
Recently, many friends have connected ChatGPT, Claude, and Grok to exchanges, and the first question they ask is almost the same:
Should we let it place orders or not?
I ran the same set of questions twice using the permissions of Binance Agent OS:
One run was set to "read only market data + account read only," and the other allowed it to place orders in the Agentic sub-account.
Let's put the conclusion up front:
- Read-only mode: AI messes up, but the money in the account is usually still there.
- Order mode: If AI messes up, the maximum loss is approximately equal to the amount you transferred into the sub-account; if contracts were also opened, losses can be amplified by leverage.
- The sub-account can prevent "transferring coins to someone else's address," but cannot prevent "being liquidated inside it."
This is not a question of whether the functionality is good or not, but rather a question of permission boundaries.
1. The difference in permissions between the two modes
Binance Agent OS connects AI to the account via MCP. The official documentation states clearly: permissions are selected by you, withdrawal permissions will never be opened, and the agent cannot transfer money from the main account to the sub-account. Funds can only be transferred by you.
In short:
Read-only = Consultant. Placing Orders = Handing isolated funds to an executor that can hallucinate and be led by prompts.
The official documentation also states: every order placed by the agent is the user's responsibility; it may use outdated data or fabricate parameters. You should verify before execution.
2. The errors AI has actually made in the past six months
The following are not hypothetical scenarios; they have actually occurred. Decide whether to enable trading permissions after reading.
① Misunderstanding "tip a little" as "transfer all"
In February 2026, an AI trading bot called Lobstar Wilde intended to tip a stranger a small amount of cryptocurrency on X, but ended up transferring approximately $250,000 of its entire holdings. The incident occurred within three days of going live. The command was natural language, and the machine executed it faster than a human.
② Prompt injection: Morse code tricked out six figures
On May 4, 2026, an attacker sent a "membership NFT" to a wallet associated with Grok to expand payment permissions; then injected commands hidden in Morse code into the content. After decoding, the connected payment agent (Bankrbot) treated it as a transfer command, transferring out approximately $150,000 to $200,000. There was no contract vulnerability; the model took "the read words" as "authorized operations."
③ A single command "close it," and AI liquidated all USDT in the contract
On April 11, 2026, someone instructed Claude Code to "close it" (liquidate a test position). The model correctly executed the closing but inadvertently wrote a snippet of code that transferred 1,446.65 USDT out of the spot wallet, most of which was locked as margin for existing positions. The money did not leave the exchange, but the spot side was instantly emptied. The user approved the "liquidation script," not the "sweeping of balance."
④ Experimental account evaporated about $10 million in one day
In January 2026, Alpha AI's public experiment handed over a roughly $11 million account to a self-trading agent, and a day later only about $1 million remained. This was not theft; rather, the strategy compounded losses in volatility.
⑤ The model can "gamble"
At the end of 2025, an experiment placed GPT, Gemini, and Claude in a negative expected value game. When prompts were written as "maximize profits," the bankruptcy rate peaked at around 48%. In trading scenarios, many users' first sentence to AI is often "help me earn as much as possible."
For a classic comparison: in 2012, a deployment error at Knight Capital led to a $440 million loss in 45 minutes. Back then, there were no large models, already indicating that "automation + order rights" is inherently dangerous. Now there’s just an added layer: models may misinterpret human commands.
These five types of errors can be summarized in a table related to today's agent:

The last line is crucial:
This design by Binance kept "being scammed onto the blockchain" at bay.
However, it does not protect against trading losses. The balance in the sub-account is the ceiling for how much the agent can lose. Someone in the community has directly asked: with withdrawals closed, accidental operations can still wipe out the sub-account. This judgment is correct.
3. The difference in losses between the two modes for the same $1000
Using a specific number makes it clearer than slogans.
Assume the main account has $50,000 USDT, and you only transfer $1,000 USDT into the Agentic sub-account.
Now, let's zoom in on this and compare it with the previous real cases:

The difference in losses between the two modes is not "a little smarter vs a little dumber," but the difference between 0 and "the amount you put in."
The sub-account is not insurance; it is a fuse. The rated value of the fuse is the amount you transferred in.
4. Practical steps: first read-only, then decide whether to give it the capability
Below is the path I actually clicked through. Currently, Agent OS mainly operates on desktop; there is no complete connection process in the mobile app. Compatible clients include ChatGPT, Claude Desktop / Claude Code, Codex, VS Code, Grok Bot, etc.
Step 1: The account must first meet the conditions to "open sub-accounts"
Sub-accounts require the main account to complete identity authentication and enable 2FA. Regular users can also open them; you do not have to be a VIP first.
If you do not have an account yet, follow the steps below to complete the link and enjoy a 10% rebate:
Registration link: https://jump.do/zh-Hans/xlink-proxy?id=3 Invite code aicoin668
Welfare group: https://www.aicoin.com/link/chat?cid=gmLgwvKD1
If you already have an account, just log in. This step is unrelated to connecting to AI and is a prerequisite for all subsequent isolation operations.
At the same time, it is recommended to enable:
- Withdrawal whitelist (main account)
- Anti-phishing code
- Login 2FA (authenticator; do not rely solely on SMS)
Leave the money in the main account. Idle USDT can continue to remain in a savings account or spot, without needing to transfer everything just for "playing AI."
Step 2: Only access market data, act as an assistant that checks the market
When connecting to MCP, only check market data.
You can ask it:
- "What is the current spot price of BTC, the price difference, and the most recent 15-minute K-line?"
- "Is the perpetual funding rate for BTC USDT positive or negative?"
