AuditsHKUDS/Vibe-Trading › Binance.US

Bot × exchange

Does Vibe-Trading work with Binance.US?

The Vibe-Trading README does not name Binance.US directly, but it names ccxt, the exchange library that ships a Binance.US adapter. Whether the bot's own code handles Binance.US's rules (symbols, order types, rate limits) is not something a README scan can tell. We did not run the bot against Binance.US: this page reports what the public code says and what the exchange itself publishes.

Binance.US facts

CoinGecko trust score
9 / 10 · rank 14
Country
United States
Established
2019
24h volume (BTC, normalized)
0
Tradable pairs
265
Quote currencies
BTC, USD, USDC, USDT
Order types (BTCUSD)
LIMIT, LIMIT_MAKER, MARKET, STOP_LOSS, STOP_LOSS_LIMIT, TAKE_PROFIT, TAKE_PROFIT_LIMIT
Markets
spot only: no futures, no margin
Puerto Rico residents
Accepted, in writing (source, 2026-09-17)
Fees
0 % maker / 0.02 % taker on spot (source, April 2026)
Official API
Yes: REST and websocket, HMAC-signed private endpoints (source, 2026-09-17)

Exchange data: CoinGecko public API and the exchange's own endpoints, 2026-09-17. More on the Binance.US page.

What the audit says about running it live

From the Vibe-Trading audit (2026-09-17), the controls that matter most once a live API key is connected:

ControlVerdictEvidence
API key permissionsPartialagent/src/trading/onboarding.py: explicit setup_hint text for several connectors, e.g. Binance 'Create a read-only Spot API key; do not enable withdrawals', OKX 'do not grant Trade or Withdraw permissions', Upbit 'do not grant withdrawal permission'. GET /search/code?q=withdraw+repo:HKUDS/Vibe-Trading+language:Python returned 10 hits, none inspected as an actual withdrawal API call
Orphaned stop-lossNot verifiedagent/src/live/mandate/model.py has no stop-loss field of any kind in HardCaps/Mandate
Websocket and data reconnectionNot verifiedagent/src/market_data.py implements a multi-source REST fallback chain with bounded retries (max_fallback_attempts=5) for market data
Order rejection handlingPresentagent/src/live/order_guard.py _allow(): inspects the broker response envelope; an error envelope is audited as kind='order_rejected'/outcome='error' and does NOT increment the daily counter; class attribute 'repeatable = False' documented as 'a live order must never be silently re-issued'
Position reconciliation with the exchangeNot verifiedagent/backtest/binance_account_reconciliation.py exists but lives under agent/backtest/ (shadow-account/backtest verification), not under agent/src/live/

Before you connect a key