Staying Safe on Hyperliquid: Self-Custody & Security
Hyperliquid never takes custody of your funds — which is its greatest strength and the source of its most important responsibility. On a self-custodial exchange, you are your own security team. Here is how to do that job well.
13 min read
On a centralized exchange, if you get phished the exchange might freeze the theft or reimburse you. On Hyperliquid there is no such safety net: you hold your own keys, transactions are final, and no support desk can reverse a signed transaction. That is the honest trade-off of self-custody — total control in exchange for total responsibility. The good news is that a handful of durable habits eliminate the overwhelming majority of real-world losses. This guide covers them.
The two rules that matter most
1. Never enter your seed phrase anywhere except your wallet’s own recovery screen. 2. Read every transaction before you sign it. Almost every catastrophic loss violates one of these two.
Understand what self-custody means
When you use Hyperliquid, your funds live on-chain in an account controlled by your wallet’s private key. The exchange cannot move them without your signature, cannot freeze your account, and cannot lock you out — but it also cannot help you if you lose control of that key. There is no password reset. This is why key management is not a side issue; it is the whole game.
Choose and configure your wallet well
Use an established, well-audited EVM wallet — for example MetaMask or Rabby — rather than an obscure one. Rabby in particular is popular with derivatives traders because it previews the expected result of a transaction before you sign. Whatever you choose, the single biggest upgrade you can make is a hardware wallet.
| Setup | Security | Best for |
|---|---|---|
| Browser hot wallet | Basic | Small, active trading balances |
| Hot wallet + hardware signer | Strong | Most serious traders |
| Dedicated trading wallet, separate from savings | Strong | Compartmentalizing risk |
| Cold wallet, never connected to dApps | Highest | Long-term storage you rarely touch |
A powerful pattern is compartmentalization: keep a dedicated wallet for active Hyperliquid trading with only what you are actively using, and keep long-term holdings in a separate cold wallet that never connects to any application. If the trading wallet is ever compromised, your savings are untouched.
Defend against phishing
Phishing — tricking you into signing a malicious transaction or revealing your seed phrase — causes far more losses than any protocol bug. Attackers are patient and convincing. Your defenses:
- Bookmark the real URL and only ever use the bookmark. Never reach the exchange through a search-engine ad, a link in a DM, or an email. Malicious look-alike domains are the number one attack vector.
- Never type your seed phrase into a website. No legitimate site, ever, will ask for it. Your seed phrase belongs only in your wallet’s recovery flow.
- Treat unsolicited contact as hostile. “Support” that DMs you first, giveaways, and urgent “you must migrate your funds” messages are scams by default.
- Slow down. Urgency is the scammer’s favorite tool. A deal or a warning that demands you act right now is a red flag in itself.
Read your transactions and manage approvals
Every action you sign has a real, on-chain effect. A wallet like Rabby will simulate and describe that effect — take the two seconds to read it. Be especially wary of token approvals, which grant a contract permission to move your tokens. A malicious or buggy contract with an unlimited approval can drain a token later, long after you signed. Prefer limited approvals where possible, and periodically review and revoke approvals you no longer need using a reputable approval-checker tool.
If a signature request looks strange, reject it
The cost of rejecting a legitimate transaction is that you try again. The cost of approving a malicious one can be your entire balance. When in doubt, cancel — the asymmetry is enormous.
API wallets for bots and automation
If you use trading bots or automated strategies, do not hand them your main private key. Hyperliquid supports API wallets (agent wallets): separate keys you authorize to place orders on your account without the ability to withdraw funds. This limits the blast radius — if the API key leaks, an attacker can disrupt your trading but cannot drain your account to their own address. Scope permissions as narrowly as your workflow allows, and rotate keys if you suspect exposure.
Operational habits that compound
- Back up your seed phrase offline. Written on paper or steel, stored securely, never photographed or saved in cloud storage or a password manager that syncs online.
- Keep your devices clean. A malware-infected computer can swap addresses or capture what you type. Keep your OS and browser updated and be conservative about extensions.
- Verify addresses carefully. Clipboard-hijacking malware silently replaces a pasted address. Check the first and last several characters every time you send.
- Use a separate browser profile for trading, with a minimal set of trusted extensions, to reduce the attack surface.
Remember the market risk, too
Security is not only about theft. The other way people lose money on Hyperliquid is by trading itself — especially with leverage. Understanding liquidations and using conservative position sizing is as much a part of “staying safe” as protecting your keys. A perfectly secured wallet can still be emptied by a 50x position on the wrong side of a wick.
A quick security checklist
- Hardware wallet connected, seed phrase backed up offline.
- Official URL bookmarked; never reached via ads, DMs, or email.
- Separate wallets for trading and long-term savings.
- Every transaction read before signing; suspicious ones rejected.
- Token approvals reviewed and revoked when unused.
- API wallets (not your main key) for any bots, with no withdrawal rights.
- Position sizing and stop-losses in place for market risk.
Get the security foundation right first, then optimize your costs. When you are ready to trade, applying referral code PERPLIST for a 4% fee discount is a safe, one-time step you take inside the official interface — see the referral code page, and the getting-started guide for the full sign-up walkthrough.
Hyperliquid Referral Code
Enter the code when you create your account, or use the direct link below — the 4% fee discount is applied automatically.
https://app.hyperliquid.xyz/join/PERPLIST