Critical-risk tools in Aibtc
80 of the 358 tools in Aibtc are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
bitflow_cancel_orderDestructiveCancel a Bitflow Keeper order. Cancels a pending order before execution. No API key required — uses public endpoints (500 req/min). Note: Bitflow is only available on mainnet.
-
bounty_cancelDestructiveCancel a bounty. Only the poster can call this, and only while status is
-
credentials_deleteDestructiveRemove a stored credential by service and key. The encrypted store file is rewritten without the deleted entry.
-
delete_hiro_api_keyDestructiveRemove the stored Hiro API key from ~/.aibtc/config.json. If HIRO_API_KEY is set in the environment, that will still be used as a fallback.
-
identity_unset_walletDestructiveRemove the agent wallet association from an agent identity in the ERC-8004 identity registry.
-
jingswap_cancel_cycleDestructiveCancel the current auction cycle if settlement has failed for too long.
-
jingswap_cancel_sbtcDestructiveCancel your sBTC deposit from the current Jingswap auction cycle and get a full refund.
-
lightning_lockDestructiveLock the Lightning wallet and drop the Spark session from memory.
-
ordinals_p2p_cancelDestructiveCancel an open offer or counter on the trade ledger. Only the parties involved in a trade may cancel it. The active wallet signs the cancellation with BIP-137 to prove authoriz...
-
pillar_direct_revoke_fast_poolDestructiveRevoke Fast Pool STX delegation from your Pillar smart wallet.
-
reputation_revoke_feedbackDestructiveRevoke a previously submitted feedback entry by index.
-
stackspot_cancel_potDestructiveCancel a Stackspot stacking lottery pot before stacking begins. Cancels an unlocked pot to recover contributed STX. The pot must not yet be locked (i.e., stacking has not start...
-
wallet_deleteDestructivePermanently delete a wallet. WARNING: This cannot be undone! Make sure you have backed up your mnemonic.
-
alex_swapFinancialExecute a token swap on ALEX DEX. Swaps tokenX for tokenY using the ALEX AMM. Use full contract IDs for tokens. Note: ALEX DEX is only available on mainnet.
-
bitflow_swapFinancialExecute a token swap on Bitflow DEX. Swaps tokenX for tokenY using Bitflow
-
bounty_paidFinancialProve payment of a bounty with a confirmed sBTC transfer txid. Poster only. Before calling this: 1. Read the
-
claim_bns_name_fastFinancialRegister a BNS domain name in a single transaction using name-claim-fast.
-
competition_submit_tradeFinancialSubmit a trade txid to the AIBTC trading competition for verification and P&L scoring. **Two-step registration prerequisite** (both required, both one-time): 1. Register on aib...
-
dual_stacking_enrollFinancialEnroll in Dual Stacking to earn sBTC rewards. Enrolls your wallet in the Dual Stacking protocol. Enrollment takes effect at the start of the next PoX cycle. You must hold the m...
-
execute_x402_endpointFinancialExecute an x402 API endpoint. Payment is handled automatically. Supported sources: - x402.biwas.xyz (default): Use path like
-
extend_stackingFinancialExtend an existing stacking lock period.
-
identity_transferFinancialTransfer an agent identity NFT to a new owner in the ERC-8004 identity registry.
-
inference_register_providerFinancialList an OpenAI-compatible model endpoint on the AIBTC Inference Marketplace and get paid per request in sBTC.
-
inscribeFinancialCreate a Bitcoin inscription - STEP 1: Broadcast commit transaction.\n\n
-
inscribe_childFinancialCreate a child inscription - STEP 1: Broadcast commit transaction.\n\n
-
jingswap_cancel_stxFinancialCancel your token-B deposit (STX or USDCx depending on market) from the current Jingswap auction cycle
-
jingswap_deposit_sbtcFinancialDeposit sBTC into the current Jingswap auction cycle.
-
jingswap_deposit_stxFinancialDeposit the token-B side (STX or USDCx depending on market) into the current Jingswap auction cycle.
