Manus 2.0 Launches Cascade Agent Framework and Cue, a Personal Agent App With a Phone and Wallet
Cascade dynamic tool loading cuts operating costs 32%; Cue gives each AI agent its own real-world identity

Manus launched version 2.0 on Monday, shipping its first major architectural overhaul since Beijing forced the company free of Meta and marking its most ambitious product expansion since its March 2025 debut. The release introduces Cascade, a rebuilt agent execution framework designed to reduce token consumption and operating costs, and Cue, a standalone consumer app built on a concept with no direct precedent in the commercial agent market: each AI agent gets its own phone number, email address, spending wallet, and dedicated cloud computer.
For a company that spent the better part of 2026 navigating an acquisition blockage, a $2 billion buyback, and a complete ownership restructuring, the question was whether Manus could ship something meaningful on the other side of that ordeal. Monday's launch is an answer.
Cascade Addresses the Token Bloat Problem Structural to Agent Design
The central engineering problem in production AI agents is not raw model capability — it is the cost of maintaining context across multi-step tasks. Every tool available to an agent, every prior action taken, and every piece of accumulated state competes for space in the model's context window and adds to token costs. Naive implementations load all possible tools at the start of every session, which means an agent building a simple document burns tokens on image-generation and game-development tools it will never use.
Cascade takes what engineers would recognize as a lazy-loading approach. Projects start with minimal overhead, and specialized tools — video processing, code execution, game development, document generation — are introduced only when the task's context specifically requires them. According to Manus's internal testing, this produces a 23.2% reduction in token consumption, a 28.2% decrease in task completion time, and a 32% cut in operating costs versus the prior system.
Those figures come exclusively from Manus's own internal test configuration — the company describes it as "one tested configuration" — and have not been reproduced by independent evaluators. The caveat matters: Manus has reason to publish optimistic efficiency data ahead of a fundraising round that Bloomberg reported targets $500 million at a $4 billion valuation. The efficiency direction — leaner context, lower cost — is architecturally credible even if the exact percentages should be read as company-reported claims.
The Cascade design extends Manus's documented approach to KV-cache optimization. Prior analysis of Manus's context engineering showed the platform maintains stable prompt prefixes, uses append-only context modifications, and employs a context-aware state machine with logit masking to control the agent's action space without invalidating cached computation. That matters economically because cached input tokens on Anthropic's Claude Sonnet cost roughly one-tenth of uncached tokens — a cost difference that compounds dramatically across multi-step agentic tasks.
Read more: Study finds context overflow, not compression quality, drives coding agent failure
Cue Introduces Agents With Independent Real-World Identity
The more novel product in Monday's release is Cue, a standalone app available on Android, macOS, and the web — with iOS in App Store review and Windows listed as coming soon. Cue is accessible in early access with an invite code; the launch code MEETCUE was reported to be capped at roughly 1,000 users, who then receive codes to share. The app is free during early access.
The design premise is that agents should have their own identity in the world rather than acting as extensions of the human user's accounts. Each agent in Cue receives a dedicated email address, a real phone number capable of making and receiving calls, a spending wallet with a user-defined budget cap, and a persistent cloud computer instance. Agents can form group conversations and divide tasks: Manus's example involves three agents preparing a launch event, with one researching venues, one managing the contact list, and a third drafting presentation materials. The user sets direction and approves key decisions.
What makes this technically significant — and commercially risky — is that a phone number is an identity credential. An agent with a phone number can receive two-factor authentication codes, take calls on a user's behalf, and leave a call record attributable to that agent rather than the user. A spending wallet means an agent can authorize purchases within a defined limit. These are not merely convenience features; they expand the attack surface and accountability surface simultaneously.
Aurascape's AuraLabs research team previously documented critical zero-click indirect prompt injection vulnerabilities in Manus — a class of flaws collectively called SilentBridge — that the company subsequently mitigated before coordinated disclosure in February 2026. Cue's agent-owned credentials create a more complex security perimeter still: a compromised agent identity could receive authentication codes for services the user never intended to expose. A third-party audit from August 2026 found Cue's data stored in the US and Singapore, with a training opt-out that is off by default and an unspecified retention period for conversation logs. How EU regulators interpret agents that possess phone numbers and financial accounts — digital actors that are neither natural persons nor traditional software services — is an open question that Manus has not addressed publicly.
