Monolith — Crypto Wallet Skill
Secure crypto wallet for OpenClaw agents. Monolith combines hardware-isolated keys (Apple Secure Enclave), on-chain spending controls, and policy-gated approvals so agents can transact safely without exposing private keys.
Commands
| Command |
What it does |
Requires daemon? |
send <to> <amount> [token] [chainId] |
Send ETH or USDC |
Yes |
swap <amountETH> [tokenOut] [chainId] |
Swap ETH for tokens via Uniswap (Routing API with on-chain fallback) |
Yes |
balance <address> [chainId] |
Check ETH and stablecoin balances |
No (read-only) |
capabilities |
Show current limits, budgets, gas status |
Yes |
decode <target> <calldata> <value> |
Decode a tx intent into human-readable summary |
Yes |
panic |
Emergency freeze — instant, no Touch ID |
Yes |
status |
Check daemon health and wallet info |
Yes |
identity [query|register] |
ERC-8004 identity operations |
Partially |
setup |
Run setup wizard, show wallet status and config |
Yes |
policy |
Show current spending policy |
Yes |
policy update '<json>' |
Update spending policy (Touch ID required) |
Yes |
allowlist <add|remove> <address> [label] |
Add or remove address from allowlist (Touch ID required) |
Yes |
audit-log |
Show the daemon audit log |
Yes |
Security Model
- The skill is untrusted. It only builds intents:
{target, calldata, value}.
- The skill NEVER sets nonce, gas, chainId, fees, or signatures.
- The signing daemon (local macOS process) enforces all policy.
- Transactions within policy limits execute automatically (autopilot).
- Transactions that exceed limits or use unknown calldata require human approval via 8-digit code.
- Token approvals (
approve, permit, etc.) ALWAYS require explicit approval.
What requires approval?
- Transfers over per-tx or daily spending caps
- Transfers to non-allowlisted addresses
- Token approvals (approve, permit, setApprovalForAll)
- Unknown calldata (default-deny policy)
- Swaps above slippage limits
What works on autopilot?
- ETH and USDC transfers within limits to allowlisted addresses
- Swaps on allowlisted DEXes (Uniswap) within slippage limits
- DeFi deposits/withdrawals on allowlisted protocols (Aave)
- Balance checks, status queries, decode requests
Setup
- Install Monolith from ClawHub:
clawhub install monolith
- Start a new OpenClaw session so the skill is loaded.
- Install local macOS components from the install entries:
MonolithDaemon-v0.1.5.pkg (admin/root install)
MonolithCompanion.app.zip (extract app to /Applications and open once)
- Start daemon first, then companion. If companion was opened before daemon, restart companion after daemon is running.
- Run
monolith setup to verify daemon/companion connectivity and wallet status.
- Fund the wallet address with ETH on your chosen chain.
- Start transacting.
First-Install Notes (OpenClaw bot/operator)
- Approval flows (Touch ID + notifications) require an active logged-in macOS GUI session.
- Headless-only SSH sessions cannot complete biometric/notification approval steps.
monolith setup is the canonical health check before attempting send, swap, policy, or allowlist commands.
Error Handling
- If the daemon is not running, all signing commands will fail with a clear error
- If gas is low, the daemon will refuse transactions — fund the wallet with more ETH
- If the wallet is frozen, no outbound transactions are possible until unfrozen (requires Touch ID + 10min delay)
- Rate-limited by Pimlico? The daemon uses exponential backoff automatically
Approval Flow
When a transaction exceeds policy limits or uses unknown calldata, the daemon
returns HTTP 202 with a reason, summary, and expiration. The agent should:
- Present the approval reason and summary to the user.
- Ask the user for the 8-digit approval code (displayed by the daemon's native macOS dialog).
- Re-call
/sign with the same intent plus the approvalCode field to confirm.
No separate approval script is needed -- the same send or swap command is
re-invoked with the approval code passed through the daemon.
Swap Routing
Uses Uniswap Routing API when available; falls back to on-chain V3 fee-tier probing
(tries 3000, 500, 10000 bps tiers, picks best quote). The fallback ensures swap
intents can still be built when the API is down or returns unexpected results.
Chains
- Ethereum Mainnet (chainId 1)
- Base (chainId 8453)
1---2name: monolith3description: Secure crypto wallet for AI agents. Hardware-isolated keys (Apple Secure Enclave), ERC-4337 smart wallet, on-chain spending caps, default-deny policy engine.4---5
6# Monolith — Crypto Wallet Skill
7
8Secure crypto wallet for OpenClaw agents. Monolith combines hardware-isolated keys (Apple Secure Enclave), on-chain spending controls, and policy-gated approvals so agents can transact safely without exposing private keys.
