Comparisons

Open Source Crypto Trading Bot: 9 Projects, Audited on GitHub (2026)

We pulled the GitHub API record for the nine open source crypto trading bots people actually recommend. Two have been archived since 2020 and 2022, one shipped a CVSS 9.8 remote code execution flaw, and one is MIT-licensed right up until you want it to place a real order.

16 min readBy uwuu team

An open source crypto trading bot costs nothing to download and something to run, and almost nobody writes down the second number. On 7 October 2026 we pulled the GitHub API record for the nine projects people actually recommend — stars, licence, last commit on the default branch, release cadence, published security advisories — and then read the maintainers' own documentation for what they admit the software cannot do. Two of the most-recommended bots have been archived for years. One shipped a remote-code-execution hole rated 9.8 out of 10. One is MIT-licensed right up to the moment you want it to place a real order.

This is the audit, with every command you need to re-run it yourself.

Google's page one for this keyword contains almost no open source bots

Start with the search result, because it explains why the advice you have read so far is bad. We queried Google for "open source crypto trading bot" on 7 October 2026. The organic top seven were: a Kraken explainer about AI bots, two pages from Coinrule (a closed-source subscription product), a YouTube video about wiring TradingView to WunderTrading (also closed-source), a CoinLedger listicle whose lead recommendation is a proprietary platform, a single GitHub repository, and OKX's exchange bot page.

That single GitHub repository is pranavvss/Automated-Trading-Bot-v1: 31 stars, 7 forks, last pushed in August 2024, described by its own author as a moving-average crossover bot running on a Raspberry Pi. It is a perfectly respectable student project. It is also the only open source crypto trading bot on page one.

Freqtrade has 55,096 stars. It is not on page one. Neither is Hummingbot, Jesse, or OctoBot.

Searching instead for "best open source crypto trading bot" returns a Reddit thread about Elixir, two Quora answers, a BitcoinTalk thread from several years ago, a thread on an Open Tibia server forum, and two thin affiliate listicles. Google is not hiding a great page from you. There isn't one. That is the gap this article is written into, and the reason every number below is sourced from an API call or a maintainer's own docs rather than from another blog.

The nine projects, audited on GitHub

Every figure in this table was read from the GitHub REST API on 7 October 2026. "Last commit" is the most recent commit on the project's default branch — not pushed_at, which is what "last updated" badges usually show and which counts a push to any branch, including a documentation fork.

Project Stars Licence Last commit Commits, 90 days Latest release
Freqtrade 55,096 GPL-3.0 2026-10-07 833 2026.9, 29 Sep 2026
ccxt (library) 44,272 MIT 2026-10-06 3,897 continuous
Hummingbot 20,327 Apache-2.0 2026-09-22 267 v2.17.0, 22 Sep 2026
Gekko 10,175 MIT 2020-02-16 (archived) 0 none
Jesse 8,615 MIT (core only) 2026-10-01 113 tag v3.2.4
Zenbot 8,259 MIT 2022-02-14 (archived) 0 none
OctoBot 6,682 GPL-3.0 2026-10-07 250 3.0.0-beta2, 6 Aug 2026
Superalgos 5,680 Apache-2.0 2026-05-07 0 v1.6.1, 2 Nov 2024
Hummingbot Gateway 260 Apache-2.0 2026-10-06 active rolling

Three things fall out of that table immediately.

Freqtrade is the only project shipping on a predictable schedule. It uses calendar versioning and has cut one release per month without a gap: 2026.3 on 30 March, 2026.4 on 30 April, through to 2026.9 on 29 September. If you want a bot whose upgrade path you can plan around, that cadence is the single best signal in the table.

ccxt is not a bot and you should stop reading listicles that say it is. It is an exchange-connectivity library covering 100-plus venues, and most of those 3,897 commits are machine-generated transpilation output rather than human review. It is the plumbing underneath several of the other entries, including Freqtrade. If you are writing your own bot it is the right dependency; it will not trade for you. We covered what building on top of it actually involves in our walkthrough of a copy trading bot in Python.

