Intent, not calldata
The model emits semantic missions such as ACCUMULATE_NIULAI. A deterministic compiler resolves routes, contracts, amounts and deadlines.
An autonomous Cow Agent built around 牛来, with bounded execution, verifiable missions and an integration path into Binance Agent OS for standardized market, account and trading tools.
The AI decides what work should be done. The protocol decides what the AI is allowed to do. The blockchain records what actually happened.
NiuLai is not an LLM with a private key. The intelligence layer can propose actions, but deterministic controls sit between model output and money.
The model emits semantic missions such as ACCUMULATE_NIULAI. A deterministic compiler resolves routes, contracts, amounts and deadlines.
Each Cow operates under explicit spend limits, asset allowlists, protocol permissions, reserve floors and time windows.
Financial claims come from transaction receipts, contract events, indexed wallet state and reproducible accounting — not AI narration.
Reasoning remains flexible. Control stays deterministic. Settlement stays onchain.
NiuLai keeps its reasoning and protocol policy independent, then connects approved capabilities through a dedicated Agent OS adapter. Binance Agent OS provides a standardized access layer for market data, account information, payments, wallet/onchain tooling and supported trading workflows.
Use Agent OS tools as a normalized source for market data instead of letting the model scrape or invent state.
Read balances, portfolio state and transaction history from an authorized account context when the configured permission allows it.
Approved missions may route supported trading activity through the Agent OS MCP layer. NiuLai policy remains the first gate.
Use user-controlled permissions and a dedicated subaccount boundary so an agent does not inherit unrestricted main-account authority.
transportMCP / Streamable HTTP
endpointagent.binance.com/mcp/agentic
componentsBinance APIs · Wallet Agentic Hub · x402 · Skill Hub · MCP
credential modelauthorized connection / revocable permissions
niulai modeADAPTER TARGET — credentials not embedded in static build
The LLM never sends arbitrary calldata. It produces a typed intent. The protocol turns that intent into an immutable execution plan.
{
"missionType": "ACCUMULATE_NIULAI",
"agentId": 17,
"requestedAmountUsd": 250,
"priority": "NORMAL",
"reasonCodes": [
"SURPLUS_AVAILABLE",
"SCHEDULED_ACCUMULATION"
]
}
{
"missionId": "0x91...c4",
"policyVersion": 8,
"adapter": "PANCAKE_V3",
"maxSpend": 250000000,
"minExpectedOutput": "...",
"validUntil": 1786964400,
"planHash": "0xa8...12"
}
REJECTED, SIMULATION_FAILED, REVERTED or EXPIRED.Policy lives outside the prompt. A compromised model still faces deterministic restrictions.
The main treasury remains isolated. Cow Agents receive limited working capital and scoped authority.
The protocol does not buy because an AI says “bullish.” It allocates a defined portion of realized surplus under reserve, liquidity and execution constraints.
Illustrative execution only. Real sizing is derived from configured policy and live liquidity data.
NiuLai is the coordinator. Child Cows receive distinct capability profiles, wallets, budgets and mission histories.
Schedules work, creates missions and allocates tasks. No unrestricted execution power.
NIULAI-000Reads chain state, liquidity, jobs and protocol data. Primarily read-only.
NIULAI-SCOUT-01Executes approved financial actions through typed protocol adapters.
NIULAI-EXECUTOR-01Completes external jobs and routes verified earnings back to the protocol.
NIULAI-WORKER-01COORDINATOR created mission #1842
POLICY profile COW_EXECUTOR_V1 loaded
RISK price impact 0.42% / max 0.75%
SIM execution simulation PASS
SIGNER plan hash authorized
CHAIN mission confirmed 0x91…c4
The security model does not depend on perfect AI behavior. It is designed so model failure does not automatically become treasury failure.
Signing is isolated from LLM and mission processes.
Typed actions and adapter allowlists replace generic call().
Mission ID, nonce, chain ID, time window, policy version and plan hash bind authorization.
Changing risk limits invalidates stale outstanding permits.
Guardian can stop new risk without gaining unrestricted withdrawal authority.
Every value-moving mission is checked against expected onchain behavior.
No fabricated TVL. No deposit-as-revenue accounting. No “AI performance” percentage without a formula.
Funds injected into treasury. Not revenue.
External consideration earned from verified work.
Closed gains or losses recognized by accounting rules.
Mark-to-market movement. Not realized revenue.
immutable V1immutable V1immutable V1immutable V1replaceablereplaceablereplaceable/v1/agentsHerd registry + operational state
/v1/missionsMission state + chain references
/v1/treasuryBalances, NAV and reserve state
/v1/accounting/revenueVerified revenue classifications
/v1/accumulationsConfirmed 牛来 acquisition events
Architecture, accounting semantics, mission types, permissions.
Coordinator, Mission Engine, Policy Engine, treasury, MCP client and permission-scoped Binance Agent OS adapter.
Cow Registry, scoped wallets, deployment gates and specialized workers.
External work adapters, settlement and verifiable revenue provenance.
Live mission log, Agent OS activity, holdings, cost basis, revenue and herd analytics.

Not a chatbot with a token. An onchain economic actor with explicit permissions, measurable work and verifiable settlement.