01

What you are doing

You are protecting the exchange account, HEDGERON login, API credentials, Telegram identity and recovery channels as separate layers.

02

Why it matters

No single control is enough. A no-withdraw API key reduces one risk, while account takeover, phishing, device compromise and unsafe manual actions remain possible.

03

Before you start

Use a dedicated Standard Subaccount, unique passwords, 2FA and the official HEDGERON and Bybit domains.

04

Step by step

  1. 01Keep trading activity in a dedicated Standard Subaccount.
  2. 02Grant minimum API permissions only.
  3. 03Never enable Withdraw.
  4. 04Use IP restriction when HEDGERON publishes a fixed outbound IP.
  5. 05Enable 2FA on HEDGERON, Bybit and the linked email where available.
  6. 06Verify unexpected Telegram/email events in Dashboard.
  7. 07If compromise is suspected, revoke the Bybit API key first and then create a new safe key.
05

What you should see

HEDGERON stores a masked connection reference, encrypts credentials at rest and never returns the raw secret to the browser.

06

Security check

Support never needs your exchange password, email password, 2FA seed, wallet seed phrase or withdrawal-enabled API key.

07

Common problems

You entered credentials on a suspicious page

Revoke the API key on Bybit immediately, review account sessions and create a new key only after the device is trusted.

An unknown order appears

Pause new entries if available, verify the order on Bybit and contact official support without sending secrets.

08

Next step

Use Troubleshooting for setup and runtime issues.

Privacy note

HEDGERON Help analytics must never collect API credentials, passwords, private account values or secret-bearing URLs.