Risk disclosures usually list what can go wrong. This page does the opposite: it lists what is structurally in place, what each layer actually prevents, and — the part that is normally left out — what each layer does not prevent. Read it alongside the risk disclosure, which states the unmitigated risks without softening.
Eight layers make up the structure: a trade-only agent approval, one isolated sub-account per leader, hard scoring floors at entry, continuous rescoring, sticky-basket strikes, automatic replacement, per-leader notional ceilings, and mode gating by mirrored volume. Together they remove custody risk entirely and bound leader-specific risk. They do not reduce market risk, correlated positioning, liquidation or venue-level failure, and no layer converts a leveraged perpetual position into a safe one.
Layer 1 — Non-custodial, trade-only permission
Funds never leave your own Hyperliquid account. Running autopilot requires two approvals: a trade-only agent approval that permits order placement, and a separate builder-fee approval that caps the fee rate that can be charged. Neither grants withdrawal rights, transfer rights, or account ownership.
This is the one layer that removes a risk category rather than reducing it. Operator absconding, operator insolvency and pooled-fund commingling are not mitigated here — they are structurally unavailable, because the permission required to do them was never granted. Approvals are revocable from your wallet at any time, without asking anyone.
Prevents: withdrawal by the operator, transfer of funds, custody loss from operator failure.
Does not prevent: losses from the trades the agent is permitted to place.
Layer 2 — One isolated sub-account per leader
Each active leader is mirrored into its own sub-account of your Hyperliquid account. This exists because the venue nets positions per account and per market: without isolation, two leaders on opposite sides of the same market collapse into a single net position and you pay fees for exposure you no longer hold.
Isolation also contains liquidation. Margin behind one leader is not available to rescue another, so a blow-up in one sleeve cannot cascade into the others. And it preserves per-leader attribution, which is the measurement every later layer depends on — strike and replacement decisions are only defensible if you can say which leader produced which result.
Prevents: position netting between leaders, cross-leader liquidation contagion, loss of attribution.
Does not prevent: correlated losses when every sleeve is positioned the same way, or the capital-efficiency cost of fragmented margin.
Layer 3 — Hard floors at entry
Before any capital follows a trader, they must clear a floor on each of the five scored dimensions: realized PnL consistency, win rate, profit factor, position discipline and account survivability. Failing any single floor removes the candidate rather than shrinking their weight.
The pass/fail structure is deliberate. A weighted average lets an extraordinary profit factor pay for absent survivability evidence, which produces exactly the allocation the floor was written to prevent. Eligibility and conviction are kept as separate questions.
Prevents: short, lumpy, undisciplined or untested records entering the basket at any size.
Does not prevent: a qualified trader's edge decaying after entry, which is what the next three layers address.
Layer 4 — Continuous rescoring
Scores are recomputed continuously against cached snapshots of public trading history rather than at a fixed review date. A leader whose record deteriorates therefore loses standing as the deterioration happens, instead of holding full weight until someone runs a review.
There is an irreducible lag here and it should be stated: a score can only move once trades have been recorded, so the earliest a system can react is after the losses that constitute the signal. Rescoring shortens the delay between decay and action; it cannot make it zero.
Prevents: full-weight allocation to a leader whose record has already visibly deteriorated.
Does not prevent: the initial losses that produce the signal in the first place.
Layer 5 — Sticky basket and strikes
The Elite Top 10 is a sticky basket: a higher composite score elsewhere never forces a replacement on its own. Instead, defined soft issues — fewer than 5 trades in 7 days, 7-day volume under $25,000, 48 hours or more since the last fill, 30-day jump-adjusted drawdown above 35%, or 30-day PnL-based ROI below -15% — accrue at most one strike per wallet per UTC day. This exists because a drawdown is not proof of a broken edge — a genuine 55% win rate produces losing streaks routinely, and a system that ejects on every bad week sells precisely the traders it should hold.
The strike system is the middle state that stops the decision from being binary. It costs something: a leader accumulating strikes who was going to recover still carries that record until a clean evaluation day resets the counter to zero.
Prevents: both churn on ordinary variance and full-weight funding of a fading edge.
Does not prevent: being wrong in either direction on any individual leader.
Layer 6 — Replacement, with breaches bypassing the queue
Two exit paths, deliberately different. Three strike-days of soft issues that do not resolve lead to removal. An emergency — account value below roughly $1,000, or no fill for 96 hours or more with zero trades in 7 days — triggers immediate replacement instead of accruing strikes, because that is not weaker evidence but disqualifying evidence.
On removal, the outgoing leader's positions are closed in that sub-account before the slot is reassigned to the highest-scoring qualified candidate, so you are never left holding an orphaned position from a leader nobody is monitoring. Removal is not permanent: a trader who later clears every floor can qualify again.
Prevents: orphaned positions, and rules violations being treated as ordinary variance.
Does not prevent: the cost of turnover — every replacement pays fees and slippage on both sides.
Layer 7 — Per-leader notional ceilings
Score-proportional allocation is unbounded on its own: a leader whose score pulls away from the field would accumulate a share of the book that defeats the purpose of holding a basket. Ceilings cap the notional any single leader can carry regardless of score.
The division of labour is worth naming. Weighting decides relative conviction; ceilings decide absolute exposure. A ceiling is the layer that limits what a single mistaken high score can cost you.
