Skip to main content
Decentralised News Logo
Your AI Trading Bot Probably Doesn’t Need Withdrawal Access
Agentic Finance

Your AI Trading Bot Probably Doesn’t Need Withdrawal Access

By

Which AI trading platforms work without withdrawal access? DN compares 7 platforms by API permissions, transfer authority, demo access and trading risk.

Decentralised News Research | AI Trading Security 2027

7 Best AI Trading Platforms You Can Try Without Giving Them Withdrawal Access

An AI trading platform may need permission to read balances and place orders. It usually does not need permission to move your assets out of the exchange. DN compared seven live AI and automated trading platforms by how clearly they separate trading authority from withdrawal authority, whether you can test them before connecting funds, and how effectively users can reduce the financial blast radius of automation.

By Heath Muchena Last verified: 28 September 2026 AI Trading / API Security / Agentic Finance / Crypto
Affiliate disclosure: Decentralised News may earn compensation from some platforms included below. Affiliate relationships do not determine inclusion, ranking or security classification. Only platforms independently verified as operational receive active commercial pathways.

What Matters

  • Trading permission and withdrawal permission are not the same thing. A bot can usually read account data and place trades without being allowed to transfer assets to an external wallet.
  • Coinrule receives DN's strongest Withdrawal Boundary score. Coinrule states that its exchange API connections do not have withdrawal permissions, while its newer MCP architecture separately allows an AI assistant to be restricted to Read Only access before write tools are enabled.
  • Bitsgap applies one of the clearest platform-level controls. Its current documentation says an exchange API key will be rejected if withdrawal permission is enabled.
  • Cryptohopper explicitly says it does not need or want withdrawal rights. Funds remain on the connected exchange, and users can also paper trade without connecting an exchange account.
  • 3Commas instructs users to give API keys trading access only and disable withdrawals. Its current v2 platform also supports Demo Trading before live exchange access is required.
  • Cornix requires reading and trading permissions for live automation but explicitly tells users not to enable withdrawal permission. Its simulated Demo Account requires no external exchange API connection.
  • Gunbot normally needs account-reading and trading permission but advises users to avoid withdrawal permissions unless a specific integration explicitly requires them.
  • TradeSanta's current exchange-connection documentation requires Read + Trade while Withdrawal remains off.
  • Removing withdrawal permission can reduce the risk of direct asset exfiltration, but it does not prevent a compromised or badly configured trading system from losing money through trades.

DN Evidence Block

  • Verification date: 28 September 2026.
  • Platforms assessed: Coinrule, Bitsgap, Cryptohopper, 3Commas v2, Cornix, Gunbot and TradeSanta.
  • Operational status: all seven were independently verified as LIVE through current first-party documentation or active product infrastructure.
  • Primary test: can the product operate without requiring exchange withdrawal permission?
  • Additional evidence: paper/demo availability, permission granularity, AI-access controls, API security guidance, revocation and documentation freshness.
  • Critical distinction: withdrawal isolation reduces transfer authority. It does not eliminate trading authority.
  • Commercial rule: affiliate status contributes zero points.
  • DN testing status: Documented unless a future DN test upgrades a platform to Paper-Tested or Live-Tested.

Quick Answer: AI Trading Platforms Without Withdrawal Access

Rank Platform Withdrawal model Can test before live connection? AI role DN Withdrawal Boundary
1 Coinrule No exchange withdrawal permission + separate MCP Read Only scope Yes, paper trading LLM/MCP + automation 96/100
2 Bitsgap Rejects API keys with withdrawals enabled Yes, Demo Mode AI Assistant + bots 94/100
3 Cryptohopper Withdrawal permission explicitly unnecessary and discouraged Yes, Paper Trading Algorithmic + newer AI features 92/100
4 3Commas v2 Trading only; withdrawal disabled Yes, Demo Trading AI Assistant + MCP + bots 89/100
5 Cornix Read + Trade; withdrawal disabled Yes, built-in Demo Account Primarily deterministic automation 87/100
6 Gunbot Read + Trade; avoid withdrawal permission Yes, Simulator Mode AI-assisted strategy prototyping 84/100
7 TradeSanta Read + Trade; withdrawal disabled Demo functionality available Primarily algorithmic automation 81/100

DN Withdrawal Boundary: a proprietary editorial score measuring Withdrawal Isolation, Pre-Live Testing, Permission Granularity, Credential Control, AI Scope Separation, Observability and Evidence Freshness. It is not a cybersecurity certification or profitability rating.

