Garnet

Self-hosted · Rust · Polymarket

The Polymarket copy-trading bot you run yourself

You pick the wallets. Garnet mirrors their trades on your own server, with your own key. No scoring, no screening, no opinions — and a shadow mode that pays the same fees as live, so you can judge a wallet before money follows it.

v0.1.0 · Sep 2026 669 tests · 0 warnings 15 crates on Tokio Free for individuals
Garnet logo

The uncomfortable truth

A copy-trading bot is worth nothing without profitable wallets to copy. Execution speed, slippage control and settlement accounting only decide how much of someone else's edge survives the trip to your account. They cannot manufacture an edge that isn't there. So Garnet does one thing: you decide which wallets are worth copying, and it copies them — fast, and without second-guessing you.

What it actually does

Detection, sizing, execution, accounting and settlement — each part built around a defect that once cost real money.

Three independent detection circuits

On 31.08.2026 Polymarket's activity/trades topic went down platform-wide for hours. Garnet hears every trade three ways:

  • RTDS websocket — the fastest;
  • /activity polling — the safety net;
  • Polygon logs — decoded from the verified V2 ABI, independent of Polymarket's infrastructure.

All three collapse onto one dedup key: a third delivery, not a third truth.

Execution that knows the exchange

  • orders are FAK only — a resting order would make you a maker, the opposite of copying a taker;
  • size is snapped to the exchange grid, not rounded;
  • fill price comes from the trade feed, not from the order;
  • "rejected" and "unknown" are different outcomes — retrying an accepted order once bought $2 where $1 was intended.

Live and shadow, side by side

Shadow mode pays the same fee, uses the same order path and reads the same book — otherwise it would flatter itself by exactly the fee you forgot to charge. /matchup then shows your result against the leader's, fees included. The killswitch stops live trading and leaves shadow running.

Accounting reconciled against the chain

Settlement is decided by tokens[].winner and token_id — never by outcome labels like Up/Down or team names. A reconciler compares the ledger with the chain every 10 minutes, and "could not read" is reported as its own outcome, never as "agreed".

Risk controls, and why each exists

Every skipped trade gets one of seven named reasons, so you always know why the bot did not copy something.

ControlWhat it doesWhy
Killswitchstops live trading, keeps positionslives in the database — a stop that a restart undoes is not a stop
Daily loss stoplatches for the UTC daya bot that merely loses money will not stop on its own
Exposure capa ceiling per event, not per tokenoutcomes of one condition are correlated
Fire-rate limitentries per wallet per windowone leader once fired 12 decisions in a minute and caused 94% of the loss
Slice windowcollapses one leader order into one copylater slices of an already-copied order lost money
Health monitormeasured by flow, not livenessboth guards once reported OK while the bot was blind for 6.5 hours

Your private key

In 2026 GitHub filled up with "Polymarket copy-trading bots" that shipped the operator's .env to someone else's server, mostly through poisoned npm dependencies. You are right to ask what this one does with your key — and you can check the answer yourself.

Where it lives, where it never goes

  • in .env on your own machine, chmod 600, ignored by git;
  • it signs orders locally (EIP-712) — the signature goes to the exchange, the key does not;
  • it appears in logs as ***REDACTED***, and a test holds that line;
  • no telemetry, no licence server, no update check.

Check it instead of trusting it

  • no npm — the engine is Rust end to end, every crate pinned in Cargo.lock;
  • the README lists every host the code talks to, with a one-line grep to verify it;
  • cargo audit is clean apart from one crate that is not compiled in;
  • with no keys set, the live path does not come up at all — shadow mode runs on public data alone.

Use a dedicated wallet funded with what you are prepared to lose. Garnet asks for one signing key and never for a seed phrase — anything that asks for a mnemonic to "copy trades" is not a copy-trading bot.

