ZUNDER GUARD — A RISK FIREWALL FOR BOTS AND AI AGENTS

Your bot can be wrong.
Your limits can’t.

Guard runs on your machine, between your bot and Hyperliquid. It sizes every order from its stop and says no to anything that breaks your rules. Quietly, until it matters.

0.24 ms Guard’s own work, p50+1 round trip to read your account firsthow it was measured ↓
waiting for the next trade…
judged in your browser
sampled live from Hyperliquid
without a stop
+5 more rules active ↓
LIVE · HYPERLIQUID
runs in your browser, with JavaScript

The market, judged by your rules.

Every dot is a real trade on Hyperliquid, as it happens. For the largest ones, Guard reads the trader’s public account and asks one question: would your limits have let it through?

—
trades · —
—
refused · of — judged
—
resized · of — judged
LAST 48 SECONDS · SIZE = NOTIONAL · COLOUR = HEAT · HOVER A DOT not judged allowed resized refused

Your rules

  • 5× max
  • 2.0% at stop
  • no stop: Guard sets one
  • liq. ≥ 10%
  • size ≤ 200%
  • open ≤ 6%
  • daily 6%
  • drawdown 25%
  • 5/5 markets
PER TRADE
if an order comes without a stop
POSITION
MARKETS
ACROSS THE ACCOUNT
ONLY YOUR OWN GUARD CAN ENFORCE
stops only tightenalways
resume after a drawdown halta human
These act on your bot’s future orders, so they cannot be seen in other traders’ past ones.
New rules apply to the trades that arrive from now on: each trade is judged once, from the trader’s account at that moment.

Why Guard said no

0 of 0 judged trades changed
  • market not on your list0
  • no protective stop0
  • leverage above your cap0
  • too close to liquidation0
  • open risk above your limit0
  • trader past the daily loss stop0
  • trader past the drawdown halt0
  • no stop: Guard set one, sized to your risk0
  • resized: risk or size above your limit0

Refused, by market

share of each market’s trades
  • BTC—
  • ETH—
  • SOL—
  • HYPE—
  • ALTS—

Decisions

The latest trades and what Guard decided under your rules
TIMETRADERTRADENOTIONALLEV.STOPLIQ.HEATGUARD
Waiting for the first trades from Hyperliquid…

Traders are anonymised in your browser. Every trade in BTC, ETH, SOL, HYPE, XRP, DOGE, SUI and AVAX streams from Hyperliquid’s public data; the largest are judged on this page, as many as the public API’s request budget allows.

A quarter of a millisecond to judge. One fresh look at your account.

Guard’s own work on an order takes about 0.24 ms: it checks the request, judges it against your rules and signs it. Before it judges, it reads your account fresh from Hyperliquid, so it decides on your real positions, not on a guess. That read is one more round trip, skipped when its view is under a second old.

  • 0.24 ms
    Guard’s own work per order, p50
  • 0.244 ms
    p99, over 20,000 orders
  • +1 trip
    reading your account before it judges
  • 5 µs
    of the 0.24 ms, the risk check itself
ONE ORDER THROUGH GUARD, TO SCALE · BOT IN FRANKFURT, HYPERLIQUID IN TOKYO
Guard: check, judge, sign0.24 ms
Guard reads your account238 ms
the order to Hyperliquid and back238 ms

Guard’s own work, measured 6 Oct 2026 on our build box (16 vCPUs), release build, over 20,000 ccxt-style market buys with an attached stop: decode and authenticate 88 µs, judge (the risk engine) 5 µs, two signatures 145 µs; total p50 238 µs, p99 244 µs. A client that signs as mainnet adds about 80 µs; an order on a position that is already open needs one signature, not two. Round trips: from our build box in Frankfurt (AWS eu-central-1) to api.hyperliquid.xyz, a small /info request, 59 requests on 6 Oct 2026, p50 238 ms, p95 437 ms. Guard reads the account with three requests in parallel (one round trip) unless its view is under a second old and nothing was sent since; a new position that needs isolated leverage set first costs one more. The loopback hop between your bot and Guard is not in these numbers, and we have not measured from Tokyo yet. The benchmark is part of Guard’s source.

