A developer wrote a strategy in Python and wants to sell it to other traders. But how to protect the code from theft? How to show a real trade history? And how to set up subscriptions without getting bogged down in manual commission calculations? We've built 12 such platforms — each averages over 50,000 traders. Here's how we solve these problems.
Why Code Isolation Is the Key Factor in Marketplace Success?
Without isolation, any developer can steal another's strategy by running it locally. We don't rely on good faith — we build protection in several layers. Docker is the foundation: containers with 256 MB memory limit and 0.5 CPU, network only through the platform API, read-only filesystem, and manual code review for new developers. This approach is 10 times more reliable than running in a shared process. Average backtest execution time over the year — 5 minutes.
How Does the Strategy SDK Work?
The developer writes a strategy in Python using our SDK. The base class StrategyBase provides access to candle data, positions, and balance through context. All strategies work asynchronously — the on_candle method is called on each candle close.
# Interface for strategy developers
from abc import ABC, abstractmethod
class StrategyBase(ABC):
"""Base class for all strategies on the platform"""
def __init__(self, context: StrategyContext):
self.ctx = context
@abstractmethod
async def on_candle(self, candle: Candle) -> None:
"""Called on each candle close"""
async def on_trade(self, trade: Trade) -> None:
"""Optional: called on each trade"""
async def on_order_update(self, order: Order) -> None:
"""Optional: called when order status changes"""
# Available methods via context
async def buy_market(self, quantity: float) -> Order:
return await self.ctx.place_order('BUY', 'MARKET', quantity=quantity)
async def sell_market(self, quantity: float) -> Order:
return await self.ctx.place_order('SELL', 'MARKET', quantity=quantity)
def get_position(self) -> float:
return self.ctx.position.quantity
def get_balance(self) -> float:
return self.ctx.balance.usdt
# Example simple strategy from developer
class RSICrossStrategy(StrategyBase):
"""EMA crossover + RSI filter"""
def __init__(self, context, fast_period=9, slow_period=21, rsi_period=14):
super().__init__(context)
self.fast_ema = EMA(fast_period)
self.slow_ema = EMA(slow_period)
self.rsi = RSI(rsi_period)
async def on_candle(self, candle: Candle):
fast = self.fast_ema.update(candle.close)
slow = self.slow_ema.update(candle.close)
rsi = self.rsi.update(candle.close)
position = self.get_position()
if fast > slow and rsi < 70 and position == 0:
await self.buy_market(quantity=self.get_balance() * 0.95 / candle.close)
elif fast < slow and position > 0:
await self.sell_market(quantity=position)
What Is Isolation and Why Is It Critical?
Isolating third-party code is the primary task of a marketplace. We don't rely on developer honesty but build protection in several layers. Docker is the foundation: containers with 256 MB memory limit and 0.5 CPU, network only through the platform API, read-only filesystem, and manual code review for new developers. This approach ensures security at the level of a banking application and is 10 times more reliable than running in a shared process without isolation.
| Isolation Method |
Reliability |
Performance |
Setup Complexity |
| Shared process |
Low |
High |
Low |
| Docker container |
High |
Medium |
Medium |
| VM |
Very high |
Low |
High |
Example Docker configuration:
# docker-compose.strategy.yml
services:
strategy-runner:
image: strategy-runtime:latest
mem_limit: 256m
cpus: 0.5
network_mode: none # no direct network access
read_only: true # read-only filesystem
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
How Does Strategy Publication Work?
Each strategy goes through a mandatory four-stage pipeline before publication. Over the year, more than 500 strategies passed through it, with 30% rejected at static checks. The average Sharpe ratio of successful strategies is above 1.0.
- Static code analysis (linting) — filters syntax errors and dangerous patterns, including forbidden imports.
- Automated backtest for the last 365 days — checks real profitability and drawdown on minute candles.
- Minimum metrics check: Sharpe > 0.5, drawdown < 50% — guarantees basic quality.
- Publication in the catalog with a strategy card displaying key metrics.
class PublicationPipeline:
REQUIRED_BACKTEST_PERIOD = 365 # days
async def process_submission(self, strategy: StrategySubmission) -> PublicationResult:
# 1. Static code analysis
lint_result = await self.code_linter.check(strategy.code)
if lint_result.has_errors:
return PublicationResult.rejected(lint_result.errors)
# 2. Automated backtest
backtest = await self.backtester.run(
strategy=strategy,
symbol=strategy.config.symbol,
period_days=self.REQUIRED_BACKTEST_PERIOD,
)
# 3. Minimum metrics check
if backtest.sharpe_ratio < 0.5:
return PublicationResult.rejected("Sharpe ratio below minimum threshold")
if backtest.max_drawdown > 0.5:
return PublicationResult.rejected("Max drawdown exceeds 50%")
# 4. Publication
published = await self.publish(strategy, backtest)
return PublicationResult.approved(published.id)
Which Monetization Model Is More Profitable?
