Custody and security
Hypertrade One keeps owner control separate from trade-only automation and never stores raw key material for a new secure signer.
Updated 2026-07-19
Your owner wallet controls withdrawals. Hypertrade One uses a user-owned embedded wallet for the default flow. A separate agent has trading authority only. Verified external-wallet registration remains unavailable until browser owner approval is complete.
Owner wallet
- The embedded wallet is owned by the authenticated provider user, not by Hypertrade's server signer.
- Owner-sensitive actions require a fresh user authorization token and a short-lived, versioned action intent.
- Hypertrade stores the public owner address and opaque provider references. It does not store an owner private key.
- External wallets remain under the user's wallet application and require ownership proof before registration.
Trade-only agent
- The secure signer is a different address with a policy-scoped provider reference.
- Hyperliquid must report the agent as valid for that owner before a desk can use it.
- Execution resolves the currently active agent from the stable trading account.
- Signing calls are serialized per signer to prevent cross-process nonce collisions.
- Rotation and revocation finalize only after the venue confirms the replacement and invalidates the previous address.
Legacy accounts
Existing encrypted agent-key rows continue to work during migration. They are isolated as legacy credentials and are never rewritten or deleted automatically. New Hypertrade One signer rows cannot store encrypted agent keys.
Fail-closed controls
- Unknown or unsupported account mode blocks new risk.
- An incomplete balance read displays Unavailable, never a guessed zero.
- Provider funding success still waits for Hyperliquid destination evidence.
- Every account, consent, signer, mode, funding, and withdrawal mutation is idempotent and audited.
- Protective orders rest at the venue so they survive an application outage.
Hypertrade never asks a Hypertrade One user for a private key, seed phrase, recovery phrase, password, one-time code, or signed owner payload.