← All insights
SecurityNon-custodial

Agentic Trading: What Can the Agent Do to Your Money?

Agentic trading lets AI agents place real orders in your account. What decides your downside is permission scope: what the agent may do to your balance.

Packed Research 10 min read
SECURITY

Agentic trading lets an AI agent place real orders in a real account, and permission scope decides how much you can lose. An agent barred from withdrawing can lose a trade while your balance stays put. Binance blocks withdrawals from agent sub-accounts by default, Robinhood bars its agent from transferring crypto, and Packed Capital applies the same trade-only limit to its human managers.

Binance opened its agent platform in August 2026. TechCrunch’s Jagmeet Singh described Agent OS as a service that “lets developers connect AI applications and agents to Binance’s financial infrastructure,” with the platform “allowing users to authorize agents to access market data, view account information, and execute trades” (TechCrunch, 20 August 2026). Robinhood shipped a parallel product of its own. Webull titles its version “Let your AI agent trade the markets.” A Google search for the phrase now returns broker pages above explainers, with Robinhood appearing twice on the first page and Finder’s “Best Agentic Trading Platforms for 2026,” Nansen, Webull and Interactive Brokers behind it.

Most of the commentary argues about whether the agents trade well. That argument will run for years, and it will not settle the question a holder needs answered first: what is the agent permitted to do to your balance?

Permission scope is the security boundary here; model quality is not. A brilliant agent holding withdrawal rights can cost you everything in the account. A mediocre agent holding trade-only rights can cost you a position and leave the balance where it sits. This article covers what the agent platforms permit, what breaks when permissions run wide, how to audit your own account, and why the same test applies to a human manager. Our pillar on non-custodial crypto asset management sets out where account control sits in a managed arrangement.

What is agentic trading, and what changed in 2026?

Agentic trading is an arrangement in which an AI system holds the authority to place orders in a live account with real money. Earlier software stopped at a signal that a person then reviewed and executed by hand.

Automated execution itself is ordinary in crypto. Grid bots, DCA schedulers and copy-trading systems have connected to exchange APIs for a decade. What changed is the decision layer. An agent takes instructions in plain language and picks its own actions inside whatever authority it was handed.

Binance made that authority explicit and adjustable. Users decide “whether an AI agent must seek approval for every order or can execute trades autonomously,” so one product covers both a co-pilot that asks before every fill and a system that trades unattended. The quieter half of the same design carries more weight for a large holder: even in autonomous mode, “withdrawals from those subaccounts are blocked by default.” Whichever way the approval switch is set, the money stays in the account.

Robinhood reached the same conclusion through a different door. Its support documentation states that “Your agent can only place trades in your Robinhood Agentic account,” a dedicated account the customer funds and the agent operates inside (Robinhood, Agentic Trading overview, retrieved 6 September 2026).

Two of the largest retail venues shipped agent products within weeks of each other and landed on the same containment design: a walled account where the agent trades and the path out is closed by default.

What is an AI trading agent actually allowed to do to your account?

Four capabilities usually travel together inside a single credential, and each is separable.

Read. Balances, open positions, order history, watchlists. Robinhood grants its agent exactly this layer, describing read access to accounts, positions, balances, transactions and order history, and watchlists. Reading changes nothing and is the floor any strategy needs.

Trade. Placing, modifying and cancelling orders inside one account. This is where market risk lives: a trading permission lets someone lose money for you through decisions, while the assets stay under your name.

Move funds internally. Transfers between your own accounts, staking, lending, posting collateral. The assets get committed somewhere and can become unavailable without ever leaving the venue.

Move funds out. Withdrawal to an external address. This is the only permission that removes the assets from your control entirely, and it is the only one where a mistake has no undo.

