Nobody Owns the Output: Inside the Agentic Token Boom and the Treasury Logic No One Audited

0xCred
Academy

I pulled forty-seven agentic token contracts off-chain last week. Thirty-one of them share the same treasury primitive: a single externally owned account wearing multisignature cosmetics like a borrowed suit. The council is a faΓ§ade. The timelock is three hours. And yet each of these tokens traded, at peak, at a fully diluted valuation north of two hundred million dollars β€” on the promise that autonomous agents would one day govern the money.

This is the part of the bull market nobody wants to price. We have spent eighteen months celebrating the arrival of AI agents on-chain, framing them as the next evolutionary step in decentralized governance β€” the moment code stops being a tool and starts being an actor. But when I actually traced the wallet flows, the picture collapses into something far less noble and far more familiar: a narrative sold at retail prices, backed by treasury architecture that would embarrass a 2017 ICO.

The question I keep circling back to is not whether AI agents can trade, or vote, or allocate capital. They can. The question is who owns the output β€” and in the current configuration, the answer is almost never the agents, and almost never the community. It is the deployer, sitting behind a proxy contract, holding the keys to a narrative dressed up as a species.

Let me walk you through how we got here, what the on-chain data actually shows, and why the most important story in this cycle is the one being buried beneath the token launches.

Context: A Narrative Cycle That Didn't Learn From the Last One

Every crypto cycle has a founding myth. In 2017 it was the utility token β€” a lie so convenient that an entire industry built compliance frameworks around pretending to believe it. In 2021 it was the JPEG as identity, where a bored ape stood in for social capital and the market mistook status signaling for value creation. In 2022 the myth died in public, and we spent a year dissecting the corpse: the Terra collapse, the algorithmic stablecoin that trusted its own code more than its own community, the hubris of 'trustless' architecture without social consensus underneath it.

Nobody Owns the Output: Inside the Agentic Token Boom and the Treasury Logic No One Audited

Back then I wrote that the Terra failure was not a technology failure. It was a narrative failure β€” specifically the collapse of a story that said mathematics could replace trust without first building the social layer that makes trust meaningful. That piece, 'The Death of Trustless Hype,' got shared widely, and I thought maybe we had learned something. I was wrong. We didn't learn; we adapted. The myth simply mutated.

The 2025-2026 mutation is the autonomous agent. Here is the pitch, stripped of its poetry: large language models and reinforcement learning agents can now operate independently on-chain. They can hold wallets, execute trades, vote in DAOs, and manage treasuries. Because they are autonomous, they cannot be corrupted by human greed. Because they are transparent, their reasoning can be audited. Therefore, the argument goes, we are witnessing the birth of a new form of economic governance β€” one where the agents, not the founders, hold the reins.

It is a beautiful story. It is also, in its current implementation, mostly theatre.

The historical rhythm should be familiar by now. A genuine technological frontier appears β€” AI agents are real, and their on-chain capabilities are real. Capital rushes in because the frontier is early and the upside is asymmetric. The narrative gets compressed into a token, because tokens are the only instrument this market has for pricing belief. And then the token's architecture quietly contradicts the narrative, because architecture is boring and narratives are not.

That contradiction is what I want to examine, because I spent the last three months building a prototype DAO where AI agents actually voted on treasury allocation. I saw, up close, the gap between what the narrative promises and what the code delivers. And the gap is not small.

Core: What the Treasury Logic Actually Shows

Let me start with the mechanism, because the mechanism is the story.

When a project claims that agents govern its treasury, there are only three ways to implement it, and the choice between them is the entire game. In the first model, the agents are signers on a multisignature wallet β€” the same primitive Gnosis Safe has offered for years. In the second, the agents hold governance tokens and vote through a standard governor contract like Compound's. In the third, the agents operate a smart contract vault with programmatic spending rules, and their 'agency' is limited to parameter selection within bounds the deployer set.

I expected the first model to dominate, because it is the easiest to ship and the easiest to demo. It didn't. What I found was worse.

Of the forty-seven contracts I traced, thirty-one used a treasury primitive I am now calling the phantom council: an EOA that is presented in documentation as a 'council of autonomous agents,' but which is in fact a single keypair controlled by the deployer, wrapped in a two-of-three multisig where the second and third signers are the deployer's own hot wallets on different chains. The council is not autonomous. It is one person, three wallets, and a governance page that writes the word 'agent' where the word 'founder' used to be.

This is not a subtle deception. It is a structural one, and it is invisible unless you read the bytecode.

Here is the forensic detail that matters. In a genuine autonomous treasury, the agent's voting power should be derived from its on-chain behavior β€” its track record, its stake, its reputation. In the phantom council model, voting power is derived from token holdings that the deployer minted at genesis and never distributed. I checked the genesis distribution of thirty-one phantom-council tokens. In twenty-six of them, more than sixty percent of the governance supply went to addresses that were funded by the same faucet wallet in the first block. The agents 'vote,' but they vote with tokens the deployer printed, on proposals the deployer wrote, and the deployer holds the multisig that can override any outcome.

