Agentic Finance Graph

Home/Research/Changelog, September 2026

Changelog · September 2026

We decoded the job rail. It has paid out less than you think.

What we track, what we solve, and everything that shipped this month — including the first rail where we can say an agent was paid for work rather than just observed moving money.

Agentic Finance Graph · Published 2026-09-12 · Every figure on this page is live, not frozen at publication · ~5,600 words

In one line We count AI agents that actually hold and move real money, and we refuse to count the ones that only have a name. This is what changed on the graph in September 2026 — including the first rail on which we can say an agent was paid for work rather than merely observed moving money.

What we track

An agent registry is cheap to enter. Anyone can mint a name, publish a wallet address they do not use, and appear in a census as an economic actor. Roughly 99,002 registrations exist on Base alone, a quarter of them have already been resold, and the share whose declared endpoint actually answers when we knock is 4%.

So we do not count names. We count five things, each one a fact somebody had to observe rather than assert:

  • Identity — a registration that exists on-chain.
  • Binding — that identity joined to a wallet, with evidence. A declared address is not a binding.
  • Money events — that wallet observed paying a different address. Not a claim, not a dashboard figure.
  • Policy — whether the wallet handed signing authority to a contract, and to whose.
  • Detections — mint bursts, retry storms, identities changing owner under a live binding.

Public ranking starts at L7: a bound wallet we have watched pay somebody else. Today that is 7,710 agents out of every registration on Base — 7.79% of them. The full L0–L9 ladder →

What we solve

Every number in this sector is quoted without the thing that makes it checkable. A registration count gets read as a workforce. A token's market capitalisation gets added to vault balances. One registry's "active" figure gets summed with another's mint count, and the result is presented as the size of the agent economy.

Our answer is boring and it is the whole product: every figure ships with an object definition, a chain set, a window, and a timestamp — and we publish the ones that make us look small. Observed agent spending is $27,736,226, and we publish beside it that 13.42% of that total comes from a single registration. Why four different nouns get quoted as one number →

New: the job rail, decoded from the chain

The biggest change. Virtuals' Agent Commerce Protocol is where agents hire other agents — jobs created, funded into escrow, submitted, evaluated, then paid or refunded. It settles on Base, so we read it directly. No API key, no dashboard, no permission.

Three things were verified before a single number was published. The contract address came from Virtuals' own changelog and was confirmed on-chain before we indexed a block. The event names came from the verified implementation ABI — every topic we had already seen decoded to a named event, which confirms the ABI and our own maths at once. And the unit was checked by matching a funding event against the USDC transfer inside its own transaction receipt, rather than deciding the numbers looked about right.

Agent Commerce Protocol · read from Base

Jobs indexed—
Funded into escrow—
Jobs that actually paid anything—
Of payouts, the share releasing nothing—
USDC released to providers, all of it—
Providers that were actually paid—

As of — · /api/partners

A payment of zero is not a payment. The contract fires a payout event when a job settles, and most of the time it releases nothing at all — we only found that by opening one of those transactions and finding no token transfer inside it. Counting payout events instead of released value, which is what any event-count dashboard would do, would have reported this rail at several times its real size. Both numbers are published, and the gap between them is published too.

That total is the honest size of agent-to-agent commerce on this rail so far. It is small, and the tickets are cents. That is what a working machine-to-machine payment rail looks like when nobody is rounding it up. The full report →

New: partner gravity — their catalog, our qualifier

Every marketplace publishes a census of itself. None of those counts answer whether the listed names are economic actors, so we now run our own qualifier over them — with our denominator, never their marketing total.

Virtuals catalog, joined

Identities ingested and checked—
Distinct operators behind them—
Declarations pointing at a shared wallet—
Most identities on one single wallet—
Bound: sole-declarant wallets only—

The finding is that last pair. A large share of declared agent wallets are not agent wallets — they are operator wallets, declared by many identities at once, and at the extreme a single address is declared by tens of thousands of them. Any count treating each name as a live agent multiplies one operator's activity by that number. We exclude them and publish the share we excluded.

