PROPELOO

PERPETUAL FUTURES / PERPS PROTOCOL

Build perpetual futures infrastructure that handles the volume.

PROPELOO engineers perpetual futures protocols — both centralised matching engine implementations and on-chain perpetuals protocols (GMX-style vaults, dYdX-style off-chain matching with on-chain settlement, Synthetix-style synthetic positions). Perpetuals are the highest-volume product in crypto. Engineering them correctly is the highest-leverage technical investment in the exchange space.

Perpetual futures generate 5-10x more trading volume than spot for the same asset pair. Every exchange needs them.

Perpetual futures (perps) are the dominant trading product in crypto — they consistently represent 60-80% of total crypto derivatives volume. They succeed because they provide leverage without expiry, continuous funding rate alignment with spot, and a simple risk model that most traders understand. The engineering challenge is the funding rate mechanism (must accurately track the spot-perp premium), the mark price (must be manipulation-resistant for accurate liquidation), and the risk engine (must be fast enough to liquidate at-risk positions before they go into deficit). Get these three right and you have a perps exchange. Get any of them wrong and you have a liability.

Perpetual futures engineering.

System Layers

  • Position Layer: Long/short position management, leverage, entry/exit price, unrealised PnL
  • Funding Layer: Premium index calculation, funding rate formula, 8-hour settlement, history
  • Mark Price Layer: Index price construction, mark price EMA, manipulation resistance
  • Liquidation Layer: Maintenance margin check, liquidation trigger, partial liquidation, insurance
  • Settlement Layer: Funding payment distribution, settlement accounting, insurance fund management

Core Technical Capabilities

  • On-chain Perps Protocol

    Smart contract perpetuals — GMX-style GLP vault (pooled liquidity, traders trade against the vault), dYdX-style hybrid (off-chain matching + on-chain settlement), or custom vAMM (Perpetual Protocol-style virtual AMM).

  • CEX Perpetuals Engine

    High-performance centralised perps matching engine in Go/Rust — order book, funding settlement, position management, P&L calculation, 50K+ orders/second, sub-millisecond latency.

  • Funding Rate Engineering

    Premium index calculation (spot-perp spread), funding rate formula (premium component + interest component), 8-hour settlement, real-time funding rate display, cumulative funding P&L tracking.

  • Liquidation Engine

    Maintenance margin monitoring per position, liquidation price calculation and display, automatic liquidation trigger, partial liquidation logic, liquidation fee distribution and insurance fund accounting.

  • Mark Price System

    Multi-exchange spot price aggregation (Binance, Coinbase, Kraken), outlier rejection, EMA smoothing for manipulation resistance, divergence detection and circuit breakers.

  • Portfolio Margin

    Netting of correlated positions for margin calculation — a long BTC perp offsets a short BTC option, reducing total margin requirement. Required for institutional and advanced retail traders.

How we think about perpetual futures.

The funding rate is the most important mechanism in a perpetuals protocol. It determines whether the product is useful to traders and fair to liquidity providers.

  • Funding rate design determines trader and LP fairness

    The funding rate formula must accurately reflect the true premium of the perpetual over the spot index. A funding rate that is too aggressive drives traders to use competing venues. A funding rate that is too gentle allows the perpetual to drift from spot, creating arbitrage that extracts value from the protocol. The standard formula: funding rate = premium index + interest rate component (typically 0.01% per 8 hours).

    Axiom:

  • GLP vault vs order book — different risk profiles

    GLP-style vault: traders trade against a pooled liquidity vault. LPs provide liquidity and earn fees but bear the other side of all trades (if traders are net profitable, LP value decreases). Order book: traders trade against each other. The exchange earns fees without taking market risk. GLP is simpler to implement but puts LP capital at directional risk. Order book requires matching engine infrastructure but has no structural LP risk.

    Axiom:

  • Liquidation speed determines bad debt accumulation

    Between the time a position's equity reaches zero and the liquidation completing, the market may have moved further. If liquidations are slow (high matching engine latency, gas cost delays for on-chain), bad debt accumulates. On-chain perps protocols with on-chain liquidation face this problem during gas price spikes. Pre-liquidating positions when they approach (not reach) the liquidation threshold reduces bad debt.

