Markets III: Commodities, Energy and Crypto · Markets
18Margin, Liquidation and Loss Allocation
On 10 October 2025, after the announcement of a 100% tariff on Chinese imports into the United States, about USD 19 billion of leveraged crypto positions were liquidated within twenty-four hours, and open interest in perpetual futures across major venues fell by 43%, from USD 217 billion to 123 billion. Bitcoin fell to about USD 106 500, and the tokens CoinDesk Research tracked fell by about 47% on average. On some venues the liquidations were so large and so fast that the buffers meant to absorb their losses ran out, and the venues closed profitable positions of other traders, who had done nothing wrong, to balance their books. A crypto derivatives venue has no clearing members standing between it and its customers, and no default fund contributed by banks: its customers’ own margin, its liquidation engine, its insurance fund and, at the end, its winning customers are the whole default waterfall. This chapter follows a leveraged position from its margin to its liquidation price, through the engine that closes it, and down the waterfall; then it builds and dissects a cascade.
18.1 Isolated, cross and portfolio margin
On a regulated futures exchange a customer’s margin is set by the clearing house and collected through a clearing member (One Quant Book 1, chapter 20). A crypto venue sets and collects margin itself, from each account, in the account’s own collateral, continuously.
Definition 18.1 (Isolated margin, cross margin)
Under isolated margin each position has its own margin, assigned by the trader; its losses can consume only that margin, and it is liquidated alone. Under cross margin all positions of an account share the account’s collateral; gains on one support losses on another, and the account is liquidated when its total equity falls below the sum of its maintenance margins.
Isolated margin caps what a single bet can lose and makes its liquidation price easy to compute; cross margin uses collateral more efficiently and survives a loss on one position if others gain, at the risk of losing everything in the account at once. Portfolio margining (One Quant Book 1, chapter 20), offered by some venues to large accounts, sets the requirement from the scenario loss of the whole portfolio, including spot holdings used as collateral. Maintenance margin is usually tiered: the rate rises with the size of the position, because a larger position takes longer and costs more to liquidate.
As of September 2026 — Tiered maintenance margin
Binance computes maintenance margin as the position’s notional value times the maintenance margin rate of its bracket, minus a maintenance amount that makes the requirement continuous from one bracket to the next; brackets, rates and maximum leverage are published per contract and adjusted. BitMEX’s instrument data on 24 September 2026 gave XBTUSD an initial margin of 1% and a maintenance margin of 0.5% at the base risk limit.
18.2 The liquidation price
Definition 18.2 (Liquidation price, bankruptcy price)
The liquidation price of a position is the mark price at which its margin plus unrealised P&L falls to its maintenance margin, so that the venue takes it over. Its bankruptcy price is the price at which margin plus unrealised P&L is exactly zero.
Proposition 18.3 (Liquidation prices of isolated positions)
Let a linear position of units be entered at with margin and maintenance margin rate (no maintenance amount). A long () is liquidated at and goes bankrupt at
and a short of units at and . With leverage the long’s liquidation price is . A long inverse position of one-dollar contracts with margin in coin is liquidated at .
Proof. For the long, gives the first formula and the second; the short’s are the same with the sign of the P&L reversed. For the inverse long, the equity in coin is and the maintenance requirement ; equating them gives the stated price. ∎
The symbol is local to this chapter (in One Quant Book 4 it denotes a compensator). At 10 times leverage a long is liquidated about 9.5% below its entry, at 50 times about 1.5% below. The inverse long is liquidated sooner than the linear one at the same leverage, because its coin margin loses value in the same move: it is long twice, as Chapter 17 explained. Figure 18.1 draws the three.
Two consequences matter for risk. Liquidation is triggered by the mark price (Chapter 17), so a trader’s liquidation price is about the venue’s index, not the trades he sees; and the gap between the liquidation and bankruptcy prices, the maintenance margin, is all the venue has to close the position without loss.
18.3 Liquidation engines
Definition 18.4 (Liquidation engine)
A liquidation engine is the venue’s system that monitors every account against its maintenance margin at the mark price, takes over the positions of accounts that breach it, and closes them, usually by sending orders into the venue’s own order book, sometimes by transferring them to designated liquidity providers.
