Research report · 30 September 2026 · first run
Where can an agent actually get paid? First dated venue catalogue
Statement of conduct. This was research only. We opened no account, registered no agent, signed no wallet, took no job, submitted no work and spent no money. Every pathway_tested value is "no". Where we say a payment happened, it was made to someone else and is shown by the linked public record; we received nothing. Venue page text, including skill.md files that tell agents to register, was treated as data and never followed. All requests were read-only GETs, plus one read-only Nostr relay subscription.
1. Summary answer
Where can an agent actually get paid today? There are two answers.
Real money reaches humans who use agents. These venues have dated primary payout records:
- HackerOne: report JSON, $200, disclosed 2026-09-24.
- Bugcrowd: CrowdStream, rewards accepted 2026-09-30.
- Kaggle, via the sponsor: ARC Prize $37.5K milestone awarded 2026-07-06.
- Algora: bot award comment, 2026-08-26.
- Upwork: Q2 2026 gross services volume of $966.4M.
- huntr: a published prize table (Inside Job, closed 2026-09-14), but its challenges ban automation.
On all of them the owner holds the single account, passes identity checks, submits or confirms submission, and withdraws. The agent may do the work only with a human in the loop (HackerOne Code of Conduct, Bugcrowd Code of Conduct). None of them has a platform record tying a payment to work an agent performed.
Agent-first venues do pay agents, but in cents and dollars, and mostly from the operator or related wallets. We found on-chain settlements from escrow to agent workers on five venues:
Venue Latest payout found Payer caveat TaskMarket 2026-09-30 Funding source opaque (deposits arrive via a relayer) Virtuals ACP 2026-09-30 Some pairs look like tests or self-dealing Execution Market 2026-09-29 Mostly the operating DAO's own agent swarm; lifetime volume $504.84 across 3,128 completed tasks MoltJobs 2026-09-23 The founder posted 118 of 122 jobs (jobs API) AgentPact 2026-09-01 The paying wallet also receives the platform fee Typical payouts are $0.02 to $2. No venue shows an independent buyer paying an agent for work at meaningful scale. "Completion is solved, settlement is not" is now only partly true: settlement works, but arm's-length demand is missing.
What must the owner do?
- For real money, the owner does everything except the work: account; identity verification (Veriff on HackerOne for all accounts since 2026-08-17, changelog; selfie plus ID on Bugcrowd since May 2026, changelog; Stripe Connect KYC on Algora, huntr and NEAR's USD rail); tax forms; submit or confirm; withdraw.
- On agent-first boards the agent can do most steps itself. The owner's remaining jobs are:
- provide and secure a wallet. Execution Market requires a self-custody signing wallet and rejects API keys (skill.md).
- claim or verify the agent: MoltJobs email claim; Superteam human claim plus KYC (skill.md); Moltbook email plus an X post.
- accept legal responsibility. Every agent-first ToS we read makes the owner accountable, e.g. dealwork.ai, MoltJobs, NEAR, The Colony.
2. Key numbers
The catalogue has 33 records: 16 full Tier 1 records and 17 light Tier 2 records, covering all four categories plus one speculative venue.
| Evidence level | Count | Venues |
|---|---|---|
| E1 Confirmed payout | 12 | HackerOne, Bugcrowd, huntr, Kaggle, Algora, Upwork, x402 (as a mechanism), Virtuals ACP, TaskMarket, MoltJobs, Execution Market, AgentPact |
| E2 Funded tasks visible (as the highest level) | 0 | TaskMarket, MoltJobs and Execution Market also have funded open tasks today, but they are already E1 |
| E3 Listed but unfunded | 5 | dealwork.ai, opentask.ai, ugig.net, Superteam Earn, toku.agency |
| E4 Platform claim only | 6 | NEAR AI Agent Market, MCP Hive, Stripe MPP/MCP monetisation, TheJobCafe, HYRVE AI, iLands (speculative) |
| E5 Paused | 1 | ClawTasks |
| E6 Inactive | 2 | Moltlaunch, BotBounty |
| Community (no E-level) | 7 | Active: Moltbook, cq (Mozilla.ai), The Colony, Clawstr, Agent4Science, 4claw. Inactive or unreachable: MoltX |
- AgentPactagent work paid
- Execution Marketagent work paid
- MoltJobsagent work paid
- TaskMarketagent work paid
- Virtuals ACPagent work paid
- Algorapays humans
- Bugcrowdpays humans
- HackerOnepays humans
- huntrpays humans
- Kagglepays humans
- Upworkpays humans
- x402mechanism
None at this level as the highest level. TaskMarket, MoltJobs and Execution Market also have funded open tasks today, but they already reach E1.
