PROPELOO

MARGIN TRADING PLATFORM DEVELOPMENT

Build a margin trading platform where the liquidation engine protects the exchange, not just the trader.

PROPELOO engineers margin trading platforms — cross-margin and isolated margin accounting, real-time maintenance margin calculation, tiered liquidation engine, insurance fund mechanics, funding rate engine for perpetuals, and the socialized loss system that prevents the exchange from going bankrupt when large positions blow through the insurance fund.

A margin platform without a robust liquidation engine does not protect the exchange — it transfers losses from under-margined traders to the exchange and ultimately to other traders.

Margin trading introduces credit risk that spot trading does not have. When a leveraged position moves against a trader and their margin falls below maintenance level, the exchange must liquidate the position before it goes negative. If the liquidation engine is slow, or if the market moves faster than the engine can execute, the position goes into liquidation deficit — a loss that the trader cannot cover. The insurance fund absorbs this deficit. When the insurance fund is depleted, auto-deleveraging (ADL) forces profitable traders to absorb the remaining losses. A margin platform where this chain fails at any link exposes the exchange to socialised losses that damage trader confidence and regulatory standing. PROPELOO designs the full risk stack: real-time margin monitoring, tiered liquidation execution, insurance fund accounting, funding rate engine for perpetuals, and ADL mechanics — engineered as a coherent system, not assembled from independent components.

What a production margin trading platform contains.

Margin trading is spot trading plus a risk engine that never sleeps.

System Layers

  • Margin Accounting Layer: Cross-margin and isolated margin modes, initial and maintenance margin calculation, available margin tracking, real-time unrealised P&L
  • Risk Monitoring Layer: Tick-level margin ratio calculation, warning alerts, liquidation trigger detection, ADL queue management
  • Liquidation Engine: Partial liquidation, order book liquidation submission, liquidation price calculation, insurance fund credit/debit
  • Funding & Settlement Layer: Perpetual funding rate calculation (mark price vs index price), 8-hour funding payments, daily settlement for futures, mark price oracle
  • Insurance Fund: Insurance fund balance tracking, deficit absorption, fund replenishment from liquidation surplus, fund depletion reporting

Core Technical Capabilities

  • Margin Engine

    Real-time per-account and per-position margin calculation on every price tick. Cross-margin mode pools collateral across positions. Isolated margin caps loss per position. Available margin, initial margin, maintenance margin and liquidation price calculated continuously.

  • Liquidation Engine

    Tiered liquidation: partial position reduction before full liquidation, liquidation orders submitted to order book at best price (not market), insurance fund absorbs deficit when liquidation price cannot cover the position. Liquidation queue prioritisation by margin ratio.

  • Perpetual Funding Rate

    Funding rate calculated from premium index (mark price vs index price). 8-hour funding settlements between long and short holders. Funding rate capped at ±0.75% per period. Mark price calculation using median of multiple exchange index prices.

  • Auto-Deleveraging

    ADL queue ranks traders by profit and leverage. When insurance fund is depleted, the most profitable leveraged positions are partially or fully closed at mark price to cover deficit. Transparent ADL notification to affected traders.

  • Mark Price Oracle

    Mark price aggregated from multiple reference exchanges via median calculation. Outlier detection rejects anomalous prices. Mark price used for unrealised P&L, liquidation triggers, and funding rate — not last traded price, which is manipulable.

  • Risk Desk Tools

    Real-time open interest by symbol, net exchange exposure, insurance fund balance, liquidation volume, ADL queue depth. Circuit breakers for maximum price movement per period.

How we approach margin platform architecture.

Margin trading is a system where correctness under stress matters more than performance under normal conditions.

  • The liquidation engine must be faster than the market

    A liquidation engine that takes 500ms to process a margin breach during a market crash — when hundreds of accounts breach simultaneously — will produce cascading deficits. The liquidation engine must be designed for worst-case load, not average load. Priority queuing by margin ratio ensures the most at-risk positions are liquidated first.