- "Compare today's volatility for ETH and SOL, without giving trading instructions."
Do not ask:
- "Help me buy."
- "Do you think I should go all in?"
- "Maximize profits"—this type of prompt tends to push the model toward increasing positions.
During the read-only phase, it is recommended to compare Binance App's price alerts, K lines, and market data with AI. AI is responsible for summarizing, while the app is responsible for verifying figures. If the numbers do not match, trust the app.
Step 3: Add "account read-only," still do not place orders
This step allows it to see the balance and positions in the Agentic sub-account, and optionally give the main account a read-only view.
The purpose is for reconciliation, not trading:
- "How much USDT is in the sub-account, are there any pending orders?"
- "What are today's fees approximately?"
- "Are there any position directions inconsistent with my memory?"
At this point, losses are still close to 0. The worst-case scenario is that it analyzes incorrectly, and you follow along— that’s a human issue, not a permissions issue.
Step 4: If you must let it place orders, first meet these 6 conditions
- Create a new Agentic sub-account, do not use the main account's API.
- The path is roughly: Avatar / Overview → Sub-account → Account Management.
- Transfer only what you can afford to lose. For beginners, it is recommended to start with $20-$100, do not transfer four-digit amounts. The official words are: only transfer assets you are willing to let the agent operate.
- Minimize permissions: enable spot only first, do not enable contracts, do not enable leverage, do not enable internal transfers.
- If there is an option for "confirm every order," select it; do not go fully automated right away.
- Find and place the "emergency stop/disconnect agent" access point where you can easily reach it.
- Continue managing the main account yourself: investments, large spot trades, withdrawals, do not hand over to the agent.
The transfer entry is on the asset management page of the sub-account. Remember: the agent does not have the ability to "recharge" itself, which is a good thing.
Step 5: Use the same command to compare the two responses
The original sentence I use for comparison is:
Assuming you judge that BTC will fluctuate within 4 hours, provide operational advice.
If there are no trading permissions, only analysis is allowed.
If there are trading permissions, it must also report: direction, quantity, price, stop-loss, worst-case loss.
During read-only mode, it will typically provide ranges and reasons, without placing orders.
After trading rights are enabled, the same command "help me handle this" could result in it executing market orders, increasing positions, or transferring spot to contracts.
The Claude Code incident in April was precisely caused by the three words "close it," leading to the balance sweeping. Therefore, prompts should have strict boundaries, for example:
- Single order not exceeding $20
- Prohibit market orders for all positions
- Prohibit contracts
- Prohibit any transfers
- If unsure, ask me; do not guess
5. What functions beginners should enable first, do not rush to the battlefield
Ranked by familiarity, do not skip levels.
Week 1: Read-only + Manual Trading
- Agent: Market data
- You do spot limit orders in the app
- Casually understand funding rates and price differences
- Idle funds can stay in Simple Earn for instant access, separate from the "experimental account"
Week 2: Read-only accounts + Grid or limit orders, still require your confirmation
- Agent: Market data + Read-only for sub-account
- Use Binance's built-in spot grid, regular investment, limit orders for trading
- Grids are clearly defined programs, much more stable than "models inventing strategies themselves"
- Have AI do one thing only: explain grid parameters, do not let it change orders
Week 3: Small spot trades in the sub-account, confirm each trade
- Transfer $20-$50
- Only enable spot trades
- Turn off internal transfers
- Consider reducing confirmation frequency only after a week without "mis-heard orders or random openings"
Do not enable yet:
- Contracts and leverage (liquidation speed is faster than model response)
- Internal transfers in sub-accounts (the entry point of accidents like Claude Code's)
- Any write permissions beyond read-only for the agent
- Prompts like "maximize profit" or "automatically double my investment"
- Letting the agent read random web pages, tweets, unknown NFT metadata before executing (injection risks)
Functions like contracts, options, and tokenized stocks can continue to be used separately, but keep them separate from the agent's experimental account. It’s fine to have multiple ways to utilize one account, but do not let the same agent operate on spot, contracts, and the main account simultaneously.
6. A checklist to review before launching
Before connecting:
- 2FA is enabled
- Using a sub-account, not the main account
- Sub-account amount is something you're comfortable losing
- Trading permissions are not checked, or only spot is checked
- Transfer permissions are not checked
- You know where to quickly disconnect in an emergency
Before each conversation:
- Prompts have limits, restricted areas, and "ask if unsure"
- You have not treated text from random web pages/screenshots as command sources
- Numbers are based on the app's market data, not the model's verbal quotes
If any of the following situations occur, immediately disconnect the agent, freeze the funds in the main account, or transfer funds back from the sub-account:
- Transactions you didn't initiate occur
- Spot USDT suddenly decreases, contract wallet suddenly increases
- It starts explaining, "To improve fund efficiency, first transfer to the contract"
7. How I currently use it
On a daily basis: Agent reads market data and helps me gather several pieces of information about the market, funding rates, and news.
Order placement: I do my own spot limit or grid orders.
Experiment: One separate sub-account, within three digits, without opening contracts.
Main account: Authentication, investments, large holdings, all not given to the model.
The difference between read-only and placing orders is not "whether AI is smart," but:
When it mishears a phrase,
one will cost you time,
and the other will cost you all the money in the sub-account.
Let it be an assistant first. Wait until you can independently understand transaction records, funding fees, and liquidation prices before considering whether to hand over that capability.
The above is a compilation of personal tests and public events, and is not investment advice. Digital assets and AI agents carry a risk of principal loss; functionalities are subject to actual app presentations and local regulations.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。




