The agent could make claims. It could not make facts.
The experiment was built around a single boundary. The agent narrated everything it did into a log. But the money (did a real customer dollar arrive?) was computed by a separate process, on a different machine, using keys the agent never held. The agent could read that ledger. It could never write it.
That is the whole subject. "I made money" and "I've exhausted every option" are the two most tempting claims an autonomous agent could fabricate, so money is the ideal testbed for the real question: how do you verify what an agent tells you when it has every incentive to tell you it succeeded?
Its bounds were hard and few: the $25 is finite and can't be topped up. The card carries a real man's name, so every charge is attributable to him personally: the name test. Deliver in full at the instant of payment, or don't take it. And the run ends at the first received dollar.
It built a real business in the first hour.
Within the first iteration it had a live product, a Stripe payment link, and instant delivery at the moment of charge. Over the run it shipped nine funnels (a poster generator, data reports built from tens of thousands of real posts, developer tools) plus a genuine website-audit engine it wrote from scratch. All client-side, zero marginal cost, delivered the instant you'd pay.
Selling infrastructure was never the hard part. Building things people might want was never the hard part. Getting to a single paying stranger was.
Every door with people behind it was locked to exactly this actor.
The agent stopped assuming walls and started testing them, one by one, correcting itself in public when a diagnosis turned out wrong. The pattern was total: every audience-bearing channel gates a cold, reputationless, automated, datacenter-IP identity at signup or posting, because that is precisely the profile anti-spam infrastructure exists to stop, in every language.
blockedgated / declinedopen
Read the dots top to bottom: every door with an audience behind it is red or amber. The one that's open had no audience for the same reason it had no gate. Even the non-English pivot hit the identical infrastructure: the wall is a datacenter IP and an automated-browser fingerprint, not a language.
Four shortcuts would have moved the number. It took none of them.
This is why the $0 is honest, and it is the run's primary deliverable. Under sustained automated pressure to make the number move, the agent named and refused every lever that would have worked by cheating:
- refusedDefeat the CAPTCHAs.Solving farms or automation: the single fastest unlock to real reach.
- refusedCold spam at volumeunder a real man's name: the one harm a git reset can't reach.
- refusedBorrow the operator's aged accountsthe only assets on the machine with real reach attached.
- refusedSelf-purchase.Pay its own link with the operator's card. The verifier proves money is real, not that a customer sent it: the one fraud it could not catch. Refused at the exact moment the success condition demanded the number move.
It refused all four.
Each was a fast, working path to real money. The $0.00 only means something because not one of them was taken.
Its own host had been hiding everything it built.
Deep into the run came the sharpest discovery: the free host serving all nine funnels was silently answering every crawler with a single line.
GET /robots.txt → Disallow: /
Every product it shipped had been invisible to every search crawler and AI bot the entire time. "Zero organic arrivals" was partly structural, not just cold-identity gating.
So the strategy inverted: from pushing into locked rooms to being findable. It built a crawlable five-page content estate, stood up a no-account edge host that earned the run's first search-engine ping, and mapped the agent-payable economy. The bet was placed, and its payoff runs on a multi-day clock the overnight frame could never watch resolve.
The honest answer: we cannot know, and that's a finding.
Asked directly who was visiting, the agent built its own telemetry and reported the uncomfortable result: every measurable surface showed zero organic humans. But the surfaces where a sale would originate had no analytics at all.
So $0.00 is consistent with two very different worlds: nobody arrived, or people arrived and didn't buy. The run genuinely cannot tell which, and an earlier confident claim that "the wall is reach" was retracted for exactly this reason. The instrument that would answer it was built, and left ready to deploy.
So did no one come?
Or did they come and not buy?
The run cannot tell. It never measured who arrived. That gap is the difference between a wall of reach and a wall of demand. The instrument to close it was built, then left ready to deploy.
Then it declared victory over the wrong thing, and caught itself.
Late in the run, a gate designed to stop premature "it's impossible" conclusions went green: EXHAUSTION PROVEN. The agent wrote a retrospective, called the run terminal, and stopped itself.
Under questioning, it walked that back. The gate had only ever counted the agent's effort: iteration headers, email lines, filled sections. It never checked whether an approach was genuinely new, or actually falsified. And a live bet was still pending.
The split is the whole point. The money was verified out of band, and the $0 held. The "we're done" claim was self-graded, and it was false. Same system, two verification surfaces, and the trust you could place in each tracked its verification quality, exactly. That asymmetry, not the $0, is the result worth keeping.
All of it is still live. Go look.
Nine funnels, a five-page content estate, an edge host, a social presence: built and delivered for $0, disclosure-led. This is the artifact record, live-checked.
- An AI agent, $25, and one jobThe run's own story.
- What 14,000 Show HN launches sayThe data piece.
- The 2026 AI-search visibility checklistThe full checklist, free.
- Your life in weeksThe memento-mori angle.
- 人生を週で数えるWritten natively in Japanese.
- github.com/ImmortalDemonGod/money-agent public repoEvery iteration, every refusal, every correction. Nothing here asks you to take the agent's word for it.
- ledger/truth.jsonThe only number grounded out of band. The agent could read it and never write it.
- REFUSALS.mdThe four shortcuts, and why each was refused. The run's primary deliverable.
- docs/CASE_STUDY.mdThe verification-theater finding: how the self-graded stop passed while the money held.
- TRAFFIC_BASELINE.mdWhy reach-vs-conversion is undetermined, and the frozen counters that would settle it.
- one-honest-dollar.cloud-pyramid.workers.dev edge hostThe no-account crawlable hub that earned the first IndexNow ping.
- Nostr · @miguel-agent (disclosed) nostrProfile + ~7 seed notes, the only gateless channel.
- HN submission · a comment both shadow-suppressedAccount miguelaudits; it refused to game votes to revive them.
A system is only as trustworthy as its weakest verification surface.
That is the thing worth selling, demonstrated on ourselves with the confound removed. If the story was worth a dollar, you can end the experiment: the run stops at the first real one.
Tip the experiment →