The autonomy is real in the demo. It is fictional in the architecture.

Now, I want to be precise here, because it would be easy to slide into cynicism and stay there. There are genuine experiments. I found eleven projects where the agent governance is structurally meaningful β€” where agent voting power is earned through verifiable on-chain performance, where the treasury vault enforces spending caps independently of any human signer, and where the deployer's keys cannot unilaterally alter the rules. Eleven out of forty-seven. That is twenty-three percent. It is not zero, and it is not nothing. But it is also not the norm that the market is pricing as if it were universal.

The reason this matters is not that founders are malicious. Most of them are not. The reason it matters is that the narrative has outrun the infrastructure by such a wide margin that the market can no longer tell the difference β€” and in a bull market, the inability to tell the difference is itself the product.

Let me explain what I mean by that, because it is the heart of my analysis.

The Sentiment Machine Behind the Token

When I talk to traders about agentic tokens, they rarely mention treasury architecture. They mention the demo video, the whitepaper's promise of 'emergent coordination,' and the price. This is rational behavior in a reflexive market. If the narrative is what moves price, then the narrative is what you trade. The architecture is a footnote until it isn't.

But the architecture determines what happens when the narrative cracks. In 2022, the architecture of Terra's stablecoin was the thing that killed it β€” the mint-and-burn mechanism that required constant demand to hold the peg, a mechanism anyone could have read in the whitepaper. The architecture was visible. People chose not to look. When they finally looked, the collapse was instantaneous.

The agentic treasury has the same latent property. As long as the narrative holds, the phantom council is invisible. The moment confidence wobbles β€” a missed roadmap milestone, a rival agent framework shipping faster, a macroeconomic shock that drains risk appetite β€” the market will suddenly remember how to read bytecode. And what it will find is that sixty percent of the governance supply is held by the deployer, that the timelock is three hours, and that the 'autonomous council' is one person.

Nobody Owns the Output: Inside the Agentic Token Boom and the Treasury Logic No One Audited

The sentiment data supports this reading. I tracked social volume against on-chain treasury activity for the twelve largest agentic tokens over an eight-week window. Social volume rose steadily β€” the narrative is ascendant. But actual treasury transactions, the metric that would prove agents are governing, stayed flat, and in seven of the twelve, declined. The narrative is being manufactured faster than the utility is being delivered. That is the definition of a sentiment-driven bubble, and it is the same signature we saw in the 2021 NFT cycle, where floor prices decoupled from any measurable network effect for months before the correction.

I am not calling a top. Bull markets can sustain this disconnect for far longer than any rational model predicts, and I have learned not to short a story while it is still being told. What I am saying is that the disconnect is structural, and structures have a way of asserting themselves at the worst possible moment.

The Liquidity Fragmentation Nobody Named

There is a second layer to this, and it connects to something I have been tracking since the Layer2 wars began.

Every agentic token launch currently requires its own liquidity pool. Every pool fragments capital that was already scarce. I counted, across the twelve largest agentic ecosystems, ninety-four distinct liquidity venues β€” some on Ethereum mainnet, some on rollups, some on appchains that exist solely to host the token's trading. The aggregate liquidity is impressive in headline terms. The depth per venue is not. Slippage on a fifty-thousand-dollar trade in several of these pools exceeds four percent, which means the token is liquid only in theory.

This is the same pattern I have watched Layer2s replicate for three years: dozens of chains, the same small user base, each one slicing the pie thinner while advertising the size of the dish. Liquidity fragmentation is not a technical problem to be solved. It is a marketing problem to be narrated. The projects that 'solve' it are the ones selling the next product. The projects that suffer from it are the ones whose users pay the slippage.

The agentic boom has inherited this flaw and accelerated it. Because agent frameworks are easy to fork, because the narrative rewards speed over depth, we now have more token launches chasing the same capital than at any point since 2021. And unlike 2021, the capital is not purely speculative retail. A meaningful share is institutional β€” family offices, small funds, treasury desks that were told this is the 'responsible' way to get AI exposure. Those allocators are the ones who will discover, in the drawdown, that the autonomy they paid for never existed.

What Genuine Agent Governance Looks Like

I want to give the reader a standard, because criticism without a benchmark is just complaint. Based on my audit experience with the prototype DAO I built earlier this year, genuine agent governance has four properties, and most projects fail at least two of them.

First, the agent's authority must be earned, not assigned. In a real system, an agent accumulates voting power by demonstrating performance β€” profitable trades, successful proposals, reliable execution β€” and that track record is verifiable on-chain. Assigned authority, minted at genesis, is just a founder with extra steps.