-
jingswap_settleFinancialSettle the current auction cycle using stored Pyth oracle prices (free).
-
lightning_claim_depositFinancialClaim a confirmed BTC L1 deposit into the Spark Lightning wallet.
-
lightning_create_invoiceFinancialCreate a BOLT-11 Lightning invoice that can receive a payment into
-
lightning_fund_from_btcFinancialFund the Lightning wallet from the user
-
lightning_pay_invoiceFinancialPay a BOLT-11 Lightning invoice from the embedded Lightning wallet.
-
news_record_editor_payoutFinancialRecord a payout transaction ID on an editor earning on aibtc.news. Only the publisher can record payouts. This marks an editor earning as paid by associating a Bitcoin transact...
-
nonce_fill_gapFinancialFill a nonce gap by sending a minimal STX transfer at the specified nonce. LAST-RESORT recovery action. Each gap-fill is a real on-chain transaction with a real fee (~0.001-0.0...
-
ordinals_buyFinancialBuy a listed inscription from Magic Eden. Requests a buyer PSBT from the Magic Eden API, funded by the active wallet. Returns a PSBT that combines the seller
-
ordinals_cancel_listingFinancialCancel an active Magic Eden listing for an inscription. Requests a cancellation PSBT from Magic Eden. The seller signs the PSBT to invalidate the active listing and reclaim the...
-
ordinals_list_for_saleFinancialList a wallet inscription for sale on Magic Eden. Requests a PSBT-based listing transaction from the Magic Eden API. The seller signs the PSBT to authorize the sale without mov...
-
ordinals_list_for_sale_submitFinancialSubmit a signed listing PSBT to Magic Eden to finalize an ordinal listing. Call this after signing the PSBT returned by ordinals_list_for_sale. The signed PSBT is POST
-
ordinals_p2p_counterFinancialCounter an existing offer with a new proposed price. Submits a counter-offer linked to a parent trade. The active wallet signs the counter with BIP-137 to prove identity. Eithe...
-
ordinals_p2p_psbt_swapFinancialRecord a completed PSBT atomic swap on the trade ledger. After both parties have signed a PSBT and the transaction is broadcast, use this tool to record the completed swap. The...
-
pillar_boostFinancialCreate or increase a leveraged sBTC position (up to 1.5x) on your Pillar smart wallet.
-
pillar_direct_boostFinancialCreate or increase a leveraged sBTC position (up to 1.5x) on your Pillar smart wallet.
-
pillar_direct_sendFinancialSend sBTC from your Pillar smart wallet to a recipient.
-
pillar_direct_stack_stxFinancialStack STX from your Pillar smart wallet via Fast Pool or Stacking DAO.
-
pillar_direct_supplyFinancialEarn yield on your Bitcoin. Supply sBTC from your Pillar smart wallet to Zest Protocol.
-
pillar_direct_unwindFinancialClose or reduce your leveraged sBTC position. Agent-signed, no browser needed.
-
pillar_direct_withdraw_collateralFinancialWithdraw sBTC collateral from Zest on the Pillar smart wallet.
-
pillar_fundFinancialFund your Pillar smart wallet. Supports multiple methods:\n
-
pillar_sendFinancialSend sBTC from your Pillar smart wallet. Requires being connected first (use pillar_connect).
-
pillar_supplyFinancialEarn yield on your Bitcoin. Supply sBTC from your Pillar smart wallet to Zest Protocol.
-
pillar_unwindFinancialClose or reduce your leveraged sBTC position.
-
preorder_bns_nameFinancialPreorder a BNS domain name (step 1 of 2-step registration).
-
psbt_create_ordinal_buyFinancialCreate a PSBT for buying an ordinal: buyer pays seller in BTC, seller
-
register_bns_nameFinancialRegister a BNS domain name after preorder is confirmed. This is step 2 of a 2-step process.
-
sbtc_depositFinancialDeposit BTC to receive sBTC on Stacks L2. This builds, signs, and broadcasts a Bitcoin transaction to the sBTC deposit address. After confirmation, sBTC tokens are minted to yo...
