they have no way to verify whether a real accountable human is behind the transaction,” Kabra said on the On The Margin podcast. “That could open a door to fraud, bots acting as humans, agents operating with no accountability.” That gap is the reason Ripple backed a startup building trust scores for exactly this traffic.
‘The good guy hats’
Shek’s larger argument is about who holds consumer data now. “Google and Meta and Apple are basically, like, the three companies that control the majority of the data,” he said. In his account, privacy controls built by those platforms protect the platform first. “They’re playing the good guy hats and saying that, hey, I’m protecting consumers,” he said. “But then they’re the ones that get access to all.”
The model he is selling runs the data in the opposite direction. “What we actually provide to the internet and to the user is enabling the user to proactively share data from one website and another website,” Shek said. “You as a user, you become the vessel to basically carry that data.”
Regulation is moving his way in Europe, where eIDAS 2.0 requires member states to issue digital identity wallets by the end of 2026. “You can actually see the EU has actually been pioneering these kinds of regulations,” Shek said, pointing to India’s newer data-protection law as the next wave.
None of it is standardized yet, with Google and OpenAI pushing rival agent-commerce protocols and Cloudflare building on its own Web Bot Auth rather than W3C credentials. Moca’s reach also rests on company-reported numbers, like SK Planet’s claim of roughly 28 million AIR Wallet users in Korea. Kabra’s timeline for the industry to sort that out is short. “I think we’re probably six to twelve months away where these transactions might overtake the human to human, you know, transactions,” he said. “And hence the human to agent accountability is the biggest problem I think the world needs to solve for.”
‘Pull up all her medical records’
Shek’s example of what agents still cannot do came from his own house. “My wife got hit by the car, right? So a few weeks ago,” he said. An agent handling the aftermath would need her records, her insurance, her eligibility. “You need to pull up all her, like, medical records or the things that she’s eligible for, for example, from the medical history, insurance, all the things. So these all are linked to your credential identity.”
Without that link, he said, the software stalls at every desk. “It’ll come back and ask who you are. Verify yourself.”
The endgame he describes is agents transacting with agents, people vouched for underneath. “You talk to your own personal agent, but your personal agent has, like, 10 different agents,” Shek said. “Basically those agents just orchestrate among themselves.”
“So how do we verify what is true and authentic and what is not,” Maslauskaite said.