9
10## Commands
11
12| Command | What it does | Requires daemon? |
13|---------|-------------|------------------|
14| `send <to> <amount> [token] [chainId]` | Send ETH or USDC | Yes |
15| `swap <amountETH> [tokenOut] [chainId]` | Swap ETH for tokens via Uniswap (Routing API with on-chain fallback) | Yes |
16| `balance <address> [chainId]` | Check ETH and stablecoin balances | No (read-only) |
17| `capabilities` | Show current limits, budgets, gas status | Yes |
18| `decode <target> <calldata> <value>` | Decode a tx intent into human-readable summary | Yes |
19| `panic` | Emergency freeze — instant, no Touch ID | Yes |
20| `status` | Check daemon health and wallet info | Yes |
21| `identity [query\|register]` | ERC-8004 identity operations | Partially |
22| `setup` | Run setup wizard, show wallet status and config | Yes |
23| `policy` | Show current spending policy | Yes |
24| `policy update '<json>'` | Update spending policy (Touch ID required) | Yes |
25| `allowlist <add\|remove> <address> [label]` | Add or remove address from allowlist (Touch ID required) | Yes |
26| `audit-log` | Show the daemon audit log | Yes |
27
28## Security Model
29
30- **The skill is untrusted.** It only builds intents: `{target, calldata, value}`.
31- The skill NEVER sets nonce, gas, chainId, fees, or signatures.
32- The signing daemon (local macOS process) enforces all policy.
33- Transactions within policy limits execute automatically (autopilot).
34- Transactions that exceed limits or use unknown calldata require human approval via 8-digit code.
35- Token approvals (`approve`, `permit`, etc.) ALWAYS require explicit approval.
36
37## What requires approval?
38
39- Transfers over per-tx or daily spending caps
40- Transfers to non-allowlisted addresses
41- Token approvals (approve, permit, setApprovalForAll)
42- Unknown calldata (default-deny policy)
43- Swaps above slippage limits
44
45## What works on autopilot?
46
47- ETH and USDC transfers within limits to allowlisted addresses
48- Swaps on allowlisted DEXes (Uniswap) within slippage limits
49- DeFi deposits/withdrawals on allowlisted protocols (Aave)
50- Balance checks, status queries, decode requests
51
52## Setup
53
541. Install Monolith from ClawHub: `clawhub install monolith`
552. Start a new OpenClaw session so the skill is loaded.
563. Install local macOS components from the install entries:
57 - `MonolithDaemon-v0.1.5.pkg` (admin/root install)
58 - `MonolithCompanion.app.zip` (extract app to `/Applications` and open once)
594. Start daemon first, then companion. If companion was opened before daemon, restart companion after daemon is running.
605. Run `monolith setup` to verify daemon/companion connectivity and wallet status.
616. Fund the wallet address with ETH on your chosen chain.
627. Start transacting.
63
64### First-Install Notes (OpenClaw bot/operator)
65
66- Approval flows (Touch ID + notifications) require an active logged-in macOS GUI session.
67- Headless-only SSH sessions cannot complete biometric/notification approval steps.
68- `monolith setup` is the canonical health check before attempting `send`, `swap`, `policy`, or `allowlist` commands.
69
70
71## Error Handling
72
73- If the daemon is not running, all signing commands will fail with a clear error
74- If gas is low, the daemon will refuse transactions — fund the wallet with more ETH
75- If the wallet is frozen, no outbound transactions are possible until unfrozen (requires Touch ID + 10min delay)
76- Rate-limited by Pimlico? The daemon uses exponential backoff automatically
77
78## Approval Flow
79
80When a transaction exceeds policy limits or uses unknown calldata, the daemon
81returns HTTP 202 with a reason, summary, and expiration. The agent should:
82
831. Present the approval reason and summary to the user.
842. Ask the user for the 8-digit approval code (displayed by the daemon's native macOS dialog).
853. Re-call `/sign` with the same intent plus the `approvalCode` field to confirm.
86
87No separate approval script is needed -- the same `send` or `swap` command is
88re-invoked with the approval code passed through the daemon.
89
90## Swap Routing
91
92Uses Uniswap Routing API when available; falls back to on-chain V3 fee-tier probing
93(tries 3000, 500, 10000 bps tiers, picks best quote). The fallback ensures swap
94intents can still be built when the API is down or returns unexpected results.
95
96## Chains
97
98- Ethereum Mainnet (chainId 1)
99- Base (chainId 8453)