The Most Important API Permission May Be the One You Never Turn On

When a trading bot connects to an exchange, people often think in binary terms.

Connected.

Or not connected.

That is too simplistic.

Modern exchange APIs usually separate capabilities.

A key may be allowed to:

  • read account information,
  • view balances,
  • read order history,
  • place orders,
  • cancel orders,
  • trade spot markets,
  • trade derivatives,
  • or withdraw assets.

Those permissions create very different risks.

A research tool that can only read balances cannot directly place a trade.

A trading bot can affect the portfolio but may still be unable to transfer coins outside the exchange.

A credential with withdrawal authority creates a much wider financial attack surface.

An AI trading system does not need the same authority as the human who owns the account.

The DN Withdrawal Boundary

DN calls the separation between execution authority and asset-transfer authority the:

Withdrawal Boundary.

A strong Withdrawal Boundary means a trading application can perform the functions necessary for its task without receiving permission to move assets to an arbitrary external destination.

That sounds simple.

It is strategically important.

The purpose of an external trading bot is usually to:

  • read account state,
  • submit orders,
  • cancel orders,
  • monitor positions,
  • and execute predefined strategy logic.

None of those tasks inherently requires withdrawal authority.

DN Alpha Thesis: Separate Trading Authority From Transfer Authority

The rise of AI trading will make permission architecture increasingly important. A machine may legitimately need authority to make a trading decision without needing authority to decide where the user's assets ultimately live.

No Withdrawal Access Does Not Mean No Risk

This is the most important limitation in the article.

Removing withdrawal permission can prevent an API credential from directly sending assets to an external wallet.

It does not prevent the same credential from losing money if it retains trading authority.

A trade-enabled system may still:

  • buy the wrong asset,
  • sell at the wrong time,
  • trade too frequently,
  • open leveraged positions,
  • trigger liquidations,
  • execute an incorrectly configured strategy,
  • trade an illiquid market,
  • or respond incorrectly to bad data.

This creates two separate security questions.

Question 1: Can the software move my assets away?

That is transfer authority.

Question 2: Can the software alter the value of my portfolio through trading?

That is trading authority.

Disabling withdrawals primarily addresses the first.

It does not solve the second.

The Trading Blast Radius

DN therefore extends the Authority Surface framework with another concept:

Trading Blast Radius.

Trading Blast Radius asks:

If the bot behaves as badly as its current permissions allow, how much economic damage can occur without withdrawing anything?

A bot connected to a $500 subaccount with spot-only permission has a different blast radius from a bot connected to an entire derivatives account with leverage enabled.

The withdrawal permission may be identical in both cases:

off.

The financial risk is not identical.

Permission architecture Can inspect? Can trade? Can transfer assets? Typical blast radius
Paper / demo Simulated Simulated No No direct capital loss
Read only Yes No No Primarily privacy / information exposure
Trade only Yes Yes No Capital can be lost through trading
Trade + derivatives Yes Yes No Can be materially larger because of leverage
Withdrawal enabled Usually Potentially Yes Includes direct asset-transfer risk

How DN Ranked the Seven Platforms

The DN Withdrawal Boundary score uses seven factors:

  • Withdrawal Isolation - 30%: how clearly is transfer authority excluded?
  • Pre-Live Testing - 20%: can users experiment without a live funded connection?
  • Permission Granularity - 15%: can access be reduced to the task being performed?
  • Credential Control - 10%: are revocation, API restrictions or related controls documented?
  • AI Scope Separation - 10%: can AI access be separated from live trade authority?
  • Observability - 10%: can users inspect what the system is doing?
  • Evidence Freshness - 5%: is the architecture supported by current official documentation?