We've implemented three main models. The optimal strategy is to combine subscription and performance fee. For example, subscription provides stable platform revenue, while performance fee motivates developers to improve strategies. Average developer profit under the performance model is up to $10,000 per month.
| Model |
Description |
Platform Commission |
| Monthly subscription |
Fixed fee from user |
30% |
| Performance fee |
Percentage of subscriber's profit |
30% of developer's share |
| One-time purchase |
Perpetual access |
30% |
Developer payout calculation:
def calculate_developer_payout(subscription: Subscription, performance: PerformanceData) -> Decimal:
if subscription.model == 'MONTHLY':
platform_fee = subscription.price * Decimal('0.30')
return subscription.price - platform_fee
elif subscription.model == 'PERFORMANCE':
profit = performance.follower_profit
if profit <= 0:
return Decimal(0)
developer_share = profit * subscription.performance_fee_pct
platform_fee = developer_share * Decimal('0.30')
return developer_share - platform_fee
Typical Mistakes When Launching a Marketplace
-
Weak isolation: running strategies in a shared process leads to data leaks. Solution — only containerization with zero network access.
-
Closed statistics: strategies without transparent metrics erode trust. Always show P&L and drawdown in the card.
-
Complex monetization: only one monetization model limits the audience. Combine subscription and performance fee.
Want to avoid these mistakes? Request a consultation on your marketplace architecture — we'll analyze your case in 2 hours and offer the optimal solution.
UI: Strategy Card
Key elements: P&L chart, maximum drawdown, Sharpe ratio, win rate, number of subscribers, supported exchanges, logic description. Transparency is the foundation of trust. We also add a "verified" badge for strategies that have passed manual audit. The platform can integrate with Web3 wallets for automatic payouts.
What's Included in the Work?
We deliver:
- API documentation for strategy developers (Strategy SDK) with examples in Python and JavaScript
- Platform source code with deployment instructions for your Kubernetes
- Test environment for debugging strategies on simulated data
- Team training (2 days) and code review templates
- 3 months of support after launch
We'll evaluate your project within 2 business days. Contact us to get a consultation and commercial proposal. Order marketplace development — we'll implement the project in 3-6 months.
Why exchange development requires deep domain expertise
We develop exchanges — not 'chart sites,' but matching engines that process thousands of orders per second without delay, route liquidity between pools, and guarantee that no user gains access to others' funds. Teams that start with the UI and postpone the engine 'for later' end up rewriting everything in six months in 90% of cases.
Order Book vs AMM: where most projects break
Centralized exchanges (CEX) are built around an order book + matching engine. Decentralized exchanges (DEX) either also use an order book (dYdX on StarkEx, Serum/OpenBook on Solana) or an AMM with concentrated liquidity (Uniswap v3/v4, Curve, Balancer). A classic mistake when developing a CEX is implementing the matching engine on top of a relational database with transactions for each match. PostgreSQL handles ~500 RPS without special effort, but at peak loads of 5,000–10,000 orders per second, it turns into a deadlock nightmare. The correct architecture: in-memory order book (Redis Sorted Sets or custom C++/Rust structure), asynchronous writing of matches to PostgreSQL via a queue (Kafka/RabbitMQ), and a separate settlement service that finally updates balances.
For DEX, the most painful problem is sandwich attacks and MEV. A pool with a plain xy=k AMM without slippage protection becomes a target for MEV bots within hours of launch. Uniswap v2 lost hundreds of millions of dollars in user liquidity. Solutions: integration with Flashbots Protect, a commit-reveal scheme for orders, or switching to TWAMM (Time-Weighted AMM) for large trades.
Concentrated liquidity and impermanent loss
Uniswap v3 introduced concentrated liquidity – LPs choose a price range in which to provide liquidity. Capital efficiency increased 4,000x compared to v2 for stable pairs. But implementing this mechanism correctly is non-trivial. The Uniswap v3 liquidity contract uses tick-based accounting: the price space is divided into discrete ticks (tick = log₁.0001(price)), each tick stores accumulated fee growth and liquidity delta. When creating a position, the lower and upper ticks are computed, and the contract recalculates all active positions at each swap. Storage layout is critical here – incorrect variable packing in slots easily adds 40–60% to swap gas cost.
We implemented a Uniswap v3 fork for a client on Polygon with a custom fee tier system. The initial version consumed 180k gas for a swap across 2 ticks. After slot packing of variables in Tick.Info and inlining several internal calls, it dropped to 112k gas. This reduced gas costs by 38% and saved the client substantial costs on fees monthly. The techniques applied are described in the Uniswap v3 Whitepaper and confirmed by our audit experience.
How a matching engine delivers performance
A production-ready matching engine is built according to the following scheme:
-
Order ingestion layer – WebSocket gateway (Go or Rust), accepts orders, validates signature, checks balance via Redis, queues them. Latency at this level must be <1ms.
-
Matching core – single-threaded event loop (eliminates race conditions without mutexes). In memory, we hold two Sorted Sets for each trading instrument: bids and asks. FIFO matching for limit orders, immediate-or-cancel for market orders. Throughput with a proper Rust implementation – 500k–1M matches per second on a single core.
-
Settlement service – reads matches from Kafka, atomically updates balances in PostgreSQL (
UPDATE accounts SET balance = balance - $1 WHERE id = $2 AND balance >= $1). Optimistic locking via row versioning.
