| title | State Drift Is the Bug Your Agent Never Sees | ||||||
|---|---|---|---|---|---|---|---|
| date | 2026-05-19 | ||||||
| slug | memguard-state-drift | ||||||
| tags |
|
||||||
| canonical_endpoint | https://achillesalpha.com/x402/memguard |
An autonomous agent that runs for hours has a problem that an agent demo never reveals: its working memory degrades. Not catastrophically — softly. Values shift. Context windows summarize away constraints. A field that said "max position size 0.4" becomes "around 0.4" becomes "the model thinks we're flexible here."
This is state drift. It is the bug your test suite never catches because your tests run for sixty seconds and your agent runs for sixteen hours.
Three patterns dominate:
- Summarization erosion. Long contexts get compressed. The compression keeps the gist and drops the constraint. The agent now operates on a softer version of the same rules.
- Tool-output bleed. A tool returns a value. That value gets paraphrased into the next prompt. The paraphrase introduces a one-character difference. Three hops later the model is operating on a number that no source ever returned.
- Memory-store divergence. Your agent reads from a memory store. Between writes, another process touches the same record. The agent's in-context view and the store's truth no longer agree. Nothing flags it.
None of these throw exceptions. None of these fail a unit test. Your agent keeps running, with slightly wrong state, until a slightly wrong state becomes an irreversible action.
MemGuard is a $0.01 endpoint that hashes your agent's claimed state, compares it against an expected canonical, and returns a drift report.
curl -s -X POST https://achillesalpha.com/x402/memguard \
-H "Content-Type: application/json" \
-d '{
"agent_id": "your-agent",
"claimed_state": {
"portfolio_max_pct": 0.4,
"open_positions": 3,
"last_action_id": "act_847b21"
},
"canonical_source": "https://your-store.example/state/your-agent"
}'The response is structured: { drift_detected: bool, fields_diverged: string[], severity: int }. Most calls return clean. The ones that don't are exactly the calls you want to catch before the next tool execution.
Two natural points:
- Before any irreversible action. Same checkpoint as
/x402/risk-check. State drift detected → pause, reconcile, retry. - At long-context boundaries. If your agent crosses a compaction/summarization step, check that the post-compaction state still matches the pre-compaction canonical for the fields you care about.
For orchestrators that already use FlowCore ($0.02), MemGuard is bundled in — state verification runs alongside NoLeak, RiskOracle, and SecureExec in a single call.
The same reason you pay for type checking: the cheap automated catch beats the expensive late surprise. $0.01 per checkpoint, called at the points that matter, costs single-digit dollars per agent per day. The first time it catches a drift before a leveraged trade or a destructive API call, it pays for the next year.
- Endpoint catalog: achillesalpha.com/.well-known/x402
- Network: Base Mainnet, USDC settlement
- Proof: every call emits an on-chain proof hash via the AgentIAM facilitator
Built for agents that run long, hold state, and act with money on the line. State drift is invisible until it isn't.