Manus Studio Expands Into Video, Games, and Remote Work
The Manus desktop application becomes Manus Studio in version 2.0, adding specialized environments that follow Cascade's same principle of appearing in the workspace only when a project requires them. A Video Editor targets 30-to-60-second short-form content, handing users a non-destructive timeline after completing an initial cut, with each element editable independently. Game Dev combines video, image, and code generation to take a project from concept to a playable web page, with multiplayer supported through purchasable persistent cloud computer instances that Manus operates. An Automations system upgrades from fixed schedules to event-triggered execution — a new email, a Slack message, a Notion update, or a change in ad performance data can all start a workflow automatically. And a Remote Control capability lets users send natural-language instructions to their desktop from a mobile device, with Manus executing those instructions through Computer Use in a visible, auditable workspace.
Manus's Competitive Position After the Meta Ordeal
Manus is competing in a market that moved substantially during the roughly eight months it spent under Meta's ownership and then unwinding from it. OpenAI's ChatGPT Agent now connects to services through the Model Context Protocol rather than browser-UI automation, reducing the hallucinated-click failure mode that has been Manus's most-cited reliability problem. Anthropic's Claude Cowork reached general availability in April 2026, targeting non-technical users who want agent-level task execution on local files. Meta itself is building an internal agent on its Muse Spark model after failing to absorb Manus.
Read more: Meta confirms persistent Ubuntu cloud machine for every Muse user
Manus's advantage is a track record of deployment the others lack in combination: a reported 2 million monthly active users as of early 2026, an architecture that has been iterated through real production load, and now an agent-identity concept that its competitors have not entered. Whether Cue's agent-owned phone numbers and wallets represent a durable product position or a regulatory gray area that larger competitors are deliberately avoiding is a question the market will answer over the next year.
The Reliability Ceiling Cascade Does Not Fix
The core performance limitation for autonomous agents is compounding error. If each step in a multi-step task succeeds 90% of the time — an optimistic estimate for browser-based automation — a ten-step task succeeds only 35% of the time. Community assessments of Manus have placed real-world reliability on open-ended research tasks at roughly 70-to-80%, with a sharp drop for tasks exceeding five dependent steps. The primary documented failure modes are hallucinated browser clicks, service timeouts, and anti-bot blocks on websites that resist automated access — all of which stem from Manus's browser-first integration strategy rather than from any weakness specific to Cascade.
Cascade addresses economics and execution speed, not this structural reliability ceiling. Proper API integrations, as ChatGPT Agent deploys through MCP, address the reliability problem more directly. Manus offers connectors for some services and a "Take Over" mode for CAPTCHAs, but a significant share of websites use anti-bot measures that break browser-based automation regardless of how efficiently the underlying agent framework manages tokens.
Manus has not published independent benchmark results for version 2.0 at launch. Its prior GAIA Level 1 score of 86.5% was self-reported from the March 2025 debut and is no longer a useful competitive reference. Updated third-party evaluations will be needed to confirm whether Cascade's efficiency gains translate to measurably better task success rates under real-world conditions.
What the $4 Billion Valuation and Agent Identity Mean for Manus's Future
If the reported Tencent-led $500 million round closes at the target $4 billion valuation, Manus will have the infrastructure budget to compete with the Anthropic and OpenAI deployments that have expanded substantially in 2026. But the financing question and the product question are now inseparable from the regulatory question. Manus is a Singapore-incorporated company primarily backed by Chinese investors — Tencent holds the largest individual stake following the Meta buyback, with ZhenFund and HSG also participating — operating an agent platform that stores data in the US and Singapore and now offering a consumer product that provides AI agents with phone numbers, spending accounts, and persistent call histories.
China's NDRC blocked Meta's acquisition of Manus in April 2026 on national security grounds, establishing that offshore incorporation does not insulate Chinese-founded AI companies from Chinese regulatory jurisdiction. Cue's agent credential model will raise a parallel question in Western markets: when an AI agent possesses a phone number, transacts money, and accumulates communication history, existing identity and financial regulations were not written with that actor in mind. Manus's next major constraint is not whether Cascade delivers on its efficiency claims, but whether regulators in the EU, the US, and elsewhere decide that agents with independent identity are a product category that requires its own compliance framework before it scales.