Skip to content
Join the waitlistWaitlist

The kill switch

What the kill switch does, in which order, why it latches, and how to trade again.

The kill switch stops everything at once and keeps it stopped. It is Session::kill in crates/zunder-exec/src/session.rs, true today. A live test against Hyperliquid testnet enters a position, simulates a crash, adopts the position after the restart and then pulls the kill switch (testnet_restart_adopts_the_position_then_the_kill_switch_flattens); it passed on 5 Oct 2026 (docs/testnet.md).

  1. Latch. The session is marked killed. From now on it never opens a position.
  2. Cancel what could open. Every resting order that is not reduce-only is cancelled. Stops stay for now.
  3. Close every position, with reduce-only market orders bounded at 5% from the reference price (exit_slippage), up to 3 attempts per position.
  4. Cancel what is left, including the stops of positions that are now closed.

Stops stay for any position that could not be closed. The switch never fails half-way: errors are collected in a report, and the report says “flat” only when the venue confirmed it and no entry can still arrive.

Try it · an example book running
  1. 1 Latch
  2. 2 Cancel what could open
  3. 3 Close every position
  4. 4 Cancel what is left

Positions

  • BTC long 0.03 · stop 58,800
  • ETH short 0.4 · stop 2,600

Resting orders

  • SOL buy limit 1.5 · opens a position
  • BTC stop 58,800 · reduce-only
  • ETH stop 2,600 · reduce-only

A kill switch that a restart undoes is not a kill switch. In Zunder’s runner, pulling it writes killed.json into the state directory. A restart sees the file, kills again to be sure, and opens nothing. To trade again, a person removes the file after looking, and restarts.

Your agent starts looping and sends the same entry every second.

Terminal window
zunder-runner kill --config testnet.toml --reason "agent looping"

Within one poll the runner cancels the agent’s resting entries, closes the open positions, and records killed with your reason.

Kill switchDaily loss stopDrawdown halt
Triggered bya person or a toola loss todaya fall from the peak
Flattensyesyesyes
Clearsa person, after lookingnext UTC daya person, after a review
  • It acts only through a running process. If Guard is down, close positions in the Hyperliquid app. The stops on the venue keep protecting positions while Guard is down.
  • It controls only orders that go through it. Orders from another key or the Hyperliquid app are not stopped.

This page as plain Markdown, for people and LLMs: /docs/concepts/kill-switch.md