Only the first is usually discussed. The other four are where real incidents happen.
01Broker credentials
The one everyone asks about, and the one with the clearest answer: if the copier runs in a vendor’s cloud, the vendor must hold a login that works.
R4Copier runs locally, so the credential stays in your OS keystore. Covered in full on the credentials page.
02The host machine
Your desktop or VPS holds the keystore and runs the terminals. Compromise it and the credential question is moot — the attacker is already inside the session that has access.
This is the largest practical risk in most setups, and it is entirely yours to manage.
03Your R4Copier account
The web dashboard shows your account numbers, copy rules and trade history. It cannot place a trade and holds no broker password, but it does describe how you trade.
Use a unique password and enable two-factor authentication in Settings.
04The software supply chain
Any application you install is a trust decision. Ours ships as a signed Windows binary, so the installer you run can be checked against the publisher it claims.
Download from r4copier.com. Cracked builds of trading software are a known malware vector.
05The broker side
Your broker or prop firm holds the account itself. Enable whatever account protection they offer and use a password unique to them.
No copier can compensate for a broker login reused from a breached website.
06You, at 2am
The unglamorous one. Copying into an account whose rules forbid the trade, or onto a slave sized off the wrong balance, costs more accounts than attackers do.
Per-slave rules and per-slave toggles exist for this. See prop firm copying.