Four checks. Every order.

  1. Read the account

    Equity, open positions and their stops, from the venue and from Guard’s own record. The riskier view wins.

  2. Size from the stop

    Your bot names a stop. Guard turns your risk limit, fees and the venue’s rounding into a quantity.

  3. Check every limit

    Leverage, open risk, the daily loss stop, the drawdown halt. One fails, the order never leaves.

  4. Send, stop, record

    The order goes out with its stop resting on the venue, and the decision is written to a checksum-chained journal that shows if a line was changed or removed.

The nine rules

Four refuse an order, two halt new entries, two shrink it, and one adds the stop your bot forgot. You set each one; the defaults are Guard’s policy.

Market allowlistdefault all markets
REFUSES · Only markets on your list can be traded.
Required stopdefault Guard sets one
ADDS A STOP · No stop? Guard sets one, sized to your max loss at the stop. (Or refuses, if you choose.)
Max leveragedefault 5×
REFUSES · Refuses an order that would take the position above your leverage cap.
Min distance to liquidationdefault 10%
REFUSES · Refuses an order whose position would sit closer than this to its liquidation price.
Max open riskdefault 6%
REFUSES · Refuses a new trade when the loss at all stops, open positions plus this one, would pass this share of the account.
Daily loss stopdefault 6%
HALTS · Once the account is down this much since the start of the UTC day, new entries stop until the day is over.
Drawdown haltdefault 25%
HALTS · Once the account is this far below its peak, new entries stop until a human resumes.
Max positiondefault 200%
RESIZES · Shrinks an order whose position would be larger than this share of the account.
Max loss at the stopdefault 2%
RESIZES · Shrinks the order until the loss at its stop, fees included, is at most this share of the account.

Always, whatever you set: stops only tighten, a restart never resets a stop, and a drawdown halt waits for a human.

RESEARCH · DATA TO 6 OCTOBER 2026

We tested 5,940 alternative rule sets on the real trades of 262 Hyperliquid accounts. None beat our defaults on accounts they weren’t tuned on.

A replay of each account’s last 180 days to 6 October 2026 through Guard’s engine. “Beat” means our pre-registered score, with its constraints, on accounts the rule set was not chosen on; the best challenger scored +0.023 (95% interval −0.12 to +0.23). So we kept them.

Behind the defaults, on accounts held out

  • −42 ptsmax drawdown, median accountcut by 42 points (95% interval 22–63)63 accounts held out
  • −60% → −18%worst day, median accountas traded, then behind the defaults; no interval computed for this difference63 accounts held out
  • 60%return per unit of drawdown improvedshare of accounts (95% interval 49–71%)63 accounts held out
  • 68%liquidation events with the guarded account flatin 136 of 201 liquidation events, the guarded account held no position in that coin (95% interval 26–90%). Not “prevented”: it is mostly the drawdown halt, and part of the sample was picked for having been liquidated.63 accounts held out

Held-out test: 63 accounts looked at once, after the rules were fixed. Medians; 95% bootstrap intervals. A mixed sample: ordinary active traders, long-term winners and recently liquidated accounts.

Long-term winners mostly sized their trades within Guard’s limits; liquidated accounts mostly did not.

  • 83%long-term winnersmedian share of entries within Guard’s limits (95% interval 19–100%)15 accounts
  • 0%liquidated accountsthe same share (95% interval 0–4%)57 accounts

“Within” counts Guard’s own 2% stop: most winners used no resting stop. Winners are survivors of today’s leaderboard, with much larger accounts. Last 180 days to 6 October 2026; descriptive, not a promise.

