Why Anchor Ledger Doesn't Custody Your Funds

August 27, 2026

Most trading platforms ask you to deposit funds into an account they control. Anchor Ledger doesn't do that. Instead, you sign a real on-chain transaction granting a capped, revocable spending permission — your assets never move to us, never sit in an account we control.

What "capped" actually means

When you link a wallet, you set a maximum amount — the Approval Cap. That number isn't a suggestion or a soft limit enforced by our servers; it's written into the on-chain approval itself. The delegate address we control literally cannot move more than that amount, because the chain itself won't let it.

What "revocable" actually means

Revoking is a transaction you sign yourself, submitted on-chain. It's not a support ticket, not "3-5 business days," not a setting that quietly does nothing. The moment that transaction confirms, our authority over your wallet ends — verifiably, on a public ledger, not because we say so.

We verify the chain. We don't trust a wallet app's word.

Before we ever mark a wallet as linked, our server queries the chain directly for the real, current on-chain allowance. A wallet app reporting "success" isn't proof of anything by itself — we've seen mobile wallet confirmations report the wrong amount before. If what's on-chain doesn't match what should be there, linking fails rather than silently trusting a client-reported success.

This is why deposits and trading run on separate chains

Solana handles deposits and withdrawals; Tron is where trade execution happens. That's not an arbitrary split — a single transaction can't reference two different blockchain clusters at once, so any feature touching two chains gets two fully separate code paths and connections, structurally, not as an afterthought.

Read more on how this works chain by chain on our Architecture page, or see the exact security controls protecting your account.