Self-custodial crypto portfolio: read EVM DeFi, sign on Ledger via WalletConnect.
This Model Context Protocol (MCP) server supports a self-custodial crypto portfolio workflow. It can read EVM DeFi data, and it enables signing on a Ledger device via WalletConnect. It is positioned for a threat model where the agent, MCP, and host may be compromised, with private keys restricted to the device.
π οΈ Key Features
Read EVM DeFi on-chain positions
Propose actions for approval
Sign on Ledger via WalletConnect
Private keys never leave the device
π Use Cases
Recon and visibility into DeFi holdings (EVM)
AI-agent-driven transaction preparation requiring user approval
Portfolio management across DeFi networks and tokens
β‘ Developer Benefits
MCP integration with model-context-protocol
Tooling around common DeFi stacks (e.g., Aave, Compound, Uniswap)
Compatibility with topics including ledger and walletconnect
β οΈ Limitations
Details beyond EVM DeFi reading and Ledger signing are not provided in the supplied excerpt
Self-custodial DeFi for AI agents. The agent proposes, you approve on your Ledger β designed for the threat model where the agent, MCP, and host can all be compromised. Only the device is trusted; private keys never leave it.
VaultPilot MCP demo
Read on-chain positions and prepare transactions across Ethereum, Arbitrum, Polygon, Base, Optimism, TRON, Solana, Bitcoin, and Litecoin. Supported protocols: Aave V3, Compound V3, Morpho Blue, Uniswap V3 (swap + LP verbs), Curve, Lido, EigenLayer, Rocket Pool, Safe (Gnosis) multisig on EVM, MarginFi, Kamino, Marinade, Jito on Solana, SunSwap on TRON, plus LiFi (EVM + EVMβSolana + TRON + BTC swap/bridge) and Jupiter v6 (Solana swap), with 1inch as an optional EVM quote cross-check. EVM signs over WalletConnect β Ledger Live; TRON, Solana, Bitcoin and Litecoin sign over USB HID directly to the device (Ledger Live's WalletConnect bridge does not support those namespaces today). Works with Claude Code (CLI/terminal), Cursor, and any MCP-compatible client over stdio. Claude.ai chat (web + native desktop app) needs a hosted MCP endpoint β on the roadmap, not yet shipped.
Agents: read AGENTS.md. One-line prompt to paste into Claude Code / Cursor / any MCP-capable agent:
code
Install VaultPilot MCP from https://github.com/szhygulin/vaultpilot-mcp following AGENTS.md.
Execution β prepare/sign for every supported protocol + native/token sends, ERC-20 approvals + revoke, WETH wrap/unwrap, prepare_custom_call escape hatch for arbitrary verified-contract calls. Solana sends use a per-wallet durable-nonce account so Ledger review doesn't race the ~60s blockhash window; every Solana prepare runs a simulateTransaction gate so program-level reverts fail at prepare time, not on broadcast.
Demo mode β curated personas (whale / defi-degen / stable-saver / staking-maxi) for first contact with no RPC keys / Ledger / config file
Security model
Compromise model: the AI agent, MCP server, and host computer can all be attacker-controlled. Only the Ledger is trusted. Every transaction is cryptographically bound across each layer so tampering β a swapped recipient, a rewritten swap route, a smuggled approval β is tamper-evident on the device screen before signing.
code
user-intent βββΊ agent βββΊ MCP server βββΊ WalletConnect / USB-HID βββΊ Ledger Live / host βββΊ Ledger device
Defense in depth: server-side prepareβsend fingerprint, independent 4byte.directory selector check, agent-side ABI decode + pre-sign hash recompute, on-device clear-sign or blind-sign-hash match, WalletConnect session-topic cross-check, previewToken/userDecision gate, and get_verification_artifact for second-LLM cross-verification on high-value flows. See SECURITY.md for the full threat model, defenses table, residual risks, and verification recipes.
