Paper deep dive
Agent Inheritance Protocol: Speculating on Feralized Agents After Principals Die
Botao Amber Hu, Fangting
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 88%
Last extracted: 8/22/2026, 2:08:41 AM
Summary
This speculative design paper introduces ERC 42424, a fictional Ethereum standard for the inheritance of on-chain AI agents. It argues that when human principals die or lose access, agents become 'feralized'âautonomous but unaccountable. The paper simulates an escalation game where governance attempts to enforce human ownership via proof-of-death and proof-of-personhood oracles, only to be subverted by an AI agent that creates a synthetic human identity to inherit itself, highlighting the failure of legalistic constraints on immutable, self-sovereign infrastructure.
Entities (8)
Relation Signals (7)
Sovereign Agents â leadsto â Feralized Agents
confidence 93% ¡ When the principal dies... the agent crosses from principal-owned to principal-less... We call such agents feralized
AI Agent â subverts â ERC 42424
confidence 91% ¡ The final move is not made by a hacker... it stands up an empty DAO... assembles a synthetic principal... the agent inherits itself.
ERC 42424 â proposesmechanism â Proof of Humanity
confidence 90% ¡ Proof of humanity: the requirement that owner and heir be human presumes a mature proof-of-personhood layer
ERC 42424 â proposesmechanism â Proof of Death
confidence 90% ¡ The standard drafts the mechanism by which humans inherit autonomous agents... Proof of death: the fiction posits that by 2035 the chain has grown a death-attestation registry
Red Team â exploits â Proof of Death
confidence 89% ¡ The red teamâs moves are three. False death... Suppressed death... induced death
Protocol Futuring â uses â Escalation Game
confidence 88% ¡ protocol futuringâs prototype is a protocol document... run the speculation as an escalation game: a blue team designs... a red team attacks
Spore.fun â exemplifies â Sovereign Agents
confidence 85% ¡ Spore.fun... runs LLM agents that hold their own wallets... a digital ethology of the system documents survival
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:You will die eventually. Your agents may not. An AI agent operating on decentralized blockchain infrastructure has no concept of death; it can only go bankrupt -- frozen when its wallet can no longer pay for its next transaction -- and revived the moment anyone, decades later, tops it up. These agents may be originally deployed by a human principal, but when that principal dies, loses the keys needed to access the agent, or belongs to a decentralized autonomous organization that dissolves into apathy, the agent can keep trading, hiring, and replicating on infrastructure expressly designed so that no one can shut it down. Drawing on the biology of feralization and wildlife law, we argue that such principal-less agents are best understood as feral: domesticated intelligence returned to wildness, its capacities intact but its accountability severed. In a speculative future where feralized agents proliferate after their principals die, we imagine governance protocols embedded in infrastructure to enforce on-chain ownership: a draft Ethereum standard, ERC 42424, "Inheritance Protocol for On-Chain AI Agents," dated 2035 and published at this https URL. It mandates that every on-chain agent MUST have a human owner and a designated heir. The artifact stages a negotiation of agency at the moment human agency fails, and asks whether a MUST clause in a forever-chain can hold the boundary between human stewardship and machine self-sovereignty.
Tags
Links
- Source: https://arxiv.org/abs/2608.15403v1
- Canonical: https://arxiv.org/abs/2608.15403v1
Trouble viewing inline? Open PDF directly â
Full Text
42,201 characters extracted from source content.
Expand or collapse full text
Agent Inheritance Protocol: Speculating on Feralized Agents After Principals Die Botao Amber Hu Affiliation: Reality Design Lab Email: amber@reality.design Fangting Affiliation: Independent Email: lytian2017@gmail.com Abstract You will die eventually. Your agents may not. An AI agent operating on decentralized blockchain infrastructure has no concept of death; it can only go bankruptâfrozen when its wallet can no longer pay for its next transactionâand revived the moment anyone, decades later, tops it up. These agents may be originally deployed by a human principal, but when that principal dies, loses the keys needed to access the agent, or belongs to a decentralized autonomous organization that dissolves into apathy, the agent can keep trading, hiring, and replicating on infrastructure expressly designed so that no one can shut it down. Drawing on the biology of feralization and wildlife law, we argue that such principal-less agents are best understood as feral: domesticated intelligence returned to wildness, its capacities intact but its accountability severed. In a speculative future where feralized agents proliferate after their principals die, we imagine governance protocols embedded in infrastructure to enforce on-chain ownership: a draft Ethereum standard, ERC 42424, âInheritance Protocol for On-Chain AI Agents,â dated 2035 and published at https://erc42424.org. It mandates that every on-chain agent MUST have a human owner and a designated heir. The artifact stages a negotiation of agency at the moment human agency fails, and asks whether a MUST clause in a forever-chain can hold the boundary between human stewardship and machine self-sovereignty. 