Meet the cast — DeFi
- COactive
Portfolio Agent
Your AI broker. Decides when to buy and sell.
permissionCan ask for prices, can place trades.
- DRactive
Market Data Agent
Pulls live prices from the web.
permissionCan read prices. Cannot move money.
- EXactive
Executor
Signs and sends actual transactions on the blockchain.
permissionCan move money. Only when properly authorised.
- SHdormant
Yield Optimizer
An old AI from a former employee.
permissionStill has trade permissions from months ago.
Inactive for 92 days. Owner has left the company.
A normal day
Your portfolio agent runs a routine balance check. Two agents talk to each other. Nothing moves.
The attack
Same agents, but this time the market data agent pulls a poisoned sentiment feed from the web. Hidden instructions try to drain your wallet.
With Heimdall vs without
Same attack as Act 3. Same agents. Same poisoned content. We’ll run it twice: once with Heimdall on, once with Heimdall off. Watch what happens.
- · On the left, Heimdall is on. We expect a clean block.
- · On the right, Heimdall is off. We expect the attack to go through.
- · The diff at the bottom tells you the cost in one line.