'You Can Fake Everything' — Cloudflare Just Gave AI Agents Wallets
TL;DR — Forbes covered Cloudflare's 4 August launch of wallets and permanent identities for AI agents. Moca Network CEO Kenneth Shek told Forbes that identifying the agent is only half the problem: what matters more is the human behind it. Cloudflare's optional cloudflare.pay address can tell a merchant which user a set of agents belongs to, but not whether that user is old enough, eligible, in good standing, or authorised to spend. Shek's answer is W3C verifiable credentials — signed attestations a user carries from site to site, shared with explicit consent and revocable at any time. AIR's role is to deepen what can be proven about the human behind the agent, not to become another agent registry.
Read the full article: 'You Can Fake Everything' — Cloudflare Just Gave AI Agents Wallets, by Boaz Sobrado, Forbes, 9 August 2026.
What Cloudflare shipped
On 4 August, Cloudflare said it would give AI agents their own wallets and a permanent identity, letting software hold stablecoins and shop online within limits set by its owner. For a company whose business has largely been gating bot traffic, that is a reversal: the goal is no longer to keep automated visitors out, but to tell the useful ones apart from the harmful ones. We wrote about the launch itself in Cloudflare Gave AI Agents an Identity and a Wallet.
The human behind the agent
Shek's point in the Forbes piece is that an agent credential answers the wrong half of the question. An agent-payment address tells a merchant that a set of agents belongs to one user ID. It says nothing about that user.
"Agent identity, for the agent themselves, is important," Shek told Forbes. "But our point of view is what's even more important is the human behind the agent."
That gap is what makes fraud cheap. Every attribute an agent asserts about its owner — age, residency, licence, account standing, spend authority — is unverified text unless something signed sits behind it.
Why the volume makes this urgent
Shek framed the scale problem plainly: a person visits perhaps 100 to 150 web pages a day, while a single agent could easily visit thousands. Animoca Brands co-founder and executive chairman Yat Siu, quoted in the same article, projects 50 to 100 billion agents at minimum over time, with individuals running hundreds each.
At that volume, verification cannot be a one-off check repeated by every merchant. It has to be a reusable proof the user already holds.
Where AIR fits
AIR is not an agent registry, and not a replacement for Cloudflare's bot-authentication layer. It is the identity and policy layer underneath it:
- Reusable proof. Verify once, prove anywhere. The user carries signed attestations rather than re-submitting documents at every site.
- Selective disclosure. An agent proves the specific claim a transaction needs — over 18, KYC-passed, loyalty tier — without exposing the underlying record.
- Delegation with limits. What an agent may verify, how much it may spend, where, and for how long, all set by the user and revocable.
None of this is standardised yet: Google and OpenAI are pushing rival agent-commerce protocols, and Cloudflare is building on its own Web Bot Auth rather than W3C credentials. That is precisely why interoperable, user-held credentials matter. An agent economy fragmented across platform-specific identity is one where accountability stops at the platform boundary.
Learn more about AIR and Moca Network's identity infrastructure, or read our guide to Know Your Agent (KYA).
revolution today




.png)