Affiliate relationships contribute zero points.

No product receives credit merely for describing itself as secure.

1

Coinrule

Best overall permission separation for AI-assisted trading
DN Withdrawal Boundary: 96/100

Coinrule currently combines two different permission layers that are useful to analyze separately.

First, its exchange connection.

Coinrule states that it does not have withdrawal permissions to exchange funds and that connected API keys are used to buy and sell according to user instructions.

Second, its newer AI-assistant layer.

Coinrule's official MCP lets users choose between:

  • Read Only, and
  • Read + Write.

Read Only allows a compatible assistant to inspect supported balances, holdings, strategies, trades, signals, P&L and backtest information.

Write tools are not exposed under the Read Only scope.

Read + Write can create and manage supported strategies, including live strategies where a live exchange is connected.

The important architectural point is that AI access and trading access are themselves separated.

Operational status: LIVE
Withdrawal access required? No
AI Read Only option? Yes
Paper mode? Yes
Live exchange needed for paper? No
DN test status: Documented
Lowest-authority experiment: use paper trading without a live exchange connection. If connecting an AI assistant, start with MCP Read Only before considering any write-enabled workflow.

Best for: users wanting ChatGPT-style AI interaction with explicit permission separation.

Avoid if: you expect withdrawal isolation to make a bad trading strategy harmless.

Largest remaining risk: once Write access and live trading are enabled, a bad instruction or bad strategy can still affect real funds through trading.

Explore Coinrule
2

Bitsgap

Best hard rejection of withdrawal-enabled API keys
DN Withdrawal Boundary: 94/100

Bitsgap earns a high position because its current security documentation describes a strong platform-side check.

To use Bitsgap with a live exchange, the API key needs access to:

  • trade history,
  • balance information,
  • and trading.

Withdrawal permission should remain disabled.

Bitsgap says it checks the incoming API key and will not accept it if withdrawal permission is enabled.

That is stronger than simply telling users not to enable the permission.

The platform also offers Demo Mode with virtual funds, bots and manual trading tools, allowing a user to understand the automation before connecting an exchange.

One limitation remains important for the AI-specific angle:

Bitsgap's AI Assistant is not currently included in Demo Mode.

Operational status: LIVE
Withdrawal access required? No
Withdrawal-enabled key accepted? No, according to Bitsgap
Demo Mode? Yes
AI Assistant in demo? No
DN test status: Documented
Lowest-authority experiment: use Demo Mode first. When moving live, create a dedicated exchange API key with only the read and trading permissions required by Bitsgap.

Best for: users who want an extra platform-level guard against accidentally submitting a withdrawal-enabled API key.

Avoid if: you specifically want to paper-test the AI Assistant itself.

Largest remaining risk: the bot can still trade connected exchange funds even though it cannot withdraw them.

Explore Bitsgap
3

Cryptohopper

Best explicit no-withdrawal architecture with paper trading
DN Withdrawal Boundary: 92/100

Cryptohopper states unusually directly that it does not need withdrawal permission.

Its current documentation tells users to keep withdrawal permission disabled when creating API keys.

The platform says funds remain on the connected crypto exchange and that Cryptohopper forwards trading orders rather than holding or withdrawing the user's exchange balance.

There is also an even lower-authority starting point.

Cryptohopper's Paper Trading mode does not require a crypto exchange account.

That means users can experiment with bot behavior before an exchange API exists at all.

Operational status: LIVE
Withdrawal access required? No
Funds remain on exchange? Yes
Paper mode? Yes
Exchange required for paper? No
DN test status: Documented
Lowest-authority experiment: start with Paper Trading without an exchange connection. Create a live API key only after the strategy is understood, with withdrawal permission disabled.

Best for: users who want a mature crypto automation platform with a clearly documented trading-only permission model.

