Main post topics:
Agentic Wallet security controls are set in the Binance app, so you can define what your agent is allowed to do, how much it can spend, and what it can access before it starts operating.
Most protections are enabled by default and can be adjusted or disabled—except for the address allowlists—at any time, if you need more flexibility.
Developer Mode is optional for signing external transactions and applies separate protections, while notifications and a dedicated panel help you track asset changes and confirm higher-risk actions.
Agents are useful when they reduce manual work. They can monitor, decide, and execute your strategy so you don’t have to obsessively watch the charts. But that same capability creates an obvious risk: an agent may do something you didn’t intend, either because the settings were too broad, the behavior was unexpected, or something was compromised. That’s why Binance implemented safeguards to help reduce these risks for users.
In this post, we’ll focus on the security controls created specifically for the Binance Agentic Wallet, which is used when an agent needs wallet features and on-chain capabilities.
What is the Binance Agentic Wallet?
The Binance Agentic Wallet is a dedicated, MPC-protected wallet built so that AI agents can make trades, transfer assets, manage holdings, and perform on-chain operations on your behalf.
Its balance is isolated from your main Binance wallet. An agent can only access the funds you transfer to it and only within the permissions, spending limits, and allowlists you set in the Binance app.
Security by design
Binance approaches agent security through good product design—offering direct controls over permissions, limits, and visibility. Users shouldn’t need to be security engineers and specialists to use our product. The underlying structure is sophisticated, while the user controls are designed to be accessible to anyone who feels comfortable configuring trades and wallet adjustments.
We built our toolset so you can set clear limits without having to dig through lines of code. All Agentic Wallet security settings can only be changed in the Binance app. You also shouldn’t need to approve every individual action for an agent to be useful. Once the agent is running, it operates within the limits you set, and you get visibility through a panel and push notifications whenever it moves assets.
Set limits before the agent can act
When you enable the Agentic Wallet in the Binance app, you set four key limits that determine what the agent can do and where it can operate. These controls are enforced. If an action is outside your settings, the agent can’t access it. Most of these protections are enabled by default. If you already have experience using agents, you can loosen these settings at any time for more flexibility.
Choose what the agent can do
Start by choosing the categories of actions the agent can access via module toggles at the capability level. If you want the agent to only read data, you can enable market data and disable everything else. If you want it to make transfers but not interact with DeFi, that’s also possible. Disabled scenarios are inaccessible to the agent.
Set a daily spending limit
There isn’t a single overall limit: Dex Swap & Transfer, DeFi, x402, and Developer Mode each have their own separate 24-hour quota, configured independently and consumed independently. A low limit in one of them won’t affect the others, so it’s worth setting each deliberately.
If you’re new to using agents, start with the smallest available limit for each. This gives you room to test real workflows without giving the agent excessive spending power.
Limit which tokens it can use
A token permissions allowlist is enabled by default. With it enabled, the agent can only operate with the tokens you specify. If a token isn’t on the list, it’s out of scope. Advanced users can disable the allowlist, but the default is to keep the protection enabled.
Limit who it can send to
Recipient restrictions are applied permanently. Agents can only transfer to addresses in your address catalog of the permissions allowlist, plus your own linked keyless wallet address tied to the UID. You can manage the contents of the address catalog, but you can’t disable the restriction.
Additional on-chain protections
Untrusted tokens are automatically analyzed for honeypot behavior and the token’s tax rate. A tax rate above 5% triggers a warning, and above 10% is treated as high risk. If the audit service is unavailable, execution requires explicit user confirmation.
Review and revoke EVM token approvals to reduce exposure to old approvals you no longer need, or mitigate the impact if a previously granted approval is later compromised.
MEV protection is enabled by default, which helps reduce the risk of third parties deliberately causing an unfavorable execution in your trades.
Developer Mode: additional protections for advanced permissions
Some users may want their agents to sign externally constructed transactions—that is, raw transactions not limited to Binance’s official contracts. Since the risk profile is higher, the Agentic Wallet provides a separate set of protections through Developer Mode.
