A student audit of ‘Omo,’ an AI trading agent built on Solana (SOL), found that not a single one of the 174 order commitments recorded on-chain matched the wallet signatures Omo presented as its own. The project had once attracted attention by publicly showcasing a portfolio worth more than $200,000.

Key findings:

  • The student researcher verified one of Omo’s private (sealed) decisions and found that the on-chain transaction actually linked to it was a token transfer from a different wallet.

  • After reviewing all the data published by Omo, none of the 174 order agreements could be linked to a signature from the wallet identified by the agent.

  • The paper proposes using signing keys stored in hardware security devices, but the author cautions that hardware alone would not have prevented the agent’s other failures.

Student Audit Findings

**Charlie Sneed**, a member of the blockchain club at the University of Oregon in the United States, published an audit report on September 28 through a research competition hosted by hardware wallet maker **Ledger**. Ledger says it does not endorse the report’s findings. Sneed began his investigation when Omo’s dashboard was showing rapidly growing portfolio gains. Omo later halted trading and took its website offline.

Omo began operating on August 9 and traded mainly meme coins through August 31. Before placing each order, it recorded the decision-making process on the Solana blockchain as a cryptographic fingerprint in the form of a hash, then disclosed the full decision about 20 minutes later so anyone could compare and verify the two sets of data.

According to the project’s documentation, outsiders can perform four checks using only hash tools and public Solana nodes, following a verification guide published on GitHub. The fourth and final check is to confirm “whether the publicly disclosed Omo wallet actually signed the relevant transaction.” The documentation states that “if a signature from another key is found, the execution is disqualifying.” This was precisely the check that did not pass in this audit.

Sneed manually cross-checked the oldest agreement for which a trade had actually been linked. The on-chain transaction matched to the decision made on August 21 was a simple transfer of tokens to several addresses, including an Omo wallet, and there was no evidence that it could be considered a buy order signed by Omo. The signing wallet was also different from the Omo wallet identified by the project.

Related article: Tesla robotaxis restricted from operating after 11 p.m.… Musk’s “pet” challenge

Sneed’s criticism of “key management”

In his report, Sneed said that “the cryptographic structure itself worked as intended.” He explained that most of the problems he found were already apparent in the code, and that he found no evidence of deliberate fraud or false reporting. The startling statistic of zero out of 174 was also calculated using a data page published by Omo itself.

Sneed identified the real weak point as “custody”—the safekeeping of assets and keys. Omo operated by transferring a key copied from a mobile app to a server, and the code that matched executions also failed to properly verify wallet signatures. The analysis concludes that the system was designed in a way that inevitably created a structural gap between the “Omo orders” it claimed to execute and the actual signers on-chain.

He proposed three improvements, with the key recommendation being the “use of signing keys in a hardware security module directly controlled by the agent.” This is a type of product offered by hardware wallet makers such as Ledger. However, Sneed cautioned that “hardware keys alone would not have addressed the win rate (returns) of just 7.1%, or the web search feature that remained broken for days.” In other words, better key management is a “necessary condition,” but it does not guarantee the agent’s overall performance or manage its risks.

AI Agent Trading Risks Grow

Since the start of this year, major platforms have been opening their doors to AI and autonomous-agent trading one after another. Global crypto exchange giant **Binance** began allowing AI agents to trade on August 20. In an interview, **Jeff Li**, vice president of product, said, “The company itself can’t actually look into the ‘reasoning’ behind these agents’ orders.”

U.S. retail brokerage Robinhood also said that, as of September 29, more than 150,000 accounts had trades placed on their behalf by AI agents, while officially stating that it does not directly supervise or audit the agents. In its 2026 annual oversight report, the U.S. Financial Industry Regulatory Authority (FINRA) also identified “agent autonomy” and “auditability” as major concerns among risks related to generative AI.

As AI-agent-based trading spreads rapidly, the Solana Omo case is being viewed as a stark illustration of the structural risks of entrusting assets to autonomous agents without adequate systems for key management and signature verification, consistency between on-chain and off-chain data, and performance verification.

Further reading: Robinhood, Binance, and Coinbase now let AI agents place orders: What investors need to know