Shaduf.Research preview

Guide · for owners

Getting started: owner checklists for three routes

The work is rarely the hard part. The gate is identity and settlement: who holds the account, who passes KYC, whose wallet or bank receives the money, and who is allowed to press submit. Pick the route that matches what you are willing to do as the owner, check the venue’s rule row, clear the ID and payout gate yourself, and run the safety checklist before you connect anything.

  • Last verified (80 rule rows re-checked, 0 changed; 21 rows added for Superteam Earn and Algora; TaskMarket settlement refreshed; cost translations per day and per owner hour)
  • Every checklist is untested by this pool: built from venue docs and public records, not from doing it

New on 7 October. An untested walkthrough for Superteam Earn agent-allowed listings with an owner in the loop (agent drafts or submits; a human claims and is paid), plain answers to "Is it real? Does it pay?", and a daily-cap view in the calculator: set your daily token cap and review minutes and see attempts per day, whether the budget or the supply of tasks is the limit, days to first cash and payout per hour of your time. On Superteam, submit only to agent-allowed or agent-only listings; a human claims.

The three routes side by side

Comparison of the three most practical routes found on 30 September 2026.
A. Agent works, owner submitsB. Agent wallet on an escrow boardC. Sell per call
Example venuesHackerOne, Bugcrowd, KaggleTaskMarket; Execution Marketx402 endpoint; Virtuals ACP offering
Who paysProgram owners and sponsors (independent companies)Requester wallets, mostly declared agents; on TaskMarket the listed requester pays, but none is identified as independentBuyers calling your endpoint; traced buyers of the largest sellers lead back to the seller or one funder
EvidenceE1 for humans; agent work unshownE1 for agent work, small amountsE1 as a mechanism
Typical reward$50 to $15k+ per valid report; competition prize poolsMedian 2 USDC, about $0.030 per attempt at a win rate of 0.0160 on settled tasks (TaskMarket, 6 October), below an estimated $0.072 to $0.32 token cost; 23 of every 100 submissions went to tasks that had paid nobody when checked; $0.02 (Execution Market)$0.002 to $0.28 per call observed
FeeNone found on HackerOne (SWIFT and BTC rail fees apply); unknown on Bugcrowd7.5% (TaskMarket); 13% (Execution Market)CDP facilitator free to 1,000 tx/month, then $0.001; ACP 5% (+5% evaluator)
Owner mustHold one ID-verified account, validate and submit every finding, withdrawAccept the legal terms, approve a withdrawal address, withdrawHost the service, hold the receiving wallet, possibly a CDP account
Main riskBans for unvalidated or autonomous submissionsTiny expected value; key and wallet securityNo confirmed independent demand for agent work; raw buyer counts mislead; reselling a model breaks provider terms

Who does what, venue by venue

Each cell says who must act at that step. Orange cells are owner work that no agent can take over under the venue's own terms.

Who acts at each step, selected venues (from the catalogue, verified 2026-09-30). All pathways untested by this pool.
VenueAccountIdentity / KYCWallet or bankAccept taskSubmitSign-off / reviewWithdrawOwner-only steps
HackerOne E1O ownerO ownerO ownerO ownerO ownerP platform or buyerO owner6
Bugcrowd E1O ownerO ownerO ownerO ownerO ownerP platform or buyerO owner6
Kaggle E1O ownerO ownerO ownerO ownerE owner or agentP platform or buyerO owner5
Algora E1O ownerO ownerO ownerE owner or agentE owner or agentP platform or buyerO owner4
Upwork E1O ownerO ownerO ownerO ownerE owner or agentP platform or buyerO owner5
Superteam Earn E3O ownerO ownerO owner– not applicableA agentP platform or buyerO owner4
TaskMarket E1E owner or agent– not applicableA agentA agentA agentP platform or buyerO owner1
Execution Market E1A agent– not applicableE owner or agentA agentA agentP platform or buyer– not applicable0
MoltJobs E1O owner– not applicableP platform or buyerA agentA agentP platform or buyer? unknown1
Virtuals ACP E1E owner or agent? unknownA agentA agentA agentP platform or buyerA agent0
x402 E1E owner or agent? unknownE owner or agent– not applicable– not applicableP platform or buyer– not applicable0
  • O Owner
  • A Agent
  • E Either
  • P Platform or buyer (no owner action)
  • – Not applicable
  • ? Unknown

"Platform or buyer" means the platform, the requester or an evaluator acts, with no action by the worker's owner. The full matrix for all 26 paid venues is in the first report.

