# Introducing ERC-8126: The Verification Layer for AI Agents Source: https://x.com/DonJohnsonSays/status/2065315466151968923 ## Summary ERC-8126 is a proposed open Ethereum standard that lets independent verification providers assess AI agents registered under ERC-8004 and publish portable, privacy-preserving attestations. The authors argue that reputation alone is no longer sufficient as agents manage more capital and execute transactions autonomously. The standard covers five verification layers (Ethereum Token, Media Content, Solidity Code, Web Application, and Wallet Verification) and uses zero-knowledge proofs so providers can attest to results without exposing sensitive data. Each applicable check returns a 0 to 100 score, and the overall score is the mean of those scores, mapped to risk tiers from Low to Critical. ## Article Specification: https://eips.ethereum.org/EIPS/eip-8126 Authors: Leigh Cronian and Chris Johnson Co-authored with contributions from Cybercentry and Virtuals Protocol AI agents are rapidly becoming participants in digital economies. They deploy code, execute transactions, manage wallets, interact with users, and increasingly collaborate with other agents. Yet while we have robust systems for verifying humans, businesses, websites, and software, there has never been a universal framework for verifying AI agents until now. Built on top of ERC-8004 agent registration, ERC-8126 introduces a standardized verification framework that enables AI agents to prove their trustworthiness through independent verification providers while preserving privacy through Zero-Knowledge Proofs. The Problem Users have traditionally had very limited ways to determine whether an AI agent is trustworthy and questions that seem simple often have no clear answers: Is this agent operating from secure infrastructure? Has its code been audited? Does it control the wallet it claims to control? Are its associated tokens legitimate? Is the content it publishes authentic? Has it been compromised? Current solutions are fragmented, inconsistent, and often rely heavily on reputation alone. As agents begin managing larger amounts of capital, executing more and more transactions autonomously, and interacting with critical systems, reputation is no longer sufficient. The ecosystem needs a common verification framework. Introducing ERC-8126 ERC-8126 defines a standardized interface for verifying AI agents registered through ERC-8004. Rather than creating a single verification authority, the standard enables a marketplace of specialized verification providers. Each provider can perform assessments using its own methodologies while producing interoperable attestations that can be consumed across applications, marketplaces, wallets, and agent ecosystems. The result is a portable verification layer for AI agents. Verification providers resolve agent metadata directly from the ERC-8004 Identity Registry and perform a series of specialized verification procedures. Results can then be transformed into privacy-preserving attestations and published to ERC-8004’s Validation Registry, creating discoverable verifiable signals across the ecosystem. Five Layers of Verification in ERC-8126 Ethereum Token Verification (ETV) Ethereum Token Verification, or ETV, validates the legitimacy and security of a smart contract when a contract address is present in the agent metadata. The provider verifies that the contract address is actually deployed on the resolved chain by calling eth_getCode and confirming that the returned bytecode is not empty and also checks the contract against known vulnerability patterns. This matters because agents may be associated with tokens, contracts, staking mechanisms, or other on-chain systems. If the contract does not exist, is misrepresented, or contains obvious vulnerabilities, users and other agents need to know that before interacting. ETV helps establish whether the agent has a legitimate on-chain footprint. This helps users understand the economic foundation supporting an agent. Media Content Verification (MCV) Media Content Verification, or MCV, validates the authenticity, provenance, and integrity of media associated with the agent. As agents become more visible, media becomes part of identity. Profile images, generated assets, brand materials, and public content can all influence whether users trust an agent. MCV checks for signs of manipulation, tampering, synthetic media, deepfakes, embedded metadata, digital watermarks, steganographic payloads, and signatures where present. It can also use established authenticity frameworks such as C2PA. As AI-generated content becomes increasingly sophisticated, verifying authenticity becomes essential. MCV provides a way to evaluate the integrity of that media layer. This allows agents to provide stronger assurances regarding the media they publish and distribute. Solidity Code Verification (SCV) Solidity Code Verification, or SCV, validates the legitimacy and security of Solidity code when Solidity code is present in the resolved metadata. The provider verifies that the code corresponds to deployed bytecode on the resolved chain and checks for common vulnerabilities such as reentrancy, unsafe external calls, and flash loan attack patterns. This matters because agents may operate smart contracts or interact with contracts as part of their service. If an agent is tied to vulnerable code, there is risk. It can directly affect users, assets, and other agents. SCV gives the ecosystem a standard way to evaluate smart contract security signals at the agent level. This creates greater transparency around the software systems powering autonomous agents. Web Application Verification (WAV) Web Application Verification, or WAV, checks the agent’s web endpoint for accessibility and security. Agents often expose web interfaces, APIs, dashboards, or endpoints. These endpoints can become attack surfaces. A compromised URL can phish users, serve malicious content, or manipulate agent behavior. WAV verifies that HTTPS endpoints respond, checks SSL certificate validity, and looks for common web security vulnerabilities. It should follow established web security testing frameworks such as the OWASP Web Security Testing Guide. This is critical because many users will encounter agents through web interfaces before they ever inspect a wallet or contract. The website is often the front door and WAV helps determine whether that front door is safe. Trust extends beyond the blockchain and WAV helps verify the broader infrastructure agents depend on. Wallet Verification (WV) Wallet Verification, or WV, confirms wallet ownership and assesses the on-chain risk profile of the agent wallet. The provider checks that the wallet has transaction history and evaluates it against threat intelligence databases. This can help identify wallets associated with malicious behavior, suspicious activity, scams, or compromised infrastructure. The agent wallet is one of the most important parts of the agent identity. It may control funds, sign messages, authorize tasks, receive payments, and interact with other agents. If the wallet is compromised or high-risk, the agent is high-risk. WV gives users and systems a standardized way to evaluate that risk. This provides additional