Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 

Repository files navigation

Security & Audits

Short version: your funds are not ours to lose.

Dexly is a self-custodial interface for trading on Hyperliquid. We do not hold, custody, or have withdrawal access to user funds. Not in an emergency, not with a court order, not if we wanted to. The architecture does not allow it.

This page exists because "trust us" is not a security model. Here is what is verified, what is not, and who verified it.


How custody actually works

You trade with one of two setups:

Bring your own wallet. MetaMask, or anything that speaks WalletConnect. The keys never touch us.

Embedded account. Created inside the app via Privy. Keys are split using Shamir's Secret Sharing and reassembled only inside a hardware-backed Trusted Execution Environment. Privy cannot see them. We cannot see them.

Either way:

Dexly can Dexly cannot
Submit orders you authorise Withdraw your funds
Read your public on-chain positions Move funds to another address
Charge the builder fee you approved Charge more than the cap you approved

That is not a policy we wrote. It is enforced by Hyperliquid at the protocol level. Before Dexly can charge you anything, you approve a maximum builder fee on-chain, and you can revoke that approval at any time without asking us.


What has been audited, and by whom

We are going to be precise here, because vague security claims are worse than none.

Hyperliquid, where your funds live and your orders execute

Hyperliquid's bridge contract has been audited by Zellic. The reports are published in Hyperliquid's own documentation.

These audits belong to Hyperliquid, not to us. We link them because they are relevant to where your money sits, not to imply that anyone audited Dexly. They did not.

Privy, the embedded wallet layer

If you use an in-app account rather than your own wallet, Privy holds the key infrastructure. Privy is a Stripe company and publishes its security posture at trust.privy.io:

Review By Date
SOC 2 Type II - April 2026
Security audit Doyensec February 2024
Security audit SwordBytes December 2023
Security audit Zellic June 2023
Security audit Cure53 February 2023

Privy also runs an active bug bounty on HackerOne.


So what is the actual risk?

Be clear-eyed about this. Self-custody removes one category of risk. It does not remove the others.

What self-custody protects you from: us. We cannot take your money, exit with it, freeze it, or lose it in a hack of our systems, because it is not in our systems.

What it does not protect you from:

  • Our app shipping a bug. A frontend can mis-render a price, mis-set a leverage value, or submit an order you did not intend. Your funds stay yours, but a bad order is still a bad order. This is the risk our unaudited code carries, and it is real.
  • Liquidation. At 50x, roughly a 2% adverse move wipes your margin. Liquidation is automatic and it does not wait for you.
  • Hyperliquid itself. If the protocol has a problem, every app on top of it has that problem, ours included.
  • Phishing. Fake Dexly apps and cloned sites exist. Install only from a link on dexly.trade. We will never ask for a seed phrase. Nobody legitimate ever will.

Reporting a vulnerability

Found something? Email hi@dexly.trade.

We respond within 48 hours. Please do not open a public issue for a security bug, and please do not test against other people's funds.

We do not currently run a paid bug bounty. If you report something real, we will say so publicly and credit you here, unless you would rather we did not.


Last updated: July 2026. If anything on this page stops being true, it gets changed here first.

About

Security and audit disclosure for Dexly. What is audited, what is not, and what self-custody does and does not protect you from.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors