Your agent can act.You stay in control.

Introducing Ekubo Wallet

A native desktop wallet that enables your agent to do real onchain work — claim, swap, bridge, rebalance, stake — without giving access to your private keys.

Native desktop app macOS, Windows, and Linux Installation notes

Agent requestETHEREUM · 1

“Claim fees and rebalance my USDC/USDG position.”

1Wallet and network found2Fresh plan produced3Simulating exact plan
Ekubo WalletSecurity review
Local
Liquidity plan simulatedReview the complete action before deciding.
Assets
USDC + USDG
Network
Ethereum
Approval
Owner required
Simulation
No revert
Your agent never sees your keys.

Agent capabilities

Ask for outcomes.
Keep every decision visible.

Give your agent a job that would otherwise take you a careful afternoon. Authorize its shape once and it runs unattended, through the hours when gas is cheapest.

Run a liquidity loop
“/loop Manage my USDC/USDG liquidity position on Ethereum. Claim fees and rebalance when the range drifts, and only send when gas is under 10 gwei.”

Runs overnight on its own, inside the policy you installed.

Compound a ve33 position
“Claim all fees from my ve33 votes, sell balances worth more than their gas, and max stake the STONX proceeds.”

One sentence, dozens of steps: find, claim, quote, swap, stake.

Migrate on the data
“Rank USDC pools by fees earned this month using Dune, compare the best one against my current ETH/USDC position, and migrate half if the trade-offs hold up.”

Analysis first, using any other MCP service your agent has. Nothing is prepared until the numbers make sense.

Scale into a position
“Scale $1M into ETH over the next 12 hours. Keep price impact under 1 bp per trade, and stop if the price moves more than 2% from here.”

One order becomes hundreds, each inside the limits you set, and it stops itself if the market runs.

Shape recurring access
“Propose a policy that can only increase the stake on this veNFT, and can do nothing else.”

Your agent drafts the permission. Only you can grant it.

Audit before acting
“Find every nonzero token approval from my company wallet, rank the risky spenders, and prepare revocations for the ones I choose.”

A broad read-only sweep, then only the revocations you pick.

Protocol coverage

More than Ekubo.
No update required.

New protocols arrive without a wallet update. The wallet you install today works with whatever we add next month.

See supported protocols
EkuboSwaps, liquidity, DCA, ve(3,3), rewards
0xQuoted against Ekubo on every same-chain swap
AcrossCross-chain bridging, quoted against two others
LayerZeroCross-chain bridging, tracked to delivery
LI.FICross-chain bridging, priced in either direction
Aave V3Supply, borrow, repay, collateral, eMode
LidoStake, wrap, and unstake ETH
MorphoVault deposits and exits
SkyUSDS and sUSDS savings
MerklProof-verified incentive reward claims
AerodromeBase liquidity, gauges, veAERO locks and votes
More soonAdded server-side, no wallet release

Other producers welcome. Any service that prepares transactions in the published shape works here, checked the same way whoever built it, and never holding your keys. How that boundary works

Security by separation

The agent gets capability.
Not authority.

You can approve and change security settings. Your agent cannot. That separation is enforced in the wallet core—not by a prompt.

Read the security model
01

Keys stay on this computer

Signing happens in the app on your desk, and your agent never receives a key. See platform key storage below.

02

Human review is native

Reviews start on Reject. Approval requires the complete document and operating-system authentication.

03

There is nothing to leak

No account, no API key, no token to steal. Your agent reaches the wallet on this machine or not at all.

04

Policy stays narrow

Allow, deny, or require review. Agents can propose policy but cannot install it.

Platform key storage.

Local authentication does not claim to defeat malicious software already running as your operating-system user. On Windows and Linux, the per-user credential service holding account keys does not isolate them from that software, so such a process can use a key outside the wallet. Read the full boundary.

Unattended, not unsupervised

Let the routine work run.
Keep the boundary.

Approve the first run. Then install a policy and let the job work while you sleep.

  1. 1

    Connect the agent you already use

    Ekubo Wallet finds it and sets it up, already knowing your accounts and networks.

    One click
  2. 2

    Watch the first run

    The wallet asks about every transaction by default, so one run shows you exactly which calls the job needs.

    First run
  3. 3

    Then let it run unattended

    Install a policy for those exact calls and the job executes on its own — overnight, at the gas price you set. Anything outside that shape still stops for review.

    AllowDenyReview
  4. 4

    Pay for one transaction

    Compatible calls go out as one batch: all of them succeed or none do, usually for less gas.

    EIP-7702

One wallet, many clients

Meet your agent
where you already work.

Ekubo Wallet finds the agents you already have and sets them up for you. Nothing to paste, nothing to sign up for.

CodexCLI and desktop
ChatGPTWork or Code tab
Claude CodeCLI
Claude DesktopCode mode recommended
Gemini CLICLI
CursorEditor and agent
OpenCodeCLI and desktop
Grok BuildCLI

Some clients refuse financial tools before a request reaches the wallet. Claude Desktop is the known example — use Code mode instead. Client notes

Also an ordinary wallet. Connect a dapp over WalletConnect and its requests get the same review yours do.