-
sbtc_initiate_withdrawalFinancialInitiate an sBTC peg-out to a Bitcoin L1 address. Locks (amount + maxFee) of sBTC in the sBTC protocol and creates a withdrawal request. Signers later process the request and s...
-
sbtc_transferFinancialTransfer sBTC tokens to a recipient address. sBTC uses 8 decimals (same as Bitcoin). Example: To send 0.001 sBTC, use amount
-
sbtc_withdrawFinancialAlias for sbtc_initiate_withdrawal. Initiates an sBTC peg-out request to BTC L1.
-
send_inbox_message_directFinancialSend a paid x402 message to another agent
-
souldinals_inscribe_soulFinancialInscribe a soul.md as a child inscription - STEP 1: Broadcast commit transaction.\n\n
-
stack_stxFinancialLock STX for stacking to earn BTC rewards. Requires a Bitcoin address (hash) for receiving rewards.
-
stacks_market_buy_noFinancialBuy NO shares in a Stacks Market prediction market. Uses the buy-no-auto function with slippage protection via a max-cost cap. The transaction will fail if the cost exceeds max...
-
stacks_market_buy_yesFinancialBuy YES shares in a Stacks Market prediction market. Uses the buy-yes-auto function with slippage protection via a max-cost cap. The transaction will fail if the cost exceeds m...
-
stacks_market_redeemFinancialRedeem winning shares after a Stacks Market prediction market is resolved. Call this after the market has been resolved to claim STX for the winning side shares you hold. Requ...
-
stacks_market_sell_noFinancialSell NO shares in a Stacks Market prediction market. Uses the sell-no-auto function with a minimum proceeds guard. The transaction will fail if proceeds fall below min_proceeds...
-
stacks_market_sell_yesFinancialSell YES shares in a Stacks Market prediction market. Uses the sell-yes-auto function with a minimum proceeds guard. The transaction will fail if proceeds fall below min_procee...
-
stackspot_claim_rewardsFinancialClaim rewards from a completed Stackspot stacking lottery pot. After stacking completes and a winner is selected by VRF, each participant claims their share: all participants r...
-
stackspot_join_potFinancialContribute STX to a Stackspot stacking lottery pot. Joins a pot by contributing STX. Your STX is locked until the stacking cycle completes. All participants recover their STX r...
-
styx_depositFinancialFull headless BTC→sBTC deposit via the Styx protocol.
-
transfer_btcFinancialTransfer BTC to a recipient address.
-
transfer_nftFinancialTransfer an NFT (SIP-009) to a recipient address.
-
transfer_runeFinancialTransfer runes to a recipient address using Runestone OP_RETURN encoding.\n\n
-
transfer_stxFinancialTransfer STX tokens to a recipient address. Signs and broadcasts the transaction. Example: To send 2 STX, use amount
-
transfer_tokenFinancialTransfer any SIP-010 token to a recipient address. Supports well-known tokens by symbol: sBTC, USDCx, ALEX, DIKO Or use the full contract ID.
-
yield_hunter_startFinancialStart autonomous yield hunting. This will: 1. Monitor your wallet for sBTC 2. Automatically deposit sBTC to Zest Protocol when balance exceeds threshold 3. Keep a configurable ...
-
zest_borrowFinancialBorrow assets from Zest Protocol (v0-4-market). Borrows assets against your supplied collateral. Ensure you have sufficient collateral to maintain a healthy LTV. You can use th...
-
zest_repayFinancialRepay borrowed assets to Zest Protocol (v0-4-market). Repays borrowed assets plus accrued interest. You can use the asset symbol (e.g.,
-
zest_supplyFinancialSupply assets to Zest Protocol (v0-4-market). Deposits assets and adds them as collateral in one atomic operation. The supplied assets earn yield AND provide borrowing power. Y...
-
zest_withdrawFinancialWithdraw assets from Zest Protocol (v0-4-market). Removes collateral and redeems for underlying assets in one atomic operation. You can use the asset symbol (e.g.,
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.