Frequently Asked Questions
What is the difference between a CEX, DEX and hybrid exchange?
A CEX (centralised exchange) holds user funds in custody and runs matching entirely off-chain — highest performance, full custody liability. A DEX runs matching and settlement on-chain, users retain custody — no custody liability, performance limited by blockchain throughput. A hybrid runs matching off-chain for performance but settles trades on-chain, giving users self-custody without sacrificing execution speed. Each model creates a different regulatory surface, custody liability and engineering architecture. The choice is not a configuration — it is a fundamental product decision.
How does a matching engine work?
A matching engine maintains an order book — a sorted list of buy and sell orders at each price level. When a new order arrives, the engine checks whether it can be matched against existing orders at the price (for limit orders) or immediately (for market orders). If a match is found, a trade is executed and both orders are updated. Price-time priority means orders at the same price are matched in the order they were received. The matching engine must process these operations atomically and deterministically — no two orders should produce a different outcome depending on processing order.
What custody model should we use?
For a new exchange: MPC-based custody (Fireblocks or in-house) combined with cold storage tiering. MPC distributes signing authority across multiple parties with no single private key ever fully assembled — compromise of one party does not compromise funds. Cold storage holds the majority of user assets with withdrawal requiring multi-party approval and a time delay. Hot wallet holds only the minimum needed for real-time withdrawals with strict velocity limits. Exchange-managed single-key hot wallets are not an acceptable custody model for any platform holding significant user funds.
How do we handle liquidity before we have users?
A CLOB exchange with no liquidity has wide spreads and no trading activity — a self-reinforcing problem. Solutions: negotiate with market makers before launch (they provide liquidity in exchange for fee rebates or token allocations), use AMM backstop liquidity for guaranteed depth, launch with a curated set of trading pairs rather than many thin markets, and consider a soft launch with beta users before public marketing. The liquidity strategy must be part of the architecture conversation — market maker API capabilities, fee tier design and spread parameters all affect market maker economics.
What compliance infrastructure does an exchange need?
At minimum: KYC (identity verification with document checking), AML (ongoing transaction monitoring against known patterns), sanctions screening (OFAC, UN, EU lists at onboarding and continuously), and transaction reporting for suspicious activity. In most jurisdictions this also requires a licensed compliance officer, a compliance policy document and record retention. The specific requirements depend on the jurisdictions you operate in and the assets you support. We build the technical infrastructure; you will need qualified legal counsel for the regulatory structure.
How do we prevent front-running?
Front-running on a CEX is primarily an information asymmetry problem — can privileged parties see order flow before execution? Controls: strict access separation between matching engine operators and trading accounts, audit logging of all order flow access, randomised execution ordering within price-time priority windows and regular independent audit of order flow handling. On hybrid or DEX models with on-chain components, commit-reveal schemes, private mempools (Flashbots Protect) or intent-based routing (CoW Protocol, 1inch Fusion) prevent mempool front-running architecturally.
What does exchange infrastructure cost to operate?
A production exchange with multi-region deployment, high-availability matching engine, custody infrastructure and compliance tooling typically costs $15,000–50,000/month in cloud infrastructure at early stage. Compliance tooling (KYC provider, AML monitoring) adds $2,000–10,000/month depending on volume. MPC custody providers like Fireblocks charge per vault and per transaction. The operational cost model should inform the fee structure design — most exchanges need $500K–2M in annualised trading volume to cover operational costs at typical fee rates.
Can we launch in multiple jurisdictions?
Yes, but each jurisdiction adds compliance requirements, KYC/AML obligations and potentially product restrictions (e.g., US users cannot access certain derivatives products). Multi-jurisdiction compliance requires geo-based access control, jurisdiction-specific KYC workflows and transaction reporting to each applicable regulator. We build the technical infrastructure to support multi-jurisdiction compliance — but each jurisdiction requires qualified legal counsel to confirm the applicable regulatory requirements. Launch in one jurisdiction with a clean compliance model before expanding.
How do we handle market manipulation?
Wash trading, spoofing and layering are active threats against exchange market integrity. Technical controls: order-to-trade ratio limits (accounts placing many orders without executing are likely spoofing), cancel rate monitoring, anomaly detection on account-level order patterns, and account relationship detection to identify entities running wash trade rings. These controls require ongoing tuning as manipulation patterns evolve. Institutional credibility requires demonstrable market surveillance — it is not optional for any exchange seeking regulatory licensing or institutional liquidity provider relationships.
What is the realistic build timeline for an exchange?
A production spot exchange with matching engine, custody, KYC/AML, market data, trading frontend and admin infrastructure: 20–32 weeks from architecture sign-off to soft launch. Adding derivatives, margin trading or complex order types extends this by 8–16 weeks. DEX or hybrid architecture adds 4–8 weeks for smart contract development and audit. Compliance infrastructure and regulatory approval processes run on a separate timeline that depends entirely on jurisdiction and licensing requirements. We deliver in milestone-based sprints with a soft launch to invited users before public release.