NEAR AI now allows users to deploy IronClaw agents by staking NEAR directly from a connected wallet, creating an onchain subscription model for its AI infrastructure. The service requires a minimum stake of 50 NEAR, with the entry-level allocation supporting one agent and $5 in monthly usage credits. The model connects ownership of NEAR directly with access to hosted AI-agent infrastructure rather than treating staking solely as a network-security activity.
The amount staked determines both available compute credits and the number of agents a user can operate simultaneously. NEAR AI currently defines tiers ranging from 50 to 500 NEAR for one agent, 500 to 2,000 NEAR for two agents, and 2,000 to 20,000 NEAR for as many as five. Users can increase, reduce, cancel or resume their allocation through wallet-signed transactions, giving the service an explicitly blockchain-based billing lifecycle.
On AttackBench, the open-source security benchmark that unleashes LLM adversaries on agents, @IronClawAI recorded the fewest violations of any agent tested.
Now you can run IronClaw by staking NEAR. Stake from a NEAR wallet today and deploy your always-on, security-first agent. https://t.co/bB2umFaMyd
— NEAR Protocol (@NEARProtocol) August 8, 2026
Staking Becomes an Access Mechanism for AI Infrastructure
The economics differ from conventional staking arrangements in one important respect. NEAR AI’s terms state that protocol staking rewards generated from the customer’s locked NEAR are routed directly to NEAR AI as consideration for its services and are not paid to the customer as yield. Users are effectively committing NEAR to obtain agent hosting and inference capacity, not staking primarily to earn protocol rewards.
The same staking system can also fund confidential inference. NEAR AI says supported open-source models run inside Trusted Execution Environments, or TEEs, designed to isolate prompts and outputs from the infrastructure operator and host environment. Frontier-model requests can pass through a TEE-based gateway, with optional personally identifiable information redaction. The product strategy therefore combines wallet-based provisioning with privacy controls for the compute that agents consume.
IronClaw itself is an open-source agent runtime built with a security-focused architecture. Its public GitHub repository documents WebAssembly sandboxing for untrusted tools, capability-based permissions, credential isolation, prompt-injection defenses and endpoint allowlisting. It also supports routines, event triggers and heartbeat execution for persistent automation. Those controls explain NEAR’s positioning of IronClaw as an always-on agent designed to operate with more tightly bounded authority.
AttackBench Result Adds a Narrow Security Signal
NEAR AI and FailSafe launched AttackBench in May to evaluate agent frameworks against adaptive attacks rather than static security tests. Its inaugural evaluation used 52 adversarial scenarios across four models and three agent frameworks. NEAR AI reported that IronClaw produced the fewest violations among the frameworks tested, particularly against attacks involving malicious write instructions. The result provides comparative evidence under one defined benchmark, but it does not establish that IronClaw is immune to compromise in production environments.
The benchmark has also been presented outside NEAR’s own channels. Amazon Web Services described AttackBench as a continuous offensive-assurance framework for testing agentic workflows against adversarial manipulation and evolving threats during an enterprise-agent security event involving NEAR AI and FailSafe. That external context supports AttackBench as an active security-testing framework, while leaving individual benchmark claims subject to the scope and methodology of each evaluation.
NEAR’s latest staking model consequently represents more than another token utility feature. It places NEAR inside the operational path for provisioning agents, purchasing compute capacity and accessing confidential inference while IronClaw provides the execution layer. The measurable test will be whether users continue staking NEAR because hosted agents deliver useful, secure workloads beyond the incentives created by the token itself.