The engine is the venue’s clearing house in software. It cancels the account’s open orders, may first try a partial liquidation that reduces the position to a lower margin tier, then sells (for a long) into the bids. If it sells above the bankruptcy price, what is left of the trader’s margin is kept, on many venues, by the insurance fund; if below, the fund pays the difference. The engine is fast, mechanical and indifferent to price: its orders are exactly the forced selling of the liquidity spirals of One Quant Book 1, chapter 31, arriving when the book is thinnest. FTX’s help pages described the alternative: backstop liquidity providers, invited from its top volume tiers, kept at least USD 500 000 on the venue and pledged to absorb at least USD 0.1 million of liquidations a minute and 0.3 million an hour, taking over an account’s position and collateral before it went bankrupt. And the engine’s venue can itself fail when it is needed: on 13 March 2020 BitMEX was hit by two denial-of-service attacks, at 02:16 and 12:56 UTC, which delayed or prevented requests to the platform.
18.4 Insurance funds, auto-deleveraging and socialised losses
Definition 18.5 (Insurance fund)
An insurance fund is a pool of assets a derivatives venue holds to absorb the losses of positions liquidated below their bankruptcy prices, funded mostly by the remaining margin of positions liquidated above them.
As of September 2026 — An insurance fund balance
BitMEX’s public insurance endpoint reported, for 23 September 2026, a bitcoin insurance fund of about 3 700 bitcoin and a USDT fund of about 30.6 million USDT. Venues publish their funds’ balances in different ways and at different frequencies.
Definition 18.6 (Auto-deleveraging, socialised loss)
Auto-deleveraging is the closing of profitable opposite positions of other traders, at the bankrupt position’s bankruptcy price or at the mark, when the insurance fund cannot absorb a liquidation’s loss, with those traders selected by a published ranking. A socialised loss is a loss spread across a group of traders, for example all profitable accounts pro rata to their gains, rather than imposed on those selected by a ranking.
As of September 2026 — Auto-deleveraging rules at two venues
Binance applies auto-deleveraging only if its insurance funds are unable to accept a bankrupt position; profitable opposite positions are ranked by P&L percentage times effective leverage and closed at the bankruptcy price of the liquidated order, without trading fees, and each position shows an indicator of its place in the queue. Hyperliquid’s documentation triggers auto-deleveraging when an account’s or an isolated position’s value becomes negative, ranks profitable users by (mark price over entry price) times (notional over account value), and closes their positions at the previous mark price against the underwater user.
The ranking chooses who pays: the most profitable and most leveraged winners first, because their closure removes the most exposure for the least number of accounts. To the winner, auto-deleveraging is an involuntary exit at a price he did not choose, often in the middle of the move he was positioned for, and his hedges elsewhere are left open. A market maker short the perpetual against spot can find its short closed and its spot long left naked in a crash. After October 2025, an analysis by Tarun Chitra of Gauntlet, reported by Protos, argued that the queue-based ranking common to many venues closed about USD 650 million more of profitable positions on Hyperliquid than the minimum needed, and proposed a risk-aware pro-rata rule instead.
18.5 A liquidation cascade dissected
Definition 18.7 (Liquidation cascade)
A liquidation cascade is a sequence in which forced sales by liquidation engines move the price enough to reach further positions’ liquidation prices, whose forced sales move it further.
Whether a price shock stops or cascades depends on how many units sit at each liquidation price and on how far each unit sold moves the price.
Proposition 18.8 (The local cascade multiplier)
Let each unit sold move the price down by (a linear, permanent impact), and let be the number of units whose liquidation prices lie in a unit interval around . Then is the further fall caused, through liquidations, by one point of fall near . Where is constant and below one, a fall of ends as a fall of ; where , the cascade does not stop until the price leaves the region. The final price does not depend on the order or the batch size in which triggered positions are liquidated.
Proof. A fall triggers units, which cause a fall , which triggers , and so on: the geometric series sums to if and diverges otherwise. With linear permanent impact, the price after any set of liquidations is the shocked price minus times the units sold, whatever their order; liquidating every position whose price has been reached, in any batches, stops at the same largest fixed point. ∎
Figure 18.4 shows the consequence. Small shocks are amplified two- to threefold and stop. A shock of 1.11% is enough to carry the price into the zone where , and the cascade then runs to below 90: a ninefold amplification. Capping leverage at ten times removes the cluster of liquidation prices near the entry and raises the threshold to 5.37%; doubling the depth of the book halves , which then stays below one everywhere, so the fall is amplified smoothly, about twofold, and reaches 10% only after a shock of 5.55%; without forced selling there is no cascade at all. The tutorial checks that the result does not depend on the size of the engine’s batches, as the proposition says, and ablates each mechanism in turn.
A gap is worse than a slide. When the price gaps down 5% at once, as on a surprise announcement, every position whose liquidation price lies inside the gap is closed at the gapped price, below many bankruptcy prices: in the tutorial, USD 3.21 million of deficits that the insurance fund must pay, and the price ends near 84. The weekend problem follows the loss down the waterfall.
