NEAR AI has introduced a staking-based route for deploying IronClaw, its open-source, always-on AI agent runtime, directly through a NEAR wallet. Users choosing the staking subscription must commit at least 50 NEAR, with higher tiers supporting additional agents and monthly inference credits. The model turns NEAR staking into a mechanism for purchasing persistent agent infrastructure rather than simply earning protocol yield.
The rollout coincides with security results from AttackBench, an open-source adversarial benchmark developed by NEAR AI and FailSafe. Its inaugural evaluation ran 52 attack scenarios across four AI models and three agent frameworks, with IronClaw recording the fewest violations across the tested configurations. The result strengthens IronClaw’s security positioning within that benchmark, but it does not establish that the agent is immune to attacks in production.
On AttackBench, the open-source security benchmark that unleashes LLM adversaries on agents, @IronClawAI recorded the fewest violations of any agent tested.
Now you can run IronClaw by staking NEAR. Stake from a NEAR wallet today and deploy your always-on, security-first agent. https://t.co/bB2umFaMyd
— NEAR Protocol (@NEARProtocol) August 8, 2026
Staked NEAR Pays for Persistent Agent Infrastructure
Under NEAR AI’s terms, staking is one of several ways to access Agent Hosting Services. The Starter tier covers 50 to 500 NEAR and supports one agent with $5 in monthly usage credits, while larger allocations can support as many as five agents. The staked principal remains under the customer’s ownership, subject to the protocol’s unstaking process. Staking rewards generated by that NEAR are routed to NEAR AI as payment for the service rather than returned to users as investment income.
IronClaw itself uses multiple security boundaries around agent actions. Its open-source implementation includes WebAssembly sandboxing for untrusted tools, capability-based permissions, endpoint allowlisting, credential isolation and leak detection. The architecture attempts to limit what autonomous tools can access even when the agent is permitted to operate continuously across external services.
NEAR AI also offers hosted IronClaw deployments inside Trusted Execution Environments through its confidential-computing infrastructure. The company says these environments isolate workload data from infrastructure operators and combine hardware attestation with encrypted execution. That confidential layer addresses a separate risk from agent permissions by limiting who can inspect sensitive data while models and agents are running.
AttackBench Provides a Narrow Security Test
AttackBench uses LLM-powered adversaries that adapt their attacks across repeated attempts rather than relying entirely on fixed prompts. In its first evaluation, NEAR AI said IronClaw showed its largest advantage in attacks involving malicious write instructions, supported by workspace-scoped permissions and explicit tool-call controls. The benchmark tests resistance to defined adversarial behavior, not every vulnerability an always-on agent could encounter.
The framework has also received external exposure through Amazon Web Services. AWS described AttackBench as a continuous offensive-assurance system for evaluating agentic workflows against adversarial manipulation and changing threat scenarios during an enterprise-agent security event involving NEAR AI and FailSafe. That independent context supports AttackBench as an active security-testing framework without turning its leaderboard into a guarantee of production safety.
NEAR’s broader strategy now connects token-based provisioning, persistent agents, isolated tools and confidential inference inside the same infrastructure stack. The practical test will be whether these controls continue limiting dangerous agent behavior as deployments move beyond benchmarks into long-running workflows with credentials, APIs and financial permissions.








