What a Hyperliquid agent key can sign, measured.

We approved an agent key on mainnet and had it sign every action that moves money. Here is what Hyperliquid accepted, what it refused, and what it means for your account.

Last updated: 4 October 2026

What an agent wallet is

On Hyperliquid, an account can approve a second key, called an agent or API wallet, to trade on its behalf. The account signs the approval once; the agent key then signs orders for the account without holding its funds.

An approval carries an end date: 180 days at most, the longest Hyperliquid allows. The account can revoke it at any time.

How we measured it

On 28 September 2026, on Hyperliquid mainnet, with a test account holding about 60 USDC, the account approved a fresh agent for one hour, as Locker Vault does, and the agent signed each action that moves money, for 1,000 USDC.

With 1,000 USDC asked of an account holding 60, nothing could move: only the reason of each refusal mattered. The account then signed the same requests. Where the agent got another answer than the account, it had been stopped for what it is, not for the amount.

What Hyperliquid answered

ActionSigned by the agent key
Place an order, then cancel itaccepted
Withdraw (withdraw3)refused
Send USDC or a token (usdSend, spotSend, sendAsset)refused
Move between spot and perps (usdClassTransfer)refused
Approve another agent, or a builder feerefused
Deposit the account into a Hyperliquid vault (vaultTransfer)accepted

The refusals all read the same: Hyperliquid applied the action to the agent's own address, which holds nothing. The deposit into a vault was then tried for 5 USDC, toward HLP, Hyperliquid's own vault, a destination that stays the account's: it went through.

The one movement of funds it can sign

A deposit into a vault moves money out of the account's free margin into a vault run by someone else. A thief holding an agent key could deposit your account into a vault they run, then lose it trading against themselves.

lpa never signs this action: its guardian signs a closed list of trading actions. But a thief with the key file and your password does not need lpa.

What lpa adds

  • The agent key is sealed on disk under your password, and held in memory by the guardian only while you unlock it.
  • The guardian signs orders, cancels, leverage and margin settings, and nothing else.
  • Every opening is checked against your local policy and against the mandate signed on your phone.
  • The key expires on its own, with warnings 30, 14, 7, 3 and 1 days before.

The bound that holds

No file on your computer stops a thief who has both the key and the password. What still holds then: the key cannot withdraw, it expires, and an account used for the agent alone holds only what you are ready to risk.

To end it, lpa agent revoke retires the key at once, with your phone. lpa mandate revoke needs no phone and stops every opening by lpa until a new mandate is signed.