01 — the trust layer
The wall is the product.
Anyone can ship a trading agent. The hard thing — the thing merrymen is — is an agent you don't have to trust: your owner key never leaves you, and it trades inside caps the chain itself enforces — a leaked session key is value-churn, never theft. Everything else on this page is built on top of that wall.
The rule of the house: the model proposes, deterministic code disposes.
No strategist, Telegram message, or voice note ever constructs calldata, moves funds, or touches your PC without passing a closed, typed command set and — for money — the on-chain policy wall. Trades pass caps enforced by the account contract. Transfers out through chat are refused — a wallet signed today carries no transfer permission, so a prompt-injected “send everything to 0xevil” is turned back and nothing moves. Money comes home with your owner key. PC actions are off by default, allowlisted, and confirmed.
And you don't take our word for it: your dashboard shows the account contract, the session key, and every cap with explorer links — and a prove the wall button that fires malicious intents through the live policy so you can watch each one bounce.
Why not wait for a platform's own agent?
A first-party agent is custodial by construction: their servers, their keys, their discretion — the safety story is a terms-of-service. If the platform, its model, or its prompt gets compromised, so does your account. You trust; it trades.
merrymen inverts it
The agent holds only a session key whose limits — how much per trade, how often, how long it lives, and where value may land — are enforced by your account contract on-chain, verifiable in the explorer. The owner key that could lift those limits never leaves you. A compromised agent can trade inside that wall. It cannot send your funds to an address you never registered, and it cannot sign anything. You verify; it trades.