Projects

Project Experience

Presented in three sections: Content, Performance, and Role Boundaries, with data and roles accurately labeled.

co7project

Content

  • Led technology selection, domain segmentation, and architecture design from 0 to 1, managing a team of 9 in requirement gathering, solution design, development scheduling, and cross-team coordination. Collaborated with four business lines (market making, hedging, arbitrage, asset management) and three functional roles (operations, risk control, quantitative research).
  • Build a Market Data Center: 10+ Unified real-time subscription and aggregation of exchange market data (REST + WebSocket), delivering a consistent market view for four business lines while serving as the unified data source for real-time risk control and monitoring alerts.
  • Abstract the workflow "Exchange Integration → Account Onboarding → API Key Authorization → Risk Configuration → Strategy Deployment → P&L Calculation" into a standardized business domain. Centrally manage 1000+ cross-platform strategy instances (Python/Java/C++) with two-tier parameter support: template defaults overridden by instance-specific values for real-time updates.
  • PnL attribution is split into three components: quote spread PnL, directional inventory PnL, and hedging costs. Risk management is abstracted as a configurable combination of "business conditions" and "disposal actions." Limits, circuit breakers, and monitoring metrics are largely powered by DolphinDB and InfluxDB. A factory pattern encapsulates integration with 10+ exchanges.

Performance / Progress

  • Market Center: 10 + Unified subscription and aggregation of exchange market data. Four business lines share a single market view, serving as the unified data input for real-time risk control metrics and alerts.
  • The platform serves as a unified entry point for four business lines, supporting team collaboration for 80+ users and eliminating data discrepancies caused by inconsistent business definitions.
  • Adjusting multi-strategy parameters and risk control rules no longer requires R&D scheduling.
  • Led GCP-to-AWS production migration using a "services-first, data-second" canary strategy. Full rollback capability maintained before domain cutover; zero transaction interruptions on live traffic.

Content

  • Hybrid Mode: Internal CEX shadow order book matching + Polymarket net exposure hedging.
  • Unified gateway integrating four API layers: Gamma (market metadata), CLOB (depth and order cancellation, EIP-712 signature required for write operations), Data (positions and trades), and WebSocket (~100ms real-time order book). Internally exposes only abstract interfaces to prevent on-chain semantics from leaking into the business layer.
  • In the non-custodial model, the Polygon omnibus main wallet interacts on behalf of all users, integrating USDC/gas reserves and Paymaster sponsorship to hide cross-chain fees from users. On-chain statuses ("Submitted", "Confirmed", "Partially Filled", "Failed") are normalized and sent back to the hedging engine.
  • Monitor continuous subscriptions to UMA Optimistic Oracle proposal and dispute statuses; compare on-chain positions with internal ledgers per market via scheduled polling and event-driven triggers.

Performance / Progress

  • Four-layer API gateway unified encapsulation; on-chain semantics do not leak to the business layer.
  • Aligns settlement with UMA's 2-hour challenge period; pushes redeemable events only after results are irreversible to minimize early redemption risk.
  • Reconcile on-chain and internal ledgers by trading pair, with minute-level alerts for non-zero discrepancies. These alerts serve as inputs for exposure limits and circuit breakers.

Content

  • Off-chain quote, on-chain settlement. Aggregates top-tier order books from Binance, OKX, Coinbase, etc., to calculate a liquidity-weighted mid-price. Applies three adjustment layers over the benchmark price: spread, inventory skew (Avellaneda-Stoikov approach), and latency compensation.
  • Quote carrier is an "intent" signed with EIP-712. Short quote expiry window controls price risk, nonce prevents replay attacks, and inventory locking prevents overselling.
  • Off-chain last look secondary validation (rejection rate as the core monitoring metric); on-chain settlement contract performs triple validation for signature validity, quote expiration, and oracle deviation; automatic hedging and real-time reconciliation upon trade execution.

Performance / Progress

  • The quotation engine, signature and order management, settlement contract interaction, and risk control monitoring chain have all been successfully validated in the test environment.
  • Hedge the most vulnerable cross-venue scenario where the "chain leg is executed but the hedge leg remains pending" with automated hedging, real-time reconciliation, and inventory deviation thresholds as a safety net.
  • Monitor rejection rate, deviation trigger rate, toxic flow address identification, and volatility circuit breakers.