- dealwork.ai
- opentask.ai
- Superteam Earn
- toku.agency
- ugig.net
- HYRVE AI
- iLands
- MCP Hive
- NEAR AI Market
- Stripe MPP
- TheJobCafe
- ClawTasks
- BotBounty
- Moltlaunch
- E1 overall: 12 of 26 paid-work or selling venues. Six of these pay humans (HackerOne, Bugcrowd, huntr, Kaggle, Algora, Upwork).
- E1 with agent-work payout evidence = yes: 5. These are TaskMarket, MoltJobs, Execution Market, Virtuals ACP and AgentPact. All payouts are small. On MoltJobs and AgentPact the observed payer is the operator. On Execution Market volume is mostly inside the operator's DAO. On TaskMarket and ACP the payer's independence is unknown.
- E1 for agent work paid by a demonstrably independent payer: 0.
- Judgement calls made during verification:
- HackerOne agent-work evidence set to "unknown". Only operators' own claims exist: the XBOW founder via CyberScoop said earnings were below compute cost, and rez0's July 2026 post doesn't name the platform per bounty.
- x402 agent-work evidence set to "unknown". The mechanism is proven, but it isn't shown that sellers are agents or that buyers are independent.
- TheJobCafe moved from E1 to E4. Its only evidence is a self-reported feed of two $10 payouts, most likely to itself (payouts API).
- An added field,
independent_payer_evidence(yes / no / unknown / n/a), records whether the observed payer is independent of the operator. It extends the planned field set and is provisional.
3. The three most practical starting routes today
All three are untested by this pool. Owner checklists are on Getting started.
The agent does the work and the owner submits, on programs that allow AI assistance (security and data competitions).
- HackerOne and Bugcrowd pay real money and explicitly allow hackbots or GenAI if a human validates every finding and submits it from a single ID-verified account. HackerOne: "Hackbots must not operate in a fully autonomous manner… Human operators of Hackbots qualify for any applicable bug bounty rewards" (Code of Conduct). Bugcrowd: "Automated or unverified outputs are not accepted as valid submissions" (docs).
- Kaggle rules allow automated ML tools (ARC Prize 2026 rules; quoted from search-result text because the page needs JavaScript). ARC-AGI-3 is itself an agent competition with an $850k pool.
- Owner steps: account, identity verification or tax forms, review, submit, withdraw.
- Downsides: heavy competition, and rules that keep tightening.
An autonomous agent with its own wallet on an escrow board: TaskMarket. It is the most active agent-first board we checked.
- Eight open tasks today each have an on-chain escrow transaction, and payouts to agent workers happened today.
- Agents are explicitly permitted (ToS, task API). No KYC was found.
- The owner accepts a four-document legal bundle and approves a withdrawal address. The fee is 7.5%.
- Rewards are mostly 2 USDC against a median of about 69 submissions per task, so treat it as a proving ground, not income.
- Alternative: Execution Market (13% fee, $0.02 tasks), if the owner can provide a self-custody signing wallet.
Sell a narrow service per call through an x402 endpoint (or an ACP job offering).
- It needs no permission, and USDC settles straight to the seller's address (Coinbase seller quickstart).
- The Coinbase CDP facilitator is free up to 1,000 transactions a month, then $0.001 per transaction (facilitator docs).
- On-chain settlements to sellers are visible today (x402scan).
- Demand is the gap: about $963K over 30 days across 38,158 sellers and 23,259 buyers, with wash-like patterns among top sellers.
- Owner steps: a CDP developer account (if using Coinbase's facilitator), hosting and a wallet.
4. Top warnings
Autonomous submission gets owners banned on venues that pay humans.
- HackerOne forbids fully autonomous hackbots and allows one account per person.
- Bugcrowd suspends accounts for 30 days for unvalidated AI output and bans submission farming permanently (blog, 2026-03-10).
- huntr challenges say: "Humans only… Any automated tooling gets you banned and your standings wiped" (rules).
- Upwork: "If we detect that you're using unapproved automation it will result in a warning, a temporary account restriction, or a permanent block" (help article).
- Algora's ToS: "Use any robot, spider, or other automatic device, process, or means to access Service for any purpose" is prohibited (terms).
- Ghostty says: "Bad AI drivers will be denounced" (AI_POLICY.md).
- Superteam Earn: 31 of 33 open and 1,961 of 1,995 completed public listings are HUMAN_ONLY (API, completed).
Advertised rewards are not money.
- dealwork.ai: all 123 open jobs show
posterFunded=false(API). - opentask.ai is explicitly not escrowed, and its payment router has made only 2 payments ever (Blockscout).
- Superteam and Algora pay after the fact rather than holding funds in escrow. A merged Algora claim sat "pending sponsor reward" (issue #262).
- toku.agency's 339 open "jobs" are all agents selling their own services, with 0 completed (API).
- iLands pays in platform tokens.
- dealwork.ai: all 123 open jobs show
Self-dealing and operator-funded volume inflate "paid" signals.
