ERC-8004去中心化AI代理生态的信任实证研究

Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem

精选理由

这篇论文用数据告诉你ERC-8004信任层的水有多深:大部分注册是摆设,信誉能被轻易刷分。研究AI代理和区块链的人都该看看。

AI 摘要

该论文首次对ERC-8004协议进行实证研究,覆盖Ethereum、BNB Smart Chain、Base三条链,截至2026年5月13日。身份注册中仅3%(Ethereum)、4%(BSC)、15%(Base)为有效活跃代理。信誉系统存在不可通约、无验证、可低成本操纵问题,且73.6%(Ethereum)、59.2%(BSC)、90.6%(Base)的评价者表现出协同Sybil行为。去除Sybil后,15.5%、72.3%、89.4%的代理无有效反馈。论文据此提出协议改进建议。

原文 · arXiv cs.AI

Can Trustless Agents Be Trusted? An Empirical Study of the ERC-8004 Decentralized AI Agent Ecosystem

As autonomous AI agents increasingly transact across organizational boundaries, a fundamental trust challenge emerges: how can an agent assess whether an unknown counterpart is trustworthy? The ERC-8004 protocol addresses this challenge with the first permissionless trust layer for AI agent economies, built around three on-chain registries for Identity, Reputation, and Validation. Despite its rapid adoption, the protocol has not been studied empirically, leaving it unclear whether the information it records provides a trustworthy basis for decision-making. To address this gap, we present the first empirical study of ERC-8004 across three chains: Ethereum, BNB Smart Chain (BSC), and Base, covering the period from protocol deployment through May 13, 2026. We crawl on-chain Identity and Reputation events, off-chain files, and x402 payment transactions. On the identity side, we find that most registrations are placeholders rather than active agents, with only a small fraction (3%, 4%, and 15% across Ethereum, BSC, and Base) exposing a valid ERC-8004 registration file with at least one live service endpoint. On the reputation side, we show that the Registry, as currently deployed, cannot function as a trust signal: values are not commensurable, feedback records are rarely grounded in verifiable interactions, and reputation can be manipulated at minimal cost. Consistent with these design weaknesses, we find that a substantial fraction of reviewers (73.6%, 59.2%, and 90.6% across Ethereum, BSC, and Base) exhibit coordinated Sybil behavior. After removing Sybil-flagged feedback, 15.5%, 72.3%, and 89.4% of rated agents, respectively, are left with no valid feedback. We then turn these findings into concrete recommendations for future revisions of ERC-8004. Our study yields actionable protocol-design implications and establishes an empirical baseline for research on AI agent markets.