
이미지: TechCrunch AI
Summary
- Binance launched Agent OS on Thursday, letting AI agents analyze markets and trade on users' behalf
- Agents only access sub-accounts, withdrawals are blocked by default, and the funds a user deposits effectively become the trading loss limit
- For its wallet feature, Agentic Wallet, Binance itself set direct caps: $50,000 daily for swaps, $100,000 for DeFi, and $20 for x402 payments
- 출시일
- 2026년 8월 20일(현지시간 목요일)
- 바이낸스 등록 이용자
- 3억 명 이상
- 연동 도구
- 챗GPT·코덱스(오픈AI), 클로드 코드(앤스로픽), 커서, MCP
- 서브계정 출금
- 기본 차단
- Agentic Wallet 일일 한도
- 정기 스왑 5만 달러, 디파이 10만 달러, x402 결제 20달러
- 경쟁사 동향
- 크라켄(3월), 코인베이스(6월), OKX(연초) 순으로 에이전트 거래 지원 발표
- 발언자
- 제프 리 바이낸스 프로덕트 부문 부사장
Handing agents the keys to the account
Binance, which has more than 300 million registered users, unveiled Agent OS on Thursday, a platform that lets AI agents analyze markets and actually execute trades. Amid the broader shift from chatbots that merely answer questions to agents that actually move money, autonomous AI has now stepped directly into the business of managing real assets. But the responsibility for defining and enforcing what that agent can and cannot do rests largely with the user, not with Binance.

What Agent OS connects
Agent OS is a platform that lets developers plug AI applications and agents into Binance's financial infrastructure. In addition to existing tools such as the Binance API, the wallet agentic hub, the payment verification and settlement API x402, and the Skills Hub, support for the Model Context Protocol (MCP) has been newly added. It also works with OpenAI's ChatGPT and Codex, Anthropic's Claude Code, and the coding editor Cursor, allowing users to grant agents permission to check price data, view account information, and execute orders.

Sub-accounts as a safeguard
Binance gives agents access only to separately created "sub-accounts," not the full account. Users assign sub-accounts to agents while restricting them to specific activities such as spot or futures trading, and withdrawals from those sub-accounts are blocked by default. Jeff Lee, Binance's VP of Product, said, "Rather than giving agents complete freedom, we put fine-grained control over what agents can do directly in users' hands." Users can set up agents to require approval for every single order, or grant permissions and let the agent execute fully autonomously.
The exchange does not set a separate cap on how much an agent can trade or lose. The amount deposited into the sub-account effectively becomes the limit. Asked whether Binance can see why an agent made a particular trading decision, Lee said in an interview, "We have no visibility at all into the reasoning behind that judgment." Because the reasoning happens on the user's own computer or within whichever AI application they choose, Binance can monitor the trading outcomes an agent produces but cannot easily determine whether that judgment was swayed by bad information or manipulation. Asked what happens if an agent is manipulated through an attack such as prompt injection, Lee again pointed to the sub-account structure as the first line of defense. The existing security, risk control, and anti-money-laundering policies that have applied to sub-account APIs carry over unchanged to Agent OS.
Binance sets direct caps on wallet and payment activity
Unlike exchange trading, which has no separate limit, payment and on-chain activity through the x402 integration and Agentic Wallet come with daily caps set directly by Binance.
| Activity | Daily limit |
|---|---|
| Regular swaps | $50,000 |
| DeFi transactions | $100,000 |
| x402 payments | $20 |
Through the x402 integration, agents can send and settle payments, and through Agentic Wallet they can handle tokens and decentralized finance (DeFi) protocols. Lee described Agent OS as a "first step" toward a platform for building AI applications that operate across both crypto and traditional financial markets.
Exchanges racing to build agent capabilities
The trend of opening up infrastructure to AI agents is not unique to Binance.
| Exchange | Timing | Details |
|---|---|---|
| Kraken | March | Open-source command-line tool with built-in MCP server, executes spot and futures trades |
| Coinbase | June | Coinbase for Agents, trading and payments within user-set limits |
| OKX | Earlier this year | Open-source MCP toolkit supporting agent trading |
| Binance | August 20 | Agent OS, MCP, sub-accounts, Agentic Wallet |
How to use it
Based on what has been confirmed from the source material, the process works as follows. First, a user creates a dedicated sub-account for the agent within their Binance account and specifies its scope of activity, such as spot or futures trading. Next, they connect an AI application they already use — such as ChatGPT, Codex, Claude Code, or Cursor — to that sub-account through Agent OS or MCP. They then decide whether the agent should seek approval for every order or execute autonomously within the permissions granted. Finally, they transfer the funds they actually want the agent to manage into the sub-account, and that amount effectively becomes the cap on what the agent can handle. The source material states that integration instructions are provided through the developer-facing Agent OS page and MCP server documentation.
It's worth noting that this announcement comes as a Guardrail evaluation found internal controls at five major AI labs largely failing, as covered in AI Labs Are Failing to Keep Their Own Systems in Check — raising questions about the state of internal oversight at companies building autonomous agents in the first place.
Editor's view
Binance's decision not to set a separate cap on trading losses, instead treating the sub-account balance as the de facto limit, reveals its design philosophy plainly. The exchange built no tools to verify whether an agent's judgment was right or wrong. According to the company, this is structurally impossible to see, since the reasoning itself takes place on the user's own computer or within whichever AI app they choose. In the end, whether an agent falls victim to prompt injection or gets misled by bad price data, the only safeguard Binance offers is that losses are capped at whatever money was put into the sub-account — and no more.
Placed alongside the sequence in which Kraken, Coinbase, and OKX rolled out MCP-based agent trading this year, Binance's announcement looks more like a late entry than a first mover. But the scale involved — 300 million registered users — changes the calculus. This announcement raises the likelihood that giving agents trading authority becomes a mainstream option rather than an experiment for a handful of early adopters.
In practical terms, the only reliable safeguard at this stage — whether for individuals or teams — is limiting sub-account deposits to money one can genuinely afford to lose. As long as the exchange has no visibility into an agent's decision-making process, risk management ultimately comes down to the cap a user sets for themselves before transferring funds. Given the possibility of an agent malfunctioning due to prompt injection or false price signals, the safer sequence is to require approval on every order at first, observe for several weeks, and only then move to autonomous execution.
Other major exchanges are likely to roll out similar sub-account-based agent trading structures in the coming months. However, if even one major incident of real losses from prompt injection or manipulated market signals gets widely reported, regulators could quickly turn their attention to the design itself — one that, as it stands, shifts the burden of control onto users.




Comments