As a veteran who has fought his way through the trenches of low-level infrastructure and quantitative high-frequency trading for more than a decade, I’ve seen too many “narrative-grade” whitepapers built by stacking novel buzzwords. Recently, Newton Protocol ($NEWT) has been widely touted in the secondary market thanks to the concept of “using TEE plus ZKP to achieve verifiable AI agents.” The official promotions are highly misleading: they claim that every step an AI agent takes is executed inside hardware enclaves, and that it generates zero-knowledge proofs for on-chain smart contracts to independently verify. On the surface, the logic seems airtight—apparently solving the trust problem of off-chain computation perfectly. But the moment you truly get in touch with production-grade node operations, or you’ve deployed a cryptography-based consensus system in a real business environment, you’ll find that behind this ornate, seemingly elegant architecture lies a fundamental system blind spot.
Newton’s core security assumption is built entirely on the illusory premise that “TEE is absolutely secure.”
First, we need to rip off the “black-box” disguise of the TEE (trusted execution environment). Newton’s AI agent runs on the project party’s or the node operator’s physical server hardware, not inside a decentralized blockchain state machine. This architecture essentially hands the lifeblood of security to the chip-isolation technology of hardware vendors. However, history and real data from academia have already stripped the TEE completely bare. Take enterprise-grade confidential computing architectures as an example: in the past few years, from Foreshadow attacks that leak data via microarchitectural side channels, to Plundervolt attacks that inject errors by manipulating processor voltage, and to more recent physical-level hardware compromises that sniff and extract protected private keys directly from the DDR5 memory bus (e.g., TEE.fail). In short, the defenses of TEE can be described as riddled with holes.
Under Newton’s architecture, once any of the above side-channel attacks compromises a node operator’s server—or if the operator is itself an insider—they can directly extract the highest control rights and the wallet private key of the AI agent inside the hardware enclave. In a purely on-chain environment (such as SVM or an optimized EVM virtual machine), all state transitions are deterministically verified via cryptographic consensus across the entire network of nodes. Such a physical-layer single point of failure is fundamentally impossible.
This leads to the second, far more lethal logical trap: ZKP (zero-knowledge proofs) here becomes a tool for polishing things up. Newton claims that on-chain contracts verify ZKPs to ensure the agent doesn’t do anything malicious. But from cryptographic principles, ZKPs can only prove that “a specific computation process strictly follows the preset circuit logic.” They absolutely cannot verify whether the “input data to the system is real,” nor can they verify whether the “execution environment has been compromised at the underlying layer.”
In other words, if an attacker breaches the TEE hardware and tampers—at the operating system level—with the AI agent’s input instructions or the price-feed data, the tainted AI agent will still carry out computations inside the enclave and, using the extracted legitimate credentials, naturally generate a mathematically perfect, flawless zero-knowledge proof. The on-chain verification contract will only mechanically check and pass like a blind person. ZKP turns into an accomplice for forging transactions, because the entire verification layer is completely blind to any code injection occurring inside the TEE black box. This is worlds apart from a pure zkML (zero-knowledge machine learning) approach that commits both the model weights and the computation process by hashing and verifies everything on-chain. Newton’s approach is at best a crude hardware-proof shell.
The collapse of technical defenses is often accompanied by the collapse of the economic model. The last line of defense for a decentralized protocol is a game-theoretic mechanism in cryptoeconomics: the cost of wrongdoing must be far greater than the benefit. Newton requires agent operators to stake NEWT tokens as a bond forfeited upon violations. But brutal market data has effectively passed a death sentence on this mechanism.$BTC
Looking back at the historical market, the NEWT token hit a high of $0.717 in July 2025, and by June 2026 the price had crashed to around $0.049—a total drop of more than 93%. This value destruction caused by liquidity exhaustion completely destroys the deterrent power of the staking mechanism. We can do a simple scenario analysis: suppose a node operator staked $100,000 worth of NEWT at last year’s peak. Today, the value of their bond is only left with less than $7,000. If the AI agent running on that node controls a $50,000 fund pool or has high-frequency trading permissions, the rules of the game change entirely. Against the enormous scissors spread between potential profit and cost, a rational economic actor has a strong incentive to proactively “break” their own TEE server, hijack the AI agent, steal the $50,000, and calmly accept that the default penalty is just $7,000. When the bond can’t even cover a fraction of the loss that users might suffer, the so-called economic guarantee is nothing more than empty paper.
The most hair-raising detail is hidden in the absence of security audit reports. As a protocol aiming to handle automated finance and cross-chain asset scheduling, Newton’s code security rating on the CertiK platform is only a pitiful 55. Even more alarming, its security audit status is clearly labeled “None” (no audit). Under today’s industrial-grade Web3 security standards, any DeFi protocol that carries real commercial value generally maintains a security rating above 85, and must also come with detailed audit reports issued by top-tier security firms with strong reputations, and even undergo strict formal verification. A rating of 55 with no audit usually means the codebase contains numerous lingering administrator-level backdoors, agent contracts that can be arbitrarily modified, or extremely fragile centralized components. Handing real money to such a shoddy outfit that won’t even meet basic code-security baselines is no different than sprinting blindly through a minefield.
In summary, the Newton Protocol tries to hide its essence—building core trust on fragile hardware—behind a glamorous AI and ZKP facade. Four major fatal flaws together form a powder keg that could be ignited at any moment: a TEE black box riddled with frequent physical-layer vulnerabilities; a one-way ZKP verification that is effectively meaningless; an economic penalty mechanism that fails completely due to token price crashes; and bottomless code-security standards. For quantitative institutions and retail users seeking deterministic behavior and compliant security, there’s a basic common-sense truth that must be recognized: if the underlying layer of a system cannot achieve 100% cryptographic self-verification, then no matter how grand the decentralized AI future it depicts may be, it is ultimately just an air castle that could collapse at any time. Don’t let pseudo-guru narratives blind you—inside the technical and capital meat grinder, the “miracles” hidden in the black box are never miracles at all, but instead scythes waiting to be used. $NEWT