Platform & Security
A withdrawal lock is any setting that prevents funds from leaving an exchange account through an API key: creating the key without withdrawal permission, restricting withdrawals to pre-approved addresses, or enabling exchange-side delays and confirmations; it is the difference between a compromised key costing you bad trades and costing you the whole balance.
Automation platforms hold API keys around the clock; the question is what those keys can do if they leak. Trading permission lets a key open and close positions, which is what automation needs. Withdrawal permission lets it send funds to an external wallet, which automation never needs and which has been the mechanism behind most bot-related thefts. Address allowlists and withdrawal delays on the exchange add a second lock even for keys that were created carelessly, and some exchanges require them for API withdrawals in any case.
AlgoVesta only requests trade-only keys and states, in the setup guide for each of the 16 supported exchanges, that the withdrawal permission must be left off; the platform has no code path that withdraws or transfers funds. Keys are verified when added, stored encrypted at rest, and can be bound on the exchange to the fixed execution IP addresses shown in the dashboard. On MetaTrader 5 the equivalent is that a broker login can trade but cannot withdraw from the broker; withdrawals are done through the broker's own client portal with its own authentication. The panic button closes positions and stops bots; it does not and cannot move funds. See trade-only API key and the Security page.
A trader creates an OKX key with trading enabled and withdrawal disabled, and enables OKX's address allowlist and 24-hour withdrawal delay on the account. A year later the key is exposed in a phishing incident. The attacker can attempt trades from an allowed IP only, which they do not control, and could not withdraw even with full account access without passing the allowlist and the delay. The trader revokes the key and rotates it.