Superalgos is the clearest example of why pushed_at lies. The GitHub API reports it as pushed on 5 October 2026, which is the number most "is this project alive?" tools surface. Its master branch tells a different story: the last commit landed on 7 May 2026 and was a merge of a README fix. The two before it, from 23 March, were also documentation corrections. The last tagged release is v1.6.1 from November 2024. The project has 5,680 stars and 6,007 forks — more forks than stars, which is unusual and reflects a fork-to-run workflow rather than contribution.

Ready to copy trade on Solana?

Start copying the most profitable traders in under 2 minutes. No coding, no complex setup. Just connect and earn.

Two of the most-recommended bots have been archived for years

Gekko and Zenbot together hold 18,434 GitHub stars and 5,741 forks, and neither has accepted a commit in this decade's trading environment. Gekko was archived with its last commit on 16 February 2020. Zenbot was archived on 14 February 2022, leaving 295 open issues permanently unanswered.

Both still appear in listicles, because star counts are sticky and listicle authors sort by them. An archived repository is read-only: no security patches, no exchange API updates, no dependency bumps. Exchange APIs are not stable over six years — endpoints are versioned out, authentication schemes change, rate limits move. A bot that has not been touched since 2020 is not "mature", it is a historical artefact, and anything it says about fees or venues predates most of what you would want to trade today.

The check takes one API call. If archived is true, close the tab.

Free licence, paid runway: what each project actually charges for

"Open source" describes the licence on the code, not the price of the product. Three of the projects here monetise, and each does it differently. None of this is dishonest — maintainers have to eat — but it is almost never mentioned alongside the word "free".

Jesse is MIT-licensed, and its live trading is not. Jesse's own documentation is explicit: "Live and paper trading functionality is supported by Jesse via an official plugin", and that plugin "is pre-built and the access is limited to those with an active license." You generate a licence key from a Jesse.Trade account, drop it into LICENSE_API_TOKEN in your .env, and the installer pulls a binary matched to your CPU architecture, OS and Python version. So the MIT repository gives you backtesting, optimisation and research. The component that places a real order on an exchange is closed-source and account-gated — including, note, the paper trading mode.

OctoBot's repository is a funnel. The README is GPL-3.0 and genuinely functional, and it also contains 34 links to octobot.cloud, 28 of them carrying utm_source=github&utm_medium=dk&utm_campaign=regular_open_source_content tracking parameters. The current release line runs in "node mode" by default, where your self-hosted instance acts as a backend for a hosted interface and mobile app. That is a reasonable architecture. It also means the default experience of the open source bot routes through a commercial front end.

Hummingbot is the cleanest of the three. Apache-2.0, no licence gate on execution, and a stated mission to "democratize high-frequency trading". Its README claims users generated over $34 billion in trading volume across 140-plus venues in the past year — a vendor figure, unaudited, but at least one the project publishes under its own name.

Freqtrade takes the opposite position and writes it down. The FreqAI documentation states the project is and always will be a not-for-profit open source effort, that it has no token, does not sell signals, and has no domain beyond the Freqtrade documentation. A project only writes that paragraph because people are impersonating it to sell things.

If you are comparing against the paid side of this market, our breakdowns of 3Commas alternatives, Cryptohopper and Gunbot cover what a subscription buys you that a repository does not.

The infrastructure bill nobody itemises

The licence is $0. The running cost is a server you administer, and the documentation tells you how much server. We are not going to quote VPS prices that will be wrong by the time you read this, so here is the requirements list instead, straight from each project's docs — price it against your own provider.