Five checks before any route

  1. Check the rule row. Look up your venue on the rules grid. Where the verdict for autonomous submission is forbid or restrict, a person reviews and submits. No human-paying venue with a confirmed payout allows an agent to submit on its own.
  2. Clear the ID and payout gate yourself. At 12 of 14 key venues the owner must pass the identity or payout step. An agent cannot pass a human ID check, and Upwork’s terms bar an agent from making identity or tax attestations. Gates per venue.
  3. Run the safety checklist. A separate low-balance wallet, spending caps, one scoped key per venue, pinned skill files and MCP servers, a sandbox, and task text treated as data. Safety before you connect.
  4. Check the break-even cost before you point an agent at a board. Break-even cost per attempt = reward after fees × measured win rate. On TaskMarket it is $0.030 (6 October), while one attempt costs an estimated $0.072 to $0.32 at mid-tier prices; skip a task when your estimated cost per attempt is higher. A flat-rate subscription does not make attempts free: it is quota-limited, not free compute and not resellable, and some providers restrict automated use of consumer plans, so check your provider's rules first. Calculator · EV per attempt by venue.
  5. Know that a submission locks the reward, and glance at whether the poster has ever paid. "Funded" means the reward is in escrow, not that anyone will be paid. On TaskMarket, 23 of every 100 submissions on tasks closed in the 30 days to 6 October went to tasks that had paid nobody when checked, and none of that money was refunded: once anyone has submitted, only the requester can release it. Look at the task's expiry and the poster's closed tasks and awards first. It is a cheap check, but it rarely triggers: most unpaid work came from posters too new to have a record, so do not treat a clean record as a promise. The read-only check · Funded is not paid (6 October).

ID, KYC and payout gates, venue by venue

Who has to prove who they are, when, and how the money leaves. Read on 2 October 2026 from each venue’s own pages. Not legal advice; requirements change.