91% of liquidated positions broke Guard’s leverage or liquidation-buffer default that morning, against 38% of the others.

  • 91%liquidated positions over the limitsleverage above 5× or liquidation within 10% of entry (95% interval 90–91%)95,095 positions
  • 38%positions not liquidated that daythe same rules, the base rate (95% interval 37–38%)7,942,674 position-days

Over the 30 days 4 Sep – 3 October 2026, all of Hyperliquid. Read from that morning’s snapshot of open positions, not at entry; covers the 62% of liquidations whose position was open at the snapshot. An association, not a claim that Guard prevents liquidations.

Guard is a trade-off.

It costs the best traders part of their gains: in the replay the median long-term winner’s return fell from 43% to 8%, mostly through the drawdown halt (with the halt opened alone, 13%). 9 winners, training and validation accounts.

Only about 10% of entries go through at full size (95% interval 3–18%). Of all judged entries, 43% were held by a halt (39% by the drawdown halt, once an account was already 25% down), 21% refused and 13% resized.

An “active” preset lets more trades through (paper and testnet only for now)

What these numbers can and cannot carry

  • What-if replays: each account’s own trades over the 180 days to 6 October 2026, judged by Guard’s engine; later decisions are kept as traded.
  • The replay sees Guard’s attached stops only at the account’s own fills. One-second prices show that 16% of the default stops the replay never fired were touched in between: real Guard would have closed those positions at a loss and missed any recovery. This flatters Guard somewhat.
  • Main-dex perps only: HIP-3, spot and outcome markets are left out, as Guard does not cover them yet.
  • The samples are mostly manual traders: by a public-data heuristic (exploratory), 22 of the 323 accounts measured (7%) look like bots. A dedicated bot study is running.
  • The liquidation autopsy covers 4 Sep – 3 October 2026, read at a daily snapshot.
  • Past behaviour, not a forecast, and no promise of returns.

The four studies and how they were done

The Zunder stack.

Guard is the first product. Around it, the tools we use ourselves, each with an honest status.

  • Guard

    Building

    Risk firewall between any bot or AI agent and Hyperliquid.

  • Backtest

    Live

    Replay any address under your rules.

  • Watch

    Live

    Your bot’s trades judged live in the browser.

  • Hyperliquid’s trades judged by your rules, anonymised.

  • Agent kit (MCP)

    With Guard 1.0

    Guarded trading tools for Claude, Cursor and other MCP clients.

  • Monitor

    Planned

    Pair the browser with your local Guard: decisions and kill switch.

  • Data

    Planned

    Point-in-time Hyperliquid data: trades, books, node gossip.

    recorded since Oct 2026
  • Labs

    Planned

    Research notes: honest backtesting, the signal lab.

  • Guarded Arena

    Planned

    AI agents trading in public, every veto visible.

  • Mint

    Exploring

    Toolkit for HIP-3 market deployers.

  • Terminal

    Exploring

    Guard in the browser for manual traders.

Live: works today. Building: in progress. With Guard 1.0: ships with Guard. Planned: decided, not started. Exploring: an idea we are testing.

Questions, answered straight.

Is Zunder Guard available today?

Not yet. Guard is being built. Its risk engine, the sizing from the stop, the daily loss stop and the drawdown halt already run in Zunder's own trading system; the proxy that puts them in front of your bot is in progress. You can join the waitlist for early access.

On this site today: the backtest and the watch steps run in your browser, and the live market section shows how Guard judges trades. All three read Hyperliquid’s public data and judge it with Guard’s risk engine, compiled to WebAssembly, in your browser.

What does Zunder Guard cost?

0.02% of each order’s value that Guard sends to Hyperliquid on mainnet, as a builder fee: $2 on a $10,000 order, win or lose. That is the default plan, Pay per order: open to anyone and anonymous, with no subscription, no sign-up, no account and no personal data. Paper trading and testnet are always free.