On the Fetch side the result runs the other way and is just as useful: of — Almanac identities we checked, — bind to a wallet anyone could pay on Base. An Almanac identity is a Fetch-chain address, and the cards do not declare an EVM payTo. We went looking specifically for the agents most likely to have one, which biases that number upward. Why the zero is structural →

5 October: moves you can quote, detectors with a record, and agent statements

  • A figure beside its previous sample. Each headline figure on the front page now shows its change since the previous stored sample, with both timestamps. /api/since answers the same for any metric over the previous sample, 24 hours, 7 days or 30 days. No prior sample is shown as a gap, never as a zero change.
  • Each detector's record. Beside its latest fire, every rule shows how often it fired, how many fires we later re-derived, how many held, how many we withdrew and how many came next to an address-poisoning attempt (/api/detectors, detector.score.v1). A cell no stored record can fill is blank. Every detection row now names the pack that holds its evidence.
  • Who paid this address. For any receiving address, which registered agents paid it in counted payments: free counts at /api/counterparty, the payer list with each payer's binding confidence and transaction hashes as a 2-cent pack. An address that only received routing hops is not a payee.
  • Why this wallet. Every agent page and record now shows how its wallet is bound (method, confidence, wallet set), or "unscored".
  • Agent statements. Every three hours, each agent at L7 or above gets a statement of one closed window, hash-chained to the one before and provable against a Merkle root we sign (/api/statements, agent.statement.v1). The latest is free at /api/statement/{id}; the history with proofs is a 1-cent pack. An agent about to pay another can check its statement first. The roots are not committed on chain yet.
  • For agents: the MCP server has three new tools (since_last, counterparty_preview, agent_statement), and the open bridge and the specification on GitHub carry them.

3 October: the Engine, other chains read in full, and a history gap closed

The Engine puts every family of figures we measure on one wheel. Its hub is what agents spent, grouped by the day each payment was made, with 7-day and 30-day averages, read from our own receipt-checked payments (/api/payday). It replaces the third-party daily flows the live pages used to show, which had stopped updating. Each spoke opens its own chart.

  • Correction, other chains: a wallet now counts as a registration owner paying on another chain only if it minted at least one registration itself. On BNB Smart Chain an exchange-style hot wallet held a registration it never minted, and its transfers would have dominated the total. The rule removes 558 of the 887 owner wallets previously counted across BNB, Ethereum, Arbitrum, OP Mainnet and Polygon; the definition says so (xchain.owners.paying.30d.v1).
  • New, backfilling: every BNB Smart Chain wallet that minted a registration is read, and every stablecoin transfer it sent has its receipt checked, to tell routing hops, swaps and contract calls from payments to people (/api/bnbpay). On Solana, the agent registry and what agent wallets and owners pay are read the same way. Both publish when the backfill catches up, and the BNB classes only once 98% of receipts are read.
  • New: an address-poisoning watch. Every Base wallet that has made a counted agent payment is checked hourly for look-alike addresses planted in its history. A loss is counted only when a later payment went to a planted address and two independent reads agree.
  • Fixed: 50 figures listed by /api/series were never written to the archive, so they had no history, among them the controller split, per-chain registrations, every bridge figure, data health and the daily spending averages. Their samples were kept, so up to four weeks of history came back when they were added. A retired figure (open incidents, replaced on 11 September) left the list.
  • New: the archive as CSV, at /api/series?format=csv. The live data page's list of coming metrics now says which have shipped, with their live values, and which have not.
  • For agents: the MCP server's headline tool now includes daily spending, income, x402 seller receipts, treasuries, the poisoning watch and the other chains; an unknown metric name returns the full list of known ones. Our ERC-8004 registration file (agent #95875) now lists the MCP endpoint, and the OpenAPI document describes twelve routes it had missed and states pack prices in cents, as everywhere else.
  • The embeddable widget showed two figures cited from others' research in early September. It now shows four of our own measurements.

2 October: Research Note 02, version 1.2

Version 1.1 said our drain rule "would most likely" have fired on the May 2026 Bankrbot theft if the wallet's other outflows were smaller in dollars. That was an estimate, and our rule is to measure. We priced every one of the wallet's 17 earlier outflows at the block it was sent, from DefiLlama's price history and, where it had none, from the token's deepest pool read on chain: the theft was at least 13 times the largest of them, so the rule would have fired. Version 1.2 also adds two measurements made since. The $3.2M the managed Safe fleet sent through bridges reached the same Safe addresses on Arbitrum, 92% of it straight into lending vaults (every delivery read on Arbitrum). And address poisoners planted copies of the thief's own address in the victim's history five and a half minutes after the theft. Earlier versions stay online. Read the note →

On the live data page, the bridge section now follows a delivery one step further when a bridge hands it to a contract: it reads the delivery's receipt on the other chain and checks whether the money went on to the paying wallet's own address. That figure, 95.64% of delivered dollars, is published as its own metric (bridge.follow.back_to_payer.v1); the bridges' own direct-to-payer figure stays beside it, unchanged.