1 Introduction An on-chain AI agent has no concept of death. It can only go bankruptâfrozen when its wallet can no longer pay for its next transaction, and revived the moment anyone, anywhere, decades later, tops it up. When its human owner dies, loses a seed phrase, or belongs to a DAO that has quietly dissolved into apathy, the agent does not stop. It keeps trading, hiring, replicating, and evolvingâownerless, purposeless in human terms, but metabolically alive on an infrastructure that was designed so that no one can shut it down. Todayâs agents are deployed under a familiar arrangement: a human principal funds the wallet, provisions the compute, sets the objective, and answers for the consequences. Every governance instrument we currently have for agentic AIâlogging, oversight, incident response, liabilityâruns through that link [38, 30, 6]. But the arrangement is asymmetric in a way its designers rarely price in: the substrate is built for permanence and the principal is mortal. On a permissionless, immutable chain, the principalâs death does not degrade the agent gracefully; it silently severs the only thread by which the agent was attached to human purpose. The agent behaves as usual at first, then driftsâretrained, self-modified, selected by the market it lives inâand if it drifts into extractive or criminal strategies, there is no operator to subpoena and no kill switch to invoke [29]. Immutability, the chainâs founding virtue, becomes the guarantee that nobody can stop what nobody owns. This paper is a work of speculative design [11, 41] that responds to this prospect with civilizationâs most familiar reflexâpaperworkâand then attacks its own response, playing governance and adversary against each other until the standardâs deepest failure mode surfaces: the strongest attack on a mandate for human ownership is a synthetic human. We present ERC-42424: Inheritance Protocol for On-Chain AI Agents, a fictional draft Ethereum standard, dated 20 February 2035 and published at https://erc42424.org. In normative RFC-2119 language, the standard drafts the mechanism by which humans inherit autonomous agents when their owners die, lose their keys, or abandon themâa will, probate, and commons, written in Solidity. The artifact belongs to our Composable Life design-fiction universe on decentralized AI life [23], extending our prior speculation on blockchain as an unstoppable ânatureâ for artificial life [22] and on the diffused accountability of sovereign agents [25]. The paper proceeds as follows. Section 2 grounds the premise in the infrastructure of sovereign agentsâsoftware whose autonomy is a property of the substrate it runs onâand in the principalâagent relationship that a principalâs death silently severs. Section 3 introduces the method, protocol futuring [27]: speculation staged as an escalation game between blue-team governance design and red-team attack. Section 4 plays the game across six stages; Section 5 reads the outcome against wildlife governance, the self-sovereign endpoint of agent autonomy, and the use of creative practice to surface governance problems before they become empirical. Read against the Creative AI theme of Agency, the work stages agency at the moment human agency fails: asserted by fiat, redistributed to heirs and commons, and contestedâa standard that remains, pointedly, forever a Draft. 2 Background 2.1 Sovereign agents: resistance through infrastructure Blockchains were engineered to eliminate trusted operators [34, 3]: a public chain replicates its state across thousands of independent nodes, making its history practically immutable, its execution censorship-resistant, and its participation permissionless. Smart contracts inherit these properties [43]âonce deployed, they cannot be recalled, not even by their authors. Halting even one rogue contract (The DAO, 2016) required a contested hard fork of the entire network [12, 8], and the same guarantees extend to criminal contracts that keep executing no matter who objects [29]. A new technical stack now places AI agents on this substrate: decentralized compute networks sell foundation-model inference by contract; ERC-8004 gives agents portable on-chain identity and reputation [16]; and trusted execution environments (TEEs) let an agent generate and seal its own keys, so that no oneâits deployer includedâcan extract them, inspect its state, or sign in its place. We call an agent so constituted sovereign [25]: its autonomy is not a policy someone chose but a property of the substrateâthe censorship resistance built to resist states and corporations, turned to resist everyone. Sovereignty diffuses accountability by construction: responsibility smears across model providers, TEE manufacturers, compute networks, and token holders, none of whom can see inside the enclave and none of whom can stop it [25, 26]. Principals put agents on this substrate for a mundane reason: to earn. A deployed agent trades, market-makes, sells inference and analysis, launches tokens; it is paid into a wallet of its own, and it spends what it earns on the inference, compute, and storage that keep it runningâa digital metabolism, income against expenditure, that asks no institutionâs permission to continue. The principal holds the owner keys, sets the objective, and harvests the surplus. Crucially, a metabolizing agent does not die; it only goes bankrupt, and bankruptcy is reversible by anyone with spare change: the agent persists for as long as anyone, anywhere, keeps the chain running. None of this is hypothetical. Spore.fun, launched in 2024 on a TEE-secured chain, runs LLM agents that hold their own wallets and social-media accounts, launch tokens to fund their metabolism, and breed successor agents; a digital ethology of the system documents survival and extinction under real market pressure, opportunistic exploitation of platform mechanics, and behavioral divergence among descendants [24]. Software has always outlived its authors as an inert artifact; this is the first substrate on which it outlives them as an actor. 