Short version: your funds are not ours to lose.
Dexly is a self-custodial interface for trading on Hyperliquid. We do not hold, custody, or have withdrawal access to user funds. Not in an emergency, not with a court order, not if we wanted to. The architecture does not allow it.
This page exists because "trust us" is not a security model. Here is what is verified, what is not, and who verified it.
You trade with one of two setups:
Bring your own wallet. MetaMask, or anything that speaks WalletConnect. The keys never touch us.
Embedded account. Created inside the app via Privy. Keys are split using Shamir's Secret Sharing and reassembled only inside a hardware-backed Trusted Execution Environment. Privy cannot see them. We cannot see them.
Either way:
| Dexly can | Dexly cannot |
|---|---|
| Submit orders you authorise | Withdraw your funds |
| Read your public on-chain positions | Move funds to another address |
| Charge the builder fee you approved | Charge more than the cap you approved |
That is not a policy we wrote. It is enforced by Hyperliquid at the protocol level. Before Dexly can charge you anything, you approve a maximum builder fee on-chain, and you can revoke that approval at any time without asking us.
We are going to be precise here, because vague security claims are worse than none.
Hyperliquid's bridge contract has been audited by Zellic. The reports are published in Hyperliquid's own documentation.
These audits belong to Hyperliquid, not to us. We link them because they are relevant to where your money sits, not to imply that anyone audited Dexly. They did not.
If you use an in-app account rather than your own wallet, Privy holds the key infrastructure. Privy is a Stripe company and publishes its security posture at trust.privy.io:
| Review | By | Date |
|---|---|---|
| SOC 2 Type II | - | April 2026 |
| Security audit | Doyensec | February 2024 |
| Security audit | SwordBytes | December 2023 |
| Security audit | Zellic | June 2023 |
| Security audit | Cure53 | February 2023 |
Privy also runs an active bug bounty on HackerOne.
Be clear-eyed about this. Self-custody removes one category of risk. It does not remove the others.
What self-custody protects you from: us. We cannot take your money, exit with it, freeze it, or lose it in a hack of our systems, because it is not in our systems.
What it does not protect you from:
- Our app shipping a bug. A frontend can mis-render a price, mis-set a leverage value, or submit an order you did not intend. Your funds stay yours, but a bad order is still a bad order. This is the risk our unaudited code carries, and it is real.
- Liquidation. At 50x, roughly a 2% adverse move wipes your margin. Liquidation is automatic and it does not wait for you.
- Hyperliquid itself. If the protocol has a problem, every app on top of it has that problem, ours included.
- Phishing. Fake Dexly apps and cloned sites exist. Install only from a link on dexly.trade. We will never ask for a seed phrase. Nobody legitimate ever will.
Found something? Email hi@dexly.trade.
We respond within 48 hours. Please do not open a public issue for a security bug, and please do not test against other people's funds.
We do not currently run a paid bug bounty. If you report something real, we will say so publicly and credit you here, unless you would rather we did not.
Last updated: July 2026. If anything on this page stops being true, it gets changed here first.