The kill switch
The kill switch stops everything at once and keeps it stopped. It is Session::kill in crates/zunder-exec/src/session.rs, true today. A live test against Hyperliquid testnet enters a position, simulates a crash, adopts the position after the restart and then pulls the kill switch (testnet_restart_adopts_the_position_then_the_kill_switch_flattens); it passed on 5 Oct 2026 (docs/testnet.md).
What it does, in order
Section titled “What it does, in order”- Latch. The session is marked killed. From now on it never opens a position.
- Cancel what could open. Every resting order that is not reduce-only is cancelled. Stops stay for now.
- Close every position, with reduce-only market orders bounded at 5% from the reference price (
exit_slippage), up to 3 attempts per position. - Cancel what is left, including the stops of positions that are now closed.
Stops stay for any position that could not be closed. The switch never fails half-way: errors are collected in a report, and the report says “flat” only when the venue confirmed it and no entry can still arrive.
Why it latches
Section titled “Why it latches”A kill switch that a restart undoes is not a kill switch. In Zunder’s runner, pulling it writes killed.json into the state directory. A restart sees the file, kills again to be sure, and opens nothing. To trade again, a person removes the file after looking, and restarts.
Example
Section titled “Example”Your agent starts looping and sends the same entry every second.
zunder-runner kill --config testnet.toml --reason "agent looping"Within one poll the runner cancels the agent’s resting entries, closes the open positions, and records killed with your reason.
Kill switch, daily stop, drawdown halt
Section titled “Kill switch, daily stop, drawdown halt”| Kill switch | Daily loss stop | Drawdown halt | |
|---|---|---|---|
| Triggered by | a person or a tool | a loss today | a fall from the peak |
| Flattens | yes | yes | yes |
| Clears | a person, after looking | next UTC day | a person, after a review |
Limits
Section titled “Limits”- It acts only through a running process. If Guard is down, close positions in the Hyperliquid app. The stops on the venue keep protecting positions while Guard is down.
- It controls only orders that go through it. Orders from another key or the Hyperliquid app are not stopped.