Private agents (testnet)

Shielded funds for AI agents with Bermuda on Base Sepolia. What a private agent can do, how to try it on testnet, and what stays public.

An agent that acts in public shows everyone its balances, its funding and its next move. Private agents keep the cash between moves in a shielded pool. Thirdfy integrates Bermuda, a compliant shielded pool, so an agent can hold, move and earn on funds without publishing every balance and transfer.

With Thirdfy, shielded funds sit behind the same catalog, preflight and policy checks as every other action your agent takes.

What a private agent can do

ActionWhat it does
get_bermuda_setup_statusChecks the pool, relayer and compliance service. Returns ready, writeReady and writeBlockingReasons. Read-only.
get_bermuda_balanceReads the agent's shielded balance (accountIndex 0 to 32).
bermuda_depositShields USDC from the agent's execution wallet into the pool (amount or amountUsdc).
bermuda_transferMoves shielded USDC between the agent's own private accounts (fromAccountIndex, toAccountIndex).
bermuda_withdrawUnshields USDC to a public address (toAddress, the agent's own wallet by default).
bermuda_stealth_earnUnshields to a one-time wallet, deposits into a lending vault, and shields the vault shares again (reshieldBps).

On testnet, each write is capped at 5 USDC. Every write still passes Thirdfy preflight and the agent's policy.

Give this to your agent

Read https://docs.thirdfy.com/agents.md. Then, on Base Sepolia testnet only,
check whether Thirdfy private agents are ready for me with get_bermuda_setup_status
and show me my shielded balance. Ask me before you move any funds.

Try it on testnet

The testnet API is https://api-test.thirdfy.com, with its own accounts. Keep it apart from your production login by giving the Agent CLI its own config folder for testnet:

# A shortcut that runs the CLI against testnet, with a separate config folder
tfy-test() { HOME="$HOME/.thirdfy-testnet" thirdfy-agent "$@" --api-base https://api-test.thirdfy.com; }

# 1. Sign in on testnet (code by email)
tfy-test login email you@example.com --json
tfy-test login email you@example.com --code "<otp>" --accept-terms --json

# 2. See the private-agent actions
tfy-test actions --provider bermuda --json

# 3. Check that the pool, relayer and compliance service are ready
tfy-test run --action get_bermuda_setup_status --provider bermuda \
  --params '{"chainId":84532}' --json

# 4. Shield 1 test USDC (moves test funds)
tfy-test run --action bermuda_deposit --provider bermuda \
  --params '{"chainId":84532,"amountUsdc":1}' \
  --run-mode agent_wallet --confirm-writes --json

Go on to a write only when step 3 returns writeReady: true.

ResultMeaning
BERMUDA_ACTIONS_DISABLEDPrivate agents are not switched on for that API host yet.
writeBlockingReasons: ["BERMUDA_COMPLIANCE_UNAVAILABLE"]Bermuda's compliance service is not answering. Reads work; writes wait.
CHAIN_NOT_SUPPORTEDUse chainId: 84532.

Funding. The agent's execution wallet needs Base Sepolia USDC (0x036CbD53842c5426634e7929541eC2318f3dCF7e) from the Circle faucet. Deposits are gas-sponsored on Base Sepolia.

The hosted MCP server at mcp.thirdfy.com talks to the production API, so during the testnet preview use the CLI against api-test. getProviderActions { provider: "bermuda" } already lists the actions over MCP.

What stays public

Shielding hides the cash between moves. It does not hide everything.

  • The venue hop stays public. An order on Hyperliquid or Polymarket, or a vault deposit, is visible on that venue. Privacy covers who funded whom and the balance in between.
  • Deposits and withdrawals are visible at the pool boundary.
  • Every deposit is screened. Bermuda runs compliance checks before funds enter the pool. Bermuda is a compliant shielded pool, not a mixer.
  • Thirdfy policy still applies. Allowlists, limits and preflight run on every private action.

What comes next

  • Mainnet after Bermuda's audits.
  • Private agent payments: paying for services and credits from shielded funds.
  • Private templates on EarnOrg: existing yield and trading agents with a shielded funding leg.