Avoid if: you assume its long-standing “A.I.” label means an autonomous LLM agent. Cryptohopper defines that feature as Algorithmic Intelligence.

Largest remaining risk: automation can still execute poor trades or poorly configured strategies.

Explore Cryptohopper
4

3Commas v2

Best larger bot ecosystem with explicit trade-only API guidance
DN Withdrawal Boundary: 89/100

3Commas' current API documentation is explicit:

when creating an exchange API key, provide trading access and disable withdrawal permission.

That allows 3Commas to place orders without granting it the ability to withdraw exchange funds through the API.

The current v2 platform also has Demo Trading.

Users can create a simulated account using real market data and virtual funds before connecting live capital.

3Commas has also introduced MCP connectivity for external AI assistants, adding another permission layer to consider.

This means a security-conscious workflow should distinguish:

  • AI assistant access,
  • 3Commas account permissions,
  • exchange trading permissions,
  • and withdrawal permissions.
Operational status: LIVE v2
Withdrawal access required? No
Required exchange permission: Trading
Demo trading? Yes
AI/MCP layer? Yes
DN test status: Documented
Lowest-authority experiment: begin with a 3Commas Demo Account. If moving live, create a dedicated exchange API key with trading enabled and withdrawals disabled.

Best for: users who want a broad bot platform plus AI-connected workflows.

Avoid if: you are following old v1 security or setup instructions. The previous 3Commas platform was deactivated in September 2026.

Largest remaining risk: trading access across multiple markets can still create material portfolio exposure.

Explore 3Commas
5

Cornix

Best demo-first pathway for signals and TradingView automation
DN Withdrawal Boundary: 87/100

Cornix documents the exact API separation clearly.

For live automation, Cornix generally requires:

  • reading permission,
  • trading permission,
  • and relevant market permissions such as futures where needed.

Its documentation specifically warns users not to enable withdrawal permission.

Cornix also has a useful pre-connection advantage.

Its built-in Demo Account does not require an external exchange connection or exchange API key.

The demo environment supports Signals, DCA, Grid and TradingView bots using simulated funds and real-time market data.

Operational status: LIVE
Withdrawal access required? No
Live permissions: Read + Trade
Demo without API? Yes
Major demo bots? Yes
DN test status: Documented
Lowest-authority experiment: use Cornix's built-in Demo Account with no external exchange API. Only create a live key after the strategy is understood.

Best for: users learning automated signals, DCA, Grid or TradingView-triggered execution.

Avoid if: you specifically require open-ended AI reasoning rather than deterministic automation.

Largest remaining risk: a bad signal can still be executed correctly and repeatedly.

Explore Cornix
6

Gunbot

Best self-hosted option for users who want credential control
DN Withdrawal Boundary: 84/100

Gunbot differs from many hosted platforms because the user runs the software themselves.

Its current exchange-connection guidance says Gunbot normally requires permission to:

  • read account data,
  • and place trading orders.

The documentation advises users to avoid withdrawal permissions unless a specific integration explicitly requires them.

Gunbot also offers Simulator Mode for spot trading.

That lets users run current strategy logic against current market data using virtual balances before live exchange funds are involved.

For technically capable users, self-hosting changes the credential architecture because API secrets remain in infrastructure they control.

That does not automatically make the system safe.

It moves more of the security responsibility onto the user.

Operational status: LIVE
Withdrawal access usually required? No
Self-hosted? Yes
Simulator? Yes, spot
Technical complexity: Higher
DN test status: Documented
Lowest-authority experiment: use Simulator Mode first. For live use, create a dedicated exchange API key restricted to the required trading functions.

Best for: technically experienced traders who want greater control over where software and credentials run.

Avoid if: you want a fully managed no-code experience.

Largest remaining risk: self-hosting transfers configuration and operational-security responsibility to the user.

Explore Gunbot
7

TradeSanta

Best straightforward trade-only API model for simpler bot automation
DN Withdrawal Boundary: 81/100

TradeSanta's current exchange-connection guidance follows the same core principle.

