Security & control
Your funds. Limited trading permission.
Your funds stay in your account. MirrorTrade gets permission to trade, not withdraw.

Your account. Your withdrawal authority.
Your funds sit in your own copy account on Hyperliquid, not with MirrorTrade or the trader you follow. Your user-owned Privy wallet authorizes withdrawals; a separate agent key lets MirrorTrade copy trades while you are offline.
A trading key with three checks
MirrorTrade encrypts each agent key with AES-256-GCM before storage. When loading it, the engine checks that the key matches the agent address recorded for your account. A signing guard allows supported trading actions and rejects withdrawals and transfers.
The key is decrypted in server memory to trade. Encryption protects stored keys; it does not eliminate the risk of a compromised server.
You can remove access
Revoke the agent through Hyperliquid using the correct copy wallet. If you also enabled agent-renewal delegation, remove that permission too: it can approve a replacement agent.
Pausing, signing out and revoking are different. Revoking does not close positions or cancel every open order. Check both. Secure your wallet login and verify recovery or export access through Privy before you need it.
What still carries risk
A trading key cannot withdraw, but it can place losing trades. Losses, liquidation, wallet compromise and Hyperliquid protocol or bridge failures remain possible. Non-custodial does not mean risk-free.
Sources
Checked against the implementation on September 26, 2026; not an independent security audit. Editor: Vansh Batra.
- Hyperliquid: API wallets and agent approvals
- Hyperliquid: exchange actions
- How MirrorTrade executes copied trades
- What take-profit and stop-loss controls do
See our editorial policy or report a correction. Security issue? Contact info@mirrortrade.co. Never share keys or seed phrases.