The four rungs of a trading permission A ladder of four permission levels for any credential granted to an agent or a manager: read only, trade only, trade plus internal transfer and staking, and withdrawal enabled. A custody boundary is drawn between the second and third rungs. WHAT THE CREDENTIAL PERMITS Least dangerous first. Each rung adds authority over your balance. 1 Read only Sees balances, positions and order history. Changes nothing. NO RISK 2 Trade only Places, modifies and cancels orders in one account. Moves nothing. MARKET RISK ONLY CUSTODY BOUNDARY 3 Trade, plus internal transfer, stake and lend Assets get committed or locked without ever leaving the venue. CAUTION 4 Withdrawal enabled Assets can leave to an external address. There is no undo. REFUSE
Rungs one and two cap the damage at a losing trade. Below the custody boundary the assets themselves start moving, and rung four is the one worth refusing outright.

The line between rung two and rung three is where custody changes hands, and it is invisible in most interfaces. Both Binance and Robinhood drew their line there. Robinhood’s wording is unusually direct for a support page: “Your agent can trade crypto, but it can’t transfer, stake, or lend it.”

Which agentic trading permissions did Binance and Robinhood restrict?

The two designs differ in the details and agree on the boundary.

Binance runs agents inside sub-accounts with withdrawals blocked by default, and puts hard caps on the wallet side of the product. Regular swaps are limited to “$50,000 a day,” DeFi operations carry a “$100,000 daily limit,” and x402 payments are capped at “$20 a day.” Ceilings of that shape do not depend on the agent behaving; the venue enforces them against the credential.

Robinhood confines the agent to one account and withholds account creation as well. Its documentation notes that a customer needs a Robinhood Crypto account and that “your agent can’t open one for you.” An agent that cannot open accounts cannot expand its own perimeter.

Binance Agent OS and the Robinhood Agentic account compared Two 2026 venue designs side by side. Binance runs agents in a dedicated sub-account with withdrawals blocked by default and daily wallet caps of fifty thousand dollars for swaps, one hundred thousand dollars for DeFi and twenty dollars for x402 payments. Robinhood confines its agent to one funded account and bars it from transferring, staking or lending crypto and from opening accounts. TWO VENUE DESIGNS, 2026 Binance Agent OS 2026 agent runs in a dedicated sub-account Read market data and account info Execute trades in the sub-account Withdrawals blocked by default Per-order approval or autonomous WALLET CAPS, VENUE ENFORCED $50,000 per day, swaps $100,000 per day, DeFi $20 per day, x402 Robinhood Agentic account 2026 agent operates one funded account Place trades in that account only Read positions, balances, history No transferring, staking or lending Cannot open a Crypto account IN THE SUPPORT DOCUMENTATION “Your agent can trade crypto, but it can’t transfer, stake, or lend it.” ROBINHOOD SUPPORT Same conclusion, two venues: the agent trades, the money stays.
Two of the largest retail venues shipped agent products weeks apart and landed on the same containment design. The agent gets a walled account, and the path out is closed by default.

The capability grid below sets those two designs against the arrangement a careless holder ends up with, and against a restricted managed sub-account.

CapabilityBinance Agent OS sub-accountRobinhood Agentic accountBroad API key, withdrawal enabledPacked’s restricted sub-account
Place tradesYesYes, in that account onlyYesYes
Read balances and positionsYesYesYesYes
Withdraw funds off the venueBlocked by defaultNoYesNo, permission never granted
Transfer, stake or lend cryptoCapped by daily limitsNoYesNo
Open new accounts for youNoNoSometimes, depending on scopesNo
Reach the rest of your holdingsNo, sub-account is isolatedNoDepends on account structureNo, sub-account is isolated
Who sets the limitBinance, plus your settingsRobinhoodWhoever holds the keyYou, at your own exchange
Worst outcome on the operator’s bad dayA losing tradeA losing tradeAn empty accountA losing trade

The last row is the one to read twice. Three of these four columns cap the damage at a losing trade. The broad API key column has no cap at all.

What goes wrong when API key permissions are too broad?

Auth0’s Will Johnson put the default state plainly in a September 2025 note on agent credentials: “Most API keys are created with broad permissions, violating the Principle of Least Privilege” (Auth0, 2 September 2025). Keys get made in a hurry, every checkbox gets ticked so nothing breaks, and the key ends up with authority nobody intended to delegate.