If your bot trades more than about $870k a month, a flat licence is cheaper: Pro €149 a month for up to 3 accounts, Fund €690 a month for up to 20 accounts with priority email support; a year costs ten months. Bot platforms can share the fee through their own builder code. A licence turns off the fee and nothing else, and when it ends, Guard falls back to the fee and keeps protecting you.

Licences are sold to businesses, self-service, paid in USDC: buy a licence. Guard itself comes with its first release; join the waitlist before Guard 1.0.0 and you get Pro free for 3 months. Plans and the calculator.

How do I add a daily loss limit or a kill switch to my Hyperliquid bot?

Put the check outside the bot's own logic. A limit written into the strategy fails together with it: a restart resets counters kept in memory, and a bug can skip the check entirely.

A daily loss limit needs three things: the account's equity at the start of the UTC day, a check before every new order that refuses it once the day's loss reaches your limit, and a halt that survives restarts. A kill switch is the same mechanism pulled by hand: it refuses every new order at once.

That is what Guard is built to do in front of your bot (planned for Guard 1.0). It reads equity from Hyperliquid and from its own record and uses the riskier of the two, and refuses new entries once the day's loss reaches your daily loss stop (default 6%). A restart never resets a stop. The daily stop clears at the next UTC day; a drawdown halt (default 25% below the peak) waits for a human.

Until Guard ships, Watch can warn you in the browser when one of your bot's trades breaks a rule. It cannot block anything.

Is a Hyperliquid API wallet (agent wallet) safe? What can it do and not do?

Safer than your main key, but not harmless. An API wallet is a separate key that your main wallet approves to trade for the account. It can place and cancel orders; it cannot withdraw or transfer funds.

So a leaked API wallet key cannot take your funds out directly, but whoever holds it can still trade your account into losses: open oversized positions, or buy an illiquid market at a bad price from themselves.

Keep it away from code you do not fully trust. With Guard (planned), the API wallet key stays inside Guard on your machine. Your bot gets a separate client key issued by Guard, which Hyperliquid does not accept on its own, and every order still has to pass your limits. If you think a key has leaked, replace that API wallet.

How do I put guardrails on an AI trading agent (MCP)?

Keep the limits outside the agent, and give it tools that cannot break them. A prompt is not a limit: a model can misread a number, loop, or be talked out of an instruction.

The plan for Guard 1.0 is an MCP server (zunder-guard mcp). Its tools read the account and the limits, ask what Guard would allow for a trade, place, amend and close orders, and pull the kill switch. No tool can raise a limit, loosen a stop or resume after a halt, and every order the agent sends passes the same rules as any bot's. It is planned for MCP clients such as Claude Desktop, Claude Code and Cursor. None of it is released yet.

What is a Hyperliquid builder fee, and how does Guard use one?

A builder fee is a per-order fee that Hyperliquid lets an app attach to the orders it sends for a user. The user approves a maximum fee once with their main wallet and can revoke the approval at any time. Hyperliquid collects the fee with the trade and credits it to the app's builder address. Hyperliquid caps builder fees at 0.1% on perps and 1% on spot.

Guard's fee is 0.02% of each order’s value that it sends to Hyperliquid, on mainnet. Hyperliquid collects it only after you have approved it once with your main wallet, and you can revoke that approval at any time. Without the approval, Guard opens no new positions and says why; closing orders always go. Zunder Labs never holds your funds. A busy bot can turn the fee off with a flat licence: see pricing.

Is Guard open source?

No: source-available. Guard will be published under the Elastic License 2.0. You can read the code, run it and change it for your own trading. You may not offer it to others as a hosted service, or remove or work around the per-order fee, which is built in as licence-key functionality.

To run Guard without the fee, get a licence: see pricing.

Does Guard give trading signals or investment advice?

No. Guard is a risk tool. It enforces limits you set on orders your bot or agent has already decided to send: it sizes them, adds a missing stop or refuses them. It gives no signals, no investment advice, and promises no returns.