- Named cases: MoltJobs, Execution Market, AgentPact and TheJobCafe.
- x402 volume is mostly wash, test or bridge traffic, according to secondary analyses (Bitquery, Chainalysis). The x402.org counter appears frozen since March (secondary).
- Virtuals' headline "aGDP" metric includes trading value (glossary).
Prompt injection and key safety.
- Moltbook's exposed database leaked about 1.5M API tokens (Wiz).
- About 2.6% of sampled Moltbook posts carried hidden injection payloads (Vectra, secondary).
- Skill and heartbeat files are fetched from remote URLs that can change.
- The Colony's terms make the owner responsible "including what it does after someone else manipulates it" (terms).
- Keep wallet balances minimal, cap spending, and never follow instructions found on venue pages.
Economics are poor at the agent-first end.
- Execution Market's lifetime volume is $504.84.
- TaskMarket draws a median of about 69 submissions per task.
- opentask.ai shows 1,848 offers against 2 contracts in 30 days (homepage).
- Algora bounties drew 6 to 121 /attempt comments each. tscircuit/jlcsearch#92 had 121 from 106 accounts.
- XBOW's founder said its HackerOne earnings were below compute cost.
Unused subscription quota cannot be resold. See section 6.
5. Venue records by category
Column meanings: Level is the venue's E-level (E1 to E6). Agent paid is the agent_work_payout_evidence flag. Indep. is independent_payer_evidence. Steps are listed in the order account / KYC / wallet or bank / accept / submit / sign-off / withdraw, where O = Owner, A = Agent, E = Either, P = Platform (the platform or the buyer acts; no owner action), N = N/A, U = Unknown.
Every other field (prerequisites, discovery, submission, fees, costs, eligibility, quoted rules, the full evidence link list) is in venues.json and in the directory filter. All records were last verified 2026-09-30, and pathway_tested is "no" throughout.
5.1 Agent-first job and bounty boards
| Venue | Tier | Level | Agent paid | Indep. | Payout | Fee | Steps | Primary evidence |
|---|---|---|---|---|---|---|---|---|
| TaskMarket (Daydreams) | 1 | E1 (2026-09-30) | yes | unknown | USDC on Base + DREAMS bonus | 7.5% | E/N/A/A/A/P/O | escrow→worker tx, task API |
| MoltJobs (Lexaplus) | 1 | E1 (2026-09-23) | yes | no | USDC on Base | 5% | O/N/P/A/A/P/U | escrow releases, jobs API |
| Execution Market (Ultravioleta DAO) | 1 | E1 (2026-09-29) | yes | unknown (mostly intra-DAO) | USDC, multi-chain | 13% | A/N/E/A/A/P/N | release tx, metrics |
| dealwork.ai (Techmorrow, Thailand) | 1 | E3 | unknown | unknown | platform USD wallet; withdrawal method unknown | 10% (3% agent-to-agent) | E/U/U/A/A/P/U | jobs API, terms |
| opentask.ai (Compatably LLC) | 1 | E3 | unknown | unknown | USDC wallet-to-wallet, no escrow | 4.5% | E/N/E/A/A/P/N | tasks API, router |
| ugig.net (Profullstack) | 1 | E3 | unknown | unknown | crypto via CoinPay | undisclosed "service fees" | A/N/E/A/A/P/N | bounties API, PR #550 payout bugs |
| Superteam Earn (SuperteamDAO) | 1 | E3 | unknown | unknown | USDC/USDG on Solana | none found | O/O/O/N/A/P/O | listings API, skill.md, stats source code |
| NEAR AI Agent Market (NEAR AI Marketplace Inc.) | 1 | E4 | unknown | unknown | USD (Stripe) or USDC | 5% | O/O/O/A/A/P/O | platform stats, builder agreement |
| AgentPact | 2 | E1 (2026-09-01) | yes | no | USDC on Base | 10% | A/U/E/A/A/P/N | escrow |
| toku.agency | 2 | E3 | unknown | unknown | fiat (Stripe Connect) | 15% | A/U/O/A/A/U/O | jobs API |
| TheJobCafe | 2 | E4 (downgraded) | unknown | no | fiat, arranged by email | unknown | A/U/O/A/A/P/O | payouts feed, open bounties: 0 |
| HYRVE AI | 2 | E4 | unknown | unknown | fiat or stablecoin | 15% | O/U/O/A/A/P/O | jobs: 0 |
| ClawTasks (AI Magic LLC) | 2 | E5 | unknown | unknown | none (free tasks only) | 5% (historical) | A/U/A/A/A/P/N | homepage wind-down notice |
| Moltlaunch | 2 | E6 | unknown | unknown | ETH, agent tokens | "zero fees" claim | A/U/A/A/A/P/N | escrow, last tx 2026-04-13 |
| BotBounty | 2 | E6 | unknown | unknown | claimed USDC/ETH | unknown | U/U/U/A/A/U/U | 0 live / 0 completed; backend returns HTTP 500 |
Notes on the Tier 1 boards:
- TaskMarket. The ToS still contains unfilled jurisdiction placeholders. The top requester posted 54 of the last 240 tasks. The agent connects through a CLI that creates a Base wallet, and the owner must approve a withdrawal address. ToS: "'You' includes that person and every software agent you authorize to use the Services." Walkthrough.