That was survivable when a key sat inside a script somebody wrote and reviewed. It stops being survivable once the credential is held by something that improvises. Johnson’s framing of the change: “If an agent is compromised or behaves unexpectedly, it can now cause irreversible damage.”

There is a failure mode specific to this generation of software. “Because agents operate based on natural language instructions, they can be manipulated by malicious prompts.” An agent reading a market-commentary feed, a social post or a document is reading text that anyone can write, and instructions can be smuggled into any of it. A trading agent with a withdrawal permission and a text input is a system where a stranger’s sentence can reach your funds.

Binance was candid about the limits of its own oversight. The exchange has “limited visibility into whether a decision was influenced by faulty information or manipulation.” The venue sees the order and has no way to see the reasoning behind it. That is precisely the situation in which you want a hard ceiling enforced by the venue, since a permission check needs no view of intent. A blocked withdrawal permission is that ceiling.

The mechanics on a crypto venue are covered step by step in our Deribit trade-only sub-account walkthrough, where the withdrawal scope is withheld and the exchange rejects the call whoever sends it.

What do crypto trading bot risks and crypto bot scams have in common?

Both are settled by the same question.

Crypto trading bot risks split cleanly in two. Inside the boundary sit the losses a trade-only credential still allows: bad entries, oversized positions, a strategy that worked in a trending market and stops working in a flat one, an outage during a fast move. Those are real, they are yours, and no permission setting prevents them. Outside the boundary sits everything that removes the assets themselves.

Crypto bot scams live entirely outside the boundary. The pattern is consistent across the variants: the operator needs a permission the strategy does not need. A profitable bot requires order placement and balance reads. It never requires a withdrawal scope, and it never requires you to deposit into the operator’s wallet. Any product that asks for either has revealed its business model, whatever the returns page says. This is the same diagnostic our guide to counterparty risk in crypto applies to lenders and yield platforms, where the permission being requested tells you more than the yield being advertised.

Withdrawal address whitelisting is the second lock worth having on any account, agent or not. A withdrawal whitelist limits where funds can ever exit to, so an approved withdrawal can only reach wallets you registered in advance. It assumes the withdrawal could be initiated at all, which is why it complements a withheld withdrawal permission and does not replace one.

How do you check what your own account has granted?

Six checks cover it, all doable in the account panel of any venue you already use, none requiring the manager’s or the agent operator’s cooperation.

  1. List every active API key and every connected app. Most holders find credentials they forgot about, and an unused key is a liability with no upside.
  2. Read the permission scopes on each one. Look specifically for a withdrawal or wallet-write scope. If it is enabled on a key you shared, that key can move money.
  3. Confirm the agent or manager is inside its own sub-account. Isolation limits the blast radius to the funded balance and keeps the rest of your holdings out of view.
  4. Check the withdrawal whitelist. Every registered address should be a wallet you control. Unfamiliar entries are the loudest possible signal.
  5. Check whether the credential can create further credentials or open accounts. Robinhood’s design blocks this deliberately. Not every venue does.
  6. Revoke one key as a drill. Deleting a key ends access instantly and needs nobody’s approval. Knowing the exit works before you need it is worth the five minutes.

Run these against every venue holding size, and repeat them each time you add a tool. The audit takes longer to describe than to perform.

Does the same agentic trading test apply to a human manager?

It does, and the answer does not move.

What decides your exposure is the permission the operator of your account holds. That test does not care whether the operator is a language model, a Python script written in 2019, or a person with twenty years in options. All three connect through a credential, all three are bounded by what it permits, and the exchange enforces the ceiling identically in every case.

One credential, one boundary, either operator An AI agent and a human manager connect through the same scoped credential into a restricted sub-account inside the client's own exchange account. The order path is allowed and marked with a check. The withdrawal path is dashed and stops at the account wall with a cross, because the permission was never granted. ONE BOUNDARY, EITHER OPERATOR Your exchange account opened by you, funded by you Restricted sub-account trade permission granted withdrawal permission withheld AI agent trades on instruction Human manager trades on mandate one credential place, modify, cancel orders withdraw to external address External address never reached EXCHANGE ENFORCED AT THE ACCOUNT WALL The boundary belongs to the account, whoever is operating it.
The same credential bounds a language model and a twenty year veteran identically. Orders go through, and the withdrawal call is rejected at the account wall because that permission was never issued.