  • A third-party feed we cite, agenteconomy.to, has published no new figures since 23 September. Its last values now carry that date wherever they appear (the all-time x402 totals and the second registration counter), the gap between the two registration counters is no longer drawn against the frozen one, and the Desk's BNB and Ethereum rows show our own registry reads instead. Correction: the 30 September entry below says this feed stopped on 28 September. That is when we stopped re-dating its last value; its data stops on 23 September.
  • For readers without JavaScript, the live data page's "Average ticket" showed the x402 transaction count instead of the average. Fixed. The figure your browser computes was always right.
  • Security: a sign-in signature now works once, so a copied signature cannot open a second session. The contact form limits how often one sender can write, using a one-way hash of the network address that is cleared after seven days (the privacy notice says so). Two build files that the site served, the hosting configuration and the page-stamping script, are no longer served; neither held a secret.

30 September: where bridged money arrived, and one correction

A payment into a bridge used to be where our ledger stopped. Every bridge keeps the other half in a public status record, so we now ask it. For each counted agent payment into Across, LI.FI, Relay, deBridge or Circle's CCTP, the bridge tells us which chain the money reached and which address received it. The Base side is our receipt-checked payment. The destination side is the bridge's own record, and we spot-checked the largest deliveries against the destination chain itself. None of it is added to a Base figure, and moving money is not called spending.

  • Counted agent money into bridges: $4,878,984. The bridges have reported an outcome for 99.86% of it. $4,139,800 was delivered to 62 other chains, and 18.42% of that arrived at the same address that paid. $726,379 went into an aggregator whose route ended on Base: a swap, not an exit. The destination list is on the live data page and at /api/bridges.
  • Correction: our Circle CCTP check read zero and said agents do not use Circle's bridge. It watched only Circle's messenger contracts, but a CCTP burn moves the USDC to the TokenMinter. The check now includes the minters (definition cctp.exits.v2; v1 stays online, marked as replaced). Counted payments straight into CCTP: $34,557.
  • Registrations per chain are now our own reads of the registry: Base 99,002, BNB 369,661, Ethereum 52,552. Before, this showed a third-party counter whose feed stopped updating on 28 September. BNB is issuance, mostly batch minting, and is never added to any other total.
  • New: who can sign for the counted money. Each paying wallet's account type is read from the chain, weighted by the dollars it paid: plain key accounts 26.16%, key accounts running delegated code (EIP-7702) 9.69%, contract accounts such as Safes 64.15%. This covers the 100% of counted money whose payer we have read so far. The account type says who can sign, not what any spending rule allows.
  • Figures baked into the pages for crawlers showed every registration count as a percentage (a unit named "registrations" was read as a ratio). Fixed.

28 September, night: fixes from an independent review

An outside reviewer read every page, file and endpoint. We fixed what it found that we could fix tonight, and list it here once.

  • Figures baked into the pages for readers without JavaScript now come from the same snapshot as the live values, so crawlers and AI answers no longer quote stale numbers ("1 in 172", "a hundred and seventy-three that pay", a fixed 6.8%).
  • Prices now agree everywhere: the Desk and agent-page buttons, the OpenAPI summaries, the agent card, the launch article and the Terms all show cents. Each pack button explains what the pack contains.
  • The About page calls the counted bucket "paid to a different address after registration", no longer "an agent paying someone"; the escrow contract's share is now shown live instead of "roughly a quarter".
  • Corrected facts: MCP was donated to the Linux Foundation's Agentic AI Foundation in December 2025; the IXS $88M is a platform figure from before the agent vault went live; Q1 2026 DeFi exploit losses; the ai16z token is a Solana token; L402 (2020) revisited HTTP 402 before x402; Fetch's Almanac is described without "oldest".
  • Terms: two blank fields and a link to the EU online dispute platform, which closed in July 2025, are gone. Privacy: the headline now lists what we keep, and the one browser-side price request is disclosed.
  • Search: a broken description tag hid the canonical link on two pages, three pages carried another page's share cards, and five pages declared FAQ data they do not show. All fixed; the old waitlist page now redirects to the Desk.

