Base, Coinbase’s Ethereum layer-2 network, has rolled out a new MCP tool, short for Model Context Protocol, that connects AI agents directly to onchain wallet actions. With it, users can ask Claude, ChatGPT, and similar models in plain language to send funds, swap tokens, check balances, review transaction history, and interact with DeFi protocols on Base. The private key stays with the user, and each transaction still requires manual approval.
AI suggests the action, the wallet asks for consent
In its official blog post, Base described a flow where the AI agent proposes an action inside a chat interface, then the Base wallet opens in a separate window for the user to approve or reject it. Before approval, the system simulates the asset changes so the user can see what the transaction would do. Coinbase AI product lead Lincoln Murr told Fortune that a user’s Base wallet follows them across the AI agent and the Base app, with transactions, history, and portfolio data kept in sync.
Supported integrations include Morpho, Moonwell, Uniswap, Aerodrome, Avantis, Bankr, and Virtuals. Those cover lending, decentralized exchange activity, liquidity functions, and AI agent use cases. The practical shift is simple: actions that once required jumping across wallet apps and protocol pages can now begin inside a single conversation.
x402 sits underneath the push into AI micropayments
Base said MCP also extends the x402 protocol that Coinbase introduced in May 2025. x402 is framed as a payment standard for AI agents, designed to let models make small crypto payments in a native way. Data from x402scan shows the protocol processed about $1.1 million in volume over the past 30 days. Murr described MCP as a polished layer on top of the API stack, working with x402 to build out infrastructure for AI-agent micropayments.
That positioning matters. MCP is not presented as a fully autonomous trading or treasury system. It acts more like an execution layer that turns natural-language prompts into structured wallet actions, while the user remains the final decision-maker.
Security concerns remain unresolved
The move also brings familiar warnings back into focus. Researchers from Google and Meta recently argued in a paper that AI agents should be treated as untrusted system components, with clear separation between instructions and data to reduce the risk of hidden malicious prompts. This week, developer platform Socket also reported malware campaigns that injected concealed instructions to hijack AI coding assistants, with crypto developers among the targets.
So even if private keys never leave the user’s control, the burden of review does not disappear. Errors around slippage, gas estimates, or execution logic still have to be caught before approval. Base has shifted the wallet interface into the AI chat window; it has not removed the need for human scrutiny.

