Your agent can act.You stay in control.

Introducing Ekubo Wallet

A native desktop wallet that lets AI agents send onchain transactions through a local MCP server—while stateless policies and native review keep you in control.

Native desktop app macOS, Windows, and Linux Read the docs

Agent requestETHEREUM · 1

“Claim fees and rebalance my USDC/USDG position. Show me the exact plan.”

1Wallet and network found2Fresh plan produced3Simulating exact plan
Ekubo WalletSecurity review
Local
Liquidity plan simulatedReview the complete action before deciding.
Assets
USDC + USDG
Network
Ethereum
Approval
Owner required
Simulation
No revert
Private keys never leave this application.

Agent capabilities

Ask for outcomes.
Keep every decision visible.

Read state, ask protocol services for exact plans, and simulate the result in your wallet. Your agent coordinates the work; you keep the final decision.

Run a liquidity loop
“/loop Manage my USDC/USDG liquidity position on Ethereum. Claim fees, rebalance when the range drifts, and ask before every transaction.”

Keep a recurring strategy observable while every exact plan still crosses the wallet boundary.

Compound a ve33 position
“Claim all fees from my ve33 votes, sell balances worth more than their gas, and max stake the STONX proceeds.”

Coordinate claims, fresh quotes, approvals, and a final stake without hiding the individual actions.

Plan a migration
“Compare moving half my ETH/USDC liquidity into USDC/USDG using current pool data. Show expected balances, gas, and range risk before preparing anything.”

Compare live positions and pools first, then request an exact migration plan only if the trade-offs make sense.

Reduce position risk
“Withdraw 40% of my most out-of-range position, collect its fees, and leave the rest unchanged.”

Resolve the exact position and make the intended partial change explicit before review.

Shape recurring access
“Propose a policy that can only increase stake on this veNFT, with no native value and no authority over any other tuple argument.”

Constrain named and tuple arguments precisely. Your agent proposes; only you can install.

Audit before acting
“Find every nonzero token approval from my company wallet, rank the risky spenders, and prepare revocations for the ones I choose.”

Separate read-only investigation from the exact transactions you eventually authorize.

Security by separation

The agent gets capability.
Not authority.

You can approve and change security settings. Your agent cannot. That separation is enforced in the wallet core—not by a prompt.

Read the security model
01

Keys stay local

Signing stays inside the native wallet. Desktop state is encrypted with SQLCipher.

02

Human review is native

Reviews start on Reject. Approval requires the complete document and operating-system authentication.

03

Local access stays local

A versioned bridge uses same-user operating-system IPC. There is no HTTP listener, OAuth flow, bearer token, or client secret.

04

Policy stays narrow

Allow, deny, or require review. Agents can propose policy but cannot install it.

Clear about the boundary.

Local authentication does not claim to defeat malicious software already running as your operating-system user.

How it works

Desktop custody.
Agent-native execution.

A local transaction interface and exact, stateless rules put automation on your terms.

  1. 1

    Connect locally

    The desktop wallet exposes a local MCP server. Your agent can read wallet state and hand exact transactions to the wallet without receiving your keys.

    Local MCP
  2. 2

    Validate every call

    The stateless policy engine checks only the exact network, target, value, and calldata the wallet is about to execute—not balances, prior activity, or session history.

    Stateless call policy
  3. 3

    Set your automation boundary

    Allow expected calls automatically to reduce signature fatigue, deny unwanted calls before they are sent, and route everything else to native owner review.

    AllowDenyReview
  4. 4

    Batch efficiently

    EIP-7702 support executes compatible calls atomically through the audited Calibur contract and can save gas versus sending every call as a separate transaction.

    EIP-7702 · Calibur

One wallet, many clients

Meet your agent
where you already work.

Ekubo Wallet detects supported local agents and installs a credential-free MCP entry. The wallet handles consent and owner presence.

CodexCLI and desktop
ChatGPTWork or Code tab
Claude CodeCLI
Claude DesktopCode mode recommended
Gemini CLICLI
CursorEditor and agent
OpenCodeCLI and desktop

Harness safeguards differ. Some clients classify financial transaction tools as disallowed and may refuse before a request reaches the wallet. Claude Desktop is a known example; use Code mode or switch to another supported harness. ChatGPT has no wallet plugin—use its Work or Code tab to reach the local MCP server installed by Ekubo Wallet.

Also a wallet for dapps. Connect with WalletConnect and send every request through the same native review.