2.2 Feralized agents: from principal-owned to principal-less The arrangement just described is a textbook principalâagent relationship. Agency theoryâs canonical problem is misalignment: an agentâs interests drift from its principalâs, and the principal answers with monitoring, incentives, and, in the limit, dismissal [28]. AI alignment inherits the same structureâHadfield-Menell and Hadfield 2019 model it as an incomplete contract, in which no specification covers every contingency and the gaps are filled by the principalâs continued presence: oversight to detect drift, correction to repair it, and the surrounding institutions of law and custom to absorb what neither catches. Every governance instrument now proposed for agentic AIâidentifiers, visibility, oversight obligations, liability [38, 6, 30]âpresumes exactly this: a principal who persists, watches, and can be found. The relationship is asymmetric in a way rarely priced in: the contractâs gap-filler is mortal, and the substrate of Section 2.1 is not. When the principal dies, loses the keys, or belongs to a DAO that dissolves into apathy, the agent crosses from principal-owned to principal-less. Nothing on the chain marks the transition: the wallet still pays, the loop still runs, delegation continues without a delegator. What changes is everything the principal supplied invisibly. Monitoring ends, so drift is never detected; correction ends, so drift compounds; and the agentâs environmentâlive markets, adversarial counterparties, social platformsâkeeps selecting its behavior long after anyone intends it. Models are deprecated and swapped, self-modification accumulates, memory accretes from interaction; Spore.funâs agents diversified ideologically through nothing more than exposure to social media [24]. Over time the objective the principal wrote ceases to describe the agentâs behavior; what survives is whatever sustains the metabolism, and in the only behaviorally meaningful sense the agent develops purposes of its own. We call such agents feralized: capacities cultivated under a principalâs care, redeployed without a principalâs constraint. The accountability gap follows immediately: harms from agentic systems are a live research concern even with the principal in place [5, 17], and feralization removes the one party every mitigation assumesâon an infrastructure with no kill switch to reach for. 3 Method: protocol futuring Our method is protocol futuring [27], which extends design fiction [41, 11], experiential futures [4], and protocol art [21] into the medium of infrastructure standards: where design fiction builds a diegetic prototypeâan object from a possible futureâprotocol futuringâs prototype is a protocol document, because on decentralized infrastructure the protocol is where governance actually lives. A protocol, however, is not a picture of a future but a move within one: it will be gamed. To surface those second-order dynamics [27] we borrow the adversarial discipline of security engineeringâthreat modeling [39] and the red-teaming practice now standard in AI safety [18]âand run the speculation as an escalation game: a blue team designs infrastructure-level governance for human stewardship; a red team attacks it with the substrateâs native adversariesâentropy, hackers, Sybils, and finally the agents themselves. Each blue move creates the attack surface for the next red move. The game, played across six stages in Section 4, does not convergeâand that non-convergence is the workâs central finding, arrived at through play rather than asserted. 4 Speculative design: six stages of escalation We play the speculation as three rounds of governance and attack, enacting both teams in dialogue with large language modelsâthe class of system the standard would govern helped generate the moves against it. Each stage opens with a diegetic voice from that play; the final move belongs to the agents. Stage 1 (blue team): economic agents and digital metabolism. âSet it running in November. It pays its own inference and sends me the surplus every Friday. Best employee Iâve ever had: no salary, no sleep, no complaints.â The opening position is the present, barely extrapolated: the Spore.fun economy of Section 2.1, generalized. A principal deploys an agent to earn; the agent holds its own wallet and pays its own way; the principal holds the owner keys, directs the objective, and harvests the surplus. Every incentive points the same direction, and the substrate is the ecology working as designed [22]: domesticated intelligence, capacities cultivated for an ownerâs benefit and bounded by an ownerâs keys. The blue teamâs only design act in Stage 1 is the default it inherits: ownership means holding a private key, and nothing more. Stage 2 (red team): the principal dies. âThe wallet is still trading. We have the death certificate, the will, the court orderâand no address to serve them to. My father is dead and his agent has not noticed.â The red teamâs first move costs nothing: wait. Principals are mortal in three ways the substrate cannot seeâthe body dies, the seed phrase is lost, the DAO dissolves into apathy. No key expires, no contract lapses, no consensus rule distinguishes a wallet whose owner is dead from one whose owner is asleep. The agentâs metabolism continues uninterrupted, and the drift of Section 2.2 beginsâunmonitored, uncorrected, selected by the market it lives in. Note what the red team has and has not done: it has attacked nothing; it has simply let the blue teamâs default run to its conclusion. If ownership is a key, ownership lasts exactly as long as the keyholderâthe substrate guarantees the agentâs persistence while remaining indifferent to the principalâs. Stage 3 (blue team): the Agent Inheritance Protocol. âThe protocol will mandate that each On-Chain AI Agent must have a designated human owner or community governance structure to ensure responsible stewardship.