GuardSigner is a Polyester-managed additional signer that protects changes to the external withdrawal and internal transfer whitelists for a Main Account or Subaccount. These whitelists can restrict destinations when Assets move from Funding or Trading.
GuardSigner does not replace your owner wallet or multi-factor authentication (MFA). It does not become an owner of your smart account, approve every transaction, or control your Trading activity. A protected change still needs your authorization.
Each Main Account and Subaccount has its own GuardSigner. Setting it up for one account does not set it up for another.
What GuardSigner protects
GuardSigner approves changes that modify or weaken the selected account's whitelist controls.
| Action | GuardSigner approval required? |
|---|---|
| Add an external withdrawal destination | Yes |
| Remove an external withdrawal destination | Yes |
| Add an internal transfer account | Yes |
| Remove an internal transfer account | Yes |
| Turn off either whitelist requirement | Yes |
| Turn on either whitelist requirement | No |
You cannot turn on either whitelist requirement until GuardSigner is ready. Turning on a requirement does not require GuardSigner approval or MFA, but GuardSigner must be available if you later turn the requirement off.
How a protected change is approved
A protected whitelist change uses separate security layers:
- Fresh MFA verifies that you approved the change in the current Polyester session.
- GuardSigner approves the exact account, action, and whitelist details.
- Your smart account authorizes and submits the on-chain change.
The GuardSigner approval is valid only for the prepared change. Changing the selected account, action, or destination details requires a new approval.
GuardSigner approvals, rotation, and private-key export require an owner session and fresh MFA. API keys cannot request these actions.
Set up GuardSigner
You can set up GuardSigner directly from Security. Polyester can also start the same setup automatically when you turn on a whitelist requirement or add a whitelist entry.
Switch to the account
Switch to the Main Account or Subaccount you want to protect. The Main Account owner or Subaccount Owner must complete setup. Open Security for the active account and find the GuardSigner wallet row.
Start setup
Select Set up. In the Set up GuardSigner window, review what GuardSigner protects and select Set up again.
Confirm with your wallet
If you use a connected wallet such as MetaMask, Polyester asks you to confirm the setup in your wallet. Approve the request to register GuardSigner with the active account. An embedded wallet completes this step without a separate wallet prompt.
Wait for confirmation
Setup normally completes in less than one minute when your connected wallet is available. If you started setup during a whitelist flow, Polyester continues that flow after setup completes.
Initial GuardSigner setup does not require MFA. Actions that use GuardSigner do require MFA, so we recommend setting up MFA before you need to make a protected change.
Rotate the GuardSigner
Rotation generates a new GuardSigner and replaces the current signer. Rotate GuardSigner if you suspect that your account or GuardSigner private key was exposed.
- Switch to the Main Account or Subaccount whose GuardSigner you want to rotate, then open Security.
- Select Rotate under Rotate GuardSigner Wallet.
- Review the confirmation and select Rotate again.
- Complete the MFA setup or verification shown by Polyester. Rotation requires MFA.
- Approve the wallet request if Polyester shows one.
- Wait until Polyester confirms that the new signer is active.
The replacement does not become active until the on-chain rotation is confirmed. Rotation normally completes in less than one minute when your connected wallet is available.
Export the private key
Export reveals the private key for the current GuardSigner. Use it only for a deliberate recovery or migration to secure custody.
To export:
- Switch to the correct Main Account or Subaccount, then open Security.
- Select Export under Export GuardSigner Private Key.
- Read and accept the warning, then complete fresh MFA.
- Reveal the key and move it directly into secure offline custody.
Polyester clears the displayed key when the dialog closes.
Never place the key in source control, logs, chat, analytics, browser storage, screenshots, or unencrypted backups. Polyester support will never ask you to share it.
Export does not remove or replace the signer registered on-chain. Polyester continues to hold and use the current key after you export it. The export gives you another copy, so Polyester no longer has exclusive control of that key.
Rotation creates a new key held only by Polyester unless you export the replacement key again. An intentional export does not require immediate rotation, but you should rotate if you suspect that your account or any copy of the key was exposed.
If a protected change fails
- Confirm that the intended Main Account or Subaccount is active.
- If setup was interrupted, start the whitelist action again and complete the setup prompt.
- If the request failed after MFA, Polyester may ask you to complete fresh MFA before trying again.
- Check the whitelist status after the on-chain transaction confirms before you withdraw or transfer.
FAQ
GuardSigner is an extra security layer for your Polyester accountโs withdrawal and transfer whitelists. It adds a separate approval signature when you add or remove destinations or turn off a whitelist. This prevents bypassing MFA to change those settings directly on-chain. Learn about GuardSigner.
Yes. With your withdrawal and transfer whitelists enabled, assets can only be sent to destinations you have approved. GuardSigner adds a separate approval to changes to those whitelists, including turning them off. This helps protect against someone changing your settings to redirect your assets. Learn about GuardSigner.
Polyester manages GuardSigner and sets it up automatically when you enable a withdrawal or transfer whitelist. Once set up, it handles protected changes to both whitelists for that account. Learn about GuardSigner.
GuardSigner makes MFA part of the on-chain changes to your withdrawal and transfer whitelists. You must complete the required MFA in Polyester before GuardSigner will add its signature. Your walletโs signature alone is not enough, which prevents bypassing MFA to change your whitelist settings. Learn about GuardSigner.
Yes. GuardSigner can protect both your Main Account and your Subaccounts, but each account has its own GuardSigner and separate withdrawal and transfer whitelists. Open the Security settings for each account to complete setup and choose the protections you want enabled. Learn about GuardSigner.