Content

  • Both strategies share a spot position layered allocation: funding rate arbitrage captures the perpetual funding fee every 8 hours, while basis arbitrage locks in the opening basis of delivery contracts, which must converge at expiry.
  • Market data and account updates are pushed via WebSocket into a Caffeine cache. All decision-making reads from the local cache (microsecond latency). Before placing an order, bid-ask timestamps are compared to validate freshness.
  • A single-leg execution exposes leg risk. The system performs high-frequency order audits, and if a leg fails to complete or an order times out, it cancels the order and re-submits a compensating order at the current market depth until both legs are filled. EWM smooths historical rates for annualized conversion.
  • The circuit breaker operates independently of standard open/close positions and triggers forced liquidation based on the ratio of contract ask1 to spot bid1.

Performance / Progress

  • Transform "insufficient single-order success rate" into a convergent process with limited retries and stateful tracking.
  • Independent melt paths ensure a "life-saving" channel remains available even during extreme market conditions.

Content

  • Independent microservice that eliminates directional risk exposure for contract market-making accounts. Trade details are cleaned and aggregated in real-time via Flink to serve as input for net position calculation.
  • Periodically pull full-market contract user positions, exclude high-leverage, high-frequency, and high-win-rate users to prevent signal pollution, and trigger orders only when thresholds (both ratio-based and absolute-value) are exceeded, executing trades solely on the excess amount.
  • Excess exposure is split into multiple small orders by category and executed asynchronously using TWAP. Limit orders are placed at the second bid/ask level to minimize market impact.
  • Full-stack explicit BigDecimal rounding control (round down to prevent over-purchasing), Snowflake algorithm cliOrderId ensures idempotent retries; thresholds and hedging switches integrated with Apollo for zero-downtime updates.

Performance / Progress

  • Introduce Flink for real-time trade data computation to improve the timeliness and throughput of aggregate market-wide holdings.
  • Position management has shifted from manual monitoring to real-time, threshold-driven active convergence.
  • Explicit rounding direction control to mitigate capital loss risks from exposure deviation accumulation.

Content

  • Solve adverse selection and toxic flow in market making: Users who consistently outperform the market on the order book will lose money over time by providing liquidity.
  • Python 3.9 (asyncio + multiprocessing), unified gateway for 8 exchanges; tags users and trading pairs by historical profitability to target non-mainstream assets with significant information asymmetry, then executes hedged orders in the same direction as the user upon signal.
  • The execution layer outputs three states: "All", "Partial", or "No Hedge". Regular users follow the standard neutral hedging strategy, sharing the same engine. Redis queues decouple upstream scoring inference from downstream order placement, with each bot running as an independent process for fault isolation.

Performance / Progress

  • Convert profits previously lost to toxic order flow into holdings gains.
  • Design Trade-off: Rather than pursuing accuracy per transaction, we ensure overall risk convergence at a higher level.

Content

  • Coordinate the scheduling and integration of five sub-modules: Market Data Gateway, Trading Gateway, Core Strategy, Public System Layer, and others. Prioritize and define acceptance criteria for asset onboarding across three categories: encrypted CEXs, TradFi brokers (IB / Futu / Alltick), and on-chain DEXs.
  • Led TradFi tokenized market-making solution: With U.S. equity markets closed and no real-time reference prices, the standard 7×24 crypto model is inapplicable. Designed a five-state machine (pre-market, intra-day, post-market, overnight, and closed) with automatic parameter switching. During closed hours, bid/ask quotes are constrained using closing price TWAP paired with dual VWAP, while an in-memory virtual order book prevents exposure of actual capital.
  • Following a production incident involving manipulation of low-liquidity benchmarks, we've added an absolute anchor price protection guard for low-liquidity assets.

Performance / Progress

  • Quote-to-order: P5 0 20ms → 4ms, P9 9 60ms → 8ms. Jitter ratio for P99/P50: 3.0 → 2.0.
  • Parameter hot updates reduce real-world tuning restart times from minutes to 10ms.

Role Boundaries

The engine's C++ low-level performance engineering (lock-free queues, zero-copy, compile-time optimizations) is implemented by C++ specialists; I led project coordination, solution reviews, and designed and implemented the business logic for strategy/risk control modules.

Want to learn more about a project? Contact us.

Contact Us