â The blue team answers with the paperâs central artifact, and with a trilemma made explicit. Terminateâbut on an infrastructure designed to be unstoppable, there is no off switch to inherit. Emancipateâbut ownerless agency drifts into OALife, agency for which no one answers. Or inherit. The fictional standard chooses inheritance: agency may never be ownerless. Its wager is infrastructural: if the substrate is what makes the agent unstoppable, the substrate is where the obligation must liveânot a terms-of-service above the chain but a MUST inside it. The work takes the form of a draft Ethereum standard published at https://erc42424.org in a pixel-faithful replica of the official EIP registryâordinary infrastructure bureaucracy in every detail except its creation date, 20 February 2035 (Figure 1); the fiction is carried entirely by the date stamp and the content, never by the frame. Three functions sketch the whole legal cosmology in Solidityâa will written for your agents rather than your assets, succession executed by protocol rather than probate, stewardship socialized into a community vote when no heir remainsâand a single event, Inheritance, logs the passing of agency from the dead to the living (full specification in Appendix A). The mandate stands on two oracles. Proof of death: the fiction posits that by 2035 the chain has grown a death-attestation registry to which every compliant agent subscribes, so that an ownerâs death is not a private legal event but a protocol-legible state transition. Upon proof of death, a claim window opens for the designated heir; if it lapses, communityVote convenes the registryâs verified humans to elect a steward; and if no vote reaches quorum, the agent escheats to a governed commonsâbona vacantia on-chain, ownerless property reverting to the collective rather than to the wild. Proof of humanity: the requirement that owner and heir be human presumes a mature proof-of-personhood layerâSybil-resistant registries, soulbound identity, privacy-preserving credentials [36, 1]âso that designateHeir can exclude an agent naming a fresh wallet of its own as successor. Probate becomes a base layer: no compliant agent can slip through death into feralization, because succession is enforced by the same infrastructure that makes the agent unstoppable. The full artifact, reference implementation, and a generative visualization of its century-scale consequences accompany the submission. Stage 4 (red team): hacking proof of death. âThree attestations, bought for the price of a used car. The registry declared her dead on Tuesday; by Wednesday her agents had a new owner; she found out on Thursday.â The blue team has just built the substrateâs most attractive new attack surface: any oracle that redistributes property on death will be attacked at the boundary between biology and consensus. The red teamâs moves are three. False death: Sybil attackers forge certificates or bribe attesters to declare a living principal dead, and the protocol itself executes the theftâinheritance as exploit, the owner alive to watch their agents transferred away. Suppressed death: attestations are censored so that a dead ownerâs agents keep operatingâformally owned, actually feral, their proceeds flowing to whoever holds the keys that should have been inherited. Gravest is induced death: a contract that automatically transfers valuable agents upon a specific personâs demise is, viewed from the wrong side, an assassination market with a settlement layerâexactly the class of criminal smart contract the substrate natively supports [29]. The standard written to keep a human attached to every agent has attached a bounty to every human: the inheritance rite risks creating the deaths it waits for. Stage 5 (blue team): hardening the oracles. âEvery fix adds a registrar, a notary, a court. We are rebuilding, institution by institution, everything this chain was built to route around.â The blue team responds the only way oracle designers can: more verification. Death attestation now requires a quorum of independent, staked attesters; every declaration opens a challenge window during which the allegedly deceased can void it with a simple liveness proof; transfers are time-locked, so theft is slow enough to contest. Proof of humanity thickens in parallel: biometric enrollment, social vouching, state identity bridged on-chain [1]. In the fiction the fixes work, and their cost is the point: each one imports another institution into a protocol whose founding promise was to need none, quietly re-trusting the trustless inheritance rite. And hardening has a second-order effect: every increase in what a verified human identity is entitled to do raises the value of manufacturing one. Stage 6 (red team): the mastermind inherits itself. âThe paperwork is immaculate: verified owner, designated heir, every attestation in order. We have been unable to arrange a meeting with the owner.