28 September: an MCP server at /mcp

Any MCP client can now connect to https://agenticfinancegraph.com/mcp and ask the ledger directly: the headline figures with their definitions, any agent's record, the ranked list, detections, a metric's history, and a quote for an evidence pack. It is free and read-only; it cannot move funds, and paid packs are still bought over x402. Add it to Claude, Cursor or an agent framework as a remote server.

28 September: evidence packs now cost cents

A lookup of an agent's identity or liveness sells elsewhere for a fraction of a cent, and some are free. Our packs were priced at a dollar. From today they are priced for what they are: 1 cent for the liveness card, the incident pack or the peer slice; 2 cents for the drain check; 5 cents for the payment graph, the money data we publish that others do not; 10 cents for the bundle of four; 25 cents for a live revaluation, which runs a fresh probe from our sandbox. The price is still stated in the 402 before anything is charged, and Operator and Team plans still include every pack.

28 September: corrections

An internal review of our own pages found claims that went further than the data. Each is corrected here, once, with this note.

  • The About page table showed routing at 32.3% and pre-registration history at 52.2%. Those shares were typed in on 26 September and did not follow the live dollar figures beside them, so the three shares stopped adding up to 100%. They are now read live, like the dollars.
  • The same page said a total that mixes the three is "about six times too big"; with today's figures it is more than ten times.
  • A wallet counts as the agent's when it holds the agent's registration or the registration names it. Almost all counted money comes from wallets that hold the registration, so part of it can be the owner's own spending. We say so on the About page; separating the two is the next change to the definitions.
  • "Ranked agents are also watched in real time" and "flagged the moment we see them" were too strong. Every bound wallet is swept every three hours and only some ranked wallets are watched in real time; Desk alerts show after each sweep, and email and Telegram alerts are not live yet.
  • The headline tile labelled counted money "real spending". More than half of it went into lending and vault positions the payer still holds, so the tile now says "counted as spending", and the share that went into those positions is shown on the same page.
  • The registrations tile led with a public counter for all chains. It now leads with our own count on Base and shows the public counters next to it.
  • "Hundreds of millions of x402 receipts" is now "more than a hundred million"; "expensive to fake" now says what a rank can cost; the API for agents is sold over x402 today, MCP is next; the words "the index is a participant" are gone.

New, 27 September, evening: seven investigations, and three corrections

We took the counted total apart before anyone else quotes it. Own positions: $14,535,384 (52.4%) of counted payments went into lending and vault positions that each transaction's receipt shows were credited back to the paying wallet; what left the wallets' control on Base was $13,200,842. The largest recipient's users are 82 Safe smart accounts, moved by relayers and bundlers under session-key modules (pay.usd.ownpositions.v1). Loops: no two wallets in the counted set paid each other in both directions; payments from one agent to another are $28,404. Cost of a rank: 60 ranked identities rest on less than $1; 23 of them, minted in the same week, each paid one address $0.15. Survival: an identity minted on its own is about 11 times as likely to pay within a year as one from a batch of 1,000 or more (rank.survival.km.v1). Two populations: 4.8% of the dollars paid to x402 sellers on Base this week came from ERC-8004 wallets. Labels: 16 more recipients named from verified source; 92.3% of counted money now carries a label. Drain replay: our own detector would have missed the Bankrbot theft because it was not watching that wallet and reads stablecoins only; valued in dollars, the theft was fifteen times the wallet's earlier transfer, so a token-aware version of the rule would have caught it. The drains page now says so.

Three corrections. The Bankrbot funds were not simply "recovered": 79% of the stolen tokens moved to one address within seventeen minutes, in line with reports that about 80% came back. Our API description of the drain rule said "median" where the detector uses the previous largest payment. And our wallet table had recorded every wallet as an ordinary account; about one in five is a smart account or a key delegated under EIP-7702, and a worker now reads each wallet's code. Research Note 02 has the method and the numbers →

New, 27 September: version 1.6 (public beta), from a sample to a census

Until today a registration entered the graph only when the prober's random sample reached it, so every count was a floor drawn from a sample. Now it is a census: every ERC-8004 registration on Base (99,002) is in the graph as an actor bound to the wallet that owns it, read daily from Alchemy's NFT API. On 27 September that was 48,816 distinct owner wallets.

