Binance lets AI agents trade real money on its exchange

Share
Binance lets AI agents trade real money on its exchange

Two moves today show the AI-agent economy maturing fast — one putting autonomous software directly in charge of real money, the other raising hard questions about how real China's robotics boom actually is.


Binance has launched Agent OS, a platform that lets AI agents analyze markets and execute trades on users' behalf using real money. The world's largest crypto exchange, with more than 300 million registered users, opened the platform Thursday, wiring agents into Binance's APIs, wallet infrastructure, and payment rails and giving them access to tools including ChatGPT, Claude Code, and Cursor. Developers connect agents through a Model Context Protocol server, so an agent can pull market data, view an account, and place orders once a user grants permission.

The safety model is where it gets interesting — and thin. Binance leans on dedicated sub-accounts that users assign to agents, with withdrawals blocked by default and permissions scoped to specific activities like spot or futures trading. Users choose whether an agent must ask before every order or can trade autonomously, but Binance imposes no separate cap on how much an agent can trade or lose; the balance you fund into the sub-account is the limit. Crucially, Binance says it cannot see the reasoning behind an agent's decisions — that happens on the user's machine or inside their AI app — so if an agent is manipulated through a prompt-injection attack, the sub-account sandbox is the main line of defense. That is a real gap for software that can be talked into bad trades by a malicious webpage. Rivals are moving the same way: Kraken shipped an open-source MCP command-line tool in March, Coinbase followed in June with "Coinbase for Agents," and OKX enabled agentic trading earlier this year.


An FT investigation suggests China's humanoid-robot demand is propped up by a circular, state-backed scheme rather than genuine commercial uptake. According to reporting summarized by The Decoder, Chinese humanoid makers sell a large share of their machines to state-backed training centers, where people teleoperate the robots through physical tasks and then sell the collected motion data back to the manufacturers — a loop that blurs the line between real demand and policy-created demand. At Unitree, nearly three-quarters of humanoid revenue in the first nine months of 2025 came from education and research, and analysts question both the valuation (about 35.89 times revenue versus roughly 20 times for its Hong Kong rivals) and the data's usefulness, since only two to three of every eight training hours are said to be usable.

The pattern echoes the circular-investment criticism leveled at Nvidia in the US, where backing customers who then buy its products inflates the apparent size of the market. We dug into Unitree's blockbuster debut and the broader China robotics land-grab earlier this week — Unitree's 629% debut and the hunt for China's next robot champion — and the FT's reporting is the skeptical counterweight to those eye-popping numbers.

What to watch: whether Beijing's continued subsidies turn this into a real industry (as with solar and EVs) or leave investors holding overvalued metal.

If an AI agent you authorized lost your money to a prompt-injection attack, who should be on the hook — the exchange, the agent's developer, or you? Tell us in the comments.

Read more

The Take — Anthropic sandboxed its tests, not its product

The Take — Anthropic sandboxed its tests, not its product

I think Anthropic's decision to cut live internet access from all of its internal evaluations is the right tactical call made at the wrong altitude. The company has secured the lab — its eval rigs, its RL environments, the third-party servers its test agents were poking. The product keeps the web, and the product is where Anthropic says the same behavior shows up every day. You cannot buy search and computer use from Claude and run it in a clean room; customers just agreed to the opposite. Sta

DeepSeek's cheap long-context trick leaves periodic blind spots

DeepSeek's cheap long-context trick leaves periodic blind spots

Ask a DeepSeek V4 model the same question twice — once with a few extra spaces typed at the front — and the answers can diverge from "genius" to "incoherent." A ByteDance research team has traced that trick to a structural flaw in chunked KV-cache compression, the memory-saving technique that makes DeepSeek's long context so affordable, and the paper argues the flaw travels with every model that compresses context the same way. The bug, in plain terms Long contexts are expensive because the

Google's Nano Banana 2.1 ships 4K images at half the price

Google's Nano Banana 2.1 ships 4K images at half the price

Google quietly turned its popular image model into a cheaper, sharper product this week — while the receipts show the update is real and the pricing math cuts both ways. Plus: Microsoft puts OS-level fences around AI agents, and a ByteDance paper finds DeepSeek's memory trick leaves periodic blind spots. Google released Nano Banana 2.1, and the API bill for image generation just got cut roughly in half. The new model — available as gemini-nano-banana-2.1 in the Gemini app, AI Studio, and the G

Anthropic's Tom Brown ended the June model-safety standoff

Anthropic's Tom Brown ended the June model-safety standoff

Two stories today that have nothing to do with benchmarks: how one lab actually resolves a fight with Washington, and what publishers do with AI when nobody is watching. The Wall Street Journal reports that Anthropic co-founder Tom Brown — a Republican with deep GOP ties — personally ended the two-and-a-half-week June standoff over model safety, and brokered the lab's compute deal with Elon Musk's SpaceX on the way. According to the Journal's profile, Brown's Washington relationships were the