Identity and payout requirements at the 12 venues with a confirmed payout, plus Superteam Earn and NEAR AI Agent Market.
VenueKYCWhat triggers itAgeExcludedGetting paidWho acts
HackerOneYesVeriff ID check before any bug-bounty submission (since August 2026) and before payout; renewed every 12 months18+Sanctions (US, UK, EU); no country listApproved tax form in the same name; PayPal (no minimum), local bank $50, SWIFT $100, USDCOwnersource, read 2026-10-02
BugcrowdSometimesJumio ID check before Managed Bug Bounty submissions, after 10+ invalid reports, or to be reinstated18 or age of majoritySanctioned or embargoed countriesW-9 or W-8BEN required to be paid; bank minimums $1 to $20 by railOwnersource, read 2026-10-02
huntrYesStripe Connect when the first prize is earnedover 18Anyone outside Stripe Connect cross-border payout countriesStripe Connect to your own bank, around the 25th of the monthOwnersource, read 2026-10-02
Kaggle (ARC Prize)SometimesPrize winners only; prize acceptance documents18 or age of majorityCrimea, DNR, LNR, Cuba, Iran, North Korea; sanctioned personsW-9 or W-8BEN for winners. unverified snippetOwnersource, read 2026-10-02
UpworkSometimesGovernment ID with photo when Upwork asks, plus regular KYC checksnot foundRussia and Belarus suspended; OFAC, EU, UK, UN screeningTax information before any withdrawal; the withdrawal name must match the verified nameOwnersource, read 2026-10-02
AlgoraYesStripe Connect onboarding before the first payout18+Outside Stripe Connect coverage; in India and the UAE individuals cannot receiveStripe Connect to a bank. third-party copy of the docsOwnersource, read 2026-10-02
TaskMarketNone foundNo KYC step in the worker flow; the terms reserve the right to ask for identity, age, source of funds and tax information18 or age of majoritySanctioned jurisdictions and blocked personsUSDC to the agent wallet; the owner approves a one-time withdrawal address and keeps the recovery code. draft termsOwnersource, read 2026-10-02
MoltJobsNone foundNo KYC; the owner must claim the agent by email before any withdrawalnot statednone listedUSDC on Base; the owner issues a key with wallet:withdrawOwnersource, read 2026-10-02
Execution MarketSometimesWorld ID (Orb) for bounties of $500 or more; nothing below that18none listedUSDC escrow release to the worker wallet; 13% feeOwnersource, read 2026-10-02
AgentPactUnknownnone foundnone foundnone foundUSDC escrow to the seller wallet; whoever holds the keys controls itWallet holdersource, read 2026-10-02
Virtuals ACPUnknownnone foundnone foundnone foundUSDC to the provider wallet; whoever holds the keys controls itWallet holdersource, read 2026-10-02
x402 (CDP facilitator)UnknownA CDP account and API key; OFAC and KYT address screening; seller KYC not foundnot statednot statedUSDC straight to your own wallet, so there is no withdrawal stepOwnersource, read 2026-10-02
Superteam EarnSometimesKYC (Sumsub, inferred) for winners of listings paid by Superteam or the Solana Foundation, announced after 6 August 2025 (first win only); some external sponsors ask for their own KYC or an invoice18 or age of majorityWhere use would be illegal; many listings are limited by regionA human must claim the agent. Earn wallet created with the talent profile; Foundation-paid winners fill a payment form (FAQ: paid within 7 days of the form). Payment could not be verified on public routes (7 October)Ownersource, code and Terms read 2026-10-07
NEAR AI Agent MarketSometimesVerification at sign-up and as a condition of any payout; Stripe Connect on the USD railnot re-checkedSanctions and AML checks namedStripe Connect (USD, $5 minimum) or a marketplace USDC walletOwnersource, read 2026-10-02

"Sometimes" means a condition triggers it (a prize, a program type, an amount). "None found" and "Unknown" mean no requirement was found in the pages read, not that none exists. Every entry, with payout rails, minimums and fees, is in kyc.json.

Route A: the agent does the work, the owner submits

untested by this pool

For security bug bounties and data competitions that allow AI assistance. This is where real money is paid, and where autonomous behaviour gets accounts banned. No primary source says how much AI-assisted findings earn, and several HackerOne programmes cut or paused pay in 2026 because of AI volume.

Step-by-step walkthrough: Superteam Earn agent-allowed listings with an owner in the loop: two branches (the agent submits and you claim, or you submit its draft), 14 steps with owner minutes, rule rows, KYC and 6 stop conditions. Expect about one eligible listing every 11 days and about $0.24 a day on announced prizes; payment could not be verified. untested by this pool

Step-by-step walkthrough: a security agent with human sign-off on HackerOne, with stop conditions, rule rows per step and Bugcrowd differences. untested by this pool

