Service changes to know about
- goodcryptoX: app and built-in wallet access end date announced for . Status & exit information · Provider notice ↗. Source checked 2026-10-03.
- Hyperbot: trading and copy-trading end date announced for . User exit deadline: September 30, 2026. Status & exit information · Provider notice ↗. Source checked 2026-10-03.
Provider announcements do not confirm current service status or successful shutdown execution. Onboarding remains suspended. Evaluated October 3, 2026 UTC; each profile carries its recheck deadline.
Correction and scope
Editorial correction — September 28, 2026: Earlier text described API keys as staying on a user’s device and presented an audit as a broad security assurance. Those statements were too general. This guide no longer makes product-wide key-storage or audit claims. The historical review date remains February 8, 2026.
Editorial update — October 3, 2026: Removed vendor-specific fees, audit findings, and repeated service deadlines from this general checklist. Product documentation and the shared status block above carry those changing details. This is not a product security audit.
Before connecting: seven checks
1. Identify the account and signer
Ask which account holds the assets and which key signs bot requests. Hyperliquid describes API wallets as signers that can act on behalf of a master account or its subaccounts. Account data must be queried with the actual account address, not assumed from the signer address. Read the current API-wallet documentation and ask the provider to explain its connection model.
Check whether the product asks you to deposit to an address it controls. If it does, read the custody and withdrawal terms before sending assets. A label such as “non-custodial” does not answer where a signing key goes or what it can authorize.
Do not treat a delegated trading signer as the account holding funds or assume it authorizes withdrawals. An agent-wallet address can return an empty balance even when the main account has assets. An email-login account, connected main wallet and vendor-created wallet can also have different control and exit procedures. Verify the current account and required authority in official instructions; never import keys into HypeChain.
2. Find out where key material is stored
Read the current connection instructions. Determine whether the private key is generated and retained locally, entered into a browser or app, or transmitted to and stored by the service. Ask about encryption, staff access, retention, incident response, and key deletion. If the documentation does not answer a question, record the storage model as unknown.
A vendor’s written storage statement is a vendor claim. HypeChain has not inspected a product’s infrastructure or independently verified its key handling.
3. Confirm permissions and revocation
Review the exact actions a connection can sign and whether the permissions can be changed or revoked. Confirm the provider’s instructions for removing access. The API-wallet documentation explains signer authority; it does not establish how a third-party service stores keys or configures its app.
Before revoking access, find out how to manage open orders and positions. Removing a signer does not itself close exposure or cancel orders.
4. Read any audit by scope, date, and status
An audit is evidence about a defined engagement and code scope. It is not a guarantee of safety or a blanket endorsement of a service.
For any product, check the auditor’s own record for the engagement date, tested scope, finding status, and whether the deployed version matches the reviewed code. If no public evidence is available, record that fact; do not treat absence of evidence as proof of safety or as proof that an audit failed.
5. Separate all trading costs
Ask for current, market-specific terms. Separate provider or builder fees from exchange fees, funding, gas, subscriptions, credits, rebates, spreads, and withdrawal charges. Check what each rate applies to and who qualifies for discounts.
Hyperliquid’s official fee documentation describes venue fees, while its builder-code documentation describes builder-fee approvals. The Info API shows fee fields in fill records. None of these pages verifies what a third-party product charges in a specific account; compare the current provider terms with the account’s own records.
6. Verify the source and destination
Start from the provider’s official documentation and follow its links to the app, API endpoint, and support channel. Check the domain and account address carefully. Do not send private keys, recovery phrases, or authentication codes through chat or email.
7. Plan the exit before the first trade
Write down how to stop the service, cancel orders, close positions, withdraw assets, and revoke delegated access. Confirm which steps remain under your direct control and where the provider’s help process is required. A test transaction does not establish future execution quality or safety.
Keep withdrawal, an internal HyperCore send and Core↔EVM movement separate. Check the destination’s exact asset/network requirements and use the account’s official history before retrying a missing transfer. For help, follow Hyperliquid’s official support guide ; unsolicited recovery DMs are not a support route. Do not send seeds, private keys or authentication codes to anyone.
Keep original history and check account, network and date coverage before relying on results. Use the Hyperliquid tax-records guide and inventory to record gaps and unresolved transfers.
Further reading
- Hyperliquid API wallets
- Hyperliquid trading fees
- Hyperliquid builder codes
- How to evaluate a trading bot
This checklist is informational, not financial or security advice. Trading can result in the loss of all funds committed. Verify product terms and account-specific instructions directly with the relevant service.