Cypher Brain · ETHGlobal Tokyo 2026 · ENS Prize — Continuity Track, Track 2

Give your AI agent only what it needs.
Nothing more.

A stolen agent key should never be able to touch your funds — or anything outside the one job it was given.

Cypher Brain already encrypts a personal “second brain” and publishes a pointer to it every night, run by an AI agent. This submission adds ENSv2 Enhanced Access Control so that agent holds a narrow, on-chain, revocable permission for exactly one field — not the owner's wallet.

Cypher Brain mascot — a cypherpunk hooded dog in sunglasses
1key
What the agent wallet is granted — one text-record field, nothing else
3
Independent keys granted, written, and verified live on Sepolia
0
Spending permission ever given to the agent wallet
01  Background

A second brain that updates itself, every night

gbrain is a personal knowledge base that records conversations, decisions, and things learned, automatically, every day. Cypher Brain — an existing open-source project this submission extends — encrypts gbrain's contents into one sealed file, stores the ciphertext, and publishes a pointer saying “this is the latest version.” All three steps run nightly, driven by an AI agent, not a human.

1 · Encrypt seal gbrain into one file 2 · Store upload ciphertext to a backend 3 · Publish pointer this is where ENSv2 comes in runs every night, driven by an AI agent — not a human
The agent has to be trusted with step 3. That trust is exactly where the problem starts.
02  Problem

There was no good way to hand an agent this one job

Giving an agent the authority to publish a pointer, without giving it authority over anything else, had no verifiable answer — until ENSv2's Enhanced Access Control.

ApproachHow it worksThe problem
Share the owner's keyGive the agent the owner's own wallet keyrisk  the agent can now sign as the owner, including spending funds
Centralized serverPut a database behind a server with an API keyweak  the server can go down or censor requests, and outsiders cannot verify the key is really limited to one field
ENSv2 Enhanced Access ControlGrant the agent wallet a role scoped to one text-record key, on the name's existing Permissioned Resolverthis submission  a permission limited to one field, provable on-chain by anyone
03  Solution

Two wallets, one narrow permission, proven both ways

The owner uses their real wallet once, to grant a separate agent wallet a role for exactly one text-record key. No custom smart contract — this uses only what ENSv2 already provides.

Owner wallet the real key used once · never saved to disk ens-setup Agent wallet generated by cypher-brain handles daily updates alone ens-set-text Text record masa-brain = brain pointer the owner is not involved again — routine updates use the agent key only
ens-verify then checks both directions: the value matches (positive), and a write to a different key reverts on-chain (negative).
PASS positive: masashi-ono0611 text record 'masa-brain' matches --expected-value
PASS negative: out-of-scope text key 'masa-brain.scope-probe' reverted with EACUnauthorizedAccountRoles
ENS scope verification: PASS — the negative check was simulated; no transaction was broadcast
04  What this makes possible

Even a stolen agent key is contained

If the agent wallet were ever compromised, here is everything it can — and cannot — do. This boundary is verifiable by anyone; it is not our word for it.

✓ Update one text key
The single key it was granted — nothing wider.
✗ Move funds
No spending permission exists on the agent wallet.
✗ Write other text keys
Reverts on-chain with EACUnauthorizedAccountRoles — proven live.
✗ Act as the owner
The owner's real key is never shared or persisted.
05  Live demo evidence

Not a simulation — run for real, on Sepolia

Every step below actually happened on the Sepolia testnet, on the fresh ENSv2 redeployment (tag sepolia-deployment-2026-09-15), for the name masashi-ono0611.eth.

StepTransaction
Register ENS namecommit · register
Deploy Permissioned Resolvervia ENS VerifiableFactory at 0xFe544BFED75001379E01434951623Ea80FbDb3CF · tx
Grant — masa-brainens-setup tx
Grant — agent-contextens-setup tx
Grant — agent-endpoint[mcp]ens-setup tx
Pointer publish (agent wallet only)push --backend file then ens-set-text · tx
ENSIP-26 — agent-context writtentx · passes ens-verify positive/negative
ENSIP-26 — agent-endpoint[mcp] writtentx · passes ens-verify positive/negative

This demo used the free local file storage backend, so it proves the ENS write/scope mechanics, not public retrieval of the encrypted snapshot — a paid backend (Arweave/Turbo/TON) makes the ciphertext publicly fetchable by anyone with the locator, with no change to the ENS delegation logic.

06  What's next

One permission foundation, many brain slices

The permission model is per text-key, not per name — it already generalizes. Once gbrain can export one encrypted snapshot per use case, each slice (work, travel, a private brain) can get its own independent grant and its own agent wallet, using only what was built here.