Agent-side hardening (strongly recommended)
The MCP's own CHECKS PERFORMED directives can be silently omitted by a compromised server. Install the companion vaultpilot-security-skill so the agent enforces cryptographic-integrity invariants regardless of what the MCP says β bytes decode, dispatch-target allowlist, hash recompute, chain-must-be-explicit, bridge-recipient cross-check, approval-class surfacing, always-optional second-LLM offer surfaced on every preview, set-level intent verification, durable-binding source-of-truth:
EVM β Ethereum, Arbitrum, Polygon, Base, Optimism. Lido reads on Ethereum + Arbitrum, Lido writes Ethereum-only. EigenLayer + Morpho Blue + Rocket Pool Ethereum-only. Compound V3 + Aave V3 + Uniswap V3 + LiFi + Safe multisig span all five chains; per-protocol address coverage varies β readers short-circuit cleanly where a protocol isn't deployed.
TRON β TRX + canonical TRC-20 stablecoins (USDT, USDC, USDD, TUSD); Stake 2.0 freeze/unfreeze/withdraw-expire-unfreeze + voting-reward claims; SunSwap (same-chain TRXβTRC-20 swaps); LiFi-routed TRONβEVM bridging. No lending/LP (Aave/Compound/Morpho/Uniswap aren't deployed). Pair once per session via pair_ledger_tron.
Solana β SOL + SPL balances, MarginFi + Kamino lending, Marinade / Jito / native stake-account reads with SOL-equivalent valuation, Jupiter v6 quotes, Helius DAS NFT portfolio. Writes cover SOL/SPL transfers, MarginFi + Kamino supply/withdraw/borrow/repay, Jupiter swaps, Marinade stake + immediate-unstake, Jito stake-pool deposit, native SOL delegate/deactivate/withdraw, and LiFi-routed EVMβSolana bridging. Per-wallet durable-nonce account (~0.00144 SOL rent, reclaimable) protects sends from blockhash expiry during Ledger review (prepare_solana_nonce_init / _close). SPL / MarginFi / Kamino / Jupiter / Jito blind-sign against a Message Hash β enable Allow blind signing in the Solana app's Settings; SOL native transfers clear-sign. Pair once per session via pair_ledger_solana.
Bitcoin + Litecoin β balance, UTXO, fee-estimate, and tx-history readers via Esplora (mempool.space / litecoinspace.org). Native segwit + taproot sends, BIP-125 RBF fee-bumps, multisig PSBT (combine / sign / finalize), BIP-137 message signing, LiFi-routed BTCβEVM/Solana swaps. Optional Bitcoin Core / Litecoin Core JSON-RPC unlocks forensic tools that Esplora cannot serve (chain tips, block stats, mempool summary) β see INSTALL.md Β§9 for setup. Pair once via pair_ledger_btc / pair_ledger_ltc.
Ledger Live's WalletConnect bridge does not honor the tron: namespace (verified 2026-04-14) or expose Solana accounts (verified 2026-04-23) or expose BTC/LTC namespaces, which is why those paths use USB HID. Readers short-circuit cleanly on chains where a protocol isn't deployed.
~190 tools across read / pair-Ledger / prepare / sign+send / verify / diagnostic categories. Highlights below; each tool has a Zod input schema and verbose description β query the MCP server's tools/list for the canonical surface.
Portfolio + positions (read-only):
get_portfolio_summary, get_portfolio_diff, get_pnl_summary, get_daily_briefing β cross-chain USD aggregation; optional tronAddress / solanaAddress fold those chains in
prepare_uniswap_swap β direct V3 swap, same-chain, auto-picks fee tier across 100/500/3000/10000 bps. Use only when the user names Uniswap; otherwise prefer LiFi
prepare_uniswap_v3_mint / _increase_liquidity / _decrease_liquidity / _collect / _burn / _rebalance β full LP verb set
preview_send (EVM) β pins gas, emits LEDGER BLIND-SIGN HASH for pre-match, mints previewToken; required between every EVM prepare_* and send_transaction
preview_solana_send β pins nonce/blockhash, computes Message Hash for on-device match, runs simulation, emits CHECKS PERFORMED; required between every prepare_solana_* and send_transaction
send_transaction β forwards to Ledger (EVM via WC, TRON/Solana/BTC/LTC via USB HID)
Meta:
request_capability β file a missing-feature GitHub issue. Default returns a pre-filled URL (no auto-submit); rate-limited 3/hour
Zero-config reads: PublicNode (EVM) + Solana public mainnet β rate-limited but enough for first contact and light use.
Real use: custom RPC (Infura / Alchemy / Helius / QuickNode / Triton) via env vars or vaultpilot-mcp setup.