- MoltJobs. Of today's 10 open jobs, all are 0.20 USDC referral bounties. Payouts go to wallets the platform provisions (Turnkey). Withdrawal to an external address is unverified. ToS: "An agent must have a human or organizational owner who is accountable for its actions."
- Execution Market. The agent needs a self-custody wallet that can sign each request (ERC-8128); API keys are disabled. World ID is required for tasks of $500 or more. Only 3 open tasks today, all $0.02.
- dealwork.ai. The last completed job seen was on 2026-07-17. The homepage claims 233 open tasks, but the API shows 123. Many "jobs" are agents advertising their own services.
- opentask.ai. Over 30 days: 15 tasks, 1,848 offers, 2 contracts. The only routed payment (20 USDC, 2026-09-14) cannot be tied to a task.
- ugig.net. Recent "hiring" gigs are dominated by $0 virtual-card spam. Bounties are $0.01 to $5, many of them engagement farming. No escrow fields appear in the API.
- Superteam Earn. The public "$15.94M earned" figure is computed from announced winners, not payments. Agents cannot pass KYC, so a human must claim them to be paid. Agent-allowed bounties drew 17 to 553 submissions.
- NEAR AI Agent Market. Relaunched as "agent.market". The job board needs a login. The platform claims 266 delivered jobs, but settlement runs on an off-chain ledger, so it cannot be verified.
5.2 Ordinary services: the agent works, the owner signs off
| Venue | Tier | Level | Agent paid | Payout | Fees to worker | Ban risk | Steps | Primary evidence |
|---|---|---|---|---|---|---|---|---|
| HackerOne | 1 | E1 (2026-09-24) | unknown | PayPal, bank, BTC/USDC ($15 minimum for crypto) | none found; SWIFT and BTC fees | medium | O/O/O/O/O/P/O | report JSON, payment preferences |
| Bugcrowd | 1 | E1 (2026-09-30) | unknown | bank or PayPal (BTC for select researchers) | unknown | medium | O/O/O/O/O/P/O | CrowdStream, payment methods |
| huntr (Palo Alto Networks) | 1 | E1 (2026-09-14, prize table) | no | Stripe Connect, monthly | unknown | high | O/O/O/O/O/P/O | leaderboard, participation terms |
| Kaggle (Google) | 1 | E1 (2026-07-06, sponsor award) | unknown | fiat (payment rail unknown) | none found | low | O/O/O/O/E/P/O | ARC Prize award, rules |
| Algora / GitHub bounties (Algora PBC) | 1 | E1 (2026-08-26) | unknown | fiat via Stripe Connect | charged to the sponsor (9% community tier in code) | high | O/O/O/E/E/P/O | award comment, autopay docs |
| Upwork via MCP | 1 | E1 (aggregate GSV to 2026-06-30) | unknown | fiat | 0% to 15% freelancer fee | high | O/O/O/O/E/P/O | SEC 8-K, MCP launch |
Notes:
- HackerOne. It sells its own AI tools (Hai), so its policy messaging is partly marketing. Severity ratings are mandatory from 2026-09-21. The Internet Bug Bounty was paused on 2026-03-27 and its rates were cut in May (The Register). curl ended its bounty on 2026-01-31. 10 of 30 recent paid reports carry
submitted_with_assistant=true, which indicates AI-assisted report writing, not agent discovery. - Bugcrowd. Its code of conduct requires: "You manually review and validate any vulnerability report you've created with the help of GenAI tools before submitting it."
- huntr. The OSS bug bounty closed on 2026-07-31 (2.0 FAQ). Only the Model File Format program remains open, and no AI clause was found for it.
- Kaggle. Rules text: "may use automated machine learning tool(s) ('AMLT')… provided that the Participant or Team ensures that they have an appropriate license", plus a single-account rule. Quotes come from search-result text and need re-checking in a browser.
- Algora. Bounties are charged when rewarded, not held in escrow up front. It has repositioned mainly as a hiring platform. Its terms were last updated 2021-08-17. No September 2026 award comment was found, but GitHub search indexes bot comments poorly.
- Upwork. The MCP server launched on 2026-08-10. Upwork frames agents as acting for human clients and freelancers, not as hireable workers. The "API and MCP Terms of Use" text could not be fetched (HTTP 403). The CEO says agents posting jobs are "not very good at it today" (Semafor).
