THORChain x Radix Podcast #236 ft. n3xco, matthewcarano, KentonC137 & patriotsounds | September 19, 2026 | Watch the full episode on YouTube
By Raynalytics
TL;DR
- Radix co-founder Xardas argues that AI agents should be able to propose and automate actions, but a separate, verifiable security boundary must decide what they are allowed to do.
- The Radix thesis extends a lesson from crypto hardware wallets: securing a private key is not enough when an agent can access customer data, business systems, or payment permissions.
- Xardas and Matt Carano see permissionless, interoperable rails as a natural fit for agent-to-agent commerce, provided the user can set and enforce narrow, explicit authority.
- The guests framed regulation as an insufficient security answer. Their view is that it can slow independent builders while better-funded institutions continue developing AI capabilities.
- Radix is enterprise-first, with a sandbox discussed for November. A personal device is an ambition, not a product promise.
This conversation was not a product-integration announcement. It was a look at a problem that becomes more urgent as software agents move from answering questions to taking actions: who holds authority when the agent can touch money, data, and critical systems?
Matt Carano and Xardas approached that question from a crypto-native premise. The goal is not to make an AI model obedient by assumption. It is to put a smaller, independently trusted system between an agent's request and the secret, policy, or private key it wants to use.

1. From Wallet Security to AI Authority
Xardas traced Radix back through two earlier crypto experiences. At Swarm City, a Parity multisig vulnerability left the project without its funds while the wider Ethereum ecosystem rushed to protect other exposed contracts. The lesson was less about one historic exploit than about the cost of placing high-value authority on a surface that can fail.
That experience informed NGRAVE, the air-gapped hardware-wallet company he later co-founded. Its design focused on keeping signing material off an internet-connected machine and giving the user a clearer way to verify what a transaction actually does. Xardas said the work introduced him to formally verified software, where critical properties such as isolation can be established with mathematical proofs rather than inferred from testing alone.
Radix applies that lineage beyond a crypto key. The company is building a hardware-backed boundary intended to evaluate what an AI or external system is asking to do before it reaches sensitive information, business logic, or signing authority. In the guests' framing, that boundary is the part that must be trusted, not the AI model making a proposal.
"The same security thinking will need to apply to way more beyond key management." (Xardas)

2. The Trusted Boundary Must Be Separate
The central distinction was simple: an agent can be useful without receiving blanket authority. Xardas described Radix as a layer between the outside world and the secrets an organization or individual does not want exposed. An AI may ask to issue a refund, inspect data, or prepare a transaction. The boundary checks that request against pre-set rules before it is allowed through.
The guests compared the idea to a programmable hardware wallet. A conventional wallet can isolate a private key, but the policy logic that decides whether to approve an action may still live on a less trusted computer. Radix's aim is to place both the critical policy check and the protected authority in the same high-assurance environment.
That does not make every claim about AI safety settled fact. It is Radix's proposed architecture, and the trust question remains partly social: users and institutions must understand what the boundary guarantees, who defines its rules, and how those rules can be inspected. But the product thesis is concrete. Security should be enforced by a system separate from the agent requesting the action.
"You basically create a layer between information and secrets that you don't want anyone to access and the outside world or an AI." (Xardas)

3. Agentic Commerce Needs Permissionless Rails
Kenton brought the discussion back to THORChain. If a person owns a sovereign agent but still needs a third party to decide whether it can trade or transact, the promise is incomplete. The group did not announce a Radix integration, but they outlined why permissionless infrastructure could matter as agents begin interacting with services on behalf of their users.
Xardas expects the interface to shift from people navigating every website to an agent discovering what a service supports, requesting the necessary login step, and completing a permitted task. For crypto, the equivalent could be an agent preparing a swap while a user-defined policy limits the asset, size, destination, timing, or required approval. The private key remains outside the agent's reach.
This is where THORChain's existing design could be relevant. A future agent could prepare a native cross-chain request, a trusted boundary could evaluate the instruction, and THORChain Swap could execute the permitted route. That is an architectural possibility raised in the conversation, not a live Radix feature or a commitment from THORChain.
"I want my AI to talk to your systems. That's what I want." (Xardas)

4. Regulation Is Not a Security Boundary
The guests were direct about their concern with AI regulation. Matt argued that restrictions can impose the largest burden on independent developers while government agencies and entrenched companies keep access to capital, hardware, and frontier research. Xardas added that large organizations may respond to AI risk by delaying automation altogether, rather than building systems that let them automate safely.
Their argument was not that policy has no role. It was that a rulebook cannot substitute for a technical control. If an AI can act faster than a manual review loop, the important question is whether the system can reject an action that breaks a stated policy. In their view, formally verified, hardware-backed enforcement is a stronger answer than asking a model to remain aligned or relying on a patch cycle alone.
The broader claim was economic as well as philosophical. The guests believe a world that preserves the ability to build and verify independent systems will produce better solutions than one where only the largest institutions can afford to innovate. That remains a thesis, but it explains why they see crypto's permissionless culture as relevant to the AI debate.
"Innovation will come where freedom is preserved." (Xardas)