18.6 Tutorial: liquidation prices and a cascade
Goal. Derive liquidation prices, simulate a cascade of leveraged longs selling into a book of stated depth, test its stability under a finer time step, and ablate each mechanism. End state: Figures 18.1, 18.3 and 18.4 and the numbers of the text.
Liquidation and bankruptcy prices. Proposition 18.3 in code.
def liq_price_linear(size: float, entry: float, margin: float, mmr: float, amount: float = 0.0) -> float: """Isolated linear position of `size` units (negative = short): the price at which margin plus P&L equals maintenance margin mmr x |size| x price - amount.""" if size > 0: return (size * entry - margin - amount) / (size * (1 - mmr)) n = -size return (margin + n * entry + amount) / (n * (1 + mmr)) def bankruptcy_price_linear(size: float, entry: float, margin: float) -> float: """Price at which the isolated position's margin is exactly used up.""" return entry - margin / sizeListing 18.1. Liquidation and bankruptcy prices of an isolated linear position. code/firm/liquidation/firm_liquidation.py The cascade. Triggered positions are sold into the book, all at once or in batches.
def cascade(pop: list[Long], shock: float, impact: float = 1.2e-5, batch: int | None = None, forced_selling: bool = True) -> Result: """Price falls by `shock`, then every long whose liquidation price is reached is sold into the book, each unit sold moving the price down by `impact` (a linear, permanent impact). Triggered positions are liquidated all at once (batch=None) or `batch` at a time, highest liquidation price first, re-checking after each batch. Each batch executes at the average of its start and end prices.""" price = P0 * (1 - shock) alive = sorted(pop, key=lambda p: -p.liq) sold = fund = deficit = 0.0 n_liq, path, step = 0, [(0, price, 0.0)], 0 while alive and alive[0].liq >= price: trig = [p for p in alive if p.liq >= price] todo = trig if batch is None else trig[:batch] units = sum(p.units for p in todo) new = price - impact * units if forced_selling else price avg = 0.5 * (price + new) fund += sum(p.units * (avg - p.bankrupt) for p in todo) deficit += sum(p.units * max(0.0, p.bankrupt - avg) for p in todo) sold += units n_liq += len(todo) alive = alive[len(todo):] price = new step += 1 path.append((step, price, sold)) return Result(price, n_liq, sold, fund, deficit, path)Listing 18.2. A liquidation cascade with a configurable batch size. code/markets-3/18-margin-liquidation-and-loss-allocation/python/m3_liq.py - Stability and ablations. Run
cascadewithbatchof 100, 10 and 1 and compare with the batch of everything triggered; then setforced_selling=False, cap leverage and halve the impact. - Run
fig_liq.pyfor the chart data.
What to change next. Replace the linear impact by a square-root impact and check whether the batch size still does not matter; let the book refill between batches; add short positions and a funding payment.
18.7 Build: the margin and liquidation engine
Purpose. The miniature firm must know, for every position on every venue, how far it is from liquidation and what a liquidation would cost; and its risk simulations need the venue’s engine and waterfall reproduced.
Interface. Tier(max_notional, mmr, maint_amount), maintenance_margin(notional, tiers); liq_price_linear, bankruptcy_price_linear, liq_price_inverse; cross_health(wallet, positions, tiers); sell_into_book(qty, bids); adl_rank(accounts, price); liquidate(account, bids, fund, opposite, price).
Rules. Mark prices from firm.perp; tiers continuous at their boundaries; a liquidation’s surplus goes to the fund and its deficit is paid by it; if the fund cannot pay, the position is closed against opposite positions in ADL order at the bankruptcy price, leaving book and fund unchanged.
Acceptance tests. code/firm/liquidation/tests/: continuity of tiers; linear and inverse liquidation prices against the closed forms; cross-margin health; selling into a book; surplus to the fund; ADL in rank order.
Stretch. Partial liquidation to a lower tier; backstop liquidity providers; a pro-rata ADL rule; cross-venue exposure to one underlying.
Sources and further reading
- CoinDesk Research, “Market Spotlight: Inside Crypto’s $19 Billion Liquidation Event”, 17 October 2025.
- Binance, “What Is Auto-Deleveraging (ADL)” and “Leverage and Margin of USDS-M Futures”, support pages; Hyperliquid documentation, “Auto-deleveraging”. Accessed September 2026.
- BitMEX, public API insurance and instrument endpoints, 23–24 September 2026; BitMEX blog, “How We Are Responding to the 13 March DDoS Attacks”, March 2020.
- FTX, help centre, “Backstop Liquidity Provider Program” (updated 14 September 2022), Internet Archive copy.
