MoonPay CEO Ivan Soto-Wright says PayBox lets Claude and ChatGPT agents hold cards and crypto wallets and spend from them, with keys structured so no single party controls them. In a Forbes interview, he describes a live demonstration in which a Claude agent booked his flight end to end. That detail matters less as a demo than as a design statement: the industry has largely solved agents browsing and selecting, and is now converging on the harder problem — giving an agent money it can actually spend, without handing it the keys to yours.
What PayBox Actually Is
PayBox is MoonPay’s attempt to give an AI agent its own financial identity rather than borrowing the user’s. Instead of an agent triggering a payment that debits a human wallet, the agent holds instruments directly: a payment card for merchant acceptance and a crypto wallet for on-chain settlement. The key-management claim is the technically interesting part. Keys are split such that no single party — not MoonPay, not the model provider, not the user — can unilaterally move funds. This is threshold or multi-party signing in some form, the same architectural family that custody providers have used for years, now applied to non-human actors. The practical effect is that an agent’s spending authority is enforced cryptographically rather than by a Terms of Service document.
Cards and Crypto as a Deliberate Pair
Why both rails? Because they fail in opposite directions. Card networks offer near-universal merchant acceptance but settle on bank timelines, carry dispute machinery designed for human cardholders, and treat an autonomous agent as a fraud signal. Crypto rails — and in practice that means stablecoins — settle instantly and programmably but require the merchant to accept them, which most still do not. Oobit and AEON have each attacked one half of this problem from the card side; MoonPay is unusual in shipping both under one agent-owned account abstraction. If the crypto wallet is USDC or USDT-based, PayBox agents get 24/7 settlement for the merchants that support it, with the card as fallback everywhere else.
Where This Sits in the Agent Payment Stack
The last year has produced a layered stack: identity and KYA checks (MetaComp’s StableX work), agent-native checkout (AEON, Coinbase Agent Payments), purpose-built settlement rails (Solana’s Payment Channels, x402), and spending instruments (Oobit’s agent Visa cards). PayBox lives at the spending-instrument layer but pulls the account itself away from the human user. That is a meaningful shift. Most prior designs kept the human as the account holder and the agent as an authorized initiator. Giving the agent its own card and wallet makes limits, allowances and revocation cleaner — you fund a PayBox the way you fund a petty-cash box — but it also makes the agent a legally novel account holder, which card networks and banks have not fully mapped.
The Unsolved Problem: Liability and Limits
The cryptography can guarantee that only the agent’s key can spend; it cannot guarantee the agent spends well. If a Claude agent books the wrong flight, or a prompt-injected agent drains its PayBox to a merchant it was told to avoid, the dispute lands in a gap between card-network chargeback rules (written for human cardholders) and on-chain finality (which has no chargebacks at all). Soto-Wright’s framing — keys no single party controls — solves custody risk, not authorization risk. Expect the next round of differentiation here: programmable spend policies, per-merchant caps, human-in-the-loop thresholds above some amount. The agent that can pay is now shipping; the guardrails are still being written.