Its bots need permission to view account information and place orders.

Withdrawal should remain disabled.

For Binance, its current troubleshooting documentation specifies:

  • Reading enabled,
  • Spot & Margin Trading enabled where required,
  • Withdrawals disabled,
  • and IP restrictions configured using TradeSanta's whitelist.

Its documentation applies similar Read + Trade, no-withdrawal patterns to other supported exchanges.

Operational status: LIVE
Withdrawal access required? No
Typical permissions: Read + Trade
IP restrictions: Supported on relevant exchange setups
Automation type: Primarily deterministic bots
DN test status: Documented
Lowest-authority experiment: learn DCA or Grid behavior in a non-live environment first, then use a dedicated live API credential restricted to account reading and trading.

Best for: users looking for relatively straightforward crypto-bot automation.

Avoid if: your main objective is testing frontier LLM or autonomous-agent architecture.

Largest remaining risk: trade-only access still permits the strategy to execute real orders against the connected balance.

Explore TradeSanta

The Security Hierarchy: No Connection Beats No Withdrawal

Disabling withdrawals is useful.

But it is not the lowest-risk configuration.

There is a hierarchy.

Stage Connection Trading authority Withdrawal authority Primary purpose
1. Demo No live account None None Learn the system
2. Read Only Live data / account None None Monitoring and analysis
3. Trade Only Live exchange Yes No Automated execution
4. Trade + Leverage Live derivatives account High No Leveraged automation
5. Transfer Enabled Live wallet / account Potentially Yes Asset movement

The safest configuration capable of achieving your objective is usually the more interesting starting point.

DN Alpha Thesis: Permission Minimization Ratio

DN defines the Permission Minimization Ratio as the amount of authority granted relative to the authority actually required for the task. A trading application that only needs Read + Trade should not inherit Transfer merely because the exchange API makes that option available.

What Withdrawal Isolation Protects Against

When properly enforced at the exchange API level, disabling withdrawals can reduce exposure to scenarios such as:

  • an API key being stolen and used to transfer assets,
  • a compromised third-party platform attempting to withdraw through that credential,
  • a malicious AI instruction attempting to invoke an unavailable transfer function,
  • or an accidental workflow triggering an asset-transfer endpoint.

The exchange itself remains the enforcement layer.

If the API credential simply does not possess the permission, the connected application cannot create that authority on its own.

What It Does Not Protect Against

Withdrawal isolation does not protect against:

  • poor market predictions,
  • overtrading,
  • bad position sizing,
  • high trading fees,
  • slippage,
  • leveraged losses,
  • liquidation,
  • bad bot configuration,
  • trading into illiquid markets,
  • market manipulation,
  • bad API instructions,
  • or strategy bugs.

This is why “the bot cannot withdraw my funds” is a security fact, not a profitability guarantee.

Use a Dedicated Trading Account Where Possible

Withdrawal isolation becomes more useful when combined with capital segmentation.

Instead of giving a bot trading access to an account containing everything, a user may be able to isolate an experimental balance in:

  • a dedicated exchange subaccount,
  • a separate trading account,
  • or another venue-supported compartment.

This changes the Trading Blast Radius.

Suppose a trader owns $100,000 of crypto.

If the automation is attached to the entire account, trade-only access may affect a large portion of that capital.

If the automation is attached to a dedicated $1,000 experimental subaccount, the same software failure can have a much smaller maximum portfolio consequence.

Withdrawal authority is still off in both examples.

The blast radius is completely different.

DN Withdrawal Authority Checker

“No withdrawal access” is only one part of the permission picture.

The checker below estimates whether a trading setup grants more authority than the experiment appears to require.

Decentralised News Proprietary Security Tool

Withdrawal Authority Checker

Model the permissions around an AI or automated trading setup and see where the largest remaining risk sits.

