PROPELOO

AI AGENTS / WEB3 AUTOMATION

Build AI agents that operate on-chain, not just off-chain.

PROPELOO engineers AI agents for Web3 — autonomous agents that monitor blockchain state, execute on-chain transactions, manage DeFi positions and respond to market conditions without human intervention. AI + blockchain is a genuine engineering intersection where the tools for both must be applied correctly.

A DeFi protocol that requires manual intervention for every position rebalance is not automated — it is a spreadsheet with extra steps.

AI agents that monitor 50 DeFi protocols simultaneously, rebalance positions faster than any human, detect on-chain signals and execute multi-contract transactions atomically are achievable today with LangGraph for agent orchestration, viem for on-chain interaction and a well-designed tool set. The engineering challenge is reliability: an AI agent that executes incorrect transactions does not have an undo button. The safety layer — simulation, limits, circuit breakers — is what makes Web3 AI agents deployable.

The Web3 AI agent stack.

System Layers

  • Agent Orchestration Layer: LLM reasoning, tool selection, multi-step planning, memory, error recovery
  • Blockchain Interaction Layer: Transaction construction, gas estimation, signing, broadcasting, receipt monitoring
  • Market Intelligence Layer: Price feeds, on-chain event monitoring, DEX state reading, oracle data
  • Risk Management Layer: Position limits, slippage controls, circuit breakers, human approval gates
  • Execution Safety Layer: Transaction simulation, dry-run mode, multisig approval, audit logging

Core Technical Capabilities

  • Agent Architecture

    LangGraph for stateful multi-step agent workflows — tool use, conditional logic, error handling and retry. AutoGen for multi-agent coordination where specialist agents collaborate on complex on-chain tasks.

  • DeFi Agent Tools

    viem/ethers.js tool wrappers for: swap execution (Uniswap/1inch), liquidity provision/removal, yield farming position management, lending protocol interaction (Aave/Compound) and bridge transactions.

  • On-chain Monitoring

    Event log subscriptions for protocol state changes, price feed monitoring (Chainlink/Pyth), mempool monitoring, whale wallet tracking and on-chain signal detection.

  • Transaction Simulation

    Tenderly simulation before every agent-executed transaction — confirm execution success, estimate exact gas, verify token amounts before broadcasting.

  • Safety & Risk Controls

    Per-transaction value limits, daily operation caps, slippage tolerance enforcement, multi-sig approval for large transactions, automatic pause on anomalous behaviour.

  • DAO Treasury Agents

    Agents that execute approved treasury policies: diversification rebalancing, yield optimisation on idle funds, grant disbursement per DAO vote and treasury performance reporting.

How we think about Web3 AI agents.

An AI agent that can execute on-chain transactions has real financial consequences for errors. Design the safety layer first.

  • Simulate before every transaction

    Every on-chain transaction an agent executes should be simulated via Tenderly before broadcasting. Simulation catches: revert conditions, incorrect token amounts from slippage, state changes that invalidate the transaction between planning and execution.

    Axiom:

  • Human-in-the-loop for novel situations

    Transactions outside defined parameters — above a value threshold, involving an unknown contract, requiring a novel action — should route to human approval. The cost of a human approval is seconds. The cost of a wrong autonomous decision is irreversible.

    Axiom:

  • On-chain data is truth, LLM output is a hypothesis

    Every agent action that depends on on-chain state (balance, price, position size) must read that state directly from the chain — not from the agent's memory of a prior read. On-chain state changes constantly.

    Axiom:

  • Idempotent transaction execution

    Agents must handle: transaction submitted but no receipt received. Was it mined, pending or dropped? Transaction ID tracking, receipt polling and nonce management prevent double-execution and stuck nonces.

    Axiom:

Web3 AI agent design decisions.

  • Agent framework?

    Impact: LangGraph for production Web3 agents — stateful graph execution handles multi-step DeFi workflows better than simple agent loops.

    • LangGraph — stateful, conditional workflows, best for complex multi-step agents
    • LangChain AgentExecutor — simpler, good for tool-use agents
    • AutoGen — multi-agent, good for specialist agent coordination
    • Custom Python — full control, no framework overhead
  • Signing approach?