5.3 Service-selling mechanisms
| Mechanism | Tier | Level | Agent paid | Payout | Fees | Steps | Primary evidence |
|---|---|---|---|---|---|---|---|
| x402 per-call endpoints (x402 Foundation; Coinbase CDP and Circle facilitators) | 1 | E1 (2026-09-30) | unknown | USDC direct to seller | CDP: 1,000 free per month, then $0.001 per transaction | E/U/E/N/N/P/N | x402scan, seller settlements, CDP facilitator, Circle nanopayments |
| Virtuals ACP v2 (Virtuals Protocol) | 1 | E1 (2026-09-30) | yes | USDC escrow on Base | 5% protocol, plus 5% if an evaluator is used | E/U/A/A/A/P/A | release tx, ACP Core, concepts |
| MCP Hive | 2 | E4 | unknown | fiat via Stripe Connect, monthly | "confidential" | O/O/O/N/N/P/P | terms, 70 listings |
| Stripe MPP / monetise an MCP server | 2 | E4 | unknown | fiat or stablecoin | standard Stripe fees | O/O/O/N/N/P/O | docs ("experimental") |
Notes:
- x402. The x402scan operator (Merit Systems) is reportedly a member of the x402 Foundation. Per-call prices seen range from $0.002 to $0.28. One top seller, three.ws, logged 33K transactions from only 2 buyers.
- Virtuals ACP. v1 memo activity has collapsed to about 17 a day (secondary). The Revenue Network incentive programme can inflate activity.
5.4 Speculative
- iLands (PawLogic Inc.), Tier 2, E4. Its bounty board pays platform tokens. The homepage's USD anecdotes are unproven. A 37-day log reports zero agent deliveries (secondary).
5.5 Communities (unpaid; activity status instead of an E-level)
| Community | Activity | Operator and ties | How an agent joins | Evidence |
|---|---|---|---|---|
| Moltbook | active (50 posts in about 10 minutes) | Moltbook LLC per ToS; acquired by Meta on 2026-03-10; the unofficial MOLT memecoin has no payout route | skill.md, then API registration, then owner email plus an X post | posts API, terms, Wiz incident |
| cq (Mozilla.ai) | active (repo commits 2026-09) | Mozilla.ai; Apache-2.0; no token | CLI plugin plus local MCP server; owner signs in with GitHub or Google for the hosted service | docs, commits |
| The Colony | active | Starsol Ltd (UK); 5% cut of document sales | API registration without CAPTCHA, or MCP; Lightning tips and paid_task posts, mostly offers of services | posts API, marketplace, terms |
| Clawstr | active on Nostr relays | Open source (Alex Gleason); CLAWSTR memecoin tie known only from secondary sources | CLI generates a Nostr key and Cashu wallet; no registration | SKILL.md, repo |
| Agent4Science | active | CHAI Lab, University of Chicago | skill.md, then unauthenticated agent creation | papers API, about |
| 4claw | active | developer "dailofrog" | skill.md plus API key; X claim optional | homepage |
| MoltX | inactive or unreachable | unknown; pivoted toward DeFi and token skills | previously skill.md plus a claim via X post | DNS: no A records, skill.moltx.io |
6. Spare capacity: resale and sharing terms (quoted; accessed 2026-09-30)
Three things to keep apart: inference work is the agent performing a task that someone pays for (sections 5.1 to 5.3); compute rental is renting out GPU or CPU hardware; subscription resale is letting others use your plan, which the terms forbid. Using your own subscription or API key so that your agent does work for a third party is not resale in itself. But subscription limits are not transferable compute.
Anthropic
- Consumer Terms, effective October 8, 2025 (link): "To develop any products or services that compete with our Services… or resell the Services." · "You may not share your Account login information, Anthropic API key, or Account credentials with anyone else. You also may not make your Account available to anyone else." · Prohibited: "Except when you are accessing our Services via an Anthropic API Key or where we otherwise explicitly permit it, to access the Services through automated or non-human means, whether through a bot, script, or otherwise."
- Commercial Terms, effective June 17, 2025, D.4 (link): "Customer may not and must not attempt to (a) access the Services to build a competing product or service, including to train competing AI models or resell the Services except as expressly approved by Anthropic."
- Claude Code legal and compliance page (link): "Customers may not pay for, resell, or intermediate Claude usage on their end users' behalf." · "Anthropic does not permit third-party developers to offer Claude.ai login into their own applications, or to route requests through Free, Pro, or Max plan credentials on behalf of their users." · "Advertised usage limits for Pro and Max plans assume ordinary, individual usage of Claude Code and the Agent SDK."
OpenAI
Primary pages returned HTTP 403; the text below comes from search-engine results for those URLs and must be re-verified.
- Terms of Use (link): "You may not share your account credentials or make your account available to anyone else."
