Back to Home

Wallet Connection Security

Last updated: August 25, 2026

TargetHit has different connection methods by venue and product. Read the connection screen and every wallet prompt before approving it. Only continue on https://targethit.com, and reject any request that differs from the method described on this page.

Exchange API credential connections

Some exchange connections use exchange-issued API keys, secrets, passphrases, or a separate API-wallet credential. Some HyperLiquid exchange-settings and Auto-Trade connections may name that credential as an API-wallet private key; it is not your main-wallet private key. Use only the credential type named by the connection screen, grant only the minimum read/trade permissions it names, and keep withdrawals disabled. These credentials are encrypted before storage and decrypted only in authorized server-side paths for connection checks, account reads, and trade execution.

TargetHit never asks for your exchange password, wallet seed phrase, recovery phrase, or main-wallet private key. A venue-issued trading credential can still place trades and create losses, so revoke it at the exchange if you suspect it has been exposed.

The keyless HyperLiquid terminal ceremony

HyperLiquid can appear in both connection methods: an exchange-settings or Auto-Trade connection may request a separate API-wallet private key, while the terminal keyless dialog uses the two-signature ceremony below. The API-wallet key is never your main-wallet key.

If you use the terminal's keyless HyperLiquid connection, a fresh attempt asks your main wallet for exactly two structured EIP-712 signatures after the wallet connection request. It does not ask you to paste a private key. TargetHit creates a fresh named trading agent on the server, seals its private key before storage, and never returns that private key to the browser.

  1. HyperliquidTransaction:ApproveAgent authorizes the public address of the fresh named trading agent. The agent can place trades and create losses, but it is not a withdrawal or transfer key.
  2. HyperliquidTransaction:ApproveBuilderFee authorizes a builder fee capped at 0.04% (4 bps) on filled orders routed with TargetHit's builder code. Signing the approval alone does not move funds or charge a fee.

These are signatures for the two displayed HyperLiquid actions, not token allowances, transfers, or contract transactions. TargetHit checks that both signatures match the prepared requests and the same main wallet, then verifies the named agent and exact builder-fee ceiling through HyperLiquid before the connection can become active.

Reject the request if you see anything else

  • A seed phrase, recovery phrase, or main-wallet private-key request.
  • A token approval, transfer, contract call, or transaction request.
  • Any EIP-712 action name, agent address, builder address, or fee cap that differs from the prepared values displayed by TargetHit.
  • A site origin other than https://targethit.com.

Pause, disconnect, and revoke

Pausing or disconnecting in TargetHit disables TargetHit routing. Disconnecting a keyless connection removes the stored sealed credential, but it does not pretend to revoke separate permissions recorded by HyperLiquid.

To remove venue-side authority, revoke the agent and builder approval in HyperLiquid. If you used an exchange API credential, revoke or delete that credential in the exchange's own settings. These venue controls remain available even if you cannot access TargetHit.

Report a security issue

Email [email protected] with the affected URL, steps to reproduce, and the impact you observed. Never send a seed phrase, private key, exchange secret, or real wallet signature in a report, and do not test against another member's account or disrupt the service.

Automated security tooling can use our standard security.txt disclosure file.

If you have any questions about this policy, please contact us at [email protected]