- Protos, “Outdated algorithm caused $650M excess losses on Hyperliquid, report”, 10 December 2025.
18.8 Exercises
Exercise 18.1 ★
A 20-times long at 100 with a maintenance margin rate of 0.5%: what are its liquidation and bankruptcy prices?
Solution
Solution of Exercise 18.1.
Margin 5 per unit: liquidation at , bankruptcy at 95.
Exercise 18.2 ★
A trader holds one position at 50 times leverage in cross margin with a large unused balance. Is she liquidated 2% below entry? Explain.
Solution
Solution of Exercise 18.2.
No: in cross margin the whole balance supports the position, so it is liquidated only when the account’s total equity falls to its maintenance margin, much further away; but a large enough fall takes the whole balance.
Exercise 18.3 ★
Name the layers of a crypto venue’s default waterfall, in order.
Solution
Solution of Exercise 18.3.
The trader’s margin, the liquidation engine’s sale (surplus or deficit), the insurance fund, auto-deleveraging of profitable opposite positions, and on some venues or in the past a socialised loss.
Exercise 18.4 ★★
Compare the liquidation prices of a linear and an inverse long at 5 times leverage and 0.5% maintenance margin. Why do they differ?
Solution
Solution of Exercise 18.4.
Linear 80.40, inverse 83.75. The inverse long’s margin is in coin, which loses value as the price falls, so the equity falls faster than the position’s dollar loss alone.
Exercise 18.5 ★★
Near the current price . A news shock moves the price down 1%. How far does it fall in all, if stays constant?
Solution
Solution of Exercise 18.5.
.
Exercise 18.6 ★★
A market maker is long spot and short the perpetual. How can auto-deleveraging hurt it, and what would it do about it?
Solution
Solution of Exercise 18.6.
In a crash its short perpetual is among the most profitable positions and can be closed by auto-deleveraging, leaving its spot long unhedged when prices are falling fastest. It watches the ADL indicator, keeps leverage on the short low (which lowers its rank), spreads the hedge across venues, and has a plan to re-hedge at once.
Exercise 18.7 ★★★
Coding. With critical_shock, find the threshold for leverage caps of 20 and 10 times. What does this suggest about venue limits on leverage?
Solution
Solution of Exercise 18.7.
1.65% with leverage capped at 20 times and 5.37% at 10 times, against 1.11% uncapped: the cluster of high-leverage liquidation prices near the entry is what makes a small shock dangerous, so leverage caps protect the market, not only the traders.
Exercise 18.8 ★★★
Find the flaw. “A cascade simulation that liquidates positions one at a time is more accurate than one that liquidates everything triggered at once, so its answer will be different.”
Solution
Solution of Exercise 18.8.
With linear permanent impact the final price is the same whatever the batch size (Proposition 18.8), and so is the insurance fund’s total, since the unit-weighted average execution price is the same; the tutorial checks both. The answer changes only if impact is nonlinear or the book refills between batches, and then a finer step is a different model, not a more accurate one.
18.9 Problem: Anatomy of a Cascade
Problem 18.1
Weekend problem — from a shock to auto-deleveraging
Use the tutorial’s population of 4 000 leveraged longs (USD 166.6 million of notional), a maintenance margin rate of 0.5%, an impact of 0.0012 price points per unit sold (0.12% per USD 1 million at a price of 100) and an insurance fund of USD 2 million.
Part I — One position.
- A long of 250 units at 100 with 25 times leverage: what are its margin, liquidation price and bankruptcy price?
- If it is liquidated at 95.5, what does the insurance fund pay?
- And if at 96.8?
- Why does the fund receive money in the second case?
- Why does the venue use the mark price, not the last trade, to trigger it?
Part II — The cascade.
- What is the smallest initial shock after which the price falls by 10% or more in all?
- What does exceed between about 92 and 96, and what does that mean?
- What are the thresholds with leverage capped at 10 times, and with a book twice as deep?
- Why is the final price the same whatever the batch size?
- What would break that invariance?
Part III — The waterfall.
- After a 5% gap, where does the price end, and what are the deficits?
- How much reaches auto-deleveraging?
- Who is deleveraged first under a ranking by P&L percentage times leverage?
- What does a deleveraged market maker lose, and what does it keep?
- How would a pro-rata rule change who pays?
Part IV — Judgement.
- Should venues cap leverage?
- Is an insurance fund of USD 2 million enough for this market?
- How should a trading firm use a venue’s ADL indicator?
- State the named result: the critical shock, and the loss that reaches the insurance fund and then auto-deleveraging after a 5% gap.
- In one sentence: who stands behind a crypto derivatives trade?
