"Open source" in this corner of the market means something specific: you run the software yourself, on your own machine, with your own exchange API keys. Nobody holds your funds, nobody executes on your behalf, and nobody can quietly change the strategy under you. The flip side is that uptime, key hygiene, upgrades and every configuration mistake are yours. That trade is the actual decision — the choice of project comes second.

The projects worth knowing

Five self-hosted frameworks carry effectively all of the community. Numbers below are from the GitHub API on 12 September 2026 — check them again before you decide, because activity is the thing that changes.

ProjectStarsLicenseBuilt for
Freqtrade54 284GPL-3.0General-purpose spot and futures, backtesting, parameter search, ML module
Hummingbot19 974Apache-2.0Market making and arbitrage across CEX and DEX
Jesse8 456MITResearch: backtest accuracy first, live trading second
OctoBot6 561GPL-3.0Web UI and configuration without writing Python
Passivbot2 097UnlicenseGrid and DCA only — deliberately makes no forecast

Star counts measure attention, not correctness or profitability. They are worth reading as one thing only: how many people will have hit the bug you are about to hit, and whether an answer already exists.

The license is not boilerplate

It decides what you may do with your own modifications. GPL-3.0 (Freqtrade, OctoBot) lets you change anything and run it privately forever, but if you distribute a modified version you must release that version under GPL-3.0 too. MIT (Jesse) and Apache-2.0 (Hummingbot) let you build something closed on top; Apache additionally grants patent rights. Unlicense (Passivbot) is a public-domain dedication with no conditions at all.

If you are only trading your own account, every one of these is equally free. The difference appears the moment you want to sell, resell or bundle what you built.

What to compare instead of stars

QuestionWhy it decides the outcome
Spot or futures?Futures needs margin, funding and liquidation logic. A spot-first bot bolted onto futures is where the sharp edges live
Which exchange, natively?CCXT covers public data well; private order and account endpoints are where venues differ and where breakage happens
Does the backtester model costs?Fees, funding, spread and slippage decide whether an edge survives. A backtester without them prints fiction
Where does risk live?If the stop-loss lives in your Python process, a crashed process is an unprotected position. Exchange-side protection survives your server
What happens on restart?The bot must reconcile real exchange state, not assume its own memory was right
Can you read the strategy?An unreadable strategy is a black box you happen to own the source of

The last three matter more than they look. Most published post-mortems of retail bot losses are not bad signals — they are a process that died holding a position, a restart that double-opened, or a stop that existed only in local memory. The system-design guide works through that layer, and the backtesting guide covers the cost modelling.

What none of them give you

No open-source bot supplies an edge. Every one of them is an execution framework: it turns rules you chose into orders, reliably or unreliably. Profitability comes from the rules and from the market, and the framework can only avoid destroying it through fees, slippage and operational failure.

None of them protects you from your own risk settings either. Leverage, position size and stop distance are yours to set, and a well-engineered bot will execute a reckless configuration flawlessly. That arithmetic is in the risk management guide.

Where CROT fits

Full disclosure: this site publishes CROT, so read this section as a self-assessment rather than a review. CROT is a young, single-exchange project — HTX USDT-M perpetuals — with a small codebase and no community to speak of. Against Freqtrade it loses on every measure that scales with adoption: exchanges supported, strategies available, bugs already found by someone else, questions already answered.

What it does differently is narrow and deliberate: a strategy-neutral engine that owns execution safety, state and reconciliation, with strategies as versioned plugins that cannot bypass it; hard stop-losses placed on the exchange rather than held in the process; and a codebase small enough to read end to end in an afternoon. If that last point is not worth anything to you, Freqtrade is the better default and it is not close.

Separately, the project runs a CrotPro copy-trading profile on HTX with a 25% profit share and publishes the RS Rotation strategy specification, whose source is not published yet. That is a different product from the self-hosted MIT bot, and copy trading has its own trade-offs.

The honest part

Pick the project with the most users unless you have a specific reason not to. Volume of users is the closest thing to free QA that exists in this category, and "I want to read every line" or "I only trade one venue" are the reasons that justify going smaller. Whatever you pick, run the test suite, trade the smallest size the exchange allows for a few weeks, and verify that a stop actually exists on the exchange — not just in a log line claiming one was sent.