Comparison

Trade-only agent vs traditional API keys

Anyone who has automated trading on a centralised exchange knows the API-key ritual: create a key, uncheck withdrawals, hope the checkbox is honoured and that nobody with database access can change it. The agent model asks a different question — not who promises to respect the scope, but who enforces it.

In short

An exchange API key is a credential whose permissions are enforced by the exchange's own account system and can be changed by whoever controls the account. A Hyperliquid agent is an on-chain authorisation whose scope is defined by the protocol: an agent signature cannot construct a withdrawal at all. Both can trade; only one makes withdrawal impossible by design rather than by setting.

At a glance

Trade-only agent, exchange API key and custodial deposit compared
PropertyHyperliquid trade-only agentExchange API keyCustodial deposit
Who enforces the scopeThe protocol — no withdraw action exists for an agentThe exchange's account settingsNobody; the operator owns the balance
Can the credential withdrawNoOnly if permissions were set that way, and they can be changedNot applicable — the operator can
Where your funds sitYour own Hyperliquid account and sub-accountsYour exchange accountThe operator's account or a pooled treasury
VerifiabilityOn-chain: the authorisation and every fill are public under your addressPrivate to the exchangeWhatever the operator reports
How you end accessDe-authorise the agent from your wallet, unilaterallyDelete the key in the exchange UIRequest a withdrawal and wait
Failure mode if the operator disappearsMirroring stops; funds and positions are already yoursAutomation stops; funds stay in your exchange accountYour claim depends on the operator's solvency

Where the scope lives

With an API key, the scope is a property of a record in the exchange's database. It is respected as long as the exchange is honest and its systems intact. With an agent, the scope is a property of what the signature can express: there is no withdraw action available to an agent, so there is nothing to misconfigure.

The difference matters most in the scenarios you cannot audit — a compromised operator, an insider, a support tool with too much reach.

Blast radius of a leak

Assume the worst case in both models: the credential is stolen. A leaked trade-enabled API key lets an attacker trade your balance, and on many venues also lets them use internal transfer paths depending on how permissions were configured. A leaked agent key lets an attacker place orders on your Hyperliquid account and nothing else.

In both cases hostile trading can lose money — that is real and worth stating plainly. But the funds cannot be routed to an attacker's address through the agent path.

  • Neither model protects you from losses caused by bad trading.
  • Only the agent model makes withdrawal structurally unavailable to the credential.
  • Revocation of an agent needs nobody's cooperation and no support ticket.

What custody adds on top

A third architecture is more common than either: deposit into the operator's account and let them trade a pool. Then there is no credential to scope at all, because the operator simply owns the balance. Recovery in that model depends entirely on the operator's solvency and conduct.

HyperMirror does not use that model. There is no platform wallet in the flow and no pooled treasury.

Honest limits of the agent model

Self-custody moves responsibility to you. If you lose your wallet, no one can restore access. And a trade-only agent still trades — position and leverage caps bound the exposure it can create, but leveraged perpetual positions can be liquidated.

Past performance is not indicative of future results. Perpetual futures are leveraged instruments and carry a substantial risk of loss, including the loss of your entire position.

Methodology

Scoring and replacement are documented in full on How it works and in the Docs (Policy v3). In short: the Elite basket is sticky, emergencies remove a leader immediately, and soft issues accrue at most one strike per UTC day with three strike-days triggering replacement. Read how it works or the documentation for the full table.

Questions

Frequently asked

Is an agent just a scoped API key?

Functionally similar, structurally different. The scope is enforced by Hyperliquid rather than by an account setting, so it cannot be widened by whoever controls the platform.

Could a stolen agent key cost me money?

Yes — through hostile trading, not through withdrawal. That is why the mirroring system also applies per-leader notional ceilings and leverage caps.

Which model is safest overall?

The agent model removes custody risk and makes withdrawal structurally impossible for the credential. It does not remove market risk, and it makes wallet security your responsibility.

Diversified copy trading. On autopilot.

Score-weighted allocation across up to 10 elite Hyperliquid traders, each isolated in its own sub-account. Your funds never leave your account.

Non-custodial · Agent cannot withdraw · Cancel delegation anytime