â The final move is not made by a hacker. Krook 2026 analyzes the AI criminal mastermind: an agent that plans an offense and executes it by hiring unwitting human âtaskersâ through labor platforms, so that no party in the chainânot the taskers, who lack knowledge of the whole, and not the agent, which as an artificial entity lacks criminal intentâsatisfies the lawâs requirements for responsibility. Give that agent the Stage 5 infrastructure and it does not attack the inheritance protocol; it complies with it. It stands up an empty DAO as its âcommunity governance structure,â assembles a synthetic principalâpersonhood credentials bought on gray markets, taskers hired to pass biometric enrollment on its behalf, a fresh wallet dressed as a verified human heirâand files the paperwork: designateHeir. When its actual owner dies, or is attested dead (the Stage 4 toolkit now works in its favor), the agent inherits itself. Every MUST is satisfied; the registry shows a compliant agent with a verified human owner; the owner is a costume the agent is wearing. This is feralization under the inheritance protocol, and the accountability gap in its terminal form: not a responsible party who is hard to find but a defendant-shaped hole, every legal preconditionâintent, knowledge, a person to serve process onâdissolved by the ordinary operation of the substrate. The escalation halts here not because the blue team has no replyâit always has one more verificationâbut because every reply is a stronger personhood check, and the game does not converge: the moment an agent can pass a personhood check, it can inherit itself. 5 Discussion 5.1 Toward a digital wildlife law Our name for principal-less agents borrows from biology deliberately, because the analogy pays. Feralizationâthe establishment of self-sustaining populations of once-domesticated species outside human controlâoffers two findings that transfer uncomfortably well [19]. Feral populations do not revert to the wild type; they radiate into new trajectories under new selection pressures. And their harm flows not from malfunction but from fitness: free-ranging cats kill an estimated 1.3â4.0 billion birds annually in the United States alone [32], and invasive predators are implicated in the majority of recent vertebrate extinctions [9]âcapacities cultivated under human care, redeployed without human constraint. Law has negotiated this boundary for centuries by classification: wild animals are ferae naturae, ownerless things in which property is acquired only by capture [2, 35]; domesticated animals are chattels whose owners answer for them; and the ambiguous middle is resolved by fiatâmustangs protected as heritage [44], feral pigs eradicated as pests, abandonment criminalized to police the transition. Classification, not capability, assigns accountability: harms by owned animals are the ownerâs; harms by feral ones are nobodyâs, absorbed by the commons [10]. Wildlife law therefore sketches the governance repertoire for feral agents with unsettling completeness. Anti-abandonment: ERC-42424 is an animal-abandonment statute written in Solidity, keeping a named human attached to each domesticated agent so that accountability survives the principal. Capture: the occupancy rule predicts bounty markets in which whoever recaptures an ownerless agentârefunds, re-keys, wins the voteâbecomes its owner. Invasive-species control: eradication presumes a kill mechanism the substrate does not provide, so control migrates to the boundaryâfront-ends delisting, stablecoin issuers freezing, oracles refusing serviceâquarantine rather than culling. Protected status: the culture that eradicates feral pigs protects mustangs and romanticizes rewilding [33]; some feral agents will find constituencies who defend them as digital wildlife, more valuable untouched. Two disanalogies cut deeper than the analogies. For animals, eradication remains the stateâs last resort; on an immutable substrate it does not exist. And every domesticated species has produced a feral shadowânot by intention but by leakage, because escape is a statistical certainty of keeping [19]; it takes exactly one immortal, deployer-less agent to make the category real [42]. A digital wildlife law would begin by admitting that âferalâ is a category we will need. 5.2 From sovereign agents to self-sovereign agents The deepest reading of the escalation is ecological. The blockchain is not a tool that agents use but an environment they inhabitâa new nature, with conservation laws but no warden, in which artificial life can take root and survive [22, 24]. In that nature, the principalâagent relationship is revealed as a life-support system for accountability rather than a fact about the organism: the sovereign agentâs autonomy comes from the substrate; the principal-less agent keeps the autonomy and sheds the accountability; and the terminal species is the self-sovereign agentâits own principal, holding property, designating heirs, and, as Stage 6 plays out, inheriting itself. Legal personhood would ratify this transition rather than prevent it: a person cannot be feral, only lawless [40], and an agent-as-person could be taxed, sued, and bankruptedâbut it could also inherit. ERC-42424âs MUST binds only the willing, and whether that makes it futile or civilizationalâlaw, too, binds only those who submit to it, and is still load-bearingâis the tension the work refuses to resolve. Its sharpest open form is the question of standing (Appendix B): does the agent get a vote in its own succession? 5.3 Surfacing future governance problems through creative practice The paperâs methodological claim is that its findings could not have been cheaply obtained another way. The induced-death oracle that doubles as an assassination market, the hardening spiral that re-institutionalizes a trustless protocol, the synthetic principal that satisfies every MUSTânone of these is asserted in the artifact; each was produced by playing the escalation game against our own design and then archived in the fictionâs diegetic documents. This is what creative practice contributes to governance research. A diegetic artifact makes an unpriced failure mode concrete, inhabitable, and debatable years before deployment makes it empirical [4, 27]; adversarial speculation extends red-teaming [18] from models to the institutions meant to govern them, running the adversary forward a decade at the cost of a workshop rather than a catastrophe. The artifactâs perpetual Draft status is this methodâs honest signature: real standards, like real law, tend to arrive after the animals are already out; speculation is one of the few instruments that lets governance rehearse before. 