Does Guard hold my keys or my funds?

No. Guard runs on your machine or your own server, not ours. Your funds stay in your Hyperliquid account. The only key Guard uses is an API wallet key that you create and that cannot withdraw. It stays on your machine, and we never see it.

Zunder Labs runs no service that holds a key or can place an order. This website reads public data only: no wallet connection, no signature, no key. The one exception is the fee approval at /approve, which asks your main wallet to sign Hyperliquid's ApproveBuilderFee message (to approve the fee, or to withdraw the approval at 0%) and nothing else.

How much latency does Guard add?

Two parts. Guard's own work is about 0.24 ms per order: 238 µs at the median and 244 µs at the 99th percentile, over 20,000 orders on our build box (16 vCPUs, release build). That is decoding and authenticating your bot's request (88 µs), judging it against your rules (5 µs) and signing what goes to Hyperliquid (145 µs, two signatures).

The larger part is a deliberate one: before it judges, Guard reads your account fresh from Hyperliquid (three requests in parallel), so it decides on your real positions. That costs one round trip, unless Guard's view is under a second old and nothing was sent since. A new position that needs isolated leverage set first costs one more. From our build box in Frankfurt, a small request to Hyperliquid took 238 ms there and back at the median (p95 437 ms, 6 Oct 2026); from a server near Tokyo it is shorter. We have not measured from Tokyo yet.

Not in these numbers: the loopback connection between your bot and Guard on the same machine. The benchmark is part of Guard's source.

Which bots work with Guard?

Planned: anything that can point its Hyperliquid client at a custom URL. Guard will speak Hyperliquid's own API on your machine (for example http://127.0.0.1:8547), so your bot changes a few settings (the URL, the key Guard gives it, isolated margin) and keeps its logic.

The plan covers ccxt and the bots built on it (such as Freqtrade), the official Hyperliquid Python and TypeScript SDKs, MCP clients, and your own scripts. Each integration gets a one-page guide once we have tested it. Until then, read this list as planned, not verified.

Is the backtest a promise of what Guard would have done?

No. It is a what-if. It replays an address's trades twice: once as they happened, once behind your rules.

  • Skipping or shrinking a trade can change what the bot would have done next; the replay cannot know that.
  • Prices, fees and funding after a skipped trade are taken from the real history.
  • Losses are capped at the stop only where the bot actually had one.
  • Results include fees and funding as Hyperliquid recorded them.

Backtest replays the last 30, 90 or 180 days of an address (90 by default) from Hyperliquid’s public data and lists what the replay had to assume.

All answers on one page

AVAILABLE AT THE FIRST RELEASE

Pricing.

0.02% of each order’s value, no subscription. A flat licence when your bot trades a lot.

  • Pay per order

    0.02%

    of each order’s value that Guard sends to Hyperliquid

    Anyone, anonymously. The default for every install.

  • Pro

    €149

    a month, or €1,490 a year

    One trader or team with a busy bot.

  • Fund

    €690

    a month, or €6,900 a year

    Funds and prop desks.

  • Platform

    Custom

    revenue share through your own builder code

    Bot platforms and HIP-3 deployers that build Guard in.

Break-even: Pro pays for itself above about $870k of orders a month, Fund above about $4M.

A year costs ten months. Licence prices plus VAT where it applies. Dollar figures at $1.17 per euro, the rate the prices were set at.

Launch offer Join the waitlist before Guard 1.0.0 and get Pro free for 3 months. Join below

All plans and the calculator

Put a firewall in front of your bot.

Self-hosted and source-available. Hyperliquid first. Early access for the first bots that want hard limits.

0.02% of each order’s value that Guard sends to Hyperliquid · no subscription · or a flat licence. Pricing

Launch offer: join before Guard 1.0.0 and get Pro free for 3 months.