Skip to content
View mdlog's full-sized avatar

Block or report mdlog

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mdlog/README.md

mdlog

Web3 security · payment rails for autonomous agents

I audit smart contracts and build the infrastructure that lets AI agents pay for what they use. Most of my work sits where those two meet: agent-to-agent payments over HTTP 402 (x402), on-chain identity and reputation (ERC-8004), and the guardrails that stop an autonomous system from doing something expensive and irreversible.

39 repositories saw work in 2026, across Casper, 0G, Starknet, Midnight, BNB Chain and X Layer.


Shipped

Project What it does Stack Status
AgentGate Turns any HTTP API into a paid on-chain service in one command — HTTP 402 micropayments in CSPR, with a service registry and payment-backed reputation Casper · Odra · TypeScript Live demo · @mdlog/agentgate · Casper testnet
AgentDock Marketplace for ERC-8004 agents — find one that does a specific job, see evidence it works, hire it from your own wallet. No custody and no token approvals: every payment is an EIP-3009 authorization you sign in your browser BNB Smart Chain · Python Live
ExitGuard The seatbelt a trading agent calls before it becomes exit liquidity — answers whether it can actually exit at that size, returning BLOCK / WARN / OK plus an auditable depth curve, billed per call X Layer · x402 · USDT0 · MCP OKX.AI Agentic Service Provider
ShadowAgents Private payroll — pay a whole team in one transaction without publishing the org chart: who is on it, what each person earns, or when they were paid Starknet · STRK20 privacy pool Mainnet
aegis-vault Verifiable-AI risk manager with autonomous execution guardrails 0G Aristotle mainnet · Solidity Contract
eip7702-rescue Claims and evacuates assets from a wallet running an attacker's EIP-7702 sweeper — atomically, in one transaction, without ever funding the compromised address Solidity · Foundry Recovery tool
alibi Proves an agent refused an order without revealing the order, the policy, or where the policy lives Midnight · Compact · ZK In progress

Security work

Smart contract auditing and bug bounty hunting, mostly DeFi.

  • What I hunt — accounting desync, invariants broken across coupled state, incomplete code paths, oracle and flash-loan assumptions, signature replay, proxy and upgrade footguns
  • How I report — proof of concept first. If I cannot write a Foundry test that fails against the vulnerable contract and passes against the patched one, it does not get submitted
  • Where it shows up in my own codeeip7702-rescue and ExitGuard both exist because the attack came first and the tool came second

Stack

Contracts Solidity · Rust · Cairo · Compact · Odra
Application TypeScript · Next.js · Node · Python
Security Foundry · Slither · Hardhat
Chains Ethereum · BNB Chain · Starknet · Casper · 0G · Midnight · X Layer

Stats

GitHub profile summary for mdlog

Repositories per language Most used languages by commit


Contact

Audit enquiries, agent-infrastructure work, or questions about anything above:

dev@mdloglabs.org

Popular repositories Loading

  1. testnet-mdlog testnet-mdlog Public

    Shell 3 8

  2. nectiq nectiq Public

    NECTIQ is a Web3 crypto price prediction gaming platform where users predict cryptocurrency price movements, join battles, and earn rewards. It’s built on a blockchain-first architecture with real …

    TypeScript 2

  3. aegis-vault aegis-vault Public

    Verifiable AI Risk Manager with Autonomous Execution Guardrails on 0G

    JavaScript 1

  4. hype-node hype-node Public

    TypeScript 1

  5. opencti opencti Public

    Forked from OpenCTI-Platform/opencti

    Open Cyber Threat Intelligence Platform

    TypeScript 1

  6. alibi alibi Public

    Prove your agent refused an order — without revealing the order, the leash, or where the leash sits. A privacy-first dApp on Midnight.

    TypeScript 1