METAL for iPhone

Read AI news in the METAL app.

Download METAL and discover fresh AI stories every day.

Download on the App Store

For iPhone · Free download

Search for METAL AI Magazine in the App Store on your iPhone.

METAL

Binance lets AI agents trade automatically, leaves risk limits to users

New Agent OS connects to ChatGPT, Claude, and Cursor; sub-account withdrawals are blocked by default

Binance lets AI agents trade automatically, leaves risk limits to users

Image: METAL

Summary

  • Binance launched Agent OS on Thursday, a platform that lets AI agents analyze markets and trade on users' behalf
  • Agents only get access to sub-accounts, withdrawals are blocked by default, and the amount a user deposits effectively sets the ceiling on trading losses
  • For its Agentic Wallet feature, Binance itself caps daily activity: $50,000 for swaps, $100,000 for DeFi, and $20 for x402 payments

Handing agents the keys to the account

Binance, which has more than 300 million registered users, rolled out Agent OS on Thursday — a platform that lets AI agents analyze markets and actually execute trades. It's a move that lands right in the middle of a broader shift: AI is moving past answering questions in a chat window and into the business of actually moving money. But deciding what an agent is allowed to do, and making sure it stays within those bounds, falls largely on the user rather than on Binance.

What Agent OS connects

Agent OS is a platform that lets developers plug AI applications and agents into Binance's financial infrastructure. On top of existing tools — the Binance API, the wallet agentic hub, the x402 payment verification and settlement API, and the Skills Hub — Binance has added support for the Model Context Protocol (MCP). It works with OpenAI's ChatGPT and Codex, Anthropic's Claude Code, and the coding editor Cursor, letting users grant agents permission to check prices, view account information, and place orders.

바이낸스 AI 에이전트 OS 기능 설명 화면으로 거래, 결제, 시장 읽기, 포트폴리오 추적, 온체인 운영, 질문 답변 기능이 나열됨
이미지: TechCrunch AI

Sub-accounts as the safety net

Rather than handing an agent full account access, Binance restricts it to a separate "sub-account" created specifically for that purpose. Users can assign a sub-account to a specific activity, like spot or futures trading, and withdrawals from that sub-account are blocked by default. "Instead of giving agents complete freedom, we put fine-grained control over what an agent can do in the user's hands," said Jeff Lee, Binance's VP of Product. Users can require the agent to get approval for every single order, or set permissions once and let it run fully autonomously from there.

The exchange doesn't set its own cap on how much an agent can trade or lose. Whatever amount a user deposits into the sub-account effectively becomes the limit. Asked whether Binance can see why an agent made a particular trading decision, Lee said in an interview that "we have no visibility at all into the reasoning behind that judgment." Because the reasoning happens on the user's own computer or inside whatever AI application they've chosen, Binance can monitor the outcomes of an agent's trades but has no way to tell whether the underlying decision was swayed by bad information or manipulation. Asked what happens if an agent gets manipulated through something like a prompt injection attack, Lee again pointed to the sub-account structure as the first line of defense. The same security, risk controls, and anti-money-laundering policies that already apply to sub-account APIs carry over to Agent OS.

Binance sets its own limits on wallets and payments

Unlike exchange trading, which has no separate cap, payments and on-chain activity through the x402 integration and Agentic Wallet do come with daily limits that Binance itself sets.

ActivityDaily limit
Regular swaps$50,000
DeFi transactions$100,000
x402 payments$20

Agents can send and settle payments through the x402 integration, and use the Agentic Wallet to handle tokens and interact with decentralized finance (DeFi) protocols. Lee described Agent OS as a "first step" toward a platform for building AI applications that can operate across both crypto and traditional financial markets.

Exchanges are racing to open up to agents

Binance isn't the only exchange opening up its infrastructure to AI agents.

ExchangeTimingDetails
KrakenMarchOpen-source command-line tool with a built-in MCP server for executing spot and futures trades
CoinbaseJuneCoinbase for Agents, enabling trading and payments within user-set limits
OKXEarly this yearOpen-source MCP toolkit supporting agent-driven trading
BinanceAugust 20Agent OS, with MCP, sub-accounts, and Agentic Wallet
바이낸스 모바일 앱에서 에이전틱 계정 접근 권한 설정 화면으로 계정 선택과 거래 옵션 토글 버튼 표시됨
이미지: TechCrunch AI

How it works, based on what's been confirmed

Based on what's been confirmed in the source material, here's the general flow. A user starts by creating a dedicated sub-account for the agent within their Binance account and defining its scope, such as spot or futures trading. They then connect an AI tool they're already using — ChatGPT, Codex, Claude Code, or Cursor — to that sub-account through Agent OS or MCP. Next, they decide whether the agent needs approval for every order or can run autonomously within the permissions they've set. Finally, they transfer the actual funds the agent will manage into the sub-account, and that amount becomes the effective ceiling on what the agent can do. According to the source, integration instructions are available through Binance's developer-facing Agent OS page and its MCP server documentation.

It's worth noting that this launch comes right after a Guardrail evaluation found that internal controls at five major AI labs are all falling short — a story covered in our piece on AI labs failing to keep their own systems in check.

Editor's take

The fact that Binance sets no separate cap on trading losses and instead lets the sub-account balance serve as the de facto limit says a lot about its design philosophy. The exchange hasn't built any tool to verify whether an agent's judgment was right or wrong — and by its own account, it structurally can't, since the reasoning happens on the user's machine or inside whatever AI app they've chosen. So whether an agent falls for a prompt injection or gets fooled by bad price data, the only safeguard Binance offers is that losses can't exceed whatever was put into the sub-account in the first place.

Set against Kraken, Coinbase, and OKX, all of which rolled out MCP-based agent trading earlier this year, Binance's launch looks more like catching up than leading. But scale changes the calculus here — with 300 million registered users, this announcement makes it far more likely that letting agents trade becomes a mainstream option rather than something only a handful of early adopters experiment with.

In practical terms, the one solid piece of advice right now — for individuals and teams alike — is to only put money into the sub-account that you can actually afford to lose. Since the exchange has no visibility into an agent's reasoning, risk management effectively comes down to whatever ceiling a user sets before transferring funds. Given the real possibility of an agent malfunctioning due to prompt injection or bad price signals, it's safer to start by requiring approval on every order, watch how things go for a few weeks, and only then move to fully autonomous execution.

It's likely that other major exchanges will roll out similar sub-account-based agent trading structures in the coming months. But if there's ever a widely reported incident where real losses result from a prompt injection or manipulated market signal, this whole approach of pushing control onto the user could draw serious scrutiny from regulators.

Comments