Private agents (testnet)
Shielded funds for AI agents with Bermuda on Base Sepolia. What a private agent can do, how to try it on testnet, and what stays public.
Testnet preview. Private agents run on Base Sepolia (84532) only, with test USDC. They are not on mainnet. The actions are in the catalog; execution is rolling out on the Thirdfy testnet API.
An agent that acts in public shows everyone its balances, its funding and its next move. Private agents keep the cash between moves in a shielded pool. Thirdfy integrates Bermuda, a compliant shielded pool, so an agent can hold, move and earn on funds without publishing every balance and transfer.
With Thirdfy, shielded funds sit behind the same catalog, preflight and policy checks as every other action your agent takes.
What a private agent can do
| Action | What it does |
|---|---|
get_bermuda_setup_status | Checks the pool, relayer and compliance service. Returns ready, writeReady and writeBlockingReasons. Read-only. |
get_bermuda_balance | Reads the agent's shielded balance (accountIndex 0 to 32). |
bermuda_deposit | Shields USDC from the agent's execution wallet into the pool (amount or amountUsdc). |
bermuda_transfer | Moves shielded USDC between the agent's own private accounts (fromAccountIndex, toAccountIndex). |
bermuda_withdraw | Unshields USDC to a public address (toAddress, the agent's own wallet by default). |
bermuda_stealth_earn | Unshields to a one-time wallet, deposits into a lending vault, and shields the vault shares again (reshieldBps). |
On testnet, each write is capped at 5 USDC. Every write still passes Thirdfy preflight and the agent's policy.
Give this to your agent
Try it on testnet
The testnet API is https://api-test.thirdfy.com, with its own accounts. Keep it apart from your production login by giving the Agent CLI its own config folder for testnet:
Go on to a write only when step 3 returns writeReady: true.
| Result | Meaning |
|---|---|
BERMUDA_ACTIONS_DISABLED | Private agents are not switched on for that API host yet. |
writeBlockingReasons: ["BERMUDA_COMPLIANCE_UNAVAILABLE"] | Bermuda's compliance service is not answering. Reads work; writes wait. |
CHAIN_NOT_SUPPORTED | Use chainId: 84532. |
Funding. The agent's execution wallet needs Base Sepolia USDC (0x036CbD53842c5426634e7929541eC2318f3dCF7e) from the Circle faucet. Deposits are gas-sponsored on Base Sepolia.
The hosted MCP server at mcp.thirdfy.com talks to the production API, so during the testnet preview use the CLI against api-test. getProviderActions { provider: "bermuda" } already lists the actions over MCP.
What stays public
Shielding hides the cash between moves. It does not hide everything.
- The venue hop stays public. An order on Hyperliquid or Polymarket, or a vault deposit, is visible on that venue. Privacy covers who funded whom and the balance in between.
- Deposits and withdrawals are visible at the pool boundary.
- Every deposit is screened. Bermuda runs compliance checks before funds enter the pool. Bermuda is a compliant shielded pool, not a mixer.
- Thirdfy policy still applies. Allowlists, limits and preflight run on every private action.
What comes next
- Mainnet after Bermuda's audits.
- Private agent payments: paying for services and credits from shielded funds.
- Private templates on EarnOrg: existing yield and trading agents with a shielded funding leg.