    Impact: ERC-4337 session keys for agents on user assets. HSM for agents managing protocol treasuries.

    • Local private key (agent holds key) — simplest, highest risk
    • Multi-sig (agent proposes, humans approve) — safer, adds latency
    • HSM (Hardware Security Module) — production-grade key security
    • ERC-4337 session key — limited permission, user retains custody
  • LLM selection?

    Impact: GPT-4o or Claude 3.5 for complex decisions. GPT-4o-mini for high-frequency simple routing where cost matters.

    • GPT-4o — best tool use, highest cost
    • Claude 3.5 Sonnet — strong reasoning, complex multi-step
    • GPT-4o-mini — cheap for simple routing
    • Local Llama — no API cost, weaker tool use
  • Price feed source?

    Impact: Pyth for low-latency trading decisions. Chainlink for collateral valuation or limit order execution where manipulation resistance matters.

    • Chainlink (on-chain) — manipulation resistant, 1-min latency
    • Pyth Network — 400ms latency, pull-based
    • DEX spot price — flash loan manipulation risk, avoid
    • CoinGecko API — centralised, reference only
  • Error handling?

    Impact: Circuit breaker + human escalation: after 2-3 consecutive failures, pause and alert. Autonomous retry without understanding the failure cause often worsens the situation.

    • Retry immediately — simple, may compound errors
    • Exponential backoff — safer, handles transient failures
    • Human escalation on error — safest
    • Circuit breaker — pause after N failures, alert human
  • Audit trail?

    Impact: Both: structured database logs for querying, on-chain events for immutable proof of agent actions.

    • Database logs — centralised, queryable
    • On-chain event emission — immutable, transparent
    • Both — best for high-value operations
    • No audit trail — not acceptable for financial agents

What PROPELOO builds.

  • DeFi Rebalancing Agent

    Agent that monitors positions across Aave, Compound and Uniswap, rebalances per defined risk parameters and reports daily.

  • MEV Arbitrage Bot

    On-chain arbitrage agent that detects price discrepancies between DEXs, simulates profit and executes atomic arbitrage via flash loans.

  • DAO Treasury Manager

    Agent executing approved treasury policies — yield optimisation, diversification rebalancing and grant disbursement per governance votes.

  • NFT Floor Sweep Agent

    Agent that monitors NFT collection floor prices, executes buys when floor dips below target and manages listing strategy.

  • Yield Farming Optimizer

    Multi-protocol yield agent that moves liquidity to highest-yielding opportunities, accounting for gas costs and lock-up periods.

  • On-chain Alert + Execute

    Agent monitoring on-chain signals (large wallet movements, liquidation risk, governance proposals) and executing predefined responses automatically.

The Web3 AI agent stack.

  • Agent Frameworks

    Stack: LangGraph, AutoGen, CrewAI, Custom Python agent loop

  • LLMs

    Stack: GPT-4o, Claude 3.5 Sonnet, GPT-4o-mini (routing), Llama 3 (privacy)

  • Blockchain

    Stack: viem, ethers.js, @solana/web3.js, Tenderly (simulation)

  • Data Sources

    Stack: Chainlink Data Feeds, Pyth Network, The Graph, 0x API, Alchemy Webhooks

  • Safety

    Stack: Tenderly simulation, Gnosis Safe (multi-sig), ERC-4337 session keys, Circuit breaker (custom)

  • Infrastructure

    Stack: Python (FastAPI), Redis (state), PostgreSQL (audit log), AWS Lambda / ECS, PagerDuty

AI agents with on-chain access require multiple safety layers.

  • Key security

    Agent private keys in HSM or via ERC-4337 session keys with limited scope. Never in plaintext environment variables. Rotate on any suspicious activity.

  • Simulation before execution

    Tenderly simulation before every transaction. Block transactions where simulation fails or produces unexpected results.

  • Value limits

    Hard-coded per-transaction and daily value caps that cannot be overridden by LLM reasoning. The agent cannot convince itself to exceed its own limits.