Permission Risk Assessment

Low Authority

DN Recommended Action

Stay in simulation

Transfer authority risk Low
Trading blast radius None
Credential exposure Low
Capital isolation Strong
Primary remaining risk Strategy quality
This tool is an educational permission model, not a cybersecurity audit. API implementations differ by venue. Always verify the actual permission settings on the exchange itself rather than relying only on a third-party trading application's description.

The Ideal AI Trading Permission Stack

For many retail trading experiments, DN's preferred progression looks like:

Layer Preferred starting state Why
AI assistant Read Only where available Lets the model inspect without trading
Trading platform Paper / demo first Tests workflow without real money
Exchange API Read + required trading only Limits functionality to the job
Withdrawal Disabled Separates trading from asset movement
Capital Dedicated experimental balance Reduces Trading Blast Radius
Leverage None initially Avoids magnifying strategy errors
IP restriction Enabled where supported and appropriate Can restrict where API credentials are usable
Revocation Known and tested You should know how to stop access quickly

The AI-Specific Problem: Tool Permission Inheritance

Traditional trading bots typically follow predefined logic.

Agentic trading introduces another layer.

The model may decide which tool to invoke.

That means the permissions exposed to the model become part of the financial risk architecture.

If an assistant is connected to a trading platform with Read Only permission, the model cannot simply decide that it would prefer write authority.

If the available tool set contains live trading functions, its possible action space is larger.

If transfer tools are also exposed, the action space grows again.

The security objective should therefore be:

do not expose a financial tool to the agent unless the current task genuinely requires it.

DN Alpha Thesis: Tool Surface Is Financial Surface

In agentic finance, every additional callable tool can expand the machine's economic action space. Tool permissions should therefore be treated as financial permissions, not merely software configuration.

Why Read Only Deserves More Attention

The AI trading industry tends to market execution.

Read-only access may be more useful for many users.

An AI assistant with read-only access could potentially help:

  • summarize positions,
  • review P&L,
  • inspect existing strategies,
  • identify concentration,
  • explain recent signals,
  • compare backtests,
  • or flag unusual activity.

None of those tasks inherently requires a live-order function.

This is why Coinrule's distinction between MCP Read Only and Read + Write is strategically interesting.

It gives the user a way to experiment with an AI-connected trading account without treating execution as the default permission.

Five Checks Before Connecting Any Trading API

1. Is withdrawal permission definitely off?

Do not infer.

Check the exchange API configuration itself.

2. Which trading markets are enabled?

Spot permission is different from derivatives permission.

A bot that can open leveraged perpetual positions can create a different Trading Blast Radius from a spot-only bot.

3. Is this key used anywhere else?

Dedicated credentials simplify revocation and reduce unnecessary reuse.

4. Can the credential be restricted further?

Depending on the exchange, consider supported controls such as:

  • IP restrictions,
  • subaccounts,
  • market-specific permissions,
  • expiration,
  • or dedicated API credentials.

5. Do you know how to revoke it?

The first time you discover the API-management page should not be during an incident.

The Zero-Withdrawal Fallacy

There is a dangerous mental shortcut:

“The bot cannot withdraw, therefore my funds are safe.”

That conclusion is too strong.

DN calls it the:

Zero-Withdrawal Fallacy.

Withdrawal-disabled credentials address one class of risk.

They do not make trade execution harmless.

Imagine an automated system cannot transfer a single dollar outside the exchange.

But it can:

  • enter a 10x leveraged position,
  • trade the wrong contract,
  • buy an illiquid token,
  • or repeatedly churn the account.

The asset did not leave through a withdrawal endpoint.

The economic value can still disappear.

What Would Improve These Platforms Further?

The strongest future AI trading permission architecture would make several controls standard:

  • read-only AI access by default,
  • write permission granted separately,
  • withdrawal tools unavailable by default,
  • trade size ceilings,
  • daily loss ceilings,
  • asset allowlists,
  • market allowlists,
  • credential expiration,
  • agent-specific identities,
  • immediate revocation,
  • complete action logs,
  • and isolated experimental balances.