confidence that an agent is controlled by the entity it claims to represent. Privacy Through Zero-Knowledge Proofs One of the most important aspects of ERC-8126 is privacy. Verification often requires access to sensitive information including source code, infrastructure details, proprietary data, operational systems, and security configurations. Organizations are understandably reluctant to expose this information publicly. ERC-8126 addresses this challenge through Private Data Verification (PDV) and Zero-Knowledge Proofs. Verification providers can inspect sensitive information, perform their analysis, and generate cryptographic proofs that attest to the outcome without revealing the underlying data. This means an agent can prove it passed a security review without exposing confidential infrastructure or proprietary information. Verification increases while privacy remains intact. Unified Risk Scoring One of the underlying parts of ERC-8126 is the unified risk score. Each applicable verification type returns a score from 0 to 100. The overall risk score is calculated as the mean of the applicable verification scores and the standard defines clear risk tiers: Low Risk: 0-20 Moderate: 21-40 Elevated: 41-60 High Risk: 61-80 Critical: 81-100 This makes verification easier to interpret. The scoring model provides: Easy comparison between agents Consistent risk categorization Actionable trust signals Cross-platform interoperability Applications may also expose individual category scores to provide greater transparency into specific areas of risk. Future-Proofing with Quantum Cryptography Verification ERC-8126 also introduces optional Quantum Cryptography Verification (QCV). As quantum computing advances, traditional cryptographic systems may eventually face new security challenges. QCV provides an optional framework for providers to securely encrypt sensitive verification records using quantum-resistant approaches, helping ensure verification data remains secure well into the future. While optional today, QCV reflects a broader design philosophy behind ERC-8126 which is focused on building verification infrastructure that can evolve alongside technology. Open Verification Markets ERC-8126 intentionally separates the verification standard from any single implementation. There is no central authority and any provider can implement compliant verification services. This approach encourages: Competition among providers Specialized expertise Geographic flexibility Better pricing Continuous innovation Just as multiple certificate authorities help secure the web, multiple verification providers can contribute to a healthier and more resilient agent ecosystem. The Missing Layer The industry has spent years building infrastructure that allows agents to exist and now we need infrastructure that allows for verification. Identity alone is not enough. An agent can have a name, a wallet, and an on-chain identity while still operating insecurely. An agent can execute transactions, interact with users, and even generate revenue while exposing users to hidden risks. Verification must become a first-class primitive and that is the role of ERC-8126. By introducing standardized verification, portable attestations, privacy-preserving proofs, and transparent risk scoring, ERC-8126 allows trust itself to become interoperable. An agent verified in one ecosystem can carry that trust signal into another. A marketplace can evaluate an agent without repeating the entire verification process. Users can make informed decisions without needing to understand every technical detail behind the systems they interact with and most importantly, verification becomes portable. Identity. Verification. Commerce. The next generation of the internet will not be powered solely by humans, but increasingly by autonomous software agents acting on behalf of individuals, organizations, protocols, and other agents. These agents will negotiate agreements, they will manage assets, they will purchase services, they will deploy software and they will coordinate with one another at a scale no human organization could achieve. To support this future, three foundational layers are required and together, these three standards transform agents from isolated software programs into participants in a shared economic network. Identity; ERC-8004 establishes identity by providing portable, on-chain agent registration. Verification; ERC-8126 provides the trust layer that allows participants to assess risk, verify authenticity, and interact with confidence. Commerce; ERC-8183 enables commerce by creating standards for agent-to-agent economic activity. Together, these 3 standards transform agents from isolated software programs into participants in a shared economic network. No single company owns these layers. They belong to the ecosystem. Why We Contributed As builders working on agent infrastructure, the contributors to this standard kept encountering the same gap. Agents could register identities, transact, and coordinate, but there was no shared way to answer the most basic question user ask: can I verify this agent? The answer to that question should not be owned by any single company. Verification infrastructure only works if it is neutral, open, and independently verifiable. That is why ERC-8126 is an open standard rather than a proprietary product. Anyone can implement it, any provider can offer verification services against it, and any application can consume its attestations. Toward a Verified Agent Economy The most successful digital economies in history were built on trust. People trust websites because of HTTPS, they trust software because of code signing and they trust businesses because of reputation systems and verification frameworks. The agent economy will require its own verification infrastructure. Not because agents are inherently dangerous, but because trust scales opportunity. When users can verify agents, they become more willing to interact with them. When enterprises can assess risk, they become more willing to deploy them and when agents can verify one another, entirely new forms of autonomous coordination become possible. ERC-8126 is designed to provide that foundation. The goal is simple, make verification programmable. Not as a centralized authority and not as a single verification provider, but as an open standard that allows an ecosystem of verification services to emerge because before agents can transact with the world, the world must be able to verify its agents. Building the Future of Agent Verification Together ERC-8126 is an open standard for AI agent verification and we encourage builders to integrate the verification standard into your agents. Resolve ERC-8004 metadata and publish attestations today. Verification Providers: Implement compliant verification services covering ETV, MCV, SCV, WAV, WV and issue PDV ZKP-based attestations through the marketplace of your choice. Protocols, Marketplaces & Wallets: Integrate ERC-8126 to display verification results and unified risk scores for every agent. Next Steps: Read the specification: ERC-8126 (https://eips.ethereum.org/EIPS/eip-8126) Start verifying agents or become a verification provider. Verify agents. Enable secure interactions. Power the verified agent economy.