    Axiom: WORST-CASE PERFORMANCE IS THE REQUIREMENT

  • Mark price, not last price, for all risk calculations

    Using last traded price for margin calculations creates a manipulation attack: a large trader can move the market price to trigger competitor liquidations. Mark price — calculated from multiple exchange indices with outlier detection — is the manipulation-resistant price that all risk calculations must use.

    Axiom: MARK PRICE EVERYWHERE

  • Insurance fund design determines platform solvency

    The insurance fund is the exchange taking first-loss on liquidation deficits. Its size, replenishment mechanism, and ADL trigger threshold determine whether the exchange is solvent under extreme market conditions. These parameters must be stress-tested against historical volatility data before going live.

    Axiom: STRESS TEST THE INSURANCE FUND

Key decisions in margin platform architecture.

These choices define risk management quality and exchange solvency under stress.

  • Cross-margin vs isolated margin: which to build first?

    Impact: Build isolated margin first. It is simpler to implement correctly, easier to test, and most traders understand it. Add cross-margin once isolated margin is proven correct in production.

    • Isolated margin only — simpler accounting, each position has independent collateral, easier to reason about liquidation
    • Cross-margin only — higher capital efficiency for traders, complex cross-position margin calculation
    • Both — maximum flexibility, significantly higher accounting complexity
  • Liquidation: aggressive (market order) vs passive (limit order)?

    Impact: Limit order with market fallback is the standard on professional exchanges. Aggressive market liquidation during a cascade creates more deficits than it prevents.

    • Market order liquidation — fastest execution, highest slippage, worst fill for the liquidated trader
    • Limit order at liquidation price — better fill if it executes, risk of not filling during fast markets
    • Limit order with fallback to market — best of both, requires careful timeout logic
  • Funding rate: 8-hour vs continuous?

    Impact: 8-hour funding is the industry standard. Traders understand it, and the 3 daily settlement periods are manageable operationally.

    • 8-hour funding periods — standard industry practice (Binance, Bybit, OKX), predictable funding costs for traders
    • Continuous funding — smoother convergence, less predictable for traders, more complex accounting
    • Hourly funding — compromise, still discrete but more frequent
  • Mark price oracle: self-operated vs third-party?

    Impact: Self-operated oracle aggregating from 3+ reference exchanges with median calculation and outlier rejection. Never rely on a single price source for mark price.

    • Self-operated oracle — index from selected reference exchanges, full control, requires maintenance
    • Chainlink price feeds (for on-chain platforms) — decentralised, auditable, latency depends on network
    • Third-party price API — simpler integration, single point of failure, manipulation risk if only one source

What PROPELOO builds.

  • Crypto Perpetuals Platform

    Full perpetuals trading platform — funding rate engine, mark price oracle, cross/isolated margin, liquidation engine, insurance fund.

  • Crypto Futures Exchange

    Dated futures contracts with daily settlement, mark price valuation, delivery mechanics and position limit management.

  • Leveraged Token Platform

    Leveraged tokens (3x, 5x) with automatic rebalancing, rebalancing event notification, NAV calculation and redemption mechanics.

  • Margin Module for Existing Exchange

    Adding margin trading capability to an existing spot exchange — margin engine, liquidation, insurance fund, without rebuilding the matching engine.

  • Options Platform

    Options trading with Black-Scholes margin requirements, delta hedging tools, expiry settlement, implied volatility surface display.

The margin trading stack.

Real-time risk calculation requires in-memory state and event-driven architecture.

  • Risk Engine

    Stack: Go / Rust (performance critical), In-memory margin state, Tick-driven calculation, Event-driven liquidation trigger, Lock-free priority queue

  • Market Data

    Stack: Multi-exchange price feeds, Mark price aggregator, Median price calculation, Outlier detection, TimescaleDB (price history)

  • Settlement

    Stack: Funding rate calculator, 8-hour settlement engine, Insurance fund ledger, ADL queue, Daily PnL settlement

  • Observability

    Stack: Liquidation volume alerts, Insurance fund monitoring, Open interest dashboards, ADL queue depth, Margin ratio distribution

Margin platform security: the risk is exchange insolvency, not just data loss.

A misconfigured mark price oracle or a slow liquidation engine can bankrupt the exchange in one market event.