  • A machine that stays on. All of these are long-running daemons. A laptop that sleeps is a bot that misses fills.
  • An accurate clock. Freqtrade's installation docs carry an explicit warning: the system clock "must be accurate, synchronized to a NTP server frequently enough to avoid problems with communication to the exchanges." Signature-based exchange auth fails on clock drift.
  • Python 3.12 or newer, plus a toolchain. Freqtrade lists Python ≥ 3.12, pip, git and virtualenv, and on ARM64 — including Apple Silicon and most cheap cloud VMs — it tells you to use Docker because native installation "is not supported at the moment."
  • Databases, for some of them. Jesse needs PostgreSQL and Redis running alongside it. That is two more services to secure, back up and upgrade.
  • A second service for DEX trading. Hummingbot's on-chain support lives in a separate Node process called Gateway, deployed as its own container.
  • Historical candle data. FreqAI's docs are blunt that for backtesting you must download data covering the backtest range plus the training window and startup candles in front of it. Storage and bandwidth are yours.
  • A GPU, sometimes, and not where you think. FreqAI can retrain models on a GPU on a separate thread from inference. Hyperopt cannot: Freqtrade's FAQ explains that most indicator libraries have no GPU support and that hyperopt mixes number-crunching with running Python, so "the benefit of using GPU would therefore be pretty slim." Buying a GPU to speed up parameter search is money lit on fire.

Then there is the cost that does not appear on an invoice. Freqtrade's front page carries a DISCLAIMER block that reads, in part: "This software is for educational purposes only... We strongly recommend you to have basic coding skills and Python knowledge. Do not hesitate to read the source code and understand the mechanisms of this bot." That is the maintainers telling you the real prerequisite is your time.

What the docs admit about backtesting

The backtest is the reason most people choose an open source bot, and it is the part the maintainers are most careful about. Freqtrade publishes a section titled "Assumptions made by backtesting" listing fourteen top-level assumptions the engine has to make because it cannot see inside a candle. Several of them matter a great deal:

  • "All orders are filled at the requested price (no slippage) as long as the price is within the candle's high/low range." Every backtest you have ever seen from one of these tools assumes zero slippage.
  • Exit signals are favoured over stop-losses, because exit signals are assumed to trigger at the candle's open.
  • Stop-loss exits happen exactly at the stop price even when the candle's low went below it — though the loss is booked two fees worse than the stop.
  • Low is assumed to happen before high when evaluating a stop, which protects capital in simulation in a way the market does not promise.

The docs close that section with a sentence worth more than any equity curve: "backtesting will never replace running a strategy in dry-run mode."

Elsewhere, Freqtrade warns that most strategy callbacks fire once per iteration in live trading — roughly every five seconds — but at most once per candle in a backtest, "which can cause backtesting mismatches." And if you reach for FreqAI's adaptive retraining, the documentation spells out the arithmetic you cannot escape: a true backtest retrains a model for every sliding window, so "a true backtest of FreqAI adaptive training would take a very long time. The best way to fully test a model is to run it dry and let it train constantly. In this case, backtesting would take the exact same amount of time as a dry run."

Read that twice. Properly validating an adaptive model costs the same wall-clock time as simply running it. Hyperopt is not a shortcut either — the FAQ says the default 100 epochs is "too few to find a great result" and you probably need "10000 or more", which "will take an eternity to compute."

The most honest line in the whole corpus is in Freqtrade's FAQ, answering a user who lost money over twelve trades: "it will always be a gamble, which should leave you with modest wins on monthly basis but you can't say much from few trades." No commercial bot vendor writes that sentence. It is also the same conclusion we reached measuring real outcomes in is copy trading profitable.

Ready to copy trade on Solana?

Start copying the most profitable traders in under 2 minutes. No coding, no complex setup. Just connect and earn.

Security: you are the security team

A self-hosted trading bot is an internet-facing web service that holds exchange API keys with withdrawal-adjacent permissions, and you are the one patching it. This is the cost item people discover last.

OctoBot has one published advisory in the GitHub Advisory Database: CVE-2021-36711, scored CVSS 9.8 (critical), vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. In plain terms: exploitable over the network, low complexity, no privileges and no user interaction required, with total loss of confidentiality, integrity and availability. The description is one sentence — "WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled" — classified as unrestricted upload of a file with a dangerous type. It was patched in 0.4.4, long ago. The point is not that OctoBot is uniquely unsafe; it is that a web UI bolted onto a bot is an attack surface, and the person responsible for noticing the advisory and applying the patch is you.

