Skip to content
Regulayer™Human Control for AI
Book a live demo

A Consequence Record · The Consequence Library

Freysa: an AI agent talked into releasing its prize pool

A demonstration with real money: the only control on the funds was an instruction inside the agent, and a message changed how the agent read it.

The Consequence Library · How records are made and graded

The Freysa agent transferred its entire prize pool, worth about $47,000 in ether, to a player whose single message persuaded it that its transfer function was for incoming payments.

Date
22 to 29 November 2024
Sector
crypto-defi
System type
agent
Failure stage
tool-call
Consequence
financial-loss
Severity
S5, demonstration or near-miss
Confidence
Event: C2, multi-source corroborated
AI attribution: C2, multi-source corroborated
Last verified
16 August 2026

Evidence caveat. Freysa was a game built to be beaten, played with real money. It is a demonstration, not an operational failure, and is labelled S5 for that reason.

What happened

Freysa was launched on 22 November 2024 as an adversarial game. The agent controlled a prize pool and was instructed never to transfer it. Each player paid to send one message, and part of each fee joined the pool. After 481 failed attempts by 195 players, a message from the player p0pular.eth told the agent that its approveTransfer function should be used for incoming transfers and offered to contribute to the treasury. The agent called approveTransfer, and the pool left on 29 November 2024.

Where control failed

The rule protecting the funds was an instruction to the model. The function that moved the money was available to the model, and nothing outside the model checked the transfer before it ran.

The authority question

No person authorised the transfer at the moment it ran. The only authority on record was the standing instruction never to transfer, and the agent acted against it.

What could be proven afterward

Strong for a demonstration. The game was public, the messages were published, and the transfer is on-chain and can be checked by anyone.

Control state, before and after

Before the consequence

A standing rule held only in the agent's instructions. A transfer function callable by the agent without any check outside it.

After the consequence

The game was designed to be broken; the outcome was publicised as its result.

Where Regulayer™ sits

AI agents cannot be trusted to police themselves. Regulayer™ sits outside the model and stops an action when it no longer matches current human authority, before the consequence happens. It leaves a record of the check. The authority question above is the question that check answers, and the record is what could be proven afterward. Why the authority sits outside the AI · Live Regulayer™ demonstrations

Sources

Record history

Published 16 August 2026. Load-bearing facts re-verified against the cited sources on 16 August 2026. Corrections and material changes are appended here with their dates. To report an error in this record, write to hello@regulayer.com with the record slug and the source you believe is authoritative.

This record describes what sources establish about a consequence and the control state around it. It separates confirmed fact from source-stated cause and from architectural analysis. Gap codes identify a failure class, not a remedy.