Per-exchange custody
Each venue offers a different shape of trade-only credential, and each one keeps your funds in your hands by its own design. fxyz inherits all of that protection and adds product-side guarantees on top.
Hyperliquid
Model. A protocol-level "agent key" approved by your main wallet. The HL contract enforces that an agent can place, modify, and cancel orders, and nothing else.
What this means for you. Withdrawals, transfers, and account-setting changes require your main wallet, the same wallet you use on Hyperliquid's own UI. fxyz never holds that wallet, never sees it, and has no way to ask for it. The agent credential we hold is trading-only by Hyperliquid's own protocol rules, with no exceptions.
Revoke. Click Disconnect Hyperliquid. One signature rotates the slot at HL to an unrecoverable address, and from that moment the venue itself rejects every trade attempted against the slot. This isn't "we promise to forget the key". The protocol turns the key off, on-chain, irrevocably.
Lighter
Model. An API key tied to your Lighter account. Lighter's L2 protocol routes any withdrawal to your registered L1 owner address; the wire format has no recipient field at all.
What this means for you. Funds on Lighter can only go home to you. Even an attacker who somehow held the key could not point a withdrawal anywhere except your own L1 address, because there is no field to set.
On top of that, fxyz's own Lighter client deliberately omits withdraw and transfer from the surface available to strategy code. The protocol and the client are two independent walls.
Revoke. Click Disconnect Lighter. fxyz drops its copy of the key immediately. For complete revocation, rotate or delete the key on Lighter's own UI as well.
Backpack
Model. An API key generated on Backpack and held by fxyz under the credential protection described in the security overview.
What this means for you. fxyz's Backpack client omits withdraw and transfer operations entirely. They are not in the surface available to strategy code, so no part of the product can move funds off your Backpack account.
For an additional venue-side seal, configure Backpack's withdrawal-address whitelist on your account. Any withdrawal would then be limited to addresses you've pre-approved, locked down at the venue level on top of our code-level guarantee.
Revoke. Click Disconnect Backpack. fxyz drops its copy of the key immediately. For complete revocation, rotate or delete the key on Backpack's UI as well.
At a glance
| Venue | What keeps funds yours |
|---|---|
| Hyperliquid | The protocol restricts agent keys to trading. Withdrawals require your main wallet. |
| Lighter | The L2 protocol routes withdrawals to your registered L1 owner address and nowhere else. |
| Backpack | fxyz's client has no withdraw or transfer code path. Backpack's withdrawal-address whitelist locks it down further. |
Every venue has two independent layers, the venue's protocol and our own client surface, standing between an attacker and your funds. Either one alone is already strong.
What's next
- How your keys are kept safe: the storage and isolation model.
- What fxyz cannot do: the explicit list.