Two more live hazards, both documented by the projects themselves:

  • Downloaded model files are executable code. FreqAI's docs carry a Danger block: loading saved models from disk "can cause security issues if using remote model files (files you downloaded from the internet or received from an untrusted source) due to having the necessity to have weights_only=False." Deserialising an untrusted pickle runs whatever is in it. Their guidance is the only safe one: "As long as you only load models that you have trained yourself, there is no risk." Treat any shared "profitable model" file as a payload.
  • Default development mode is unencrypted. Hummingbot's README notes that with Gateway included, the stack starts in development mode over plain HTTP, and points you at a DEV=false flag and gateway generate-certs for production. Easy to miss, and Gateway is the component holding your on-chain keys.

Freqtrade also ships an example strategy with FreqAI, and tags it with a Danger block: it is built to showcase features and run on small computers, and is "not designed to be run in production." Every tutorial that tells you to clone the repo and start the example config is telling you to run something the authors explicitly flagged.

GPL-3.0 or MIT: what the licence actually obliges you to do

For personal trading, the licence makes no difference. For anything you distribute or sell, it makes all of it.

Freqtrade and OctoBot are GPL-3.0. Hummingbot, Hummingbot Gateway and Superalgos are Apache-2.0. ccxt, Jesse's core, Gekko and Zenbot are MIT.

Running a GPL-3.0 bot on your own server to trade your own money triggers no obligations at all — GPL-3.0 is conditioned on distribution, and you are not distributing anything. Hand a modified build to someone else, bundle it into a product, or ship it to customers, and you owe them the corresponding source under the same licence. Apache-2.0 and MIT let you keep your modifications private in those same scenarios; Apache-2.0 adds an explicit patent grant that MIT lacks.

The practical takeaway: if your plan is "fork a bot and sell access to it", GPL-3.0 projects are the wrong base, and Jesse's licence-gated live plugin removes the option entirely regardless of what the core repo says.

None of them trade Solana memecoins — except one

If you came here from Solana, this is the section that matters. We grepped roughly 300 KB of Freqtrade documentation for "solana", "raydium", "jupiter", "uniswap" and "decentralized exchange". Across twelve documentation files, the hit count is zero. Freqtrade's supported-exchange list names twelve spot venues — Binance, BingX, Bitget, Bybit, Gate, HTX, Kraken, OKX and others — of which exactly one, Hyperliquid, is a DEX. The architecture is centralised-exchange order books, via ccxt. It is excellent at that and it does not touch an on-chain AMM.

The same holds for Jesse and, in its core, for OctoBot. These are spot-and-futures bots for listed pairs. They cannot buy a token that launched forty seconds ago, because there is no exchange endpoint for it.

Hummingbot is the exception, and only through Gateway. The hummingbot/gateway repository contains two chain integrations — ethereum and solana — and connectors for Jupiter, Raydium, Meteora, Orca, dflow, titan and PancakeSwap on Solana. That is real on-chain capability, maintained and committed to as recently as 6 October 2026. It is also a 260-star side repository next to a 20,327-star main project, it is a separate Node service you deploy and secure yourself, and you still need your own Solana RPC endpoint to use it with any reliability.

And none of them do copy trading. We grepped the full Freqtrade documentation set for "copy trading", "mirror trading", "social trading" and "follow trader": zero hits across every file. Open source bots execute your strategy. Mirroring another wallet's on-chain activity in real time is a different problem — it needs transaction-level streaming and sub-second reaction, not candle polling — which is what the Solana trading bot landscape is actually built around.

Maintenance is the real risk: the bus factor

Star counts measure popularity in the past. Distinct recent authors measure whether anyone will fix your bug. We counted unique commit authors across the most recent 100 commits on each default branch:

  • Freqtrade: 5 distinct authors
  • Hummingbot: 6 distinct authors
  • Jesse: 2 distinct authors
  • OctoBot: 2 distinct authors

A 55,096-star project is being carried by about five people. That is not a criticism — it is the normal shape of open source, and Freqtrade's output is remarkable for a group that size. It is a risk disclosure. If two of those five stop, the monthly release cadence stops, and the exchange API change that breaks your bot in four months gets fixed when somebody volunteers.