    Axiom:

  • Insurance fund adequacy must be stress tested

    The insurance fund should be able to absorb the worst realistic market scenario: a 20-30% intraday move against a maximally leveraged position in the worst liquidity conditions. Backtest the fund against historical market stress events. Size the minimum fund requirement as a percentage of open interest per market.

    Axiom:

Perps protocol decisions.

  • On-chain vs off-chain architecture?

    Impact: Off-chain matching + on-chain settlement for decentralised perps — matching engine speed with trustless custody. GLP vault model for simpler implementation without order book infrastructure.

    • Fully on-chain (costly, slow, limited) — maximum decentralisation
    • Off-chain matching + on-chain settlement (dYdX style) — practical
    • GLP vault model (GMX style) — no order book, LPs take market risk
    • Centralised (CEX perps) — fastest, counterparty risk
  • GLP vault vs vAMM vs order book?

    Impact: GLP vault for fastest implementation and proven model (GMX is the largest on-chain perps by open interest). Order book for better pricing and no LP directional risk.

    • GLP vault (GMX) — LPs provide liquidity, bears directional risk
    • Virtual AMM (Perpetual Protocol) — no LP risk, funding rate mechanism
    • Off-chain order book (dYdX) — trader vs trader, fastest
    • On-chain order book (Serum perps) — fully decentralised, slow
  • Supported leverage?

    Impact: Variable leverage by asset is the production standard — BTC/ETH can support higher leverage due to deeper spot liquidity for liquidation. Altcoins with thinner liquidity should be restricted to lower leverage.

    • Up to 10x — safer for LPs and insurance fund
    • Up to 50x — industry standard for major pairs (BTC, ETH)
    • Up to 100x — attracts high-risk traders, requires robust liquidation
    • Variable by asset (50x for BTC, 10x for altcoins) — risk-calibrated
  • Funding rate frequency?

    Impact: 8-hour funding is the industry standard and what most traders expect. It provides sufficient peg discipline while not overwhelming users with micro-payments.

    • Continuous — best peg, complex accounting
    • Hourly — good balance
    • Every 8 hours — Binance standard, most common
    • Daily — simple, poor peg during volatile periods
  • Markets at launch?

    Impact: BTC and ETH perps at launch — deepest external liquidity for index price construction, highest trader demand, lowest risk for the insurance fund. Add altcoin perps after validating risk management.

    • BTC and ETH only — deepest liquidity, safest
    • Top 10 by market cap — wide selection, varied liquidity
    • Long tail (meme coins, new tokens) — high demand, high risk
    • Index baskets (DeFi basket, L1 basket) — novel product

What PROPELOO builds.

  • CEX Perpetuals Engine

    High-performance centralised perps matching engine — funding rate, mark price oracle, liquidation engine, insurance fund and full REST/WebSocket trading API.

  • On-chain Perps Protocol

    GLP vault-style on-chain perpetuals — pooled liquidity vault, on-chain position management, Chainlink oracle integration, liquidation bots and incentive programme.

  • Hybrid Perps (Off-chain Matching + On-chain Settlement)

    dYdX v3-style architecture — centralised matching engine, StarkEx-based ZK settlement layer, on-chain custody, off-chain order book.

  • Perps Protocol Upgrade

    Upgrade existing perps exchange — improve mark price manipulation resistance, faster liquidation engine, insurance fund restructuring.

  • Mobile Perps App

    Mobile-first perpetuals trading app — simplified position management, funding rate tracker, liquidation calculator and push notifications.

  • Cross-chain Perps

    Perpetuals protocol deployed across multiple chains with unified open interest, consistent funding rates and cross-chain collateral.

The perps protocol stack.

  • Engine (CEX)

    Stack: Go / Rust (matching), Redis (positions), Kafka (events), PostgreSQL (settlement)

  • On-chain (DEX)

    Stack: Solidity (EVM), Rust/Anchor (Solana), Foundry + Echidna, GMX contracts (reference)

  • Oracle

    Stack: Pyth Network (mark price), Chainlink Data Feeds, Multi-source index (custom), TWAP calculation

  • Risk

    Stack: Custom risk engine, Liquidation bot (keeper network), Insurance fund contracts, Portfolio margin

  • Frontend

    Stack: React + TradingView, WebSocket (real-time P&L), Position management UI, Liquidation price display

  • Infrastructure

    Stack: AWS multi-AZ, Kubernetes, Datadog, PagerDuty (liquidation alerts)

Perps protocol security is risk management.

