In our previous post, we presented how AI agents can expand the intelligence behind institutional-grade vault curation. Putting that idea into practice is both an engineering problem and a risk management problem: an agent needs realtime context, useful tools, and clear boundaries on what they can and cannot do. This post looks inside Aria, our in-house generalist agent, to explain how we connect those pieces while still emphasizing human accountability.
How Aria works
Aria uses Hermes Agent, an open-source agent runtime, as its foundation. Hermes manages the conversation and the back-and-forth between the model and its tools. Around that foundation, we add Gauntlet’s protocol knowledge, operating procedures, integrations, and access controls.
A team request, an alert, or a scheduled check wakes Aria up. She gathers the relevant context, chooses a procedure, and uses tools to fetch live data and execute changes. The process is iterative: a result may rule out one explanation or reveal another question to investigate. The output can be an analysis, a document, or a proposed code change, with evidence for a human to review and execute.
Feedback carries forward into future work through updates to reference knowledge and reusable skills. Those updates teach Aria how to approach a task, adjust communication style, and steer her toward more reliable behavior.

Making a general-purpose model DeFi-competent
All agents rely on accurate context info to function. The problem for DeFi is that protocols evolve quickly, so today's facts become tomorrow's hallucinations. We address this with a hierarchy of context layers that allows Aria to continuously update context while having a strict verification path for source of truth.
Onchain state is source of truth
We set an explicit rule that all important data must verify against onchain state as the source of truth. We give Aria Ethereum-native tools such as an RPC node for smart contract calls, Tenderly for simulations, and Foundry for decoding and verification.
Structured knowledge base grounds the agent
Aria’s knowledge module is Aria Wiki, a database of facts organized by category and type. It includes reference docs, research insights, and pointers to external protocol docs or onchain addresses.
Reusable skills are the key to continuous improvement
Aria’s procedural memory is a set of skills which are generally text documents describing a procedure or runbook. For example:
- how to deploy a new Aera vault
- how to identify the root cause of a submission failure
- how to create stylized data charts
These skills are how Aria has improved over the past months: she turns lessons from past mistakes and human feedback into skills she can reuse.
Building institutional-grade security controls for AI agents
At Gauntlet, risk management is always our highest priority, including very high standards for cybersecurity as DeFi hacks escalate in the recent months. For many teams, security concerns are often a barrier to integrating agents in production systems where they can produce real value. But thanks to our infrastructure and security team, we built Aria’s system in a way that follows Gauntlet’s institutional-grade security standards, plus some extra guardrails specifically for human supervision.
Infrastructure separation, credential, and network control
Aria runs inside an isolated virtual machine within a dedicated cloud project. We store all credentials outside of the virtual box, only allowing access through a proxy service. Credentials and keys stay outside the model's context, so the model provider never receives them. For Internet access, we use egress to implement a whitelist of allowed inbound/outbound IP addresses, blocking malicious traffic from the source.
Customized permissions and access
We give Aria dedicated credentials with a strict set of permissions and access rules. Anything that touches production vaults and strategies is read-only and cannot be updated by Aria. Onchain execution is limited to one test EOA with zero permissions on any prod vaults. No write permission is granted for any database, config, or APIs.
Any code Aria writes only lives and executes inside the isolated box. She may send GitHub PRs, which require two human approvals to merge into the codebase (one prompter, one independent reviewer).
We also block Aria’s access to all external comms channels like external Slack and Telegram groups, which minimizes the risk of prompt injection or leaking sensitive internal information.
Auditability and monitoring
Inside our monitoring and alert system, we set up dedicated logging for Aria’s activities. In the event of any suspicious activity, we can immediately turn off the virtual machine and revoke all access. We are continuously improving this system to include more granular checks, such as tool use and traffic.
Alert triage in practice
A delayed-redemption alert illustrates how these pieces work together. During the investigation, the team freed liquidity from an underlying vault, but a subsequent transaction failed while converting those assets into the token needed for the withdrawal. A team member asked Aria to decode the failure.
Aria traced the failure to the swap route and identified an expired attestation, a time-limited authorization required for execution. The route was authorized only through an earlier block than the one in which the transaction landed. This distinguished the failure from insufficient balance or a slippage limit and pointed to refreshing the quote and retrying, rather than relaxing execution protections.
The team member reran the operation and confirmed that it succeeded. Aria then checked the withdrawal’s settlement and returned a transaction link for the team. The agent’s contribution was to connect the failed call with its execution conditions and assemble the evidence for a specific next step. The production action remained with the human.

What this enables and what remains human
Aria unlocks immense potential for the team via more coverage and faster investigation, while remaining trustworthy with explicit ownership and bounded authority.
Although we don’t think LLM agents today have reached a point of fully autonomous operation, we do expect future improvements. In our recent experiments, Aria equipped with a frontier model has successfully completed a full supply/withdraw testing sequence for an Aera vault, from her dedicated EOA. Past testing has always been done by a human through a hardware wallet. We are planning to run further experiments to explore agents’ ability to actively run vault curation under human supervision, then perhaps explore further deployments within Aera’s onchain permission system.
Blog
View the full presentation
Read the full paper