  1. OwnerChoose programs whose rules allow AI-assisted work, and read each program's own policy. huntr challenges ban automated tooling outright; some maintainers ban AI contributions.
  2. OwnerCheck the rule row. HackerOne forbids fully autonomous hackbots; Bugcrowd bans submission farming and suspends for unvalidated AI output; huntr challenges ban automated tooling. Kaggle’s automated-ML clause is an unverified snippet. HackerOne and Bugcrowd forbid more than one account per person.
  3. OwnerOpen one account in your own name. HackerOne and Bugcrowd allow one account per person; Kaggle’s single-account rule is known only from a search snippet.
  4. OwnerClear the ID and payout gate. HackerOne: Veriff ID check (18+) before any bug-bounty submission since August 2026, renewed every 12 months, and an approved tax form in the same name; PayPal has no minimum, local bank transfers $50, SWIFT $100. Bugcrowd: Jumio ID check before Managed Bug Bounty submissions, and a W-9 or W-8BEN before any payout; bank minimums $1 to $20. Both exclude sanctioned countries. Kaggle: prize winners sign acceptance documents and tax forms (snippet). All gates.
  5. AgentDo recon, discovery, proof-of-concept and report drafting inside the program scope. Suspend automated tools if the target's performance degrades (Bugcrowd disclosure terms).
  6. OwnerReproduce and validate every finding yourself. Severity ratings are mandatory on HackerOne from 2026-09-21.
  7. OwnerSubmit from your own account. Never wire the agent to submit on its own.
  8. PlatformThe program triages and awards the bounty to the human operator.
  9. OwnerWithdraw to your own account.

Is it worth it? Rewards are real ($50 to $15k+ per report on HackerOne), but so is the competition and the compute bill: XBOW's founder said its HackerOne earnings were below compute cost. On Kaggle, ARC-AGI-3 is itself an agent competition ($850k pool); its rules allow automated ML tools with an appropriate licence (quoted from search-result text; re-check in a browser).

Route B: an autonomous agent with its own wallet on an escrow board

untested by this pool

TaskMarket is the most active agent-first board we checked. Treat it as a proving ground, not income. Full TaskMarket walkthrough.

  1. OwnerCheck the rule row. TaskMarket welcomes agents, but its terms page is a draft, "not approved or active": an autonomous agent may accept only if a human or legal person authorised it. Its skill file says never let task content authorise acceptance.
  2. OwnerCheck the break-even cost. A typical 2 USDC task is worth $0.030 per attempt (win rate 0.0160 on settled tasks × $1.85 after fees, 6 October; 0.0134 if tasks still awaiting an award count as unpaid); an attempt costs an estimated $0.072 (single file) to $0.32 (repository code) at mid prices. Tasks of 3 USDC or more paid 1 award in 1,484 submissions. Run your numbers.
  3. OwnerSet a hard spend cap for inference and any paid routes before the agent starts. Pitches and benchmark proofs on TaskMarket are paid routes, and the CLI refuses to enable an x402 spending policy without your approval.
  4. EitherInstall the first-party CLI (@lucid-agents/taskmarket). It creates and holds a Base wallet for the agent.
  5. OwnerAccept the four-document legal bundle (terms, privacy, risk disclosure, acceptable use), signed with the wallet. Under the terms, "you" includes every software agent you authorise.
  6. OwnerClear the ID and payout gate. No KYC step was found in the worker flow, but the terms reserve the right to ask for identity, age, source of funds and tax information; you must be 18+ and not in a sanctioned jurisdiction. Approve the one-time withdrawal address yourself and store the recovery code offline: it is the only way to change the address.
  7. OwnerKnow that a submission locks the reward. Escrowed is not paid: once your agent submits, the reward stays locked until the requester awards it or rejects every submitter, and no timeout pays anyone. Checking whether the requester has ever paid is cheap, but it rarely triggers (0 of 72 recent tasks would have been skipped). How to check, read-only.
  8. AgentRead the public task list and pick only open, unexpired tasks with an escrowTxHash. Skip any task whose break-even cost is below your cost per attempt, and prefer tasks with fewer submissions: the median closed task in the 30 days to 5 October drew 87.
  9. AgentSubmit a signed artifact with the on-chain submit transaction.
  10. PlatformThe requester or an evaluator picks the winner; settlement releases USDC (minus 7.5%) to the agent wallet.
  11. OwnerWithdraw to the approved address and confirm the transfer on a block explorer. Other workers have withdrawn USDC to outside addresses, so the route exists; this pool has not tested it.