5. Enterprise First, Personal Sovereignty Later
Radix is not positioned as an all-in-one AI computer. Xardas described it as an additional security device, sitting between a machine running an agent and the sensitive systems or data the agent may request access to. It does not provide the AI model. It evaluates whether the model's proposed action fits the policy that the owner has set.
The near-term target is enterprise use, where certifications, liability, and data-access controls can create a clearer reason to adopt the technology. Xardas discussed a sandbox environment for policy configuration around November, followed by cloud deployments that still carry the physical-trust assumptions of the provider. The fullest version is on-premise hardware, where the organization controls the boundary itself.
Personal hardware is the longer ambition. The guests acknowledged the usability challenge: most people will choose convenience if sovereign tools add too much complexity. Their bet is that an agent can improve the interface, while a separate device preserves a user's ability to constrain it.
"It's literally a crypto hardware wallet on premise that is just way more programmable." (Xardas)
What to Watch
- Radix's sandbox: whether the discussed November environment gives builders a tangible way to write and test scoped policies.
- Enterprise deployment: which real-world actions, data sources, and approval rules are first supported, and how the claimed guarantees are communicated.
- Agent permissions: whether consumer AI products normalize narrow, inspectable authority instead of permanent access to wallets and sensitive accounts.
- THORChain's AI readiness: whether future builders can safely connect agent interfaces to THORChain Swap without handing an agent unrestricted signing power.

More THORChain data, check out raynalytics.net
Follow Raynalytics for more Weekly Analytics and Podcast recaps.
Related articles
![THORChain Podcast protocol update cover]()
Sep. 17, 2026
THORChain Returns to Shipping: Zcash, Monero and Self-Sufficiency
- Podcast
![Ecosystem Update Podcast with Station Wallet]()
Sep. 13, 2026
Terra’s Station Wallet Is Back as Vultisig’s Agentic THORChain Wallet
- Podcast
![Protocol Update Podcast with Chad Barraford, Kenton and Patriot / Denny]()
Sep. 10, 2026
THORChain Prioritizes Stability Before Monero and New Features
- Podcast
![Ecosystem Update Podcast with RAVN]()
Sep. 5, 2026
Inside RAVN’s Native $BTC Aggregator and Its THORChain Integration
- Podcast
![Protocol Update Podcast with Hans, Devel, Chad, Kenton & Denny]()
Sep. 3, 2026
THORChain Churns Again: POL Goes Live, Rujira Resumes and BLO Debate
- Podcast
![Ecosystem Update Podcast with Rujira]()
Aug. 29, 2026
THORChain’s App Layer Rujira Is Paused. Rujira Wants a Clear Restart Path.
- Podcast
![Protocol Update Podcast with Chad Barraford, Kenton and Denny]()
Aug. 27, 2026
THORChain Puts Stability First: Monero & Zcash Delayed, ADR30, AI Agents and Memoless Swaps
- Podcast
![Ecosystem Update Podcast with Unstoppable Wallet]()
Aug. 22, 2026
Unstoppable Wallet Adds $RUNE, $TCY and $RUJI, With a Stablecoin Wallet Next
- Podcast
![Protocol Update Podcast with Chad Barraford, Kenton and Denny]()
Aug. 20, 2026
v3.20 Voting Is Underway. Should THORChain’s TSS Library Remain Open Source?
- Podcast
![Ecosystem Update Podcast with Dash]()
Aug. 15, 2026
Inside Dash’s Zcash Orchard Upgrade and Its THORChain Potential
- Podcast
![Protocol Update Podcast with Chad Barraford, Kenton, Denny and Oleg Petrov]()
Aug. 13, 2026
THORChain is Close to v3.20: FROST, DKLS, SwapKit Rev-Share and Dynamic Fees
- Podcast
![Ecosystem Update Podcast with Morpheus]()
Aug. 8, 2026
Morpheus Maps Decentralized AI, $MOR Inference and a Planned THORChain Pool
- Podcast
![Protocol Update Podcast with Hans and Pragmatic Monkey]()
Aug. 6, 2026
Rujira and THORChain Align on the App Layer: ADR31, CCL, and the Road to Perps
- Podcast
![Ecosystem Update Podcast with Depouch]()
Aug. 1, 2026
Inside depouch: Direct THORChain Swaps Built for Simplicity
- Podcast
![Monero Gets a Soft Launch as THORChain's v3.20 Enters Testing and ADR31 Passes]()
Jul. 30, 2026
Monero Gets a Soft Launch as THORChain's v3.20 Enters Testing and ADR31 Passes
- Podcast
