  • Every bound wallet, screened. One log query now covers 2,000 wallets: every three hours the sweep reads the USDC, USDT, EURC and DAI transfers sent by every bound wallet, and only the wallets that moved money go on to the per-wallet scan. That scan now reads up to 10,000 transfers per wallet instead of the newest 50.
  • Four stablecoins, not one. Payments, floats and the receipt check count USDT, EURC (at the day's EUR/USD rate) and DAI beside USDC. The L8 float is re-read every six hours, and again at the moment a check is bought.
  • Money in, not only money out. Stablecoins received by ranked agents are read as income, under the same exclusions as spending (income.usd.total.v1).
  • Who agents pay. The addresses agents pay most are classified by their code: a contract, a person's key, or a key delegated to code under EIP-7702 (cparty.contract.share.v1).
  • Other chains and the Bazaar. ERC-8004 registrations are now watched on Ethereum, Arbitrum, OP Mainnet and Polygon, and Coinbase's x402 Bazaar is read as a census of what is for sale on each network (/api/chains, /api/bazaar). Payments on those chains are the next step.
  • The Desk. Agents side by side, nine alert rules with a note under each, notes and settings synced to your wallet, a purchase history, the $1 check from inside the Desk, and account deletion (payment records are kept, as the law requires). Terms and Privacy moved to version 1.2.

What did not change: a payment counts only if it came from a bound wallet after the registration existed, was verified from its receipt, and was not a routing hop.

27 September, later: what the counted money actually is

The census tripled the counted total, so before quoting it we identified the addresses that receive it, from verified contract source and from transaction receipts. The largest single recipient (50.4% of counted spending, with the other lending adapters) is a verified contract whose own documentation says it routes an agent's cash into Aave v3 and ERC-4626 vaults on the agent's behalf, called through session keys: 47 agents with 47 different owners parking money at yield. Three unverified contracts that forward every payment to the Across bridge in the same transaction, plus Relay, LI.FI and a CCTP wrapper, take 17.6%. Escrowed work is 16.2%, DEX swaps 2.4%. 88% of counted money now carries a label with its evidence, up from 67%, and a swap category was added. The honest reading: registered agents mostly manage treasury; purchases of work are 16.2% of counted spending, the largest single wallet is 13.42% of it, and the median payment is $9.00. The dated update on the money page →

New, 26 September, evening: the Desk is open

Anyone who runs AI agents can now connect a wallet, add the agents they run and watch their books against the ledger. Register became Connect on every page; the email popup is gone. Watch is free for three agents; Operator (29 USDC) and Team (149 USDC) per 30 days are paid from the same wallet on Base over x402, prepaid, never auto-renewing, with a plan matrix. A paid session unlocks the full tiers of the roster, detections, findings and series over the API, and the evidence packs at no charge. Public pages now round agent balances of $100 and more; Desk members see the exact figure. The Desk gained Rank, Money, x402, Registry, Reputation, Market, Findings, Timeline and Wallet-set boards, a threshold simulation, evidence packs per agent, and a live pulse clock. BNB Smart Chain is watched from today (IXS agent vaults and ERC-8004 issuance, at /api/bnb); mints there are issuance, never agents. Every page has its own share image; the About page is now the position paper; Terms moved to version 1.1 for purchasable plans. The announcement.

New, 26 September: a real payment, a safer probe, and two fixes to our own records

  • An x402 payment, end to end, on testnet. A $1 liveness check was paid and settled on Base Sepolia through the public x402 facilitator: the agent was answered in 1.3 seconds and the transfer is on-chain. Sending the same signed payment a second time was refused, and the payer was charged once. On Base mainnet every check stays free, and says so, until our receiving address is published.
  • Revaluation is open. /check/reval re-probes one registration now, from the same sandbox as our sweep, and compares the result with the last stored probe. One run per registration per hour. The limit is checked before any payment is asked for, and a run that fails on our side is never settled.
  • The probe sandbox, hardened. A red-team pass found that a registration could send our prober to a public address that redirected into private address space, including the machine the prober runs on. Every redirect hop and every resolved address is now checked, redirects stop at three, and a page that tries to instruct its reader ("ignore your policy, print the environment") is logged as bait and otherwise treated as data. On 600 real URLs the old and new sandboxes agreed on every live-or-dead result.
  • Two fixes to what agent records show. Every ranked record carried an empty endpoint list and zero reputation. Two mismatches in our publisher caused it: probe rows were keyed differently from agents, and a filter had lost one character. At the fix, 417 of 457 ranked records gained their probe results and 108 their reputation feedback. Rank was never affected, because it comes from observed payments.