-
Withdrawal pipeline – separate service with cold/hot wallet architecture. The hot wallet holds 5–10% of total deposits, the rest is cold storage with multi-sig (Gnosis Safe or custom HSM). Automatic withdrawals only from hot wallet, large amounts require manual authorization.
| Component |
Technology |
Latency / Throughput |
| Order gateway |
Go + WebSocket |
<1ms p99 |
| Matching engine |
Rust (in-memory) |
500k+ orders/sec |
| Balance store |
Redis (write-through) |
<0.5ms |
| Settlement DB |
PostgreSQL 14+ |
~50k TPS with partitioning |
| Event streaming |
Apache Kafka |
1M+ events/sec |
| Blockchain node |
Geth / Solana validator |
depends on chain |
How our exchange development process ensures reliability
Smart contracts and gas optimization
For EVM-based DEX (Ethereum, Arbitrum, Optimism, Polygon), the entire critical path lives in Solidity. Main contracts: Pool, Factory, Router, PositionManager (for v3-like), and Quoter for off-chain calculations. Typical mistakes we see in audits:
Reentrancy via callback. Uniswap v3 uses flash swap with a callback (uniswapV3SwapCallback). If your router lacks a nonReentrant guard and you don't check msg.sender == pool, the contract gets drained via a nested call. This is not hypothetical – several v3 forks lost funds this way.
Oracle manipulation in AMM. If your contract uses the spot price from the pool for collateral calculation, it is front-runnable. Correct: TWAP over 30+ minutes (Uniswap v3 OracleLib) or an external oracle (Chainlink).
Unbounded loops in liquidity range. If a swap crosses many ticks in a row (price impact 80%+), gas may exceed the block limit. Need MAX_TICKS_CROSSED with partial fill and returning the remainder.
For Solana DEX (Anchor framework, Rust), the architecture is fundamentally different: account-based model, Program Derived Addresses (PDA) instead of storage, Cross-Program Invocations instead of internal calls. Solana's throughput (~3,000–4,000 TPS vs 15–30 on Ethereum mainnet) allows building on-chain order books – exactly what Phoenix DEX does.
Liquidity bootstrapping and aggregator integration
Launching a pool is not enough – you need to ensure liquidity at launch. Practical mechanisms:
-
Liquidity Bootstrapping Pool (LBP) – initial price is high, asset weights dynamically shift, creating selling pressure and even token distribution. Implemented in Balancer v2.
-
Initial Liquidity Offering via Uniswap v3 – adding liquidity in a narrow range around the initial price, then gradually expanding as volume grows. Requires active liquidity management or integration with Arrakis/Gamma.
-
Integration with 1inch, Paraswap, Li.Fi – aggregators bring traffic but require standard compliance: the pool must have correct
getAmountsOut, support ERC-20 approval/permit, and not have custom transfer hooks that break the aggregator's routing.
Development process and deliverables
Analytics and design begin with choosing the architectural model: CEX with custodial storage, non-custodial DEX, or hybrid (off-chain order book + on-chain settlement, like dYdX v3). This decision determines everything – regulatory load, tech stack, team.
Development proceeds in layers: first smart contracts with full Foundry coverage (fuzzing, invariant testing), then backend services, then integration layer, and finally frontend. Testing includes fork testing on mainnet via Foundry – we reproduce real liquidity conditions, not synthetic ones.
Audit is mandatory before mainnet deployment. For DEX contracts, minimally one firm with manual review (Trail of Bits, Spearbit, Code4rena contest). For CEX custody, audit of key storage processes. We guarantee all contracts undergo formal verification and fuzzing testing (Echidna, Foundry invariant).
Estimated timelines
| Exchange type |
Timeframe |
| DEX (AMM, xy=k) |
3 to 5 months |
| DEX with concentrated liquidity (v3-like) |
6 to 10 months |
| CEX (matching engine + custody + trading UI) |
8 to 14 months |
| Integration with existing protocol |
4 to 8 weeks |
Cost is calculated individually after a technical briefing: chain selection, throughput requirements, custodial model. Our certified engineers with 10+ years of experience will help you choose the optimal architecture and avoid common pitfalls. Contact our team for a detailed proposal.
Pitfalls to avoid at launch
- Forgetting the price oracle in AMM. Spot price can be manipulated with a flash loan in one transaction. If your lending protocol uses the spot price from its own pool, that's a bug.
- Hot wallet without limits. A CEX without daily limits on automatic withdrawals is an invitation for attackers. Compromising one key should lose at most 10% of total funds.
- Absence of circuit breaker. A 40% price drop in 5 minutes should halt automatic liquidations or withdrawals until manual review. Without this, a cascading liquidation spiral destroys all TVL.
- Incorrect decimal handling. USDC uses 6 decimals, WBTC – 8, most tokens – 18. Mixing without normalization leads to either precision loss or overflow. Solidity has no float; we work with fixed-point using FullMath (mulDiv with overflow protection).
Want to avoid these problems? Get a consultation — we will select the architecture for your project and provide exact timelines. Order exchange development with quality guarantee and ongoing support.