Non-custodial copy trading on Hyperliquid, explained
"Non-custodial" is used loosely enough that it has almost stopped carrying information. It is worth being precise, because the difference between a system that cannot move your funds and one that merely promises not to is the difference between a bounded risk and an unbounded one. This page sets out exactly what a Hyperliquid agent approval grants, what it cannot do, how builder fees and sub-accounts fit in, and how the model compares with custodial copy trading and API-key bots.
Non-custodial copy trading on Hyperliquid means your capital never leaves an account you control. You sign an agent approval authorizing a named agent address to submit trading actions on your account, and separately approve a maximum builder-fee rate. Withdrawals, transfers and ownership changes remain signable only by your own wallet, and the approval can be revoked on-chain without moving funds.
Custody versus permission
Custody is the ability to move funds. Permission is the ability to act within an account without moving funds out of it. Conflating the two is why the word 'non-custodial' has become unreliable: a platform can honestly say it never touches your withdrawal rights while still holding a permission broad enough to cause real damage, and another can call itself non-custodial while requiring a deposit into a pooled address.
The test is mechanical, not rhetorical. Ask which key signs a withdrawal. If the answer is any key other than yours, the arrangement is custodial regardless of the language used to describe it.
What a Hyperliquid agent approval actually grants
Hyperliquid supports agent wallets: you sign an approval that names a specific agent address and authorizes it to submit trading actions for your account. That agent key can open, size, modify and close positions. It is the same primitive whether it is used by your own script or by a copy system.
The approval is scoped to trading. It does not confer ownership, and it does not extend to the account's fund-movement actions. It is also revocable: you can withdraw the permission with your own wallet, and doing so does not require the operator's cooperation or any transfer of assets.
Grants: placing, modifying and closing perpetual-futures orders on your account.
Does not grant: withdrawals, transfers to other addresses, or account ownership changes.
Revocable on-chain by the account owner at any time.
The builder-fee approval, and why it is separate
Hyperliquid has a native builder-fee mechanism: the party that builds an order can attach a fee, and the account owner approves a maximum rate in advance. This is a second, distinct signature from the agent approval, and it exists so the fee is bounded by something you signed rather than by a promise in a pricing page.
HyperMirror charges 0.1% of mirrored notional volume through this mechanism. Because the charge rides on the order itself, it is visible on-chain per fill, and because the maximum rate is approved by you, it cannot be raised unilaterally beyond what you authorized. There is no subscription and no share of your equity.
Sub-accounts: isolation without giving up custody
Hyperliquid sub-accounts belong to your main account. They let capital be partitioned into separate margin and position contexts while remaining under the same ownership, which is what makes multi-leader mirroring possible without custody and without netting.
HyperMirror uses one sub-account per mirrored leader. Two leaders holding opposite sides of the same perp keep both positions instead of cancelling into a single net exposure; a margin problem in one sleeve does not consume the margin backing another; and per-leader results stay attributable, which is what scoring and replacement depend on.
None of that changes who owns the funds. The sub-accounts are yours, and their balances are visible to you on-chain at all times.
Contrast: custodial CEX copy trading
On a centralised exchange, copy trading generally requires your funds to sit in an account the exchange controls, sometimes routed through an internal copy-trading wallet. Your position is a database entry that the exchange can freeze, and your ability to exit depends on the exchange processing a withdrawal.
That structure adds a risk that has nothing to do with trading: the solvency and operational integrity of the custodian. It has been the dominant source of total loss in this industry, and it is not diversifiable by picking better traders.
Contrast: API-key bots
API-key bots look non-custodial and often are not, because API permissions are coarse. Keys are frequently issued with withdrawal rights available, and the security of the arrangement then depends on the user setting the right toggles and the operator storing the key safely. A leaked key with withdrawal enabled is equivalent to a stolen account.
An agent approval differs in that the narrowness is enforced by the exchange's action model rather than by configuration hygiene. The agent key simply cannot sign a withdrawal, so a compromise of that key is bounded to trading damage — serious, but not total loss of the balance.
Contrast: vaults and pooled structures
A vault pools depositors' capital into a single managed account. Your exposure is a share of a pool rather than positions you own, exit is a redemption subject to the vault's terms, and every depositor's positions net together inside one book.
Vaults are a legitimate structure with real advantages — simplicity, and a manager who can act on the whole book at once. But they are not non-custodial in the sense used here, and the difference shows up precisely when you most want to leave.
What non-custodial does not protect you from
Being non-custodial removes counterparty risk on your balance. It does not remove market risk, and it is important not to let the custody story do work it cannot do. A trade-only agent can still open leveraged positions that lose money, and a mirrored leader can still be liquidated.
It also does not eliminate execution divergence: your fills, timing and account size differ from the leader's, so your results will differ from theirs. And it does not remove operational risk in the software itself, which is why per-leader notional ceilings, independent leverage caps and sub-account isolation matter as bounds on what a malfunction can cost.
Nothing here is financial advice. Perpetual futures are leveraged instruments: a position can be liquidated in full, and past performance of any trader is not indicative of future results. Copy trading does not remove that risk — it changes who makes the decision, not what the market can do to it.
At a glance
Who can move your funds, by copy-trading structure.
Structure
Funds held by
Can the operator withdraw?
How you exit
Custodial CEX copy trading
Funds held byThe exchange
Can the operator withdraw?Effectively yes — withdrawals are processed by the custodian
How you exitRequest a withdrawal and wait
API-key bot
Funds held byThe exchange account
Can the operator withdraw?Only if the key was issued with withdrawal rights
How you exitDelete the key
Vault / pooled fund
Funds held byThe vault account
Can the operator withdraw?The manager controls the pooled account
How you exitRedeem a share, subject to vault terms
Hyperliquid agent approval
Funds held byYour own account and sub-accounts
Can the operator withdraw?No — the agent cannot sign withdrawals
How you exitRevoke the approval with your wallet
Methodology
Scoring and replacement are documented in full on How it works and in the Docs (Policy v3). In short: the Elite basket is sticky, emergencies remove a leader immediately, and soft issues accrue at most one strike per UTC day with three strike-days triggering replacement. Read how it works or the documentation for the full table.
Questions
Frequently asked
What does non-custodial mean on Hyperliquid?
That your capital stays in an account you own. A copy system receives a trade-only agent approval, which authorizes order placement and management but cannot sign withdrawals, transfers or ownership changes.
Can HyperMirror withdraw my funds?
No. The agent approval does not include withdrawal or transfer rights, and there is no deposit into an operator wallet at any point in the flow.
Do I have to give up my private key or seed phrase?
Never. You sign an approval with your wallet. A private key or seed phrase is never requested and would never be needed for this model to work.
How do I revoke the agent approval?
With your own wallet, on-chain. Revocation does not require the operator to cooperate and does not involve moving funds, because the funds were never held elsewhere.
What is the builder fee and why do I approve it separately?
It is Hyperliquid's native mechanism for charging a fee on an order at build time. You approve a maximum rate in advance so the charge is bounded by your signature. HyperMirror's rate is 0.1% of mirrored notional volume.
Why does each leader need its own sub-account?
Because an account holds one net position per market. Without isolation, two leaders on opposite sides of the same perp cancel out while you still pay costs on both legs, and per-leader attribution becomes impossible.
Is non-custodial the same as safe?
No. It bounds counterparty risk on your balance. Leveraged perpetual futures can still lose the entire position, and mirrored results diverge from the leader's.