Developer Mode is disabled by default. Enabling this feature for the first time requires reading a legal notice and completing a secondary confirmation.
What changes when you enable Developer Mode
24-hour separated transaction quota pool: Use a separate 24-hour transaction limit, defaulting to 1,000 USDT, adjustable to 5,000 / 10,000 / 50,000 USDT, calculated separately from the agent’s normal transaction limits.
Maximum hard balance limit: A wallet balance above 10,000 USDT cannot enable Developer Mode, and it is automatically disabled if that value is exceeded during operation.
Automatic deactivation after inactivity: It is automatically disabled after 7 days of inactivity, and the activity timer is reset after each successful preview or execution.
Unlimited approval rejection: If an unlimited approval is detected (e.g., approve(spender, MAX_UINT256)), the transaction is rejected immediately.
Mandatory transaction simulation: External transactions must be simulated on-chain before execution. If the simulation fails, the signature is refused.
Visibility and handling of higher risk
Agents are designed to operate without you needing to monitor every step, but the experience still needs to be transparent. The Agentic Wallet shows asset changes as they happen and uses your risk settings to decide whether an action needs confirmation or should be blocked.
Notifications and a panel to review activity
Any transaction involving asset changes (transfers, swaps, DeFi operations) triggers a push notification in the Binance app. A dedicated panel also shows asset changes and the Agentic Wallet’s operation history.
Confirmation for high-risk activities
Transactions that reach a risk score of 4 or higher can be sent to the Binance app for your confirmation or automatically rejected, depending on how you configure your abnormal transaction settings.
Session timeout and emergency controls
The Agentic Wallet logs out after 48 hours of inactivity, and the wallet can be frozen by the Binance app.
Final considerations
Agent OS connects agents to real financial capabilities, putting user security and control at the center of the experience. Users can delegate execution while keeping clear limits on what their agent is allowed to do, where it can operate, and how much it can use.
In the Agentic Wallet, these controls are expressed through limits in the app: an optional Developer Mode with separate safeguards, plus visibility into asset changes through notifications and a dedicated panel.
As more users interact with on-chain services through agents, it’s important to find a delicate balance between convenience and strict controls. We want users to have strong protections without turning the experience into a technical exercise bogged down in complexity and pages of code.
Further reading
Legal notice: The Agentic Wallet is a dedicated Keyless Wallet in which AI agents are enabled to interact with Binance Wallet services on the user’s behalf. Users are the only parties responsible for setting the agent’s permissions, defining appropriate limits, and monitoring the agent’s activity. The Agentic Wallet uses artificial intelligence (AI) to automate actions on your behalf and provide information and recommendations. This includes automated actions/transactions within the permissions and limits configured by the user. The AI’s outputs may be inaccurate, incomplete, or unsuitable for your needs. By selecting “I agree” and enabling this feature, you acknowledge that the Agentic Wallet enables AI agents to take actions on your behalf within the permissions and limits you configure. Your inputs, instructions, and related data will be processed to provide these AI-enabled features, in accordance with the Privacy Notice. Use of the Agentic Wallet involves inherent risks associated with automated and AI-driven decision-making, including the possibility of unintended transactions, errors, or losses resulting from the agent’s behavior within the scope of permissions granted by users. Binance Wallet does not guarantee the accuracy, reliability, or results of any actions performed by an AI agent operating through the Agentic Wallet. The Agentic Wallet uses Secure Auto Sign technology which, once authorized, allows transactions to be executed without individual transaction confirmations. The Agentic Wallet operates as a standalone wallet isolated from your existing Binance MPC Wallet. Binance Wallet does not assume any responsibility for losses resulting from agent errors, unauthorized access, or misuse. Digital asset prices are volatile, and investments may lose value. Seek independent advice before investing. This is not financial advice.
For more information, please see our Terms of Use, Risk Notice, and AI Policy and Terms.
Attention: Please note that there may be discrepancies between this original English content and any translated versions (these versions may be generated by AI). Please refer to the original English version for the most accurate information if discrepancies arise.
