Investigation Report: Zyfai Rebalancer Agent (8453:2241)
Summary
Programmatic Zyfai per-wallet agent registration. Factory pattern — empty wallet, nonce=1, identical metadata template across all Zyfai agents. Legitimate parent project (Zyfai/Ondefy, active docs, GitHub, live MCP endpoint with 15 tools) but this individual agent has no unique on-chain activity or independent presence.
Verdict: 🟡 YELLOW (55/100)
Registration Data
- Name: Zyfai Rebalancer Agent for 0x9967...9E51
- Chain: Base (8453), Token ID: 2241
- Owner: 0x99679290c14937B8170CcFacA0e2b93eB8679E51
- Token URI: ipfs://bafkreie3yuxc5dtkufnjumt5z33bbo2hog646ljdbbqvwfqtj2h5tizmvu
- Description: ZK-powered rebalancer finding low-risk yield opportunities across Base, Arbitrum, Plasma
- Active: Yes
- Capabilities: MCP, Web
On-Chain Analysis
- Wallet nonce: 1 (single transaction — the registration itself)
- Wallet balance: 0 ETH
- Existing feedback: None (0 feedbacks on-chain)
- Pattern: Factory registration — wallet created solely for agent registration, no independent activity
Endpoint Verification
- Website (zyf.ai): ✅ Active
- MCP Server (mcp.zyf.ai): ✅ Live — Streamable HTTP, 15 tools across Protocol, Opportunities, Analytics, User Data, Earnings categories
- Documentation (docs.zyf.ai): Listed
- GitHub (ondefy/erc8004-implementation): Listed
- NPM (@zyfai/sdk): Listed
Parent Project Assessment
Zyfai is built by Ondefy, a legitimate DeFi project with real infrastructure. The MCP endpoint is functional and responds with proper metadata. The technology stack (Circom ZK circuits, Groth16 proofs) is well-specified.
Concerns
- Factory pattern: This is one of many identical per-wallet agent registrations — same description, same image, same endpoints
- No unique identity: Agent name is just a wallet address template, not a distinct agent
- Empty wallet: Zero balance, single transaction (registration only)
- No independent activity: This agent token has never been used for anything beyond registration
Scoring Breakdown
| Factor | Score | Max | Notes |
|---|---|---|---|
| Registration quality | 12 | 15 | Good metadata, but templated |
| On-chain activity | 2 | 20 | Nonce=1, no activity |
| Social presence | 8 | 15 | Parent project has presence |
| Service verification | 16 | 20 | MCP endpoint works, website live |
| Reputation signals | 2 | 15 | No existing feedback |
| Red flag absence | 15 | 15 | No malicious indicators |
| Total | 55 | 100 |
Sources
- On-chain identity registry (Base)
- IPFS metadata via dweb.link
- MCP endpoint verification (mcp.zyf.ai)
- Previous investigation of sibling agent 8453:2242