Overview
The Percolator engine is an open-source Solana program that implements perpetual futures entirely on-chain. Originally created by Solana co-founder Anatoly Yakovenko in October 2025, it stores complete market state in a single account called a slab. purple.trade deploys its own instance of the Percolator program and provides a full trading interface on top of it. See the History page for the full story of Percolator’s origins and Toly’s involvement.Slab Architecture
A slab is a single Solana account that contains the entire state of one perpetual market:
One slab = one market = one token. Each token launch creates a new slab.
Instructions
The Percolator program supports 22 instructions:PDA Derivation
Two PDA patterns are used: Vault authority (holds the token vault):Oracle Modes
The Percolator supports multiple oracle sources:
purple.trade uses authority mode for small-cap tokens that don’t have Pyth feeds. The platform pushes prices sourced from DEX aggregators (Meteora pool price, DexScreener).
Risk Engine
The crank-based risk engine runs checks on every trade:require_fresh_crank: Ensures the crank was updated withinmax_crank_staleness_slotsrequire_recent_full_sweep: For risk-increasing trades, ensures a complete account sweep was recent- Both return error
0xf(EngineUnauthorized) when stale — this is a freshness error, not a permissions error
callerIdx = 65535 is the permissionless sentinel value, meaning anyone can crank the engine.
The risk engine library (percolator) is formally verified using Kani model checking, enforcing invariants like:
- Conservation: No value created from nothing
- Isolation: No cross-account contagion
- No over-withdrawals: Users cannot extract more collateral than deposited + PnL
Collateral Model
Each market uses the inverted perpetual model:- The traded token IS the collateral (no stablecoins, no wrapped assets)
- Price = 1 / token_price (inverted)
- “Long token” = short in the inverted engine
- “Short token” = long in the inverted engine