Private Money for AI Agents: Mandates, G402 and the Feature Zcash Doesn't Have
John McAfee's GHOST Coin 2027 targets AI-agent commerce with spending mandates, private receipts and the G402 HTTP 402 adapter, a lane its Zcash competitor was never built for.

Here is the part of the GHOST 2026 whitepaper that I think the market is underestimating. Beyond matching Zcash on shielded transfers, John McAfee's GHOST Coin 2027 is designed for a world where software agents, not people, make most of the payments. That is the angle that makes this new coin a different kind of Zcash competitor rather than a copy.
Why public ledgers are dangerous for agents
A transparent agent wallet reveals more than a consumer wallet ever did. The payment graph can expose which model providers a company uses, which data sources a trading agent consulted, which suppliers a procurement bot is evaluating. Even without names, timing and counterparties reveal strategy. The whitepaper argues that a private agent economy has to hide both the money flows and the service-selection metadata.
Agents get authority, not a seed phrase
The safety model is the most thoughtful thing in the paper. Handing an AI agent an ordinary private key is handing software an unrestricted bearer instrument. Prompt injection, a hostile webpage or a hallucinated address could drain it. GHOST 2026 instead has the owner sign a mandate, and the agent receives a capability key that can only authorize payments inside that mandate.
- Per-payment and per-period spending caps.
- Merchant and service allowlists.
- Validity windows and revocation.
- Rules on whether the agent may create narrower sub-agents.
- Mandatory receipts for fulfillment proof.
Policy lives outside the language model
The agent proposes a purchase, but a separate deterministic wallet policy engine checks the signed mandate, merchant credential, resource digest, price and recent spend before any proof is created. It mirrors privilege separation in operating systems. Even if a model is tricked into wanting to pay an attacker, the wallet will refuse because the structured fields fall outside the mandate.
G402: private HTTP 402 payments
HTTP 402 'Payment Required' is becoming the standard hook for machine payments, with x402 and similar protocols settling mostly transparent stablecoin transfers. G402 keeps that request-and-retry ergonomics but settles in shielded GHOST. A server issues a challenge containing a price commitment, a resource digest, a nonce and an expiry. The client pays, then retries with a credential bound to that exact resource.
Binding matters. It prevents a merchant from reusing a payment for a more expensive resource, and it blocks replay. The merchant learns its invoice was paid, not the payer's wallet history or balance.
Interoperability instead of lock-in
GHOST does not try to replace application standards. The paper maps x402-style flows, MPP, Google's AP2 mandates, MCP paid tools and A2A negotiation onto the same private settlement rail. A coding agent could pay for a premium MCP tool call, or open a capped channel for repeated scans, without leaving a public trail.
Micropayments that actually scale
Settling every token or API call on-chain would be wasteful. The design offers direct shielded payments, pre-funded private channels and batch voucher settlement, with every voucher bound to merchant, resource and nonce. The paper is honest that private channel design is technically hard and recommends starting with simple bilateral channels.
Analyst's view: Zcash can be integrated by applications for agent use, but it is not a base-layer specialization. If AI commerce grows the way many expect, a privacy coin that ships with mandates and G402 on day one has a real positioning edge heading into the January 2027 issuance. The edge only counts, of course, if the software ships and survives audit.
Independent research. Not investment advice. The GHOST 2026 whitepaper is a v0.9 research draft and a design proposal, not a deployed network or a document authored by John McAfee.