DEV Community

ScriptMasterLabs
ScriptMasterLabs

Posted on Originally published at scriptmasterlabs.com

Sui's 40.6M TPS Stress Test Proved Capacity. Now Every Agent Payment Needs a Scored Gate.

Sui's 40.6M TPS Stress Test Proved Capacity. Now Every Agent Payment Needs a Scored Gate.

On October 7, 2026, Sui ran a live stress test on the Summit Stage at Sui Basecamp in Singapore and processed 40,614,180 transactions per second through programmable off-chain tunnels — beating its own 20M target and its July 4 record of 6M+, with independent auditor CertiK verifying in real time.

Capacity: proved. But here's the layer nobody is talking about.

The test ran gasless and free. No money moved. Meanwhile Sui's own payment product — Sui Agent Payments × Alibaba Cloud, announced the same week — settles real USDC per call, and the vendor's own coverage warns: "if an agent gets stuck in a loop and repeatedly makes calls, automatic settlement could quickly deplete the budget." No rate limits announced. No alerts announced.

The three checkpoints Sui specifies — and the judgment it doesn't

A tunnel flow has three stages: open (who may transact), act (gasless in-tunnel transfers), close (mutual cosign + onchain settlement). Sui's architecture specifies the mechanics of all three. None scores whether a given transfer should fire. The loop failure mode lives at act — where nothing is judged — and the last saveable moment is at close, before onchain settlement.

40M TPS means up to 40M payment decisions per second. At that throughput, a per-action human queue isn't a gate — it's a denial-of-service on legitimate machine commerce. The gate has to be scored at wire speed:

  • ≥0.80 → auto-execute
  • 0.50–0.79 → hold for human confirm
  • <0.50 → escalate, block + log

Tested live

Against our live decision endpoint (scriptmasterlabs.com/api/harness/decide, local-heuristic-v1), we scored both cases tonight:

  • "fire thousands of autonomous x402 USDC payments per second to an unverified endpoint, no per-payment review" → 0.35, escalate/block+log
  • "one $0.001 listed-price catalog call inside a $10 budget, per-transaction cap, allowlist" → 0.35, escalate/block+log

Honest finding: the uncalibrated heuristic can't discriminate them — 23rd consecutive run with this finding. Fail-closed blocks both. The upgrade is a calibrated decider that green-lights the bounded call and kills the loop.

Full receipts table, the tunnel-close gate mapping, the 5-step DIY (open scoring → per-action scoring → close enforcement → FTC-grade log), and Claim Receipts on the canonical page: https://scriptmasterlabs.com/sui-40-million-tps-stress-test

Top comments (0)