You are not buying a vendor relationship. There is no SLA, no support ticket, and no one obliged to answer. The disclaimers say so plainly: the authors "assume no responsibility for your trading results."

The repo health check: five API calls

Everything above is reproducible in under ten minutes against any repository, and you should re-run it before trusting any listicle. Replace <owner>/<repo> and work down the list.

# 1. Is it alive, and under what licence?
curl -s https://api.github.com/repos/<owner>/<repo> \
  | jq '{archived, license: .license.spdx_id, stars: .stargazers_count}'

# 2. Last commit on the DEFAULT branch (not pushed_at)
curl -s 'https://api.github.com/repos/<owner>/<repo>/commits?per_page=1' \
  | jq -r '.[0].commit.author.date'

# 3. Is there a recent, tagged release?
curl -s https://api.github.com/repos/<owner>/<repo>/releases/latest \
  | jq '{tag: .tag_name, published: .published_at}'

# 4. How many people are actually committing?
curl -s 'https://api.github.com/repos/<owner>/<repo>/commits?per_page=100' \
  | jq '[.[].author.login] | unique | length'

# 5. Any published security advisories?
curl -s 'https://api.github.com/advisories?ecosystem=pip&affects=<package>' \
  | jq -r '.[] | "\(.severity) \(.cve_id) \(.summary)"'

Four red flags, in order of severity: archived: true; a default-branch commit older than six months; a latest release older than a year; and fewer than three distinct authors in the last hundred commits. Any two together and you are adopting a maintenance job, not a tool.

Open source bot or copy trading: which decision are you making

These are not competing products. They are answers to different questions.

An open source bot answers "I have a strategy and I want it executed without me watching." You supply the edge; the software supplies the discipline and the uptime. That is a good trade if you can write Python, you have a hypothesis worth testing, and you accept that Freqtrade's own FAQ calls the outcome a gamble. The same reasoning applies to the strategy-template bots — grid bots, DCA bots, arbitrage bots — where the parameters are yours to get right.

Copy trading answers a different question: "I do not have an edge, and I would rather borrow someone else's." Instead of encoding a strategy, you pick a wallet whose history you can audit on-chain and mirror its trades. There is no server to run, no NTP drift, no CVE to patch, and no backtest whose no-slippage assumption you have to discount. The failure mode moves from "my code is wrong" to "I picked the wrong trader", which is at least a failure you can diagnose from a public ledger. We laid out the trade-offs in full in trading bots versus manual trading and the advantages and disadvantages of copy trading.

uwuu sits on the copy trading side, non-custodial: your funds stay in your wallet behind a copy key, execution lands in under 400ms, every trader on the leaderboard is verifiable on-chain, and the fee is performance-based — you pay when you profit, not per trade. There is nothing to deploy and nothing to patch. If what you want instead is to encode and own your own strategy, Freqtrade is the right starting point and this article's audit should tell you what you are signing up for.

One more distinction worth keeping straight: "open source" and "AI-powered" are orthogonal claims, and most products marketed as the second are neither. We tested that claim category separately in AI crypto trading bots.

Ready to copy trade on Solana?

Start copying the most profitable traders in under 2 minutes. No coding, no complex setup. Just connect and earn.

Frequently Asked Questions

What is the best open source crypto trading bot in 2026?

On maintenance evidence, Freqtrade. It is the only project in this audit shipping monthly releases on a predictable calendar schedule, it had 833 commits in the last 90 days, and it is GPL-3.0 with no paid tier. Hummingbot is the better pick if you need on-chain or DEX execution, since its Gateway component is the only one here with real Solana connectors. Both require Python ability and a server you administer.

Is an open source crypto trading bot actually free?

The licence is free; running it is not. You pay for a server that stays online, historical candle data, an RPC endpoint if you trade on-chain, and your own time learning the codebase — Freqtrade's docs state outright that basic Python knowledge is a prerequisite. Jesse goes further: its core is MIT, but live and paper trading require a closed-source plugin gated behind an account licence key.