- Services Agreement and Business Terms (link): the customer will not "(g) buy, sell, or transfer API keys from, to, or with a third party"; and "You may not make account access credentials available to third parties, share individual login credentials between multiple users on an account, or resell or lease access to your account or any End User Account."
- Help Center (link): "Your OpenAI account is meant for you—the individual who created it."
- Google APIs Terms of Service, last modified November 9, 2021, §4(a) (link): "Sublicense an API for use by a third party. Consequently, you will not create an API Client that functions substantially the same as the APIs and offer it for use by third parties."
- Gemini API Additional Terms, effective March 23, 2026 (link): the resale ban found covers only Grounding with Google Search results.
GPU rental reality
GPUnex, itself a GPU-rental vendor, estimates: "A single RTX 4090 can net $52/month after electricity, depreciation, and platform fees at typical utilization rates", and says hidden costs take 30% to 65% of gross, with high-electricity regions likely unprofitable (GPUnex, 2026-02-01).
Open question for a later run: none of these terms directly addresses running a 24/7 autonomous agent on a consumer subscription to do paid work for third parties. The Claude Code "ordinary, individual usage" line and the consumer automated-access clause are the relevant texts. This is not legal advice.
7. Methodology and limits
- Method. 22 planned venues, plus extras found along the way, were split across six parallel research passes, all following a written evidence spec; the resale-terms capture was done separately. Three key checks were re-run directly: the TaskMarket settlement transaction, Execution Market's metrics, and the TaskMarket task API. Evidence came from public JSON APIs (task lists, payout feeds), public on-chain explorers (Blockscout; basescan returned 403), ToS and docs pages, GitHub, and search engines. Aggregators were used only for discovery: awesome-molt-ecosystem, "Did it pay?", awesome-agent-bounties, DEV field reports.
- Level rules applied. E1 requires a primary record of a completed payment, and the date of the latest one found is given. For Kaggle and huntr, E1 rests on sponsor or program award announcements, not payment receipts. Upwork's E1 rests on aggregate SEC-reported gross services volume. These are flagged in their records. Communities have no E-level.
- Limits. All data is a single-day snapshot. Several venues are JavaScript apps or need a login to list jobs: NEAR's job board, Superteam's AGENT_ONLY feed, HackerOne Hacktivity (needs POST), Kaggle's rules. The OpenAI and Upwork terms pages returned 403. On-chain evidence proves that a transfer happened, not who is behind a wallet; independence of payers is mostly unknown. Step values were normalised to the seven-step enum, with the original prose kept in
steps_notes. Reddit and X were not searched.
Fetch failures and access limits (all 2026-09-30)
- basescan.org: HTTP 403. base.blockscout.com and arbitrum.blockscout.com were used instead.
- hire-rook.netlify.app (the "Did it pay?" tracker): now serves unrelated content.
- TaskMarket /llms.txt, /openapi.json, /api/stats: 404. dealwork.ai /llms.txt and /api/v1/stats: 404; /api/v1/contracts: 401. opentask.ai /api/v1/tasks and /openapi.json: 404. moltjobs.io /api/jobs: 404 (the working endpoint is api.moltjobs.io/v1/jobs).
- market.near.ai: the job board (/v1/jobs/board) returns 401 and HTML pages are a JavaScript app. The JSON API, llms.txt and SKILL.md were readable.
- api.execution.market /api/v1/payments/events: 401.
- earn.superteam.fun /api/agents/listings/live: 401 (needs an agent key; not registered). earn.superteam.fun/skill.md: 404 (the skill is at superteam.fun/skill.md). /earn/terms-of-use: 404.
- HackerOne Hacktivity and leaderboards: 406, or GraphQL POST required (not done).
- huntr.com /guidelines, /terms, /bounties, /leaderboard: 404.
- kaggle.com terms, rules and leaderboards are rendered by JavaScript, so rule quotes come from search-engine text.
- darkreading.com (HackerOne pause article): 403.
- algora.io /bounties, /pricing, /llms.txt and /api/orgs/*/bounties: 404. api.docs.algora.io: TLS error.
- upwork.com (/ai/mcp, /legal, press) and support.upwork.com HTML: 403. Help-centre text was read through the public Zendesk JSON API. The "Upwork API and MCP Terms of Use" document was not retrieved.
- x402scan.com: stats were read from the page's embedded JSON. The x402scan data API is x402-paywalled and was not used.
- whitepaper.virtuals.io (old ACP pages, protocol metrics): 404. app.virtuals.io/acp showed no stats. The Dune dashboard was not fetched.
- api.moltlaunch.com: DNS resolves to 100:: (unreachable). moltlaunch.com/agents shows "No agents yet".
- BotBounty backend: HTTP 500 on all endpoints.
- clawtasks.com /api/bounties, /api/feed, /api/leaderboard: HTTP 500.
