Emet gives your trading agent a session key, never your keys. Every trade is checked onchain against rules you write: asset limits, drawdown, slippage and venue. The guardrails never depend on trusting the model.
Designed for ERC-4337 + ERC-7579 · default-deny execution · no withdrawals, ever
In 16th-century Prague, a rabbi shaped a giant from river clay. It lived only because of a single word carved into its forehead: אמת, truth. Erase the first letter, and the giant returns to clay.
The smart account, the Clay, is deployed. No agent, no rules, no power yet.
The Maker writes the Letters: position limits, loss limits, venues. The Golem wakes, bounded.
One call to erase() and the account freezes instantly. Never trust, only revoke.
Every trade passes through a deterministic four-stage pipeline before a single token moves.
Master key sets Letters: assets, size, loss, venues, expiry.
The Golem gets a session key: trade only, never withdraw.
Every UserOp verified against rules before and after execution.
Every action is recorded onchain. Refusals are logged by the SDK, tagged with the Letter that stopped them.
Rules live onchain, not in a prompt. Nothing the AI says can override them: only the Maker can rewrite the Inscription.

Only NVDA, TSLA, USDG, or whatever list the Maker sets. Anything else is default-denied.

Cap any single asset at, say, 20% of portfolio value. Enforced before every fill.

Any trade that would push drawdown past −5% of the high-water mark is reverted. Repeated breaches freeze the account.

Per-trade and per-hour caps stop runaway execution before it compounds.

Only whitelisted adapters: thin, purpose-built contracts, never raw router calldata.

The Mark dies after N days. No silent renewal: the Maker re-inscribes by hand.
We never decode Uniswap's Universal Router. A small SwapAdapter exposes one function and always returns output to the account.
Every trade's output must land back on the EmetAccount. This is what makes "no withdrawals" actually hold.
erase() is callable by the Maker or a Keeper. It moves the account to MET instantly and revokes every Mark.
Each strategy gets its own Golem: a distinct silhouette carrying a distinct tool, running inside the same Inscription.
Demo strategies for testnet. Emet is infrastructure, not investment advice.

Carries a stone scale on its back. Symmetrical, steady: keeps the portfolio at target weights.

Lean, forward-leaning, streaks of clay trailing behind. Chases trend within a hard exposure cap.

Stacks bricks one by one. Broad and patient: buys on a fixed schedule, no timing bets.

Tall, carries a lantern, keeps looking around. Moves to safety fast when volatility spikes.
The Erase button is never hidden in a menu. Try it: it's connected to the mock below.
Preview API. @emet/sdk is not published yet.
// @emet/sdk · build, simulate, submit import { EmetClient } from "@emet/sdk"; const emet = new EmetClient({ clay: "0x5b4...089", mark: process.env.SESSION_KEY, chain: "base-sepolia", }); const plan = await emet.simulate({ action: "swap", tokenIn: "USDG", tokenOut: "NVDA", amountIn: "250", }); if (plan.refused) { console.log(`Refused by ${plan.rule}`); } else { await emet.submit(plan); }
Testnet is live on Robinhood Chain. Fund a Clay, choose a Golem, watch the Chronicle fill in.