Blockchain DailyTERMINAL
PROTECTED

WILLIAMSBOT AUTO-COPY SECURITY

Execution security, engineered in layers.

Your exchange account remains yours. Blockchain Daily separates strategy authority, customer authorization, credential decryption, risk enforcement, and exchange execution so no single ordinary system component is trusted to do everything.

Browser-encrypted keysIsolated signersSigned targetsVerified disarm

SEPARATION OF AUTHORITY

One instruction. Multiple independent checks.

OUTBOUND-ONLY EXECUTION PATH
01WilliamsBotSigns strategy targetPosition · orders · lineage
02TerminalAuthorizes mandateUser · subscription · market
03Isolated signerVerifies and fencesKMS · risk policy · receipt
04ExchangeConfirms live stateOrders · position · cleanup

DEFENSE IN DEPTH

Protection across the complete execution lifecycle.

01CREDENTIAL BOUNDARY

Encrypted before storage.

The browser creates a unique AES-256 key, encrypts the exchange credential, and wraps that key to an AWS KMS public key. The Terminal stores only the encrypted envelope and has no KMS decrypt permission.

AES-256-GCM · RSA-OAEP-SHA-256 · TENANT-BOUND AAD
02STRATEGY AUTHORITY

Every target proves its origin.

WilliamsBot signs the complete intended position and working-order state. The signer verifies the run lineage, strategy, venue, instrument, sequence, and previous-target hash before it can touch an exchange.

SIGNED TARGETS · HASH-CHAINED STATE · ROUTE LOCKS
03EXECUTION INTEGRITY

Stale workers cannot trade.

Mandate generations, executor leases, and strongly consistent action receipts fence every exchange operation. Completed work is returned from its receipt; an ambiguous exchange outcome is reconciled instead of blindly transmitted again.

LEASE FENCING · DURABLE RECEIPTS · IDEMPOTENT ACTIONS
04CLEAN EXIT

Off means exchange-verified.

Disarm cancels mandate-owned orders, closes exposure reduce-only, and samples the exchange repeatedly. The Terminal clears the credential only after it verifies a signer-produced, KMS-signed cleanup receipt.

REDUCE-ONLY FLATTEN · REPEATED VERIFICATION · SIGNED RECEIPT

INDEPENDENT SIGNER POLICY

Risk limits live where trades are signed.

The execution service checks the live exchange account and an immutable, version-pinned policy before authorizing a position-increasing action. A website or database change cannot silently raise these limits.
01
AllocationMaximum authorized capital
ENFORCED
02
LeverageHard execution ceiling
ENFORCED
03
PositionMaximum live notional
ENFORCED
04
OrdersSize, count, and total notional
ENFORCED
05
Daily lossDollar and percentage limits
ENFORCED
06
DrawdownAccount high-water protection
ENFORCED

VENUE ISOLATION

Separated exchange boundaries.

Lighter and Hyperliquid do not share customer decryption keys, executor credentials, risk-policy identities, receipt namespaces, or cleanup-signing keys.
LIGHTER

Dedicated KMS signer

Programmatic API keys are bound to the customer, run, account index, and exact market. Managed key indexes 4–254 are required.

SEPARATE KEY · SECRET · POLICY · RECEIPTS
HYPERLIQUID

Dedicated API-wallet signer

The encrypted API-wallet key is bound to the customer’s master account address, WilliamsBot run, and exact Hyperliquid asset.

SEPARATE KEY · SECRET · POLICY · RECEIPTS

VERIFIED DISARM

A switch is not proof.

The browser can request cleanup, but it cannot declare the account safe. Final shutdown requires trusted exchange verification.
  1. 01Cancel mandate-owned ordersManual and unrelated strategy orders are not adopted by appearance.
  2. 02Flatten reduce-onlyThe closing action cannot intentionally reverse the position.
  3. 03Sample exchange statePosition and managed-order state are checked repeatedly.
  4. 04Verify signed receiptOnly then is the mandate marked off and its envelope cleared.

THE HONEST SECURITY BOUNDARY

Security controls operational risk. It does not remove trading risk.

What the architecture protects
  • Database theft exposing plaintext credentials
  • Stale or duplicate executor activity
  • Tampered, misrouted, or unsigned targets
  • Execution outside signer-enforced limits
  • False “off” status without cleanup proof
What no execution system can eliminate
  • Market losses, liquidation, and adverse fills
  • Exchange outages, ADL, or venue intervention
  • Temporary network and API uncertainty
  • Risk created by customer-selected leverage
  • Compromise of the customer’s own device or exchange

RESEARCH THE STRATEGY. UNDERSTAND THE EXECUTION.

Review the evidence before allocating capital.

Explore historical methodology, then observe WilliamsBot’s current paper positions and working orders.