MoonPay PayBox Lets AI Agents Pay Without Holding Your Funds

MoonPay has launched PayBox, a non-custodial payment vault that connects to Anthropic's Claude and OpenAI's ChatGPT and lets an AI agent prepare and execute crypto trades, transfers, and card purchases without ever taking control of the user's money. The product went live on July 29, 2026, and closes the last gap in conversational AI: until now an assistant could research a swap or find a restaurant, but the moment money had to move, the user was pushed out to a separate wallet, exchange, or checkout page.
A user connects PayBox to Claude or ChatGPT through a custom connector, describes the action in plain language, and approves the resulting transaction with a passkey. Requests can be as simple as onramping $100 into PYUSD, swapping tokens for SOL, bridging assets to Robinhood Chain, or booking a flight. The AI drafts the transaction; the human authorizes it; the funds move only after approval.
How does PayBox let an AI move money without holding it?
The security architecture is the core of MoonPay's pitch. Wallet keys are split using multi-party computation (MPC) across hardware-isolated secure enclaves (TEEs), so no single party, not the AI agent and not MoonPay, ever holds a complete private key or can sign a transaction alone. A compromised phone does not hand an attacker the ability to move funds, because the missing key shares are not present on any one device.
The underlying key management comes from Sodot, the Israeli infrastructure firm MoonPay acquired in April 2026 in an all-stock deal reported at roughly $100 million. Sodot's technology secures a large base of institutional wallets for clients including eToro and BitGo. MoonPay describes that base as more than $50 billion in assets across over 10 million wallets, though its own April acquisition announcement described the same figure as $50 billion in transactions rather than assets under management. The distinction matters for readers assessing scale, and the two framings should not be treated as interchangeable.
PayBox also handles conventional card payments. Card transactions route through Visa's agentic commerce protocol, so the vault can pay with a stored card without the AI ever seeing or storing the raw card number. Every passkey approval is scoped to a single action and expires after use, which is designed to defeat replayed or captured authorizations.
What can users actually do with it today?
PayBox launches with support for Solana and EVM-compatible chains including Ethereum, Hyperliquid, Tempo, Base, Robinhood Chain, Arbitrum, and Polygon. Beyond token swaps, bridging, and DeFi deposits, the vault connects to real-world commerce through x402, the payment standard for agent-initiated transactions. Initial x402 integrations cover restaurant reservations, travel bookings, and shopping across major online retailers.
The x402 detail deserves context the announcement leaves out. The standard was created inside Coinbase and, as of its operational launch on July 14, 2026, is now governed by the Linux Foundation through a vendor-neutral body with roughly 40 members. MoonPay sits among the premier members alongside Circle, Visa, Mastercard, Stripe, and Ripple. PayBox is therefore not building on a MoonPay-owned rail but plugging into shared infrastructure the largest payment and crypto firms have already agreed to back.
What are the two control modes, and where is the risk?
Every credential runs under one of two user-defined models. In Always Ask, every transaction requires a fresh passkey approval. In Autonomous, the AI can act within spending limits and rules the user sets in advance. Changing any permission requires a new human passkey approval, and access can be revoked instantly.
The residual risk sits inside the autonomous mode. An agent operating within granted limits can still execute a transaction that is technically valid but poorly judged, and onchain transfers do not reverse. MoonPay's model constrains who can move money and how much, but it does not, and cannot, guarantee the agent's judgment on any individual trade. Finance professionals evaluating the tool for treasury or trading use should read the permission model as a containment layer, not a substitute for oversight.
How does this fit MoonPay's wider agentic push?
PayBox is the latest step in a build-out MoonPay has run through most of 2026. In March the company introduced an open wallet standard for AI agents backed by PayPal, the Ethereum Foundation, and the Solana Foundation. In May it shipped an app for buying crypto inside ChatGPT, and in June a desktop app linking Claude and Codex to wallets. The pattern points to MoonPay positioning itself as the settlement layer for autonomous AI commerce rather than a single-product vendor.
MoonPay reports more than 30 million customers across 180 countries and more than 1,700 enterprise clients, and holds a New York BitLicense, a New York Limited Purpose Trust Charter, US money transmitter licenses, and MiCA authorization in the EU.
Why This Matters to FinanceX Readers
Agentic commerce is moving from concept to live infrastructure faster than most institutions have built policy for it. The competitive question PayBox raises is not whether AI agents will transact, but who owns the trust layer when they do, and MoonPay is betting that layer is non-custodial and standards-based rather than a walled garden.
For payment firms, custodians, and treasury teams, the near-term signal is that the major card networks and crypto issuers have already converged on x402 as the settlement standard, which narrows the field of viable agentic payment models considerably. The slower-moving risk is governance: autonomous spending by software agents will test existing controls, audit trails, and liability frameworks long before regulation catches up.