Quick start

Rust stable, Docker for Postgres, Redis and NATS, a Polymarket account with L2 API keys, and a Telegram bot token.

git clone https://github.com/AndreySchurko/garnet-polymarket.git
cd garnet-polymarket
docker compose up -d                       # Postgres, Redis, NATS
cp .env.example .env                       # secrets, then chmod 600
cp config.example.toml config.toml
cargo build --release --bin garnet-core --bin garnet-tg --bin garnet-dash

./target/release/garnet-core --config config.toml --preflight   # 13 probes

Then start in shadow mode, from Telegram:

/add 0xWALLET…    copy this wallet from now on
/mode shadow      paper trading: same fees, same book
/stake 10         $10 per signal
/health           is the flow alive?

Run it for a few days and read /pnl, /matchup and /slippage before you consider /mode live. Full instructions are in the README.

Services

I build and run this software. If you would rather not do it yourself, I can do it for you. Scope and price are agreed up front, in writing; payment in crypto.

Wallet Intelligence reports

The engine copies; the wallets decide the result. Reports rank wallets from on-chain Polymarket history against filters you set — ROI, trade count, hold time, drawdown, market type — with the metrics that decide how much of an edge survives a taker fill.

  • One-shot — a single report on your filters, CSV and analysis, addresses ready for /add;
  • Subscription — regular re-runs, new qualifying wallets, alerts when a copied wallet stops working;
  • Institutional — custom metrics, longer histories, raw data export, commercial license included.

Data and analysis, not investment advice or a promise of returns.

Server setup & deployment

  • VPS provisioning, hardening, users, firewall;
  • Docker, Postgres, Redis, NATS, systemd units;
  • Caddy and TLS for the dashboard;
  • Garnet installed and configured, preflight green;
  • your wallets loaded, shadow mode running;
  • a walkthrough so you understand what you now own.

You hand over a bare server. You get back a working bot.

Maintenance & monitoring

  • OS and dependency updates, backups;
  • monitoring and alerting that reaches you;
  • incident response when Polymarket changes an API;
  • upgrades to new Garnet releases;
  • a monthly health report on the bot and the server.

A trading bot is not a set-and-forget asset. This is the part most people skip and then regret.

Customisation & new modules

  • new exit strategies, sizing models, risk rules;
  • extra detection circuits and data sources;
  • custom reporting and dashboards;
  • integration with your own systems;
  • performance work on the hot path.

Built to the repository's conventions, with tests, so it survives the next upgrade.

Trading bots, built to order

Not only Polymarket.

  • other prediction markets — Kalshi, Limitless and others;
  • centralised crypto exchanges — spot, futures, market making;
  • DEX and on-chain strategies;
  • copy trading, arbitrage, market making, custom logic;
  • Rust or Python, on your infrastructure or mine.

Fifteen crates and 669 tests of evidence that I finish what I start.

Commercial license

Garnet is free for individuals trading their own funds. Companies, funds and anyone trading third-party money need a commercial license. Evaluation is always free: read the code, run the tests and use shadow mode before any conversation about money.

License terms

FAQ

Is it profitable?

By itself, no. Garnet has no opinion about which wallets are worth copying — that is the entire design. Run it in shadow mode with wallets you believe in and read /matchup: your result against the leader's, fees included, is the only honest answer.

Is it open source?

It is source-available under the Business Source License 1.1: free for individuals trading their own funds, with the full source to read and audit. Companies and funds need a commercial license. Each version converts to Apache-2.0 four years after release — for v0.1.0, on 2030-09-25.

Can it front-run the leader?

No, and nothing here claims otherwise. Garnet copies trades that have already executed. What it does is avoid losing seconds on top of that — nothing on the hot path waits sequentially when it could wait in parallel — and /latency measures the result end to end, per trade, on your own server.

Where should I run it?

On a VPS close to Polymarket's infrastructure, in a jurisdiction where Polymarket allows trading. The README lists the providers and RPC endpoints the bot has actually been run with.