Audit Reveals Solana AI Trading Agent Never Signed Its Own Orders
A student-led audit of Omo, an AI-driven trading agent on Solana (SOL), has uncovered a significant discrepancy: none of its 174 orders were signed by its own wallet. The audit, conducted by Charlie Sneed of the University of Oregon's blockchain club, found that the agent's cryptographic fingerprints did not match any trades it claimed to execute.
Omo, which launched on August 9 and traded memecoins until August 31, posted cryptographic hashes of its decisions on the Solana blockchain. However, Sneed's manual verification of the oldest decision with a trade attached revealed that the paired transaction was a token transfer signed by another wallet, not Omo's own. The audit highlighted that Omo's custody practices were flawed, as it used a key copied from a phone app and stored on a server, without verifying signatures.
Sneed proposed three fixes, including using a hardware-held signing key, though he acknowledged that this would not have addressed other issues like Omo's 7.1% win rate or the failing web search that persisted while the agent continued trading. The audit paper, published on September 28 through a Ledger-sponsored research competition, emphasized that while the cryptography held up, the lack of proper key custody and trade-matching checks was a critical weakness.
The findings come amid growing interest in AI trading agents. Binance and Robinhood have recently opened their platforms to such agents, though both companies have noted limitations in supervising or auditing their activities. The audit underscores the risks associated with autonomous trading systems and the need for robust oversight mechanisms.