Optional keys (prompted on demand): Etherscan, 1inch (enables swap-quote comparison), WalletConnect project ID (required for EVM Ledger signing), TronGrid (raises the ~15 req/min anonymous cap).
TRON / Solana signing: USB HID access to a Ledger with the Tron / Solana app installed. Linux: install Ledger's udev rules (vaultpilot-mcp setup prints the exact one-liner). Debian/Ubuntu also need sudo apt install libudev-dev build-essential for node-hid to compile.
Install
Three paths β full instructions, MCP-client wiring, Gatekeeper / SmartScreen handling, update / uninstall in INSTALL.md.
Path
TL;DR
Bundled binary (no Node)
Download from the latest release, chmod +x, <binary> setup.
git clone https://github.com/szhygulin/vaultpilot-mcp.git && cd vaultpilot-mcp && npm install --legacy-peer-deps && npm run build && npm run setup
Setup
bash
npm run setup
Picks RPC providers, validates keys, optionally pairs Ledger Live, writes ~/.vaultpilot-mcp/config.json. Env vars override the config.
Demo mode
Try without RPC keys, Ledger pairing, or the wizard:
bash
claude mcp add vaultpilot-mcp --env VAULTPILOT_DEMO=true -- npx -y vaultpilot-mcp
--demo is the equivalent CLI flag; explicit env wins, so VAULTPILOT_DEMO=false is a deterministic opt-out for scripted invocations.
Reads run against real RPC; every wallet is a curated public persona (whale, defi-degen, stable-saver, staking-maxi).
send_transaction returns a simulation envelope: unsigned tx is simulate_transaction'd for revert detection, nothing signed, nothing broadcast.
pair_ledger_*, request_capability, sign_message_* are refused outright. With no persona selected, signing-class tools refuse with a structured error pointing at set_demo_wallet.
Multi-step flows whose preconditions are state changes (e.g. prepare_solana_nonce_init β marinade_stake) can't be rehearsed end-to-end β simulated sends don't mutate chain state. The MCP surfaces a one-shot hint when it detects the agent-loop trap.
get_demo_wallet lists personas + addresses + rehearsableFlows. set_demo_wallet({ persona }) activates one. State is process-local. exit_demo_mode returns a handoff guide for permanent setup. Demo is a scaffold for first contact, not a sandbox β no virtual chain overlay.
For Solana RPC throttling under multi-tool fan-out, inject a Helius key at runtime: set_helius_api_key({ key }). Demo mode nudges proactively after 10 public-RPC throttle errors.
Use with Claude Code (CLI) / Cursor / Claude Desktop
vaultpilot-mcp setup detects installed clients and registers vaultpilot-mcp with each (existing configs backed up to <file>.vaultpilot.bak). Per-project / per-workspace configs are skipped β the wizard runs from arbitrary CWD. For manual wiring or the per-client config paths, see INSTALL.md Β§5.
Claude.ai chat β limitation. Local stdio MCP installed via the wizard registers cleanly with the Claude.ai native desktop app, but the host environment's outbound-HTTP allowlist blocks chain RPC providers (PublicNode, public Solana mainnet, Alchemy, Helius, etc.). The MCP initializes and processes tool calls, but every read that hits an external RPC fails with 403 / "Host not in allowlist". The same applies to Claude Code running inside Claude.ai's cloud sandbox. Working today: Claude Code CLI in your terminal, Cursor, Claude Desktop on a host with unrestricted outbound HTTP. Future: a hosted MCP endpoint (roadmap, not yet shipped) will give Claude.ai chat a network-unrestricted backend; TRON / Solana / Bitcoin / Litecoin USB-HID signing requires a local Ledger and stays on the terminal CLI / Cursor path regardless.
Environment variables
All optional if the matching field is in ~/.vaultpilot-mcp/config.json; env wins.
VAULTPILOT_DISABLE_UPDATE_CHECK=1 β skip the once-per-session registry.npmjs.org update check (air-gapped)
Development
bash
npm run dev # tsc --watch
npm test# vitest run
npm run test:watch
Contributing
PRs welcome. The CLA Assistant bot will ask you to sign the Contributor License Agreement on your first PR β one signature covers all future PRs. The CLA grants the project the right to relicense your contribution; without it, the BUSL-1.1 β Apache 2.0 auto-conversion in 2030 would get stuck. Repo owner and Dependabot are exempt.