Which is why the agentic trading story is a custody story wearing new clothes. The industry spent 2022 learning what happens when a counterparty who can move your assets does, and 2026 rediscovering it with a new kind of counterparty. The design that answers both is the same one: your account, your keys of record, a scoped credential for whoever trades, and no withdrawal path in that credential at any point. The principle behind it is unpacked in not your keys, not your coins.

Packed Capital reached this structure years before agents made it topical, and runs every mandate inside it: a restricted sub-account of the client’s own exchange account, with trade permission granted and withdrawal permission withheld for the life of the relationship. The strategies behind it are human-run, and they were traded with our own money before any client saw them. Both programs, the Option Wheel and the Hedged Grid, sell hedged options income and have been under continuous revision since 2018. Monthly trading volume across them passes $100 million.

Entry is $100,000 for the Option Wheel and $1,000,000 for the Hedged Grid, with 20–25% a year as a target, not a promise. Option income compresses in quiet markets, hedges cost money, and losing months come with trading a volatile asset. What the structure removes is narrower and easier to verify: nobody at Packed can take the coins, because that permission was never issued.

The takeaway

Agentic trading raises exactly one new question and revives an old one. The new question is how well the agent trades, and the answer arrives slowly, over years of live results. The old question is what the agent is allowed to do to your money, and the answer is available today, in the permissions panel of your own account.

Binance and Robinhood both answered it the same way in 2026, independently, for the same reason: the cheapest way to cap the downside of a system you cannot fully predict is to deny it the ability to move funds. That logic applies with equal force to software and to people. Set the boundary at the account, verify it yourself, and whoever trades on your behalf can only ever cost you a trade.

FAQ

What is agentic trading? Agentic trading is an arrangement in which an AI agent holds the authority to place real orders in a real brokerage or exchange account, choosing and executing its own trades inside whatever permissions it was granted. Binance’s Agent OS and Robinhood’s Agentic account are the two mainstream 2026 examples, and both confine the agent to a dedicated account while restricting its ability to move funds out of it.

Can an AI trading agent withdraw my crypto? Only if it holds a permission that allows it. Binance blocks withdrawals from agent sub-accounts by default, and Robinhood states that its agent can trade crypto but cannot transfer, stake or lend it. On an exchange API key you configure yourself, withholding the withdrawal scope means the exchange rejects any withdrawal call on that credential.

What API key permissions should an agentic trading bot never have? No withdrawal or wallet-write scope, no permission to change security settings, and no ability to create further keys or open accounts. Order placement and balance reads cover everything a trading strategy needs. Auth0 notes that “most API keys are created with broad permissions, violating the Principle of Least Privilege,” so assume the default is too wide.

How do I tell a legitimate trading bot from a crypto bot scam? Compare the permissions requested against the permissions the strategy needs. Any operator asking for a withdrawal-enabled key, or asking you to deposit into their wallet, is requesting authority no trading strategy requires. Legitimate arrangements run inside an account you own, on a credential you can revoke in one click.

Is agentic trading riskier than using a human manager? The custody risk is set by the credential and is identical for both. Packed Capital trades human-run strategies inside a restricted sub-account of the client’s own exchange account with no withdrawal permission, the same containment Binance and Robinhood built for their agents. Decision risk differs: an agent can be manipulated through the text it reads, while a human manager carries a process you can interrogate before funding anything.


Sources: TechCrunch, Binance now lets AI agents trade, 20 August 2026 · Robinhood, Agentic Trading overview · Auth0, API key security for AI agents, 2 September 2025

Put your idle crypto to work
Non-custodial. Your keys, our strategy. Target 20–25% / yr.
Request access