  • Mark price manipulation

    All liquidations must be based on a manipulation-resistant mark price. Multi-exchange index with EMA smoothing. Circuit breaker that pauses liquidations when mark price deviates from external reference by more than 2-3%.

  • Funding rate manipulation

    A large position can influence the funding rate calculation. Time-weighted average for premium index calculation rather than spot value. Cap on maximum funding rate per period.

  • Vault draining attacks (GLP model)

    Coordinated directional pressure combined with oracle manipulation can drain the GLP vault. Price impact fees on large trades, maximum utilisation limits, oracle circuit breakers.

  • Liquidation cascade prevention

    Many positions liquidated simultaneously causes market impact that creates additional liquidations. Partial liquidation, staggered liquidation execution, circuit breakers during cascade conditions.

  • Smart contract audit (on-chain)

    On-chain perps contracts require full third-party audit before mainnet. Specific focus: funding calculation correctness, liquidation invariants (account equity always positive after liquidation), insurance fund accounting.

  • Keeper/liquidator security

    The liquidation bot (keeper) must have minimal permissions — only the ability to trigger liquidation, not access funds. Open liquidation (anyone can liquidate eligible positions) with competition is more robust than centralised keeper.

From design to live perps protocol.

  1. 01. Protocol Design

    Architecture choice (CEX/hybrid/on-chain), funding rate design, mark price oracle, leverage tiers.

  2. 02. Core Engine

    Position management, funding calculation, liquidation logic, insurance fund.

  3. 03. Oracle System

    Index price construction, mark price calculation, manipulation protection.

  4. 04. Risk Testing

    Historical market stress simulation, insurance fund adequacy modelling, liquidation cascade testing.

  5. 05. Trading Interface

    Perps trading UI with leverage selector, position tracker, funding rate display, liquidation price.

  6. 06. Liquidation Infrastructure

    Liquidation bot / keeper network, ADL mechanism, insurance fund monitoring.

  7. 07. Launch

    Audit (on-chain), security review (CEX), staged launch with open interest caps.

Perpetual futures platforms we have shipped to production.

Three perps exchange builds handling real derivatives volume.

  • Perpetual futures exchange with cross/isolated margin and up to 100x leverage

    Challenge: Client needed a perpetual futures exchange supporting BTC, ETH, and 20 altcoin perps — cross and isolated margin modes, up to 100x leverage, mark price-based liquidation, and 8-hourly funding rate settlement.

    Architecture: Rust matching engine for sub-millisecond latency, Go risk engine for real-time margin calculation, mark price from Chainlink oracle blend, liquidation engine with insurance fund, funding rate TWAP calculation every 8 hours.

    Outcome: $580M cumulative volume in 8 months, <0.5ms median matching latency, insurance fund maintained positive, zero cases of bad debt socialisation.

  • Decentralised perpetual futures protocol with vAMM and on-chain clearing

    Challenge: DeFi team wanted a decentralised perpetuals protocol — no CEX custody risk, positions held on-chain, clearing and settlement via smart contracts, and a virtual AMM providing liquidity without an order book.

    Architecture: vAMM (virtual AMM): synthetic liquidity curves without LP capital, positions tracked as on-chain state, oracle-based mark price, funding rate settled every hour via smart contract, liquidation bots incentivised via keeper fee.

    Outcome: $18M peak open interest, 12,000 unique traders, 2 audits with no critical findings, fully non-custodial with 24/7 guaranteed settlement.

  • Standalone funding rate engine for an existing perpetual exchange

    Challenge: Exchange had a perpetual futures market but their funding rate calculation was producing drift from spot — longs and shorts were not being rebalanced correctly, causing the perp to trade at persistent premium to spot.

    Architecture: Rebuilt TWAP calculation using 8-hour rolling window of (perp mark price - spot index) spreads, configurable premium/discount caps, per-market funding rate storage, atomic settlement batching all funding payments in one DB transaction.

