Protecting your instance

Because you run GRIDer on your own server, you also own its security — and the good news is that it comes down to a few simple habits. This page is the short, practical checklist. For how the non-custodial model works, see Non-custodial & security.

The one thing that matters most: access to your server

GRIDer runs on your machine, so whoever can reach your machine controls what the app does. Keeping that access to yourself is the single most effective thing you can do.

  • Protect your server provider account. Turn on two-factor authentication (2FA) with your VPS provider (Hetzner and the others all offer it), use a strong, unique password, and don't reuse it anywhere else.
  • Keep your access credentials private. Your provider login, your SSH key (if you use one), and the install link and token you received with your licence are all keys to your instance. Don't share them or paste them into chats, screenshots or tickets.
  • Let the installer harden the box for you. The one-click installer already sets up a firewall (only the web and SSH ports open), brute-force protection for SSH, and automatic security updates. You don't need to configure anything.
  • If you connect over SSH, prefer an SSH key over a password, and keep that key safe.

That's most of the job. The rest below is about staying safe when you connect your wallet.

Why this is where the risk really is

We'd rather be straight with you: the realistic risk is not that GRIDer moves your funds — it can't; your trading access is order-only and your main wallet's keys never touch the software. The realistic risk is that someone gets into your server and changes the app itself. A modified app could try to trick your wallet. That's exactly why the checklist above — keeping server access to yourself — comes first.

There's also a simple habit that makes such an attempt easy to spot.

What GRIDer will (and won't) ask your wallet to do

GRIDer only ever asks your main wallet to sign a message: once to log in, and once to approve a trading agent. That's it.

GRIDer will never ask your wallet to send funds, make a transfer, or approve token spending.

So if a screen that looks like GRIDer ever makes your wallet pop up a transaction to confirm, or a token approval, treat it as a red flag: decline it and check your server. A normal login or agent approval is a message signature, never a transfer.

Use a wallet that shows you what you're signing

Modern wallets can simulate a request and warn you before you approve something harmful. This is your safety net, and it works even if an app is misbehaving.

  • Wallets like Rabby, or MetaMask with its built-in security alerts, preview what a signature or transaction will actually do and flag known drainer patterns.
  • Take a second to read what your wallet is asking before you approve — especially anything mentioning approve, permit, transfer or a spending allowance, which a normal GRIDer login or agent approval never involves.

Keep trading access trading-only

  • Create API keys or agent wallets without withdrawal permission (GRIDer's flows already do this for you where the exchange supports it — see Instance setup).
  • Revoke or rotate trading access on the exchange when you change servers, end a licence, or suspect anything is off.
  • Back up your secrets volume so you can restore your instance; keep that backup somewhere safe. See Updating GRIDer and Logs & support.

Next: the FAQ.

results matching ""

    No results matching ""