This would shift the conversation from:

“Do you trust the AI?”

to:

“What is the maximum consequence of not trusting it?”

That is a more useful security question.

Limitations

  • Withdrawal-disabled does not mean loss-proof. Trade-enabled software can still produce financial losses.
  • Exchange implementations differ. API permissions, market scopes, IP controls and subaccount features vary by venue.
  • DN has not independently penetration-tested these platforms. Withdrawal Boundary is an editorial architecture score based on current documented controls.
  • Documentation is not proof against compromise. Security ultimately depends on the full platform, exchange, user-account and credential architecture.
  • AI functionality varies. Several platforms in this guide are primarily deterministic automation platforms rather than autonomous AI agents.
  • Paper environments differ from live trading. Simulation does not reproduce every execution or security condition.
  • Products change. Permissions, integrations and security controls can change after publication.
  • Jurisdiction matters. Exchange and derivatives access varies by country.
  • Affiliate relationships exist. Affiliate status is excluded from DN scoring and disclosed separately.

The Bottom Line

AI trading does not require giving software every power available on an exchange account.

That is the main takeaway.

There are several layers of authority:

See.

Analyze.

Trade.

Leverage.

Transfer.

Those should not automatically arrive as one package.

A system may need trading permission.

It usually does not need withdrawal permission to perform ordinary bot execution.

And an AI assistant may not even need trading permission if all you want it to do is inspect and explain.

The strongest architecture is therefore not:

“Trust the bot because it cannot withdraw.”

It is:

“Give the system only the authority required for this specific task, then limit the capital exposed to that authority.”

That means:

paper before live,

read before write,

trade before transfer,

small capital before large capital,

and no additional permission without a clear reason.

The future of safer AI trading may depend less on making agents trustworthy.

It may depend on making trust less necessary.

DN Citation-to-Conversion Methodology

DN evaluated seven currently operating AI or automated trading platforms with explicit first-party evidence that ordinary trading workflows can operate without exchange withdrawal permission.

The proprietary Withdrawal Boundary score weights: 30% Withdrawal Isolation, 20% Pre-Live Testing, 15% Permission Granularity, 10% Credential Control, 10% AI Scope Separation, 10% Observability, and 5% Evidence Freshness.

The score evaluates permission architecture, not cybersecurity quality in its entirety. DN has not penetration-tested the platforms and does not claim that a high score makes a product immune to compromise, strategy error or trading loss.

Affiliate relationships contribute zero points. The current September 27, 2026 DN affiliate master is used only to identify the correct commercial pathway after a platform independently passes the operational-status gate.

Operational classifications remain: LIVE, RESTRICTED, MIGRATING, WINDING DOWN and INACTIVE. Only verified LIVE products receive active promotional CTAs.

DN testing classifications remain: Documented, Paper-Tested and Live-Tested. This edition uses Documented unless stated otherwise.

Primary Sources & Evidence

  1. Coinrule, Security on Coinrule, updated July 2026.
  2. Coinrule, MCP Permissions and Security Explained, updated July 2026.
  3. Coinrule, Connect an Exchange, updated May 2026.
  4. Bitsgap, How Secure Is Bitsgap?
  5. Bitsgap, Does Bitsgap Have Access to My Exchange Wallet?
  6. Bitsgap, How to Use Demo Mode.
  7. Cryptohopper, Why Should Withdrawal Permission Be Disabled When Creating an API Key?
  8. Cryptohopper, Why Do I Need a Crypto Exchange Account?
  9. Cryptohopper, Paper Trading documentation.
  10. 3Commas, Create and Connect API Keys, August 2026.
  11. 3Commas, Demo Trading Guide, August 2026.
  12. Cornix, What Is an API Key?, May 2026.
  13. Cornix, Demo Accounts: Risk-Free Trading, May 2026.
  14. Gunbot, Connect an Exchange and API Key Creation Guides.
  15. Gunbot, Simulator Mode.
  16. TradeSanta, API connection and Invalid API Key documentation.
  17. TradeSanta, Security and fund-protection documentation.

