가격-시간 우선순위 매칭엔진과, 비트겟 사건에서 실제 쓰인 공격 패턴(소액 테스트 인출 → 관리자 백엔드 장악 → 위조 대량 인출)을 막는 방어 로직을 처음부터 직접 구현했습니다. 지금은 전부 무료로 공개합니다.
진짜 거래소 운영자용이 아닙니다 — 시스템설계 면접을 준비하거나, 포트폴리오에 넣을 묵직한 프로젝트가 필요한 백엔드 개발자를 위한 학습 자료입니다. 매칭엔진 설계는 코인베이스·로빈후드 같은 핀테크 기업 면접의 단골 주제입니다.
가격-시간 우선순위로 매수/매도 주문을 체결하는 최소 매칭엔진.
// 가격-시간 우선순위 매칭엔진 (최소 구현)
class MatchingEngine {
constructor() {
this.buyBook = []; // 매수: 가격↓, 동가는 시간↑
this.sellBook = []; // 매도: 가격↑, 동가는 시간↑
this.fills = [];
}
addOrder(side, price, qty) {
const order = { id: crypto.randomUUID(), side, price, qty, time: Date.now() };
if (side === 'buy') {
this.buyBook.push(order);
this.buyBook.sort((a, b) => b.price - a.price || a.time - b.time);
} else {
this.sellBook.push(order);
this.sellBook.sort((a, b) => a.price - b.price || a.time - b.time);
}
this.match();
return order;
}
match() {
while (this.buyBook.length && this.sellBook.length && this.buyBook[0].price >= this.sellBook[0].price) {
const buy = this.buyBook[0], sell = this.sellBook[0];
const qty = Math.min(buy.qty, sell.qty);
buy.qty -= qty; sell.qty -= qty;
this.fills.push({ price: sell.price, qty, buyId: buy.id, sellId: sell.id, time: Date.now() });
if (buy.qty <= 0) this.buyBook.shift();
if (sell.qty <= 0) this.sellBook.shift();
}
}
}
비트겟(2026.09) 사건 패턴 대응: 속도체크 + 다단계승인 + 타임락.
// 위조 인출 방어 — 비트겟(2026.09) 사건 패턴 대응
class WithdrawalGuard {
constructor({ velocityWindowMs = 10000, velocityThreshold = 3, timelockMs = 10000 } = {}) {
this.recent = [];
this.velocityWindowMs = velocityWindowMs;
this.velocityThreshold = velocityThreshold;
this.timelockMs = timelockMs;
}
request(amount, approvals = 1) {
const now = Date.now();
this.recent = this.recent.filter(r => now - r.time < this.velocityWindowMs);
this.recent.push({ amount, time: now });
// 1) 속도체크: 짧은 시간 내 임계치 초과 요청
if (this.recent.length > this.velocityThreshold) {
return { status: 'blocked', reason: 'velocity_check' };
}
// 2) 다단계 승인: 고액은 단일 권한으로 불가
const requiredApprovals = amount > 1000 ? 2 : 1;
if (approvals < requiredApprovals) {
return { status: 'pending', reason: 'multi_approval_required' };
}
// 3) 타임락: 고액은 즉시 집행하지 않고 지연
if (amount > 1000) {
return { status: 'timelocked', releaseAt: now + this.timelockMs };
}
return { status: 'approved' };
}
}
이 상품에 대한 피드백이나 질문이 있으면 알려주세요. 회신을 원하시면 이메일을 남겨주세요(선택).