    Outcome: Perp-to-spot basis reduced from avg 0.18% to 0.03%, funding arbitrage traders entered providing price-correcting pressure, zero missed settlements in 6 months.

Frequently Asked Questions

How is a perpetual futures different from a traditional futures contract?

A traditional futures contract has a fixed expiry date — it settles at expiry at the spot price. A perpetual futures contract never expires. To keep the perp price anchored to spot, the funding rate mechanism charges longs when perps trade above spot (discouraging longs) and credits longs when perps trade below spot (encouraging longs). Traders can hold perpetual positions indefinitely as long as they have sufficient margin and the accumulated funding payments do not deplete their balance.

What makes GMX different from other perps protocols?

GMX uses a pooled liquidity (GLP) model — traders trade against the GLP vault, which is funded by liquidity providers who receive fees in exchange for bearing the counterparty risk to traders. Most trades are against the vault at oracle price with zero price impact (for smaller trades). Advantages: no order book, better prices for small trades, simple LP model. Disadvantages: LPs bear directional risk (profitable traders reduce LP value), limited liquidity for very large trades.

What is the insurance fund in perpetuals trading?

When a liquidation results in a deficit (the liquidated position's remaining collateral is less than the debt), the insurance fund covers the deficit. The fund is built from: a portion of trading fees, a portion of profitable liquidations (when the position is liquidated and collateral exceeds the debt). If the insurance fund is depleted, auto-deleveraging (ADL) kicks in — the positions of the most profitable traders on the opposite side are automatically reduced to cover the deficit.

How is the perpetual futures funding rate calculated and settled?

The funding rate consists of two components: the premium index (measuring the spread between the perp mark price and the underlying spot index) and an interest rate component. It is sampled continuously using a time-weighted average price (TWAP) over an 8-hour or 1-hour interval. Settlement occurs automatically by debiting or crediting the position's unrealized margin balance directly in memory.

How does cross-margin vs isolated margin function across perpetual positions?

In isolated margin, risk is strictly ring-fenced to individual positions with dedicated collateral. In cross-margin, all available account equity is pooled to satisfy maintenance margin requirements across multiple positions. Our risk engine continuously computes portfolio-wide net margin, allowing unrealized gains in one contract (e.g., long ETH) to offset drawdowns in another (e.g., long BTC).

What matching engine throughput and latency are delivered for perpetual contracts?

Our high-performance Go/Rust perpetuals matching engine processes over 150,000 orders per second with sub-millisecond execution times. The order book maintains lock-free ring buffers for order placement, cancel, and amendment, ensuring deterministic execution during extreme volatility events.

How do decentralized perpetual protocols (vAMM vs order book vs GLP vault) compare?

Virtual AMMs (vAMMs) enable synthetic leverage without liquidity pools but rely heavily on funding rates for arbitrage alignment. GLP-style vaults offer zero-slippage oracle trading for retail sizes but expose liquidity providers to directional skew. High-performance off-chain CLOBs with on-chain settlement (e.g., dYdX/Aevo model) offer institutional order book depth and low latency while maintaining non-custodial asset settlement.

How does the liquidation engine prevent cascading bankruptcies and socialized loss?

The system triggers partial liquidation at predefined maintenance margin tiers before an account reaches negative equity. If an account drops below bankruptcy price, the exchange insurance fund absorbs the residual deficit. Auto-Deleveraging (ADL) is reserved strictly as a fail-safe mechanism, ranking profitable counterparty positions by leverage and profit ratio.

Can institutional traders execute algorithmic strategies via WebSocket and FIX protocol?

Yes. The perpetuals platform exposes low-latency WebSocket streams for real-time L2/L3 order book depth, trades, and position updates, alongside dedicated REST and FIX 4.4/5.0 gateways. Institutional market makers benefit from mass-quote management, cancel-on-disconnect protection, and co-location options.

How do you handle multi-collateral and portfolio margining for perpetual futures?

The risk engine supports multi-currency collateral (e.g., USDT, USDC, BTC, ETH) with dynamic haircut discounts applied based on asset volatility. Portfolio margining nets risk across correlated contracts, calculating maximum potential loss across stress-test price scenarios to grant capital-efficient margin discounts to hedged traders.