HexaDocs

Security and custody

How your embedded wallet works, what Hexa's signer can and cannot do, and how to keep your account safe.

Your wallet

Hexa wallets are embedded wallets from Privy. When you sign up, Privy creates a Solana wallet and an EVM wallet that belong to your account. The private keys are generated and secured by Privy; Hexa never sees, stores or transmits your private key.

To trade for you without asking you to sign every transaction, Hexa is added to your wallet as an additional signer with a policy: a list of rules, enforced by Privy, that says exactly which transactions Hexa's key may sign. Anything outside the policy is refused by Privy, whoever asks.

What Hexa's signer can do

  • Sign transactions that call only approved programs: the system and token programs, the launchpads and pools Hexa trades on (such as pump.fun, PumpSwap and Meteora DBC) and the swap routers it uses (such as Jupiter, DFlow, OKX and 0x).
  • Any plain SOL transfer above 0.05 SOL is refused.
  • Sign swaps through the 0x router and the four.meme contracts, with token approvals for the exact amount of each trade (never unlimited).
  • Sign the messages that place and manage your orders on Hyperliquid (perpetuals) and Polymarket (predictions).

On top of Privy's policy, every transaction passes through Hexa's isolated signing service, the only part of Hexa that can request a signature. It re-checks each transaction before signing: swaps are simulated first, buy sizes, priority fees and tips have hard ceilings, and the platform fee can't exceed the published rate. Every signature is recorded in an audit log.

What Hexa cannot do

  • Export your private key: the policy denies key export to Hexa's signer.
  • Withdraw without you: a withdrawal is created only by your signed-in request with a fresh two-factor code, and the signing service sends only a transfer that matches that request exactly, after its 60-second delay.
  • Let automation move funds out: limit orders, take-profit and stop-loss, copy trading, agents and API keys can only swap. They can never withdraw, transfer or approve spending to someone else, and they act only within the session you grant.

How strong is this?

These rules are enforced by Privy's policy engine and by Hexa's signing service, and Hexa administers them. They are strong operational safeguards, not a substitute for caution: keep on Hexa what you intend to trade.

Sessions for automation

Automations that act while you're away need a session you grant under Settings → Automation · Session keys:

  • Choose what it's for: Orders (limit, triggers, take-profit and stop-loss), Copy (copy trading) or Agent (AI agents).
  • Set Max per trade, Daily cap and Expires in (up to 30 days).
  • Press Revoke at any time to end it.

A session can only swap within its caps, and each wallet holds one session at a time: granting a new one replaces the previous one on that wallet.

Perpetuals trading key

When you enable perpetuals, Hexa creates a Hyperliquid trading key for your account and seals it inside its signing service. It can place and cancel orders on your Hyperliquid account but can never withdraw; withdrawals from Hyperliquid are signed by your main wallet. The key expires after 30 days and is renewed for you.

Keep your account safe

  • Turn on two-factor authentication, and back up your authenticator.
  • Review your sessions under Settings → Security · Sessions. Sign out any device you don't recognise, or press Sign out everywhere.
  • Never share codes. Hexa staff will never ask for your sign-in codes or two-factor codes, and will never ask you to send funds.
  • Check the address before you sign in, and bookmark it.
  • Revoke sessions you no longer use, and stop copies and agents you're not watching.

Your account

  • Your account is tied to the sign-in you created it with. Google with the same email reaches an email account; a Telegram or wallet sign-in is a separate account. Hexa doesn't link sign-in methods today.
  • To close your account: Settings → Security · Sessions → Delete account… Withdraw your balances and close positions first. Order history, the ledger and the audit trail are kept as the law requires.