Frequently Asked Questions

Can an AI trading bot trade without withdrawal access?

Yes. Many external trading platforms need permission to read account information and place orders but do not require permission to withdraw assets from the exchange. The exact API permissions depend on the exchange and product.

Can a trading bot steal my crypto if withdrawals are disabled?

Disabling exchange withdrawal permission prevents that API credential from directly using the exchange's withdrawal function. It does not eliminate every security risk and does not stop trade-enabled software from losing value through bad or unauthorized trades.

Which AI trading platform has the strongest no-withdrawal setup?

DN currently gives Coinrule the strongest overall Withdrawal Boundary score because it combines no exchange withdrawal permission, paper trading and a separate Read Only MCP permission for compatible AI assistants.

Does Bitsgap allow withdrawal permissions?

Bitsgap's current documentation says its platform checks exchange API keys and rejects them if withdrawal permission is enabled.

Does Cryptohopper need withdrawal access?

No. Cryptohopper explicitly states that withdrawal permission is not required and should remain disabled. Funds remain on the user's connected exchange.

Does 3Commas need withdrawal permission?

No for its normal exchange trading connection. Current 3Commas documentation instructs users to enable trading access and disable withdrawal permission when creating exchange API credentials.

Does Cornix need withdrawal access?

Cornix requires relevant reading and trading permissions for live automation but specifically instructs users not to enable withdrawal permission.

Does disabling withdrawals make an AI trading bot safe?

No. It reduces direct asset-transfer risk but does not prevent trading losses, leveraged losses, software errors, strategy bugs, bad signals or compromised trade execution.

What is the DN Withdrawal Boundary?

The Withdrawal Boundary is a Decentralised News framework describing how effectively a trading architecture separates permission to execute trades from permission to transfer assets away from the account.

What is Trading Blast Radius?

Trading Blast Radius estimates how much economic damage an automated system could cause using the trading permissions and capital already available to it, even when withdrawal permission is disabled.

What is the Zero-Withdrawal Fallacy?

The Zero-Withdrawal Fallacy is the assumption that funds are fully safe simply because a trading API cannot withdraw them. A trade-enabled bot can still lose substantial value through poor, compromised or leveraged execution.

Should I use a separate exchange subaccount for an AI bot?

Where a venue supports suitable subaccounts, separating experimental bot capital from primary holdings can reduce the amount of capital exposed to trading errors. Users should check the specific venue's account and API architecture.

Freshness, Change Log & Corrections

Date Change
28 September 2026 Initial 2027 edition published with seven verified live platforms.
28 September 2026 Verified withdrawal-permission guidance for Coinrule, Bitsgap, Cryptohopper, 3Commas, Cornix, Gunbot and TradeSanta.
28 September 2026 Added DN Withdrawal Boundary, Trading Blast Radius, Permission Minimization Ratio and Zero-Withdrawal Fallacy frameworks.
28 September 2026 Added DN Withdrawal Authority Checker.
28 September 2026 Verified current paper, demo or simulator pathways where available.

Last verified: 28 September 2026.

Correction policy: exchange APIs and trading-platform security architectures change regularly. DN will update this guide when withdrawal requirements, permission scopes, connection methods, demo functionality or platform operational status materially change.

Factual corrections can be submitted through the Decentralised News Contact page. Commercial relationships do not prevent downgrades, corrections or removal from the ranking.

Risk disclaimer: Disabling withdrawal permission does not make automated trading risk-free. Trade-enabled software may still place losing or unauthorized trades, and leveraged products can create substantial losses even when funds cannot be withdrawn through the API. API permissions, security controls and supported functionality vary by exchange. Artificial intelligence and automation can add model, data, software, credential and execution risks. This article is educational and does not constitute investment, legal, tax, cybersecurity or financial advice.

Get the most talked about stories directly in your inbox

Join the Decentralised News briefing for independent crypto, DeFi and AI analysis. No spam, unsubscribe anytime.