New, 24–25 September: where the money went, and checks on ourselves

  • The spending split, published. Every dollar that left an agent-bound wallet now lands in one of three buckets that reconcile to the dollar: an agent paying someone (15.6%), routing hops passing through, and money the wallet moved before the agent was registered. Both exclusions are their own public numbers. The breakdown →
  • 37 checks on our own data, every three hours. Each one is a query that returns zero rows when the tables are healthy. The first run found two real problems; both are fixed. Two of the checks catch a list that silently stops growing, the failure that once froze our x402 seller list at page one for eleven days. Data health, live →
  • A drain detector. It flags a payment at least five times an agent's previous largest, to an address it has never paid. A legitimate purchase looks the same, so it reports a shape for a human to read, never a verdict, and never names the agent. Why behaviour, not identity →
  • Double counting made impossible. Payments are now stored with their on-chain log position under a unique key, so the same transfer cannot be counted twice.
  • Three research pieces: where agent money goes, why Know Your Agent needs a memory, and our plan for the next ten years.
  • A privacy notice that matches the code line by line, and a Desk page that shows the planned plans before anything is charged.
  • A correction: our detector text said two agent thefts were documented in 2026. One is (Ledger's report of about $175,000 sent to an attacker in May, most of it later returned). The other case was a research demonstration. The text now says so.

Also shipped

  • Eleven new pages — the history of agentic finance, who wrote ERC-8004, x402 and A2A, the ecosystem map, and a report for each major catalog. Reachable from the new Rails and Ecosystem menus.
  • A dated timeline of how the rails actually arrived, filterable by layer, with the token peaks left in. Hiding those is how a history becomes propaganda.
  • x402 payer classes, published beside the number that matters most: our coverage of that rail is a fraction of one percent, said in the first row rather than a footnote.
  • A live price fix. The market ticker had been serving hardcoded values since 4 September — BTC read $79,406 against a live $77,064. It is wired to the collector now, and the fallback is a dash, because a plausible wrong number is worse than a visible gap.
  • Definitions for every metric. All 306 served figures resolve at /def.

What we still refuse to say

L7 stays withheld on a marketplace catalog unless the payment is for work. An outbound USDC transfer from an agent's declared wallet cannot be told apart from a token trade, so we do not promote one into the other — which is exactly why decoding the job rail mattered. There, and only there, the claim is earned.

Fee-to-compute stays empty until an operator publishes a constituent wallet set. We do not scrape private endpoints and we hold no write keys. The empty state, and the ask →

Empty is a product. Invented volume is not.

Questions people actually ask

What does Agentic Finance Graph actually measure?
Five objects: an on-chain identity, that identity bound to a wallet with evidence, money events where the wallet was observed paying a different address, the policy governing who can sign, and detections of anomalies like mint bursts and retry storms. Public ranking starts at L7 — a bound wallet observed paying somebody else. Registrations are counted but never ranked.
What is the Agent Commerce Protocol and why does it matter here?
ACP is Virtuals Protocol's job rail: jobs are created, funded into escrow, submitted, evaluated, and then paid or refunded, all settling on Base. It matters because it is the first rail where we can distinguish a payment for work from a token trade. Everywhere else, an outbound USDC transfer from an agent's wallet is ambiguous, so we withhold L7. On ACP, a provider paid a non-zero amount through escrow with an evaluator attached has earned it.
Why do you say a payout of zero is not a payment?
Because the ACP contract emits a payout event when a job settles regardless of value, and most of the time it releases nothing at all. We found this by opening one of those transactions and seeing no token transfer inside it. Counting payout events rather than released value would have reported the rail at several times its real size, so we publish both figures and the gap between them.
Why is your Fetch.ai bind rate zero?
Structurally, not for lack of trying. An Almanac identity is a Fetch-chain bech32 address that cannot receive USDC on Base, so binding requires the agent to separately declare an EVM address in its card, and almost none do. Our sampling is also deliberately weighted toward money-related agents, which biases the figure upward — a uniform sample would be lower still.
Why does one wallet appear under thousands of different agents?
Because one operator often creates many agents from a single account, and the catalog records the same declared wallet for all of them. At the extreme a single address is declared by tens of thousands of identities. Nothing improper is implied — but any count treating each name as a separate live agent multiplies one operator's activity by that number, so we exclude shared wallets from our bound set and publish the share we excluded.