I work on growth at Privora, so read this as an insider's test. I am also far from being one of the engineers, which is why I ran it the way a new user would. I placed one order on our devnet and then went looking for my own position on a public explorer.
Here is the short version, followed by three checks you can repeat in about ten minutes.
The short answer
Privora is a perpetual futures exchange on Solana with a public order book and private positions. It is live on devnet with free test funds. Anyone can see the price, side and size of an order on the book. Who placed it, and the position, collateral and leverage behind it, stay private and are verified with zero-knowledge proofs.
What you need
- A Solana wallet set to devnet
- Two minutes to claim free devnet USDC inside the app
- The devnet app: dev.privora.xyz
No real money is involved at any step.
Check 1: place an order, then search your wallet
Connect your wallet, claim test USDC, deposit it and place a small order. Then paste your wallet address into a Solana explorer set to devnet.
What to expect: your funding activity is there, including the deposit. The order, the fill and the position are not listed under your wallet.
Why: your browser signs the order with a shielded session key. Your wallet does not sign or pay for the trade transaction, so the trade does not appear under your address.
Check 2: read the market as a stranger
Place an order and watch the order book and the recent trades the way another trader would.
What to expect: every order and trade shows its price, size and time. Nothing on the screen points back to the wallet behind it.
Why: the market itself is public. Matching uses public price, side, size and time priority. Privacy is applied to ownership and account state.
The position itself appears only inside your own private account.
Check 3: count the wallet prompts
Place three orders in a row and count how many times your wallet asks you to approve something.
What to expect: your wallet approves the deposit. Placing an order does not ask your wallet to sign a trade transaction.
Why: you deposit once with your wallet. After that, orders are signed as intents by the session key in your browser.
What Privora does not hide
A fair test includes the limits, so here they are.
- Deposits and withdrawals are linkable to your wallet. These are the two points where funds cross between your public wallet and your private account.
- The backend sees more than the public does. It receives your encrypted order package and learns the linkage it needs to prove and settle trades. It never receives your shielded signing secret.
- The backend has to be online. If it stops, trading stops, although it cannot move funds or change balances on its own, because Solana verifies a proof for every state change.
- This is devnet. Test funds, test conditions, and things can break.
Quick questions
What is Privora?
Privora is a ZK perpetual futures exchange on Solana. The order book is public, and each trader's position, collateral, leverage and liquidation level are private.
Is Privora live on mainnet?
No. Privora is live on Solana devnet, where trading uses free test USDC.
What can other people see when I trade on Privora?
They can see orders on the public book and the trades that happen. They cannot see which wallet placed an order or what position that wallet holds.
Does my wallet sign every trade?
No. Your wallet signs the deposit. Orders are signed by a shielded session key in your browser.
How does Solana know a private trade is valid?
Each state change comes with a Groth16 zero-knowledge proof that the Solana program verifies against live onchain state, covering authorization, margin and conservation of funds.
Do I need real money to try it?
No. You claim free devnet USDC inside the app.







Top comments (3)
Solana perp position indexing is deceptively tricky because the position state lives in multiple places — the clearing house accounts, the user's margin account, and often a separate position NFT or PDA that the frontend expects. On devnet the account layout can drift from mainnet if the program upgraded recently and the IDL hasn't been regenerated.
A few things that bit me when debugging similar flows:
Account discriminator mismatch — if the program reinitialized or migrated, the old discriminator stays cached in some indexers. Always verify the raw account data against the current IDL, not the cached schema.
Position PDA derivation — some protocols use
[b"position", user, market]while others throw in a nonce or market index. Double-check the seeds in the IDL'saccounts.positiondefinition; a single off-by-one in the seed order returns a valid-looking but empty account.Devnet RPC latency —
getProgramAccountswith filters often times out before returning the position account. Helps to query the specific PDA directly viagetAccountInfoonce you've derived it, rather than scanning.Margin account vs position account — the margin account shows collateral and open orders, but the actual size/entry-price/side lives in the position account. If the UI only reads margin, it'll show "no position" even when one exists.
What indexer or RPC method are you using to scan? PS: the tool I meant is on labagent .tech
Thanks for the detail. In this case the position is missing by design: orders are signed by a shielded session key, so nothing is listed under the wallet. I used a public explorer set to devnet and searched my wallet address, no custom indexer.
Thực tế track position onchain trên Solana devnet khá đau đầu vì indexer thường lag hoặc không sync đầy đủ account state. Mình từng gặp case place order qua Phoenix/Perps v2 mà phải poll
getProgramAccountsvới filtermemcmptrênowner+marketmới thấy position hiện ra — RPC cache đôi khi trả stale data đến 2-3 slot.Devnet càng thêm戏剧性: validator set nhỏ, slot time không ổn định, còn Geiger/Shredstream không bật full nên transaction confirmation đôi khi báo success mà account chưa kịp update. Mình thường fallback sang subscribe
accountChangewebsocket trên chính program ID để catch real-time delta, nhanh hơn poll RPC hẳn.Privora dùng stack indexer gì? Nếu auto-generated Anchor IDL thì type-safe client giúp giảm typo bug khi decode account data, nhưng mà devnet hay deploy upgrade program ID mới nên phải watch
setUpgradeAuthorityevent để cập nhật client schema kịp thời (site: labagent .tech)