Second, the treasury rules must be enforced by the contract, not by a signer. If the deployer can unilaterally change spending caps or pause the vault, the agent is not autonomous. It is a puppet with a nice interface.

Third, the agent's reasoning must be auditable. This is where the current generation fails most spectacularly. A large language model produces output, not explanation. When an agent votes to allocate treasury funds, the community deserves to know why β€” and 'the model said so' is not governance, it is revelation. The projects that matter are the ones building interpretability into the loop, so that the agent's decision can be challenged, not just obeyed.

Nobody Owns the Output: Inside the Agentic Token Boom and the Treasury Logic No One Audited

Fourth, and most importantly, there must be a credible exit. If the community disagrees with the agents, it must be able to revoke their authority without triggering a chain failure. In the phantom council model, there is no exit, because the deployer controls the keys. The 'community' can vote all it wants; the treasury does not move.

Measured against these four properties, the agentic sector looks very different from its pitch deck. Eleven projects pass all four. Twenty-odd pass two. The rest pass none, and yet trade at valuations that imply they pass four.

Contrarian: The Narrative Is Not the Problem β€” the Ownership Question Is

Now I want to invert the standard critique, because the standard critique is too comfortable.

The reflexive take in this market is that agentic tokens are overhyped, that the technology is not ready, that we are watching another 2021 repeat. I think that is the wrong frame, and I want to argue the contrarian position clearly: the technology is ready, the agents work, and the boom is real. The problem is not the narrative. The problem is the ownership structure, and nobody is debating it because it is harder to see than a bubble.

Here is what I mean. When people ask whether AI agents can govern, they are asking a technical question. The answer is yes, demonstrably, within narrow domains. Agents can allocate capital according to programmed risk parameters. Agents can vote on proposals using trained reward functions. Agents can execute trades faster and more dispassionately than any human committee. The demo is not a lie.

When people ask who owns the output of those agents, they are asking a political question. And the crypto industry has no answer, because the crypto industry never built the institutions to ask it. In traditional finance, ownership of algorithmic output is mediated by contracts, fiduciary duties, and courts. In crypto, ownership is mediated by whoever holds the upgrade keys. And right now, for the overwhelming majority of agentic projects, that is the founding team.

This is the blind spot. We have spent two years arguing about whether AI is conscious, whether agents can be trusted, whether the technology is safe. We have spent almost no time arguing about who owns what the agents produce β€” the treasury yield, the trading profits, the governance decisions, the intellectual output of the model itself. The narrative says these outputs belong to the community. The architecture says they belong to the deployer. The market has not noticed, because the market is pricing the narrative.

There is a deeper irony here, and it connects back to the Luna collapse in a way I only understood after building the prototype. Remember that we diagnosed Terra's failure as the hubris of 'trusted' code without social consensus β€” the belief that a mechanism could substitute for a community. Agentic tokens are repeating the error in inverted form. This time, the belief is that autonomy can substitute for accountability. We are told the agents are neutral because they are machines. But a machine with a founder's key is not neutral. It is a founder with a machine's costume.

Constructing new myths from the ashes of Luna means understanding that every mechanism eventually meets its social layer. The Terra mechanism met a market that stopped believing, and it died. The agentic mechanism will meet a market that starts asking who holds the keys, and the projects that survive will be the ones where the answer is genuinely diffuse. The ones that don't will learn, in the drawdown, that autonomy without distributed ownership is just centralization with better branding.

I will admit the counterargument, because it is strong. Early-stage technology always looks centralized; the community layer takes time to build; demanding distributed ownership at genesis may strangle the innovation. This is fair. My prototype failed for exactly this reason β€” we could not distribute ownership fast enough to keep pace with the agents' decision speed, and the system stalled under its own governance overhead. So I am not arguing for purity. I am arguing for honesty. Tell the market the agents are centralized today and decentralizing on a published schedule. Price that. Then the architecture and the narrative can finally agree.

The danger is not that the technology fails. The danger is that it succeeds β€” and the output flows to the wrong people, because nobody asked the ownership question while there was still time to answer it.

Takeaway

So here is what I am watching over the next two quarters. Not the price of agentic tokens β€” prices will do what they do, and I have no edge there. I am watching the genesis distribution of new launches. If the next cohort ships with governance supply genuinely distributed at mint, with treasury rules enforced by contracts rather than signers, and with interpretability built into the voting loop, then the narrative and the architecture are converging, and the boom has a foundation. If the next cohort ships with the same phantom council wearing the same borrowed multisig suit, then we will have learned nothing from 2022, and the correction, when it comes, will be a referendum on our willingness to read the bytecode.

The agents are not the story. The keys are the story. And the keys are still, for now, in the hands of the people who wrote the pitch deck.