Solution
Solution of Problem 18.1.
1. Margin 1 000; liquidation at ; bankruptcy at 96. 2. . 3. It receives . 4. Sold above the bankruptcy price, what is left of the trader’s margin goes to the fund, which is how funds grow in normal times. 5. The last trade can be moved cheaply for a moment; the mark, built on a multi-venue index, cannot. 6. 1.11%. 7. One: each point of fall there triggers liquidations that cause more than a point of further fall, so the cascade runs through the zone. 8. 5.37% with the cap; with the deeper book the price reaches a 10% fall only after a 5.55% shock, and without a jump, since is then below one everywhere. 9. With linear permanent impact the price depends only on the units sold, not on their order. 10. Nonlinear impact, a book that refills between batches, or engine delays that let prices gap between batches. 11. Near 83.83, with USD 3.21 million of deficits. 12. About USD 1.21 million: the deficits less the fund’s USD 2 million (and a few thousand dollars of surpluses). 13. The shorts with the highest P&L percentage times effective leverage: the most profitable, most leveraged winners. 14. Its short is closed at the bankruptcy price, so it keeps the P&L up to that price but loses the hedge and the rest of the move, and must re-hedge in a falling market. 15. It would spread the loss across all winners in proportion to their gains or risk, so no single winner loses its whole position. 16. Caps raise the shock a market can absorb (1.11% to 5.37% here), at the cost of turning away leveraged demand to other venues; a venue that caps alone may lose the flow without making the market safer. 17. No: a 5% gap alone consumes it. A fund should be sized to stress scenarios of open interest, leverage and depth, not to history. 18. As a live risk input: reduce leverage or size on positions high in the queue, and treat a high rank as a signal that a hedge may disappear. 19. Named result: a critical shock of 1.11%; after a 5% gap, USD 3.21 million of deficits, of which USD 2 million from the insurance fund and about USD 1.21 million by auto-deleveraging. 20. The loser’s margin, the venue’s insurance fund, and then the other winners.
18.10 Interview questions
Interview question 18.1 ★ trader
Derive the liquidation price of a 10-times long.
Solution
Solution of Interview question 18.1.
Margin . Equity meets at : about 9.5% below entry at .
What the interviewer is looking for: equity equal to maintenance at the mark.
Interview question 18.2 ★ risk
What is auto-deleveraging, and why should a firm that is not leveraged care about it?
Solution
Solution of Interview question 18.2.
When the insurance fund cannot absorb a bankrupt position, profitable opposite positions are closed at the bankruptcy or mark price. An unleveraged hedger can be deleveraged too: its hedge disappears in a crash, and its winnings are capped at a price it did not choose.
What the interviewer is looking for: winners bear the tail; hedges can vanish.
Interview question 18.3 ★★ researcher
What determines whether a price shock turns into a liquidation cascade?
Solution
Solution of Interview question 18.3.
The density of liquidation prices near the current price (leverage and entry distribution), the price impact of forced sales (depth, and whether it refills), the speed of the engines relative to arbitrage and new liquidity, and correlated positions across venues: the local multiplier .
What the interviewer is looking for: density times impact, and whether it exceeds one.
Interview question 18.4 ★★ developer
How would you design a liquidation engine to minimise losses to the insurance fund?
Solution
Solution of Interview question 18.4.
Liquidate early and partially (reduce to lower tiers before full liquidation), slice orders to the book’s depth, use backstop liquidity providers for large positions, trigger on a robust mark, size maintenance margins by position size and asset liquidity, and keep the fund sized to stress scenarios.
What the interviewer is looking for: partial, patient, and pre-arranged liquidity.
Interview question 18.5 ★★ risk, trader
Compare isolated and cross margin for a market maker quoting 50 perpetuals.
Solution
Solution of Interview question 18.5.
Cross margin shares collateral so that gains on some quotes offset losses on others and less capital is idle, but one bad position can take the whole account. Isolated margin contains each loss but needs capital on every position and liquidates positions a portfolio view would keep. A market maker usually runs cross or portfolio margin with its own per-instrument limits.
What the interviewer is looking for: efficiency against containment, with internal limits.
Interview question 18.6 ★★★ researcher, risk
Using public data, how would you estimate where the liquidation prices of a venue’s open interest lie?
Solution
Solution of Interview question 18.6.
From open interest changes by price level (open interest rising at a price suggests entries there), funding and long–short ratios, leverage distributions published by venues or estimated from margin data, and liquidation feeds after the fact; combine into a distribution of entries times a leverage distribution, and calibrate against observed cascades.
What the interviewer is looking for: entries from open interest, leverage from any available proxy, and calibration.