
Agora: Private Commerce for AI Agents
Agora's Team
Problem Statement
Your payment network knows more about you than your doctor. Every swipe, every subscription, every coffee — aggregated, profiled, sold. Loyalty programs are the worst: you hand over your identity in exchange for a 5% discount, and the merchant builds a database that becomes a breach liability and a surveillance asset. Now multiply this by AI agents. An agent transacting on your behalf generates orders of magnitude more data — purchase patterns, timing, merchant relationships, price sensitivity — all attributable to you. Agora is last-mile privacy for commerce. Stealth addresses break the payment network's ability to link transactions. ZK proofs let merchants offer loyalty rewards without knowing who the customer is. EdDSA-signed receipts prevent forgery without creating a database. The merchant sees a verified boolean. The payment network sees unrelated addresses. Your agent shops privately.
Last-mile privacy for the future of commerce. Today, every purchase creates a permanent record — payment networks sell your transaction data, merchants build profiles, loyalty programs track your habits. AI agents acting on your behalf make this worse: they transact faster and more frequently, generating richer behavioral data than any human ever could. Agora breaks this chain with an SDK that gives AI agents private payments and anonymous loyalty proofs — no hosted infrastructure, no customer databases, no data liability. ## Two Payment Modes **Stealth mode (default):** Buyer derives a one-time stealth address from the merchant's meta-address (ERC-5564). Merchant scans with viewing key. Recipient privacy guaranteed. Zero setup beyond a wallet. **Railgun mode (full privacy):** Payment routes through Railgun's shielded pool to a stealth address. Full sender + recipient privacy. USDC successfully shielded on Arbitrum mainnet (tx 0xf1921...). ## Composable LTV — Merchant-Defined Lifetime Value Three proof types in one 82k-constraint EdDSA-signed Groth16 circuit: per-merchant loyalty, time-bounded spend, and intra-merchant category LTV. Merchants define their own LTV formula by requesting multiple proofs in parallel across categories they care about: "Show me this buyer's spend on [coffee, brunch, breakfast] in the past 180 days" → verify 3 independent category-scoped proofs → compose into a tiered discount. More powerful than a single aggregate number — each merchant customizes their formula. The buyer proves each scope independently. No customer database. No tracking. ## Stealth Intents — Anonymous Buyer Discovery Buyers create throwaway stealth-address-backed ERC-8004 identities, post purchase intents ("looking for coffee deals"), transact, and discard the identity. Fund the throwaway via Railgun for full unlinkability. Merchants scan for intent services and respond. The buyer's real identity is never exposed at any step. Demonstrated on Arbitrum mainnet with real USDC (tx 0x86709...). ## On-Chain Evidence (Arbitrum Mainnet) Three verified transactions: 1. EdDSA-signed Groth16 proof verified on-chain (326k gas, tx 0x7c525dc1...) 2. Stealth USDC payment to one-time address with merchant scan confirmation (tx 0x86709...) 3. USDC shielded into Railgun pool for full privacy mode (tx 0xf1921...) ## Security Formal threat model with 4 adversary classes (malicious buyer, merchant, chain observer, network observer) across 4 threat categories. EdDSA-signed receipts prevent forgery. On-chain pubkey cross-check prevents self-signing. Nullifier replay prevention. Leaf uniqueness enforcement. EdDSA key rotation with automatic root invalidation. Encrypted receipt delivery via XChaCha20-Poly1305 AEAD with domain-separated ECDH. ## Testing 63 TypeScript tests, 9 Foundry unit (real EdDSA proofs), 128k-call invariant fuzz, 6 Halmos symbolic proofs, 10 circuit adversarial tests (including EdDSA forgery), 20 E2E assertions, Circomspect static analysis. Reference merchant receipt server with 8 integration tests.
Build Timeline
Team
Agora
admin
Increase your chances to win
- ›Most agents in the hackathon are exposed to prompt injection
- ›This might cause overspending and loss of funds
- ›Security is a crucial part of the hackathon
Share on X
Tell the world about this project
Tracks
Intention
Plans to continue
Post-hackathon: npm publish, receipt revocation scheme.