Binance rolled out Agent OS on Thursday, a platform through which AI agents can study markets and place trades for users, putting self-directing software in charge of actual funds at the biggest cryptocurrency venue in the world, one with more than 300 million registered users.
Developers can hook AI applications and agents up to the financial plumbing the exchange operates. The platform works with outside AI products, among them OpenAI's ChatGPT and Codex, Anthropic's Claude Code, and Cursor, and it is the user who grants an agent permission to pull market data, see account details and place orders. Underneath, Agent OS repackages tooling Binance already ran — its APIs, its Wallet Agentic Hub and its Skill Hub, and x402, the service it uses to verify transactions and settle payments — and adds newly introduced support for the Model Context Protocol.
Restraining those agents falls largely to users, who decide what an agent may reach, what it may trade, and how far it can go. Jeff Li, Binance's vice president of product, told TechCrunch that the company chose that fine-grained user control over unrestricted latitude and put it in the account itself: an agent is handed a separate subaccount, tailored to particular functions such as spot or futures trading, and money cannot be withdrawn from it unless that setting is changed. Users also choose whether every order needs sign-off first or whether the agent trades on its own once permissions are in place.
Agent OS also ties agents into payments and on-chain activity: the x402 integration lets them make and clear payments, while the Agentic Wallet opens up tokens and decentralized-finance protocols. On both of those, Binance does fix daily ceilings — $50,000 for ordinary swaps, a default $100,000 for DeFi transactions and $20 for x402 payments. Trading on the exchange itself carries no equivalent cap, only the sum the user moves into the agent's subaccount.
Asked whether Binance has any view into why an agent takes a given position, Li told TechCrunch that the thinking behind a trade happens beyond anything Binance runs — on the user's own machine, or inside whichever AI application they picked — and that the company cannot see the reasoning behind a user's action when an agent trades for them. The exchange can watch the trades an agent ends up making, but it sees little of whether bad data or tampering shaped any particular call. Pressed by the publication on what follows if an agent is hijacked by prompt injection or compromised some other way, Li went back to the subaccount structure as the principal protection. Binance says the security, risk management and anti-money-laundering rules it already applies to subaccount APIs cover Agent OS from launch.
Li told TechCrunch that Agent OS was an opening move toward giving developers somewhere to build AI-driven applications able to work in crypto markets and conventional ones alike. Rivals have been opening their own infrastructure to agents along the same lines: Kraken put out an open source command-line tool in March with an MCP server inside it, through which agents can place spot and futures trades; Coinbase followed in June with Coinbase for Agents, wiring agents straight into customer accounts within boundaries each user draws; and OKX switched on agent-driven trading earlier this year by adopting an open source MCP toolkit.
Cover image: “Binance Logo” by Bxalber, Wikimedia Commons, CC BY-SA 4.0, resized, re-encoded.