Security
Your money stays on your own Binance account.
HafizeBot never holds your trading funds. Autotrading works through an API key you create on your own Binance account, and the bot uses it to place and manage futures orders there. This page says what the key needs, what we do with it, and how to take it back.
We never hold your trading funds
Your trading capital stays in your own Binance futures wallet. The bot sends futures orders to Binance with your key; it has no function that withdraws or transfers money out of your account. The only money you ever send us is the USDT you pay for VIP, through /join in @hafizebot or on the billing page of your account.
Futures trading is the only permission to switch on
On the key, tick Enable Futures. Spot and margin trading are not needed. When you send /on, the bot asks Binance about the key; if Binance refuses it or says futures is not enabled, autotrading stays off and the bot tells you why.
Withdrawals are never needed
Leave Enable Withdrawals off. HafizeBot never needs it and never asks for it. If you save a key that has it switched on, the keys page warns you, and so does the bot when you send /on. Switch it off on Binance.
Restrict the key to our server
Under the key's IP access restrictions, choose Restrict access to trusted IPs only and add 91.99.78.29. That is the server HafizeBot trades from, so the key then works from there and nowhere else, even if it ever leaked. If a key is open to any IP, the keys page and the bot warn you.
Your key is encrypted at rest
The key, secret and passphrase you save are encrypted with authenticated encryption (libsodium secretbox) before they are written to our database, and the encryption key is not kept in the database. Your secret is never shown again: the keys page only confirms that a key is set and shows its last four characters.
A key can be saved in one place only: hafizebot.com/app/keys, after you log in with Telegram. HafizeBot will never ask for your key or secret in a Telegram chat or by email.
Delete or revoke a key
On HafizeBot: open your keys page and choose Delete key, or go straight to the delete step. You confirm on a second page; autotrading is switched off first, then the key, secret and passphrase are wiped. Positions and orders already open on Binance stay open; manage them in Binance.
On Binance: open API Management and delete the key. From then on Binance refuses it, so nothing can trade with it. Do this as well if you think the key has leaked.
Checklist
- A new, system-generated key made only for HafizeBot.
- Enable Futures on, Enable Withdrawals off.
- IP access restricted to
91.99.78.29. - Pasted only at hafizebot.com/app/keys, after logging in with Telegram.
- No warning on the keys page after saving. If there is one, fix the key on Binance and save it again.
- Deleted in Binance's API Management when you stop using HafizeBot.
Step by step: connect a Binance API key, or the Autotrader guide (PDF).