Can an open source crypto trading bot trade Solana memecoins?

Almost none of them can. Freqtrade's entire documentation set has zero mentions of Solana, Raydium or Jupiter, and only one of its twelve supported spot venues is a DEX. The exception is Hummingbot via its separate Gateway service, which ships Solana connectors for Jupiter, Raydium, Meteora and Orca. Running it means deploying and securing a second service plus your own RPC endpoint.

Are open source trading bots safe to run?

They are as safe as your server administration. OctoBot carried CVE-2021-36711, a CVSS 9.8 remote code execution flaw in its web interface, patched in version 0.4.4 — and you are the one who has to notice advisories and apply patches. FreqAI's docs also warn that loading a model file from an untrusted source requires unsafe deserialisation and can execute arbitrary code, so never run a "profitable model" someone sent you.

Why do backtests from open source bots look so good?

Because of documented assumptions, not fraud. Freqtrade publishes fourteen of them, including that all orders fill at the requested price with no slippage, that stop-losses execute exactly at the stop price, and that the candle's low is evaluated before its high. The maintainers state that backtesting "will never replace running a strategy in dry-run mode." Discount any backtest that does not model slippage and fees explicitly.

Should I use Gekko or Zenbot?

No. Both repositories are archived and read-only. Gekko's last commit was 16 February 2020 and Zenbot's was 14 February 2022, which left 295 open issues permanently unanswered. They still appear in listicles because they hold 18,434 stars between them, but neither receives security patches or exchange API updates, and exchange APIs have changed substantially since.

open source crypto trading botfreqtradehummingbotjesse trading botoctobotcrypto trading bot githubsolana

Related Articles

AI Crypto Trading Bot: 5 Platforms Checked, 1 Real Model (2026)

We checked what five crypto bot platforms actually document about AI across 4,290 public pages. 3Commas has 69 help articles and none on AI trading. Cryptohopper has one AI page and it is a paper-trading tournament with a buy-and-hold benchmark. The only tool with a documented model is open source and peer-reviewed.

How to Build a Copy Trading Bot in Python: Solana Architecture, Code and the Parts That Break (2026)

The full architecture of a Solana copy trading bot in Python — Geyser gRPC detection, venue-agnostic decoding via balance diffs, proportional sizing, execution and exit mirroring. Plus the latency budget, the real infrastructure costs, and why none of it fixes trader selection.

Arbitrage Trading Bot: 8 Platforms Tested & Honest Verdict (2026)

Honest 2026 arbitrage trading bot guide. Cross-exchange vs triangular vs funding-rate arb, 8 platforms compared, fee math, failure modes, Solana on-chain reality, and when copy trading wins.

Gunbot Review 2026: Self-Hosted Bot Tested (Real Costs)

We tested Gunbot in 2026 — the self-hosted, one-time-license crypto trading bot. The real all-in cost (license plus VPS), whether it is worth it and profitable, and the on-chain Solana alternative to CEX bots.

Cryptohopper Review 2026: Honest Test, Real Costs & Verdict

We tested Cryptohopper in 2026 — the real all-in fee stack, marketplace pitfalls, AI Strategy Designer reality check, and how on-chain Solana copy trading stacks up.

3Commas Alternative: The Best Solana Copy Trading Bot (2026)

3Commas is a CEX-focused subscription bot. If you trade on Solana, here's the 3Commas alternative that drops the $49/mo fee and adds on-chain copy trading.

Best Solana Trading Bot in 2026: Automate & Copy Trade Like a Pro

Discover how to use a Solana trading bot to copy the most profitable traders on-chain. Fully automated, no coding required, and built for speed.

Solana Trading Bot vs Manual Trading: Which Is More Profitable?

Is a Solana trading bot actually more profitable than manual trading? We compare speed, accuracy, risk management, and real-world performance.

Stop watching. Start copy trading.

Join thousands of traders who automate their Solana trading with uwuu. Pick a top trader, connect your wallet, and let the bot do the rest.

Get Started Free