Log in

Security & Key Custody: How Polyspect Handles Your Keys

Most security pages tell you what you want to hear. This one tells you how the system actually works, where the real risk sits, and what you should do about it. If you've been burned before, you're the reader we wrote this for.

Polyspect ranks and lets you copy Polymarket traders using Polymarket's public APIs. We have no inside access to Polymarket, and we are not affiliated with it. What follows is about Polymarket copy trading security on our side: when a key is involved, when it isn't, and who can read it.

Paper trading needs no key at all

Every account starts with virtual (paper) strategies. Virtual money mirrors a real trader's live trades so you can watch the equity curve before risking a cent. There is no private key, no wallet connection, and no signing. Nothing in a paper strategy can move real funds, because there are no real funds attached to it.

This is the honest answer to "is it safe to try Polyspect?" — paper mode carries zero custody risk. You can evaluate a trader for weeks without ever exposing a wallet.

Live trading needs a signing key — here's how we hold it

To place real orders, Polyspect needs a key that can sign transactions on your behalf. We designed the path so the website itself never touches the plaintext:

  1. Encrypted in your browser. Your private key is encrypted on your device before anything is sent. The web server receives ciphertext, not the key.
  2. Decrypted only by an isolated worker. A separate trading worker — not the website — is the only component that can decrypt the key to sign an order at the moment a trade fires.
  3. The website never sees the plaintext key. The dashboard, the API, and the database that powers the leaderboard never hold a usable key.

This is non-custodial signing in the sense that the website never holds a key it could use to drain you. We will not call the whole platform "non-custodial," because the trading worker does decrypt your key to sign. That is a real distinction, and pretending otherwise would be the opposite of why you're here.

The honest part: a key that can trade can also withdraw

Any private key capable of placing trades is also capable of withdrawing from that wallet. There is no version of automated trading where that isn't true. So the protection that matters most isn't a marketing claim — it's how you fund the wallet.

Combine that with the built-in guardrails on live copy trading — fixed per-trade size, stop-loss, take-profit, trailing stops, slippage limits, and position and daily-loss caps — and you control both the downside and the exposure.

Securing the account itself

Wallet custody is one layer; your login is another. Polyspect protects accounts with:

Turning on 2FA before you enable live trading is the single highest-value step you can take to keep an attacker out of the account that manages your strategies.

What this means before you go live

Prediction-market trading carries real risk of loss, and past performance does not predict future results — copying a profitable trader can still lose money. Security reduces the chance of someone else taking your funds; it does nothing to guarantee a strategy wins. Read our risk disclosure before funding a live wallet, and understand how copy trading works end to end.

Start on paper, with no key and no risk. Create a free account, watch a trader's virtual equity curve, and only fund a dedicated wallet once you've decided the edge is real.