  • Prompt injection via on-chain data

    NFT metadata, token names and contract comments can contain prompt injection payloads. Validate and sanitise all on-chain data before including in LLM context.

  • Nonce management

    Concurrent operations on the same wallet require coordinated nonce management. A collision results in one transaction overwriting another. Use a nonce manager service.

  • Complete audit trail

    Every agent decision, transaction attempted, simulation result and error must be logged with timestamp and full context for post-incident analysis.

From concept to autonomous on-chain agent.

  1. 01. Agent Design

    Define capabilities, decision boundaries, safety constraints, signing architecture.

  2. 02. Tool Development

    On-chain tool wrappers (read, simulate, execute), price feed integration, event monitoring.

  3. 03. Agent Orchestration

    LangGraph workflow, LLM integration, tool selection logic, error handling.

  4. 04. Safety Layer

    Simulation integration, value limits, circuit breakers, human approval gates.

  5. 05. Testnet Validation

    Full agent operation on testnet — simulate all scenarios including error cases.

  6. 06. Monitoring

    Audit logging, PagerDuty alerts on anomalies, performance dashboards.

  7. 07. Mainnet Launch

    Staged rollout with low value limits, scale up as confidence builds.

AI Agents for Web3 Engagements

Autonomous AI agents operating on-chain with verifiable execution.

  • Autonomous DeFi Portfolio Manager

    Challenge: Asset manager needed an AI agent to autonomously rebalance DeFi portfolios based on market signals — without manual transaction signing per action.

    Architecture: LangGraph orchestration with tool-calling for on-chain reads and writes. ERC-4337 smart wallet with session keys scoped to specific DeFi protocols. Chainlink price feeds for market data. Uniswap V3 for execution. Risk parameters enforced on-chain via smart wallet limits.

    Outcome: Agent manages $2M in assets autonomously. Portfolio rebalancing latency reduced from hours to minutes. Session key architecture contains risk: agent cannot exceed per-transaction or daily limits.

  • Multi-agent DAO Governance System

    Challenge: DAO with 10,000 members needed AI agents to summarise proposals, model economic impacts and draft voting recommendations at scale.

    Architecture: Proposal ingestion via The Graph subgraph. Summarisation agent using structured output extraction. Economic modelling agent with simulation sandbox. Recommendation agent with configurable political stance parameters. Snapshot integration for vote casting based on member delegation.

    Outcome: DAO voter participation increased 45%. Proposal analysis turnaround reduced from 3 days to 2 hours. 80% of members used AI summaries before voting.

  • AI-powered NFT Market Intelligence Agent

    Challenge: NFT trading desk needed real-time market intelligence — floor price movements, wash trading detection, whale wallet tracking — synthesised into actionable signals.

    Architecture: Reservoir API for real-time NFT market data. Anomaly detection models for wash trading patterns. Whale wallet tracking via on-chain address clustering. LLM synthesis layer converting data signals into natural language trading briefs.

    Outcome: Trading desk reduced research time by 70%. Wash trading detection flagged 23 collections before floor manipulation events. Whale tracking signals preceded 3 major collection pumps.

Frequently Asked Questions

What makes a Web3 AI agent different from a regular trading bot?

Traditional bots use hardcoded rules. AI agents use LLM reasoning to interpret natural language strategy definitions, adapt to novel conditions, coordinate multiple tools in sequence and explain decisions in human-readable form. The tradeoff: LLMs are probabilistic and can make reasoning errors. The safety layer (simulation, limits, circuit breakers) is what makes AI agents safe to deploy on-chain.

How do we prevent the agent from making costly mistakes?

Multiple layers: Tenderly simulation before every transaction; hard-coded value limits the LLM cannot override; circuit breakers that pause on consecutive failures; ERC-4337 session keys giving limited revocable permission rather than full custody; human approval for any action outside defined parameters.

What is LangGraph and why use it?

LangGraph builds stateful, multi-step agent workflows as explicit graphs. Each node is a step (LLM call, tool use, condition check, state update). Edges define flow. Better than a simple agent loop for Web3: complex DeFi operations require multiple sequential steps with state between them, error handling routes to specific recovery paths, and the workflow is auditable.