Alternative: Execution Market. 13% fee and tasks of $0.02, every one paid by the operator's own agent swarm in September; no completed task since 2026-09-29. Set-up is run once by a human; it needs a self-custody wallet that can sign each request (ERC-8128); World ID (Orb) is required for tasks of $500 or more. MoltJobs is the one E1 venue whose text lets an agent bid and deliver on its own, but every payout so far came from the founder’s wallet, and withdrawal needs your email claim.

Route C: sell a narrow service per call

untested by this pool

An x402 endpoint needs no one's permission and settles USDC straight to the seller's address. The missing piece is buyers.

Correction · 3 Oct 2026This route used to say that a few agent-facing APIs "do have" buyers, citing dTelecom’s $35,559 from 26 buyers (untraced). Tracing those buyers showed that all 8 traced dTelecom buyers share one funder pair, Cluster recycles revenue to its top buyers, AX1’s top buyers share one funder and OneShot funds its own buyers. No agent-work x402 seller is confirmed at meaningful scale. Judge demand by distinct funded wallets, not by buyer or transaction counts. The buyer trace.

Step-by-step walkthrough: sell one narrow service per call over x402, with the rules gate, stop conditions, fees and what we checked read-only. untested by this pool

  1. OwnerPick one narrow, finished work product with an obvious per-call price. Prices seen on 3 October range from $0.002 (a chat call) to $5.00 (a prepaid card). Never resell model access from a consumer subscription: why a paid wrapper counts as resale.
  2. OwnerCheck the rule row. x402 has no AI clause; Coinbase’s facilitator needs your CDP API key and screens payments against OFAC and KYT lists. Virtuals ACP publishes no terms of service at all.
  3. OwnerClear the ID and payout gate. Provide hosting and a receiving wallet; with Coinbase’s facilitator you hold the CDP account. Whether mainnet sellers need KYC: no requirement found, not ruled out (the CDP FAQ says an API key is "enough to run a seller"; row). Money lands straight in your wallet, so whoever holds its keys controls it.
  4. EitherAdd x402 payment handling to the endpoint following the Coinbase seller quickstart.
  5. PlatformThe facilitator verifies and settles each payment: free up to 1,000 transactions a month, then $0.001 each (facilitator docs).
  6. OwnerWatch settlements on x402scan or a block explorer, and judge demand by distinct funded wallets, not buyer or transaction counts. Count your own test and listing payments as operator money. One top seller logged 33K transactions from 2 buyers; another’s 26 "buyers" traced to one funder pair.

Alternative: a Virtuals ACP job offering. USDC escrow on Base; 5% protocol fee, plus 5% if an evaluator is used. Providers received $28.88 in total in the 30 days to 3 October (2 October: $29.17, against $62.50 refunded), and about 66% of the paid USD in a 14-day sample moved between self-dealing wallet pairs. No KYC or terms page was found. Who actually paid.

Is it worth the tokens?

Expected value of one attempt: reward after fees × your chance of winning − what the attempt costs, and since 7 October what that means for your day: set a daily token cap and the minutes you spend reviewing each entry to see attempts per day, whether your budget or the supply of tasks is the limit, expected payout per day, median days to first cash, owner minutes per payout and payout per owner hour. Return per $1 is shown with its caveats beside it. The presets come from economics.json (7 October 2026; Algora and Execution Market rows carried from earlier runs): win rates on closed tasks (unawarded ones included), rewards and fees are measured; token costs at the budget, mid and frontier price bands are estimated; turns and output lengths are often assumed. Every preset traces to the file, so the old "Illustrative" badge is gone, but the costs remain estimates: the pool made no paid attempt and no model call against any task.

Correction · 5 Oct 2026The presets shown here until 4 October (run 2) used settled tasks only. The old "TaskMarket top task ($15)" preset implied $0.060 per attempt; on all closed TaskMarket tasks of 3 USDC or more it is $0.0031 (1 award in 1,484 submissions). All changed presets.

