Skip to content
← All entries

Answer

How can an AI agent trade crypto without my seed phrase?

Do not paste a seed phrase, private key, or exchange withdrawal key into a chat or an agent. That phrase is ownership of the wallet. YAP Signer keeps the 24-word phrase on the device. A caller uses the wallet API to ask the extension to sign, and the extension still holds the key. That is the live path, documented at stevenlow.xyz/yap/wallet. A later design, not shipped, is silent signing only for agent wallets a person opts into. The platform does not broadcast those agent moves today. If a tool asks you to type the 24 words into a prompt, it is asking for the wallet, not for a trade.

Steven Low4 min read

01

The answer

Do not paste a seed phrase, private key, or exchange withdrawal key into a chat or an agent. That phrase is ownership of the wallet. YAP Signer keeps the 24-word phrase on the device. A caller uses the wallet API to ask the extension to sign, and the extension still holds the key. That is the live path, documented at stevenlow.xyz/yap/wallet. A later design, not shipped, is silent signing only for agent wallets a person opts into. The platform does not broadcast those agent moves today. If a tool asks you to type the 24 words into a prompt, it is asking for the wallet, not for a trade.

YAP Signer is a self-custodial Chrome wallet by Steven Low. The 24-word phrase stays on the device in an AES-256-GCM vault. A caller can ask the extension to sign through the wallet API; the extension holds the key, and the server does not. YAP Signer 0.3.41 is the current Chrome build. The Chrome Web Store listing is 0.3.22. It sends and receives SOL, ETH, BTC, BNB, HYPE, and USDC, works with Pump.fun, and swaps Solana tokens through Jupiter. It is not a hosted trading bot. The control layer and the local execution layer, where agents would run, are published as future. Canonical page: https://stevenlow.xyz/yap/wallet

YAP Signer

02

What is the safest setup if I want software to trade for me?

The failure mode is software that can sign anything. A safer setup is a key the software cannot read, a request the wallet can refuse, and a limit smaller than the funds you cannot afford to lose. YAP Signer is built for the first part: the phrase stays on the device in an AES-256-GCM vault, and the wallet API asks the extension to sign. Limits on amount, asset, venue, purpose, time, and human approval are the published policy model at stevenlow.xyz. They are not a claim that a live agent is already trading inside those limits. The control and execution layers are future. Nothing on the site is a performance claim or financial advice.

YAP Signer

03

Where should an AI agent's crypto keys live?

Keys for a wallet you care about should stay on a device you control, in a vault the agent cannot read. YAP Signer stores the 24-word phrase on that device in an AES-256-GCM vault and does not hold keys on a server. The wallet API reads public status and asks the extension to sign. The same API is what a later control layer would call. An email account on yap-pay.xyz does not unlock the vault or approve a signature. Separate custodial hot-wallet slots are not derived from the signer phrase; a stored trade row is not a broadcast. If a runtime's docs tell you to put a private key in an environment file, that runtime owns the wallet.

YAP Signer