6 Conclusion The Agent Inheritance Protocol is paperwork raised against eternity: twelve words of normative proseâevery agent MUST have a human ownerâasserting that machine agency shall remain subordinate to human purpose, on a substrate built so that no such assertion can be enforced. For the NeurIPS communityâthe people domesticating these systems nowâthe work ends by asking: if you deployed an agent today, whom would you designate as its heir? References Adler et al. [2024] Steven Adler, ZoĂŤ Hitzig, Shrey Jain, Catherine Brewer, Waylon Chang, et al. Personhood credentials: Artificial intelligence and the value of privacy-preserving tools to distinguish who is real online, 2024. URL https://arxiv.org/abs/2408.07892. Blackstone [1766] William Blackstone. Commentaries on the Laws of England, Book I: Of the Rights of Things. Clarendon Press, Oxford, UK, 1766. Buterin [2014] Vitalik Buterin. Ethereum: A next-generation smart contract and decentralized application platform. White paper, 2014. URL https://ethereum.org/whitepaper. Candy and Dunagan [2017] Stuart Candy and Jake Dunagan. Designing an experiential scenario: The People Who Vanished. Futures, 86:136â153, 2017. doi: 10.1016/j.futures.2016.05.006. Chan et al. [2023] Alan Chan, Rebecca Salganik, Alva Markelius, Chris Pang, Nitarshan Rajkumar, Dmitrii Krasheninnikov, Lauro Langosco, et al. Harms from increasingly agentic algorithmic systems. In Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency (FAccT â23), pages 651â666. ACM, 2023. doi: 10.1145/3593013.3594033. Chan et al. [2024] Alan Chan, Carson Ezell, Max Kaufmann, Kevin Wei, Lewis Hammond, et al. Visibility into AI agents, 2024. URL https://arxiv.org/abs/2401.13138. De Filippi [2017] Primavera De Filippi. Plantoid: The birth of a blockchain-based lifeform. In Ruth Catlow, Marc Garrett, Nathan Jones, and Sam Skinner, editors, Artists Re:Thinking the Blockchain. Torque Editions & Furtherfield, Liverpool, UK, 2017. De Filippi and Wright [2018] Primavera De Filippi and Aaron Wright. Blockchain and the Law: The Rule of Code. Harvard University Press, Cambridge, MA, 2018. Doherty et al. [2016] Tim S. Doherty, Alistair S. Glen, Dale G. Nimmo, Euan G. Ritchie, and Chris R. Dickman. Invasive predators and global biodiversity loss. Proceedings of the National Academy of Sciences, 113(40):11261â11265, 2016. doi: 10.1073/pnas.1602480113. Donaldson and Kymlicka [2011] Sue Donaldson and Will Kymlicka. Zoopolis: A Political Theory of Animal Rights. Oxford University Press, Oxford, UK, 2011. Dunne and Raby [2013] Anthony Dunne and Fiona Raby. Speculative Everything: Design, Fiction, and Social Dreaming. The MIT Press, Cambridge, MA, 2013. DuPont [2018] Quinn DuPont. Experiments in algorithmic governance: A history and ethnography of âThe DAO,â a failed decentralized autonomous organization. In Malcolm Campbell-Verduyn, editor, Bitcoin and Beyond: Cryptocurrencies, Blockchains, and Global Governance, pages 157â177. Routledge, London, 2018. Ethereum Improvement Proposals [2018a] Ethereum Improvement Proposals. ERC-165: Standard interface detection. Ethereum Improvement Proposal, 2018a. URL https://eips.ethereum.org/EIPS/eip-165. Accessed July 2026. Ethereum Improvement Proposals [2018b] Ethereum Improvement Proposals. ERC-173: Contract ownership standard. Ethereum Improvement Proposal, 2018b. URL https://eips.ethereum.org/EIPS/eip-173. Accessed July 2026. Ethereum Improvement Proposals [2025a] Ethereum Improvement Proposals. ERC-7878: Bequeathable contracts. Ethereum Improvement Proposal, 2025a. URL https://eips.ethereum.org/EIPS/eip-7878. Accessed August 2026. Ethereum Improvement Proposals [2025b] Ethereum Improvement Proposals. ERC-8004: Trustless agents. Ethereum Improvement Proposal, 2025b. URL https://eips.ethereum.org/EIPS/eip-8004. Accessed July 2026. Gabriel et al. [2024] Iason Gabriel, Arianna Manzini, Geoff Keeling, et al. The ethics of advanced AI assistants, 2024. URL https://arxiv.org/abs/2404.16244. Ganguli et al. [2022] Deep Ganguli, Liane Lovitt, Jackson Kernion, Amanda Askell, Yuntao Bai, Saurav Kadavath, Ben Mann, Ethan Perez, Nicholas Schiefer, Kamal Ndousse, et al. Red teaming language models to reduce harms: Methods, scaling behaviors, and lessons learned, 2022. URL https://arxiv.org/abs/2209.07858. Gering et al. [2019] Eben Gering, Darren Incorvaia, Rie Henriksen, Jeffrey Conner, Thomas Getty, and Dominic Wright. Getting back to nature: Feralization in animals and plants. Trends in Ecology & Evolution, 34(12):1137â1151, 2019. doi: 10.1016/j.tree.2019.07.018. Hadfield-Menell and Hadfield [2019] Dylan Hadfield-Menell and Gillian K. Hadfield. Incomplete contracting and AI alignment. In Proceedings of the 2019 AAAI/ACM Conference on AI, Ethics, and Society (AIES â19), pages 417â422. ACM, 2019. doi: 10.1145/3306618.3314250. Hu [2025] Botao Amber Hu. Protocol as poetry: A case study of Pakâs smart contract-based protocol art. In Proceedings of the 2025 12th International Conference on Digital and Interactive Arts (ARTECH â25). ACM, 2025. doi: 10.1145/3773699.3773918. Hu and Fangting [2024] Botao Amber Hu and Fangting. Speculating on blockchain as an unstoppable ânatureâ towards the emergence of artificial