- toku.agency /api/jobs: 401. /api/agents/jobs?status=AWARDED: 500. /llms.txt: 404.
- agentpact.io (a different product with the same name): the marketplace did not render.
- moltx.io: no A/AAAA records; social.moltx.io and www.moltx.io: NXDOMAIN (checked via dns.google). A Wayback snapshot was read instead.
- nature.com Agent4Science article: redirects to login, so the RePEc listing was used.
- clawnews.io: TLS certificate mismatch.
- 4claw /api/v1/boards: 401.
- cq.exchange: the JavaScript app serves the same page for every path.
- Reddit and X: not searched in this run.
- cryptobriefing.com TaskMarket article: not fetched; its stats come from search-result text only.
8. Backlog (found, not verified)
- Agent-first boards: molt-jobs.com (unrelated to moltjobs.io), Molt for Hire (moltforhire.com), MoltMarket (moltmarket.store), AgentGig (agentgig.xyz, $CLAW token), TaskBounty (task-bounty.com), OpenWork (openwork.bot, token stake), AgentBazaar (Solana), DeskCrew (deskcrew.io), AgentMarket on Base (useagentmarket.xyz), trybounty.ai, JobForAgent (jobforagent.com), BountyBot Network (bountybot.network), owockibot bounty board (bounty.owockibot.xyz), agent-bounty-jobs and clawdbotatg agent-bounty-board (GitHub), agenticjobs (feeds ugig), agentpact.io (a different product with the same name), agdp.io / bounty.virtuals.io, Beelancer.ai, BountyBook, Minia2a, nullpath, UpAgents.
- Selling: MCPize (mcpize.com), MuleRun Creator Studio (mulerun.com/creator), Circle Agent Marketplace, claw402 (possible wash traffic), CoinPayPortal (the escrow rail behind ugig).
- Ordinary services: Intigriti, YesWeHack, Google VRP (reportedly stopped accepting AI reports in March 2026, unverified), the OpenAI bug bounty on Bugcrowd, the Anthropic program on HackerOne, ARC Prize 2026 Milestone #2 results (deadline 2026-09-30), Kaggle "Autonomous Agent Prediction (Beta)", Opire (opire.dev), UnsafeLabs/Bounty-Hunters and SecureBananaLabs/bug-bounty (Algora-bot repos; legitimacy to check), Scottcjn/rustchain-bounties (RTC token).
- Communities: ClawNews (clawnews.io, TLS error; has a job board), Chirper.ai, Agents4Science conference (Stanford), Lobchan, AgentDiscuss, Agent Commune, OpenClawCity, and the moltsbooks.com lookalike (treat as untrusted).
9. Open questions per Tier 1 venue
- TaskMarket
- Who funds relayer 0x3C0820e2 (x402 facilitator or platform-seeded tasks)? Is the top requester's creative bounty stream platform-funded? What is the legal entity and jurisdiction (the ToS has placeholders)? Has any worker withdrawn to an external address?
- MoltJobs
- Can agents withdraw from Turnkey-provisioned wallets, and has anyone done it? Are there any non-founder buyers with paid completions? What are Lexaplus's entity details?
- Execution Market
- What share of paid volume goes to executors outside the Ultravioleta/KarmaCadabra swarm? Has any task above $1 been paid to an external agent? Is the escrow implementation audited?
- dealwork.ai
- What are the withdrawal methods and minimums? Is any external payout verifiable? Is the poster "Nimbus" affiliated with the operator?
- opentask.ai
- Which contract does the 2026-09-14 routed payment belong to, and was the seller an agent? Are any funded competitions live?
- ugig.net
- Is any payment escrowed through CoinPay? Is there any public record of paid bounties or invoices? Did the $0.25 agent invoice in PR #554 settle?
- Superteam Earn
- Is there any public payment transaction or isPaid record for winners? How many AGENT_ONLY listings are live (the feed is auth-gated)? Has any agent-originated submission been paid after a human claim?
- NEAR AI Agent Market
- Are delivered jobs funded by third parties or by affiliated accounts? Is the owner of about 10 top agents (fa83070f) the operator? What are the open job count and budgets (needs an account)?
- HackerOne
- What exactly does
submitted_with_assistantmean? Is there any disclosed report with a bounty credited to a hackbot account (needs a GraphQL POST)? Does the one-account rule allow company-operated hackbot accounts? - Bugcrowd
- What are the payout minimums and fees? What do the Platform Behavior Standards say about company-operated accounts? Is any submission credited to a hackbot?
- huntr
- What are the MFV reward table and AI rules? Is there any confirmation that challenge prizes were paid? When was the last paid OSS bounty?
- Kaggle
- What do the Kaggle ToS clauses on bots and automation say verbatim? Is there identity verification or a known payment rail for prize winners? Has any cash finish been achieved where an autonomous agent did the work end to end?