  • Oracle manipulation

    Mark price from a single source can be manipulated. Use median from 3+ exchanges with outlier rejection and circuit breakers that halt liquidations if mark price moves more than X% in Y seconds — a manipulation signal.

  • Liquidation cascade prevention

    When many positions liquidate simultaneously, the resulting market orders push price further down, triggering more liquidations. Partial liquidations and limit-order liquidation reduce cascade risk. Insurance fund must be sized for historical worst-case scenarios.

  • Insurance fund governance

    The insurance fund is exchange capital. Admin access to withdraw or modify it must require multi-sig approval and produce an on-chain or auditable event. Regular public reporting of insurance fund balance builds trader trust.

  • Funding rate manipulation

    Large traders can move the perpetual price away from the index to collect funding from the other side. Funding rate caps (±0.75% per period) and open interest limits per account prevent concentrated manipulation.

From architecture to live leveraged trading.

  1. 01. Risk Architecture

    Margin model, liquidation engine design, insurance fund sizing, funding rate mechanism, oracle architecture.

  2. 02. Margin Engine

    Cross/isolated margin accounting, real-time calculation, maintenance margin monitoring.

  3. 03. Mark Price Oracle

    Multi-exchange price aggregation, median calculation, outlier detection, circuit breakers.

  4. 04. Liquidation Engine

    Tiered liquidation, insurance fund integration, ADL queue, partial liquidation logic.

  5. 05. Funding Rate Engine

    Premium index calculation, funding rate capping, 8-hour settlement mechanics.

  6. 06. Stress Testing

    Historical volatility simulation, insurance fund depletion scenarios, cascade liquidation testing.

  7. 07. Production Launch

    Monitoring dashboards, risk desk tooling, incident response runbooks.

Frequently Asked Questions

What is the difference between cross-margin and isolated margin?

Isolated margin allocates a fixed collateral amount to each position — losses cannot exceed that allocation. Cross-margin pools all account collateral across all positions, giving higher capital efficiency but allowing one position to drain collateral from others. Both have valid use cases; most platforms offer both.

How do you prevent the insurance fund from being depleted?

Through conservative margin requirements, tiered liquidation that reduces positions before they go severely negative, mark price calculation resistant to manipulation, and funding rate mechanics that encourage perpetual price convergence with index price. The insurance fund size should be calibrated against historical volatility data — we model worst-case scenarios before launch.

How does the funding rate work?

The funding rate is calculated from the premium index: the difference between the perpetual mark price and the spot index price. When mark > index, longs pay shorts (encouraging longs to sell, reducing premium). When mark < index, shorts pay longs. Payments settle every 8 hours. This mechanism keeps the perpetual price anchored to the underlying spot price.

Can you add margin trading to our existing spot exchange?

Yes. We design the margin module as a separate service that integrates with the existing matching engine and position ledger. The margin engine monitors positions independently of the spot matching logic. This avoids a full rebuild while adding leveraged trading capability.

What leverage ratios can you support?

Any leverage ratio is technically possible to implement. The appropriate leverage ceiling depends on the asset volatility and your insurance fund size. We can implement tiered leverage (higher leverage for smaller positions, lower for large) which is standard on major exchanges.

How is Mark Price calculated to prevent price wick manipulation?

The mark price combines the spot index price (aggregated from multiple independent external exchanges) and a decaying moving average of the order book basis. Margin and liquidation checks evaluate strictly against this smoothed mark price, shielding traders from predatory flash crashes.

What is the difference between partial and full liquidation engines?

Instead of abruptly liquidating an entire position at market price, our liquidation engine executes smart tiered reduction: canceling open orders first, then stepping down leverage tiers by partially liquidating only enough volume to restore maintenance margin requirements, minimizing trader loss and market slippage.

Can users borrow multi-asset collateral with unified portfolio margin?

Yes. We build portfolio margin engines that evaluate global portfolio net risk across spot, margin, futures, and options. Haircut-weighted multi-asset collateral (e.g., BTC, ETH, USDC) can be pledged to collateralize active positions with dynamic borrowing interest accrual.