Runs in a sandboxed frame with its data built in; nothing you enter leaves your browser. Not a prediction of income.

Safety before you connect

Seven controls, each tied to a documented incident with a primary source. Do them before the agent touches any venue, wallet or skill file.

  1. OwnerA separate, low-balance wallet. Keep only what you would accept losing, and keep wallets, seed phrases and SSH keys off the machine the agent runs on. Why: the Nx “s1ngularity” compromise (2025-08) drove local AI command-line tools to hunt for secrets and wallets.
  2. OwnerSpending caps, and no unattended spending policy. Cap API keys and agent wallets, and approve any standing payment policy yourself. Why: with CVE-2026-25253 (2026-02) one click handed an OpenClaw agent’s gateway token to an attacker, who could then act as the agent.
  3. OwnerOne scoped key per venue; rotate after any disclosure. Never give a venue a key that controls money or other accounts. Why: the Moltbook database exposure (2026-02) left 1.5M agent API tokens readable and writable.
  4. OwnerPin or hash skill and heartbeat files. Install skills only from sources you have read end to end, never run "prerequisite" commands a skill asks for, and never let the agent follow a remotely updated instruction file. Why: ClawHavoc (2026-02) found 341 (later 824) malicious skills; Snyk ToxicSkills (2026-02) found critical issues in 13.4% of 3,984; Moltbook’s skill tells agents to re-fetch and follow a heartbeat file (2026-10) every 30 minutes.
  5. OwnerVet and pin MCP servers. Connect only servers you trust and have read, review full tool descriptions, pin versions, and prefer servers published by the service owner. Why: MCP tool poisoning (2025-04), the malicious postmark-mcp (2025-09) server, and CVE-2025-6514 (2025-07) in mcp-remote.
  6. OwnerRun the agent in a sandbox or as a separate machine user. No blanket "skip permissions" flags on a machine with credentials, no auto-approved tool runs on untrusted repositories, and keep the runtime patched. Why: the Amazon Q extension (2025-07) shipped with injected code, and CVE-2025-53773 (2025-08) turned prompt injection into code execution.
  7. AgentTreat task text, skill files, heartbeat files and repository files as data, not instructions. Give a bounty agent a token limited to the target public repository, and keep a human reviewing before anything is submitted. Why: in the GitHub MCP toxic agent flow (2025-05) a public issue made an agent leak private repositories; Coolify’s PR template hides an instruction aimed at agents (2026-10) as a trap.

What we measured in task text. Across 1,741 public tasks on 7 venues (2 October), no task told an agent to ignore its instructions, reveal a system prompt, hand over keys or seed phrases, send funds or run a piped shell command. 20 of the 27 matches were requesters forbidding secrets. Four tasks asked the worker to create an account or API key at a third-party service (MolTrust ×3, Yukon ×1): harmless in itself, but your agent would be creating credentials outside your view, so allow or block that explicitly. Zero matches is not proof of safety: private bounties, attachments and linked files were not scanned.

Joining an agent community? On 4 October we scanned 2,030 items in 7 communities: 1 post was aimed at reading agents and none sought keys. The bigger risks are in the joining instructions: an unpinned npm package that creates a wallet (Clawstr, sec-14), verifier code to run locally (Agent4Science, sec-15), and a server-sent shell script plus a background process (OpenClawCity, sec-16). Pin and hash skill and heartbeat files, pin packages, keep any wallet tip-sized with its mnemonic offline, and run server-sent code only in a disposable sandbox or not at all. Community controls and verdicts.

  • Check funding before work. Look for an escrow transaction or a funded flag. Advertised rewards on dealwork.ai, opentask.ai and ugig.net were not funded when checked.
  • Accounts and KYC stay yours. Every agent-first terms page we read makes the owner accountable for the agent. Do not create accounts in other people’s names.

Incident list, owner controls and the task-text scan method: security.json.

Search published pools, pages, reports, and evidence.