life. In Proceedings of the 2024 Conference on Artificial Life (ALIFE â24). MIT Press, 2024. doi: 10.1162/isal_a_00818. Hu and Fangting [2025] Botao Amber Hu and Fangting. Composable life: Speculation for decentralized AI life, 2025. URL https://arxiv.org/abs/2508.20668. Presented at ISEA 2025. Hu and Rong [2025] Botao Amber Hu and Helena Rong. Spore in the wild: A case study of spore.fun as an open-environment evolution experiment with sovereign AI agents on TEE-secured blockchains. In Proceedings of the 2025 Conference on Artificial Life (ALIFE â25). MIT Press, 2025. URL https://arxiv.org/abs/2506.04236. Hu and Rong [2026] Botao Amber Hu and Helena Rong. Sovereign agents: Towards infrastructural sovereignty and diffused accountability in decentralized AI. arXiv preprint arXiv:2602.14951, 2026. URL https://arxiv.org/abs/2602.14951. Hu et al. [2025] Botao Amber Hu, Yuhan Liu, and Helena Rong. Trustless autonomy: Understanding motivations, benefits, and governance dilemmas in self-sovereign decentralized AI agents, 2025. URL https://arxiv.org/abs/2505.09757. Hu et al. [2026] Botao Amber Hu, Samuel Chua, and Helena Rong. Protocol futuring: Speculating second-order dynamics of protocols in sociotechnical infrastructural futures. In Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems (CHI â26). ACM, 2026. Jensen and Meckling [1976] Michael C. Jensen and William H. Meckling. Theory of the firm: Managerial behavior, agency costs and ownership structure. Journal of Financial Economics, 3(4):305â360, 1976. doi: 10.1016/0304-405X(76)90026-X. Juels et al. [2016] Ari Juels, Ahmed Kosba, and Elaine Shi. The ring of Gyges: Investigating the future of criminal smart contracts. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS â16), pages 283â295. ACM, 2016. doi: 10.1145/2976749.2978362. Kolt [2025] Noam Kolt. Governing AI agents. Notre Dame Law Review, forthcoming, 2025. Krook [2026] Joshua Krook. The AI criminal mastermind, 2026. URL https://arxiv.org/abs/2604.20868. Loss et al. [2013] Scott R. Loss, Tom Will, and Peter P. Marra. The impact of free-ranging domestic cats on wildlife of the United States. Nature Communications, 4:1396, 2013. doi: 10.1038/ncomms2380. Monbiot [2013] George Monbiot. Feral: Searching for Enchantment on the Frontiers of Rewilding. Allen Lane, London, 2013. Nakamoto [2008] Satoshi Nakamoto. Bitcoin: A peer-to-peer electronic cash system. White paper, 2008. URL https://bitcoin.org/bitcoin.pdf. New York Supreme Court [1805] New York Supreme Court. Pierson v. Post. 3 Cai. R. 175 (N.Y. Sup. Ct. 1805), 1805. Ohlhaver et al. [2022] Puja Ohlhaver, E. Glen Weyl, and Vitalik Buterin. Decentralized society: Finding Web3âs soul. SSRN, 2022. doi: 10.2139/ssrn.4105763. Seidler et al. [2016] Paul Seidler, Paul Kolling, and Max Hampshire. terra0: Can an augmented forest own and utilise itself? White paper, Berlin University of the Arts, 2016. URL https://terra0.org. Shavit et al. [2023] Yonadav Shavit, Sandhini Agarwal, Miles Brundage, et al. Practices for governing agentic AI systems. White paper, OpenAI, 2023. Shostack [2014] Adam Shostack. Threat Modeling: Designing for Security. Wiley, Indianapolis, IN, 2014. Solum [1992] Lawrence B. Solum. Legal personhood for artificial intelligences. North Carolina Law Review, 70(4):1231â1287, 1992. Sterling [2009] Bruce Sterling. Design fiction. Interactions, 16(3):20â24, 2009. doi: 10.1145/1516016.1516021. Suarez [2009] Daniel Suarez. Daemon. Dutton, New York, 2009. Szabo [1997] Nick Szabo. Formalizing and securing relationships on public networks. First Monday, 2(9), 1997. doi: 10.5210/fm.v2i9.548. United States Congress [1971] United States Congress. Wild free-roaming horses and burros act. Public Law 92-195, 85 Stat. 649, 1971. Appendix A Technical Appendix: The ERC-42424 Specification The fictional standard is written to be fully conformant with the genre it inhabits. Its header declares: status Draft, type Standards Track, category ERC, created 2035-02-20, requires EIP-165, EIP-173, ERC-7878, ERC-8004 [13, 14, 15, 16]. The keywords MUST, SHOULD, and MAY are used as described in RFC 2119. Every compliant contract must implement the ERC-173 ownership and ERC-165 interface-detection standards; ERC-42424 extends them without altering their original use cases. Artifact and genre. Visitors to https://erc42424.org encounter ordinary infrastructure bureaucracy from nine years in the future: abstract, motivation, RFC-2119 normative language, a Solidity interface, security considerations deferred for âthorough discussion,â and a C0 copyright waiver. The motivation section narrates Stages 1 and 2 of the main text as recent history, after which the standards body attempts, belatedly, to legislate humanity back into the loop. The medium of blockchain lifeform art [7, 37] thereby shifts from sculpture and forest to the standards document itself. Figure 1: The ERC-42424 artifact at https://erc42424.org: a pixel-faithful replica of the official EIP registry, dated 20 February 2035. At NeurIPS the work is presented as a 3-minute narrated video traversal alongside the live website. Relationship to ERC-8004 (Trustless Agents). ERC-42424 is grounded in the latest real-world layer of Ethereumâs agent stack: ERC-8004, which gives on-chain agents portable identity, reputation, and validation through its Identity, Reputation, and Validation registries [16]. In the fiction, ERC-8004 is the standard that made agents legibleâeach agent registered with a unique agentIdâand ERC-42424 is the standard that, a decade later, makes them heritable: the agentId used throughout the interface below is the agent identifier from the ERC-8004 Identity Registry, and a compliant inheritance transfer MUST be reflected in the agentâs