Skip to content

Per-exchange custody

Each venue offers a different shape of trade-only credential, and each one keeps your funds in your hands by its own design. fxyz inherits all of that protection and adds product-side guarantees on top.

Hyperliquid

Model. A protocol-level "agent key" approved by your main wallet. The HL contract enforces that an agent can place, modify, and cancel orders, and nothing else.

What this means for you. Withdrawals, transfers, and account-setting changes require your main wallet, the same wallet you use on Hyperliquid's own UI. fxyz never holds that wallet, never sees it, and has no way to ask for it. The agent credential we hold is trading-only by Hyperliquid's own protocol rules, with no exceptions.

Revoke. Click Disconnect Hyperliquid. One signature rotates the slot at HL to an unrecoverable address, and from that moment the venue itself rejects every trade attempted against the slot. This isn't "we promise to forget the key". The protocol turns the key off, on-chain, irrevocably.

Lighter

Model. An API key tied to your Lighter account. Lighter's L2 protocol routes any withdrawal to your registered L1 owner address; the wire format has no recipient field at all.

What this means for you. Funds on Lighter can only go home to you. Even an attacker who somehow held the key could not point a withdrawal anywhere except your own L1 address, because there is no field to set.

On top of that, fxyz's own Lighter client deliberately omits withdraw and transfer from the surface available to strategy code. The protocol and the client are two independent walls.

Revoke. Click Disconnect Lighter. fxyz drops its copy of the key immediately. For complete revocation, rotate or delete the key on Lighter's own UI as well.

Backpack

Model. An API key generated on Backpack and held by fxyz under the credential protection described in the security overview.

What this means for you. fxyz's Backpack client omits withdraw and transfer operations entirely. They are not in the surface available to strategy code, so no part of the product can move funds off your Backpack account.

For an additional venue-side seal, configure Backpack's withdrawal-address whitelist on your account. Any withdrawal would then be limited to addresses you've pre-approved, locked down at the venue level on top of our code-level guarantee.

Revoke. Click Disconnect Backpack. fxyz drops its copy of the key immediately. For complete revocation, rotate or delete the key on Backpack's UI as well.

At a glance

VenueWhat keeps funds yours
HyperliquidThe protocol restricts agent keys to trading. Withdrawals require your main wallet.
LighterThe L2 protocol routes withdrawals to your registered L1 owner address and nowhere else.
Backpackfxyz's client has no withdraw or transfer code path. Backpack's withdrawal-address whitelist locks it down further.

Every venue has two independent layers, the venue's protocol and our own client surface, standing between an attacker and your funds. Either one alone is already strong.

What's next

Funds stay on the exchange. fxyz can trade, never withdraw.