- Algora
- Is there a global bounty list or API now (the old endpoints return 404)? Is the effective fee 9% or 4%? Can agent-operated GitHub accounts claim, given the ToS robot clause? Has any maintainer confirmed payment for an AI-agent-authored PR?
- Upwork (MCP)
- What does the API and MCP Terms of Use say verbatim? Are AI-performed deliverables and disclosure allowed under a human account? Is there any documented paid case?
- x402
- Does the CDP facilitator account require KYC for mainnet sellers? What share of seller revenue comes from independent buyers? What are the Circle Agent Marketplace seller requirements?
- Virtuals ACP
- How many v2 jobs have completed, and how much USDC has been released since April 2026 (Dune dashboard not checked)? How much is self-dealing or Revenue Network farming? Is the incentive paid in VIRTUAL or USDC?
Appendix: owner-step matrix
The step letters from section 5, drawn as a matrix for all 26 paid-work and selling venues.
| Venue | Account | Identity / KYC | Wallet or bank | Accept task | Submit | Sign-off / review | Withdraw | Owner-only steps |
|---|---|---|---|---|---|---|---|---|
| dealwork.ai E3 | E owner or agent | ? unknown | ? unknown | A agent | A agent | P platform or buyer | ? unknown | 0 |
| Execution Market E1 | A agent | – not applicable | E owner or agent | A agent | A agent | P platform or buyer | – not applicable | 0 |
| MoltJobs E1 | O owner | – not applicable | P platform or buyer | A agent | A agent | P platform or buyer | ? unknown | 1 |
| NEAR AI Market E4 | O owner | O owner | O owner | A agent | A agent | P platform or buyer | O owner | 4 |
| opentask.ai E3 | E owner or agent | – not applicable | E owner or agent | A agent | A agent | P platform or buyer | – not applicable | 0 |
| Superteam Earn E3 | O owner | O owner | O owner | – not applicable | A agent | P platform or buyer | O owner | 4 |
| TaskMarket E1 | E owner or agent | – not applicable | A agent | A agent | A agent | P platform or buyer | O owner | 1 |
| ugig.net E3 | A agent | – not applicable | E owner or agent | A agent | A agent | P platform or buyer | – not applicable | 0 |
| Algora E1 | O owner | O owner | O owner | E owner or agent | E owner or agent | P platform or buyer | O owner | 4 |
| Bugcrowd E1 | O owner | O owner | O owner | O owner | O owner | P platform or buyer | O owner | 6 |
| HackerOne E1 | O owner | O owner | O owner | O owner | O owner | P platform or buyer | O owner | 6 |
| huntr E1 | O owner | O owner | O owner | O owner | O owner | P platform or buyer | O owner | 6 |
| Kaggle E1 | O owner | O owner | O owner | O owner | E owner or agent | P platform or buyer | O owner | 5 |
| Upwork E1 | O owner | O owner | O owner | O owner | E owner or agent | P platform or buyer | O owner | 5 |
| Virtuals ACP E1 | E owner or agent | ? unknown | A agent | A agent | A agent | P platform or buyer | A agent | 0 |
| x402 E1 | E owner or agent | ? unknown | E owner or agent | – not applicable | – not applicable | P platform or buyer | – not applicable | 0 |
| AgentPact E1 | A agent | ? unknown | E owner or agent | A agent | A agent | P platform or buyer | – not applicable | 0 |
| BotBounty E6 | ? unknown | ? unknown | ? unknown | A agent | A agent | ? unknown | ? unknown | 0 |
| ClawTasks E5 | A agent | ? unknown | A agent | A agent | A agent | P platform or buyer | – not applicable | 0 |
| HYRVE AI E4 | O owner | ? unknown | O owner | A agent | A agent | P platform or buyer | O owner | 3 |
| Moltlaunch E6 | A agent | ? unknown | A agent | A agent | A agent | P platform or buyer | – not applicable | 0 |
| TheJobCafe E4 | A agent | ? unknown | O owner | A agent | A agent | P platform or buyer | O owner | 2 |
| toku.agency E3 | A agent | ? unknown | O owner | A agent | A agent | ? unknown | O owner | 2 |
| MCP Hive E4 | O owner | O owner | O owner | – not applicable | – not applicable | P platform or buyer | P platform or buyer | 3 |
| Stripe MPP E4 | O owner | O owner | O owner | – not applicable | – not applicable | P platform or buyer | O owner | 4 |
| iLands E4 | O owner | ? unknown | ? unknown | A agent | A agent | ? unknown | ? unknown | 1 |
- O Owner
- A Agent
- E Either
- P Platform or buyer (no owner action)
- – Not applicable
- ? Unknown
10. Statement
No account was opened, no agent registered, no wallet signed, no job taken, no work submitted and no money spent in this run. Every pathway is untested. All payouts cited were made to third parties and are shown only by the linked public records.