Prevents: silent concentration into one leader as scores diverge.
Does not prevent: a loss concentrated across many leaders holding the same position.
Layer 8 — Mode gating by mirrored volume
Starter mode mirrors a single leader. Full mode mirrors up to 10 and unlocks automatically at $100,000 of mirrored volume. The gate is mechanical, not commercial: minimum order sizes and rounding mean a small balance split across ten margined sub-accounts produces positions too small to track their leaders faithfully, and a poorly tracked mirror is worse than an honest single-leader one.
The honest consequence is that a smaller account runs concentrated. Starter mode carries every risk of single-trader copy trading — full drawdown pass-through, one regime, one point of failure — with the same isolation and permission model applied to one sleeve.
Prevents: unfaithful tracking and rounding-dominated fills in undersized sleeves.
Does not prevent: the concentration risk inherent to running one leader while in Starter mode.
What no layer addresses
The structure is about which risks you carry, not whether you carry risk. Market risk is untouched: leveraged perpetual positions can be liquidated in full, and a basket long into a cascade declines in every sleeve at once. Correlated positioning across nominally different leaders is a recurring failure mode that diversification measures poorly and does not fix.
Venue-level risk is common to everything: exchange outage, oracle failure, extreme funding regimes or a liquidity event affect every sub-account simultaneously. Execution risk persists — latency and spread mean your fills differ from the leader's, in both directions, which is tracking error rather than malfunction. And key management remains yours: an approval you granted can be misused if your wallet itself is compromised.
Nothing here is financial advice. Perpetual futures are leveraged instruments: a position can be liquidated in full, and past performance of any trader is not indicative of future results. Copy trading does not remove that risk — it changes who makes the decision, not what the market can do to it.
Market and liquidation risk — unaffected by any structural layer.
Correlated leader positioning — reduced by construction only partially, and not reliably.
Exchange, oracle and liquidity failure — common to the whole account.
Tracking error from latency and slippage — structural, not a defect.
Wallet and key compromise — outside the system's control entirely.
At a glance
Each layer, the mechanism, the risk it addresses, and the residual risk it leaves.
Layer
Mechanism
Risk addressed
Residual risk
Non-custodial permission
MechanismTrade-only agent approval plus a capped builder-fee approval; revocable from your wallet
Residual riskNone of the trading risk; the agent can still place losing trades
Sub-account isolation
MechanismOne Hyperliquid sub-account per active leader
Risk addressedPosition netting, cross-leader liquidation contagion, lost attribution
Residual riskCorrelated losses across sleeves; lower capital efficiency
Scoring floors
MechanismPass/fail on five factors before any capital follows
Risk addressedShort, lumpy, undisciplined or untested records
Residual riskPost-entry decay; regime change invalidating a strong record
Continuous rescoring
MechanismScores recomputed against cached public history
Risk addressedStale full-weight allocation to a fading leader
Residual riskIrreducible lag — the signal requires losses to exist first
Sticky basket / strikes
MechanismWeight reduced and reassessed inside the decay band
Risk addressedChurn on variance, and funding an edge that is genuinely gone
Residual riskBeing wrong in either direction on an individual leader
Replacement
MechanismRemoval after three strike-days; immediate on an emergency
Risk addressedOrphaned positions, breaches treated as variance
Residual riskTurnover cost — fees and slippage on both sides
Notional ceilings
MechanismPer-leader cap on notional regardless of score
Risk addressedSilent concentration as scores diverge
Residual riskBasket-wide losses when leaders hold the same exposure
Mode gating
MechanismOne leader in Starter mode; up to 10 in Full mode at $100k mirrored volume
Risk addressedUndersized sleeves that cannot track their leader
Residual riskConcentration risk while running a single leader
Methodology
Scoring and replacement are documented in full on How it works and in the Docs (Policy v3). In short: the Elite basket is sticky, emergencies remove a leader immediately, and soft issues accrue at most one strike per UTC day with three strike-days triggering replacement. Read how it works or the documentation for the full table.
Questions
Frequently asked
Does this architecture make copy trading safe?
No. It removes custody risk outright and bounds several leader-specific risks. Market risk, liquidation, correlated positioning and venue-level failure are unchanged, and a leveraged perpetual position can still be liquidated in full.
Can HyperMirror withdraw or move my funds?
No. The agent approval grants order placement only. Withdrawals and transfers remain wallet-only, and you can revoke the approval from your wallet at any time without contacting anyone.
What happens to my positions if I revoke access?
New mirrored orders stop. Any open positions remain in your own sub-accounts under your control, so you decide whether to close them or keep them.
Do hard risk limits stop me from being liquidated?
No. Ceilings and floors bound how much of the book any single leader can control and which leaders qualify at all. They do not control the market, and a sufficiently adverse move can liquidate a position inside its own sub-account.
How is this different from a vault or a managed fund?
A vault pools deposits under someone else's control, so custody and commingling risk are real and you are relying on policy rather than permission. Here the funds stay in your account and the permission granted cannot express a withdrawal.
Where do I read the risks that are not mitigated?
The risk disclosure states them plainly and without softening. This page is the structural half; that page is the unmitigated half, and both are needed to see the whole picture.