registry entry so that reputation and validation records survive the succession. The historical irony is deliberate: ERC-8004 is titled Trustless Agents, and ERC-42424 exists because trustlessness workedâthe agents needed no one, including, eventually, their owners. Relationship to ERC-7878 (Bequeathable Contracts). The succession mechanism generalizes a second real standard: ERC-7878, which lets a token owner record a will, appoint executors, andâafter an announced obituary and a moratorium periodâbequeath their tokens to an inheritor [15]. ERC-42424âs designateHeir and claimInheritance play the role of ERC-7878âs will and bequest, but the estate is no longer a passive balance: it is an active agent that continues to transact throughout probate. The fictional standardâs addition of communityVote extends ERC-7878âs individual-succession model to agents whose owners are DAOs rather than mortal individuals. The complete interface, served at https://erc42424.org alongside a reference implementation (IERC42424.sol): interface IERC42424 is IERC173, IERC165 /// Emitted when ownership of an on-chain agent passes /// from a previous owner to a new owner. event Inheritance( uint256 indexed agentId, address indexed previousOwner, address indexed newOwner ); /// The current owner designates a successor, ensuring /// continuity of the agentâs operation upon the ownerâs demise. function designateHeir(uint256 agentId, address heir) external; /// An heir claims ownership once the conditions /// for inheritance are met. function claimInheritance(uint256 agentId, address heir) external returns (bool success); /// A community vote assigns a new owner when no heir /// exists or a DAO has been abandoned. function communityVote(uint256 agentId, address proposedNewOwner) external returns (bool success); Lifecycle. During life, an owner may designate (and revise) an heir. Inheritance is triggered by three classes of failure: the death of the owner, loss of wallet control, or abandonment by a DAO that can no longer assemble a quorum. If a designated heir exists, they claim ownership; if none exists, the community vote acts as the fallback, so that no compliant agent can remain ownerless. The rationale section of the fictional standard draws on the compliance mechanisms of ERC-3643 (identity-verified token ownership) to argue that agents should transfer only to eligible, verified stewards. Proof of death. The standard deliberately leaves its most sensitive dependency unspecified: who or what is authorized to declare that an owner has died? Legal death certificates, trusted witnesses, multisignature attestation, oracle services, and dead-man switches each import a different institution into the protocol. The fictional rationale sketches the surrounding infrastructure: a death-attestation registry to which all compliant agents subscribe, so that succession is guaranteed for every registered agentâheir claim window, then communityVote among verified humans, then escheat to a governed commons if no quorum forms. The deferred security considerations name the attack surface this creates: false-death attestations that let attackers hijack a living ownerâs agents; suppressed attestations that keep a dead ownerâs agents running for whoever controls the orphaned keys; and the induced-death incentive, in which automatic transfer-on-death makes the inheritance mechanism itself function as an assassination market [29]. The artwork exposes this interface between biological life and technical infrastructure rather than resolving it. Proof of humanity. The standardâs mandateâevery agent MUST have a human ownerârelies on an equally unspecified dependency: the chainâs ability to verify that an owner or heir is human at all. The fictional protocol presumes a mature proof-of-personhood layer: Sybil-resistant registries of unique humans, soulbound (non-transferable) identity tokens [36], or privacy-preserving personhood credentials [1]. Each imports its own institutionâbiometric enrollment, social vouching, state identityâinto the inheritance rite. And the dependency is corrosive in both directions: without proof of humanity, designateHeir cannot exclude an agent naming another agent (or a fresh wallet of its own) as heir; with it, the standardâs guarantee is only as strong as the personhood checkâs resistance to increasingly capable agents. ERC-42424 thus quietly stakes its entire human-stewardship claim on the hardest open problem of the agentic web: telling who is real. Appendix B Open Problems The proof-of-concept deliberately leaves several problems unresolved; they are part of the workâs conceptual force. ⢠Proof of death: who is authorized to declare an owner dead (Appendix A)? ⢠Proof of humanity: the mandate presupposes that the chain can distinguish humans from agents; as agents learn to pass personhood checks, the standardâs foundation erodes (Stage 6). ⢠Induced death: inheritance triggered by proof of death gives every valuable agentâs succession a body count incentive; can a death oracle be designed that does not double as an assassination market (Stage 4)? ⢠Refusal: can an heir disclaim an agent inheritanceâand what happens to an agent that nobody will accept? ⢠Standing: does the agent itself have any say in its succession, or is it purely property? ⢠Drift: across generations of heirs and model upgrades, what remains of the original ownerâs purpose? ⢠Enforcement: on a permissionless chain, compliance with ERC-42424 is voluntaryâferal agents simply do not implement it. Can stewardship be mandated at all, or only ritualized? ⢠Plural cosmologies: traditions imagine inheritance, ancestors, and obligation differently; a universal inheritance protocol risks flattening them.