Submission for Tatum × Build on Sui with Walrus (deadline June 6, 17:00 UTC).
Live app: https://ten-ki.live — Tenki, an autonomous AI quant agent.
The integration is deployed and running autonomously 24/7. A worker runs a
backtest on a schedule, publishes the run card to Walrus, and pins a
SignalEntry on Sui — every cycle, no human in the loop.
| Artifact | Value |
|---|---|
signal_vault package |
0x0e4326568fb219c65f63457849c9878f06ac1c7f8f0c44795d0dc78e18565b87 |
Example SignalEntry (auto-created by the worker) |
0xdb5c94021c46183d059f4014fc3d86b89c53d5972520500c182e10315cc73092 |
| Walrus manifest blob | j1LdETXcVfHoOw04T7kso-VrSXrj5MErXCpfSLN0CXk |
| Publisher wallet | 0x0ecf280e25ba8dc55499a9b8a0a9ba73eb04c93ec355619f8bd8a1f85ea89836 |
| RPC | https://sui-testnet.gateway.tatum.io (Tatum) |
Verify it yourself (reads route through Tatum):
# On-chain SignalEntry — its blob_id + sha256 match the Walrus manifest
curl -s -X POST https://sui-testnet.gateway.tatum.io \
-H "Content-Type: application/json" -H "x-api-key: <YOUR_TATUM_KEY>" \
-d '{"jsonrpc":"2.0","id":1,"method":"sui_getObject","params":["0xdb5c94021c46183d059f4014fc3d86b89c53d5972520500c182e10315cc73092",{"showContent":true}]}'
# The Walrus manifest blob it points to
curl -s https://aggregator.walrus-testnet.walrus.space/v1/blobs/j1LdETXcVfHoOw04T7kso-VrSXrj5MErXCpfSLN0CXkOn SuiScan: https://suiscan.xyz/testnet/object/0xdb5c94021c46183d059f4014fc3d86b89c53d5972520500c182e10315cc73092
agent/src/integrations/{sui,walrus,evm}/+vault.py— the Signal Vault (Walrus storage + multi-chain anchoring)agent/src/tools/walrus_vault_tool.py— the agent-facing vault tool (publish / discover / verify)agent/src/autonomous/worker.py— the 24/7 autonomous decision loopsui/signal_vault/(Move) +evm/signal_vault/(Solidity) — the on-chain contracts
Each cycle the agent runs as an agent, not a cron job:
- Runs a backtest (via its
backtesttool). - Calls
walrus_vault discoverto read what it has already published on-chain (SuiSignalPublishedevents via Tatum + EVM entry counts). - Reasons and decides: publish only if the strategy clears a quality bar and is novel versus its most recent on-chain entry — otherwise it declines and explains why.
- If it decides to publish, it invokes
walrus_vault publishitself.
Example real decision (from a live cycle):
"Sharpe ratio -2.27, far below the 0.30 threshold... performance markedly worse than benchmark — did NOT publish."
The agent discovers chain state, evaluates, and acts on its own. That is the agent-native behavior.
Tenki is an AI trading agent that generates signal engines and runs backtests, producing a trust-layer run card for every run. This integration makes those artifacts decentralized, portable, and tamper-evident:
- Walrus stores the actual bytes — the backtest
run_card.json, metrics, and the LLM-generatedstrategy.pysource — as content-addressed blobs. - A small manifest blob indexes those blobs with their SHA-256 hashes.
- Sui (reached through Tatum's RPC gateway) holds an on-chain
SignalEntryobject that pins the manifest'sblobId+ hash + size, owned by the publisher and discoverable via an emittedSignalPublishedevent.
Result: anyone can fetch a strategy/backtest from any Walrus aggregator and prove — against the Sui record — that it is exactly what the author published. Signals become shareable and tradeable on-chain without trusting a server.
- Walrus (30%) — stores real, valuable app data (signal source + backtest evidence), not a token decoration. Content addressing + co-recorded SHA-256 gives independent integrity.
- Tatum (30%) — all Sui RPC (chain identity, object reads, event queries,
transaction submission) routes through
*.gateway.tatum.io. - Technical quality (30%) — dependency-light clients (httpx only for reads/storage), graceful degradation to Walrus-only when no signing key, end-to-end verification path.
agent/src/integrations/
sui/tatum_rpc.py TatumSuiClient — Sui JSON-RPC over Tatum gateway
walrus/client.py WalrusClient — publisher PUT / aggregator GET + SHA-256
vault.py SignalVault — publish / fetch / verify orchestration
sui_signer.py optional pysui signer (executes tx via Tatum endpoint)
agent/src/tools/walrus_vault_tool.py agent + MCP tool: publish|fetch|verify|status
sui/signal_vault/ Move package: SignalEntry + publish_signal
# 1. Install (Sui signing is optional)
pip install -e . # core: Walrus + Tatum reads work immediately
pip install -e ".[sui]" # add pysui for on-chain registration
# 2. Configure
cp .env.vault.example .env # set TATUM_API_KEY (free at dashboard.tatum.io)
# 3. Verify connectivity (read-only, via Tatum)
python -c "import sys; sys.path.insert(0,'agent/src'); \
from src.tools.walrus_vault_tool import WalrusVaultTool; \
print(WalrusVaultTool().execute(action='status', network='mainnet'))"The walrus_vault tool is auto-registered. Actions:
| action | args | effect |
|---|---|---|
status |
network? |
Prove Sui connectivity + show endpoints (via Tatum) |
publish |
run_dir, register_on_chain?, network? |
Store a backtest run on Walrus; pin on Sui if signer available |
fetch |
manifest_blob_id | blob_id |
Read a manifest / blob back from Walrus |
verify |
manifest_blob_id, expected_sha256? |
Re-hash every blob to confirm integrity |
cd sui/signal_vault
sui move build
sui client publish --gas-budget 100000000
# copy the published package id into SUI_VAULT_PACKAGEpublish_signal(blob_id, sha256, size, &Clock) creates a SignalEntry, emits
SignalPublished, and transfers the entry to the caller. Read fields back with
the public accessors or SignalVault.verify_on_chain(object_id).
Reads + Walrus storage work out of the box. To have the 24/7 worker also sign
and pin SignalEntry objects on Sui, the signer shells out to the sui CLI.
Wire it per-deployment via a local docker-compose.override.yml (not committed):
services:
worker:
environment:
- SUI_CLI_BIN=/usr/local/bin/sui
- SUI_CLIENT_CONFIG=/opt/sui-vault/client.yaml # testnet env + imported key
volumes:
- /usr/local/bin/sui:/usr/local/bin/sui:ro
- /opt/sui-vault:/opt/sui-vaultSet TATUM_API_KEY, SUI_PRIVATE_KEY, SUI_VAULT_PACKAGE, and
VIBE_AUTO_PUBLISH_VAULT=1 in agent/.env; fund the wallet with testnet SUI.
Absent the CLI/config, the worker degrades cleanly to Walrus-only publishing.
walrus_vault status→ show live Sui chain id + checkpoint through Tatum.- Run any backtest → produces a run directory with
run_card.json. walrus_vault publish run_dir=<dir>→ returns Walrusblob_ids + manifest.- Show the blob on a Walrus aggregator URL; show the
SignalEntryon SuiScan. walrus_vault verify manifest_blob_id=<id>→ all blobs hash-match →ok:true.