---
title: Auto-Deleveraging (ADL)
url: https://www.emergentmind.com/topics/auto-deleveraging-adl
type: topic
---

# Auto-Deleveraging (ADL)

Auto-deleveraging (ADL) is a last-resort loss socialization mechanism used by perpetual futures venues when liquidation and insurance buffers are insufficient to restore solvency. In formal models of recent work, ADL is the rule by which an exchange chooses both the amount of residual loss to socialize and the solvent accounts from which positions or unrealized profits are forcibly reduced. Three complementary research directions now frame the subject: ADL as an online learning problem on a PNL-haircut domain, where haircuts apply to positive PNL rather than posted collateral principal [2602.15182]; ADL as a risk-based optimization problem whose benchmark solution minimizes future expected shortfall by deleveraging the most highly levered accounts first [2603.15963]; and ADL as a mechanism-design problem constrained by an impossibility trilemma between solvency, revenue, and fairness [2512.01112].

## 1. Operational setting and trigger conditions

In the formal perpetual-futures model, a venue maintains open positions
\[
\mathcal P_n=\{\mathfrak p_i=(q_i,c_i,t_i,b_i):i=1,\dots,n\},
\]
where \(q_i\ge 0\) is notional size, \(c_i\ge 0\) is posted collateral, \(t_i\) is entry time, and \(b_i\in\{+1,-1\}\) is side. The venue quotes a mark price \(p_t\), observes a spot-oracle price \(\hat p_t\), and typically uses funding-rate transfers to keep \(p_t\approx \hat p_t\). One discrete funding rule given in the literature is
\[
\gamma_t=\kappa\Bigl(\frac{L_t}{S_t}-\frac{p_t}{\hat p_t}\Bigr),\qquad
L_t=\sum_{b_i=+1}n_{i,t},\;S_t=\sum_{b_i=-1}n_{i,t},
\]
with cumulative funding
\[
\Gamma_i=\sum_{s=t_i+1}^{T}(b_i q_i)\gamma_s p_s.
\]
Equity at terminal time is then written
\[
e_{i,T}=c_i+b_i q_i (p_{\hat T}-p_{t_i})+\Gamma_i,
\]
where \(\hat T=\min(T,\tau_i)\) and \(\tau_i\) is the first time maintenance margin is breached [2512.01112].

Liquidation is triggered when
\[
e_{i,t}\le \mu\,p_t\,|q_i|.
\]
A liquidation slice \(\Delta q\) realizes an execution price \(p^{\rm exec}\) and may generate bad debt
\[
D=\max\{0,\,-[e_t+b\,\Delta q\,(p^{\rm exec}-p_t)-\tau_t(\Delta q)]\}.
\]
Insurance absorbs shortfall when possible. With insurance-fund balance \(\IF_t\), realized shortfall \(D_t\), and residual shortfall
\[
R_t=(D_t-\IF_t)_+,
\]
ADL is invoked precisely when \(R_t>0\) [2512.01112].

In this setting, an ADL policy returns two objects: a severity \(\theta_t\in[0,1]\), interpreted as the fraction of \(D_t\) to socialize, and a haircut vector \(h_t=\{h_{t,i}\}_{i\in W_t}\) over the surviving winner set \(W_t=\{i:e_{i,t}>0\}\). Feasibility requires
\[
\sum_{i\in W_t} h_{t,i} e_{i,t}=\theta_t D_t
\le \sum_{i\in W_t} e_{i,t},
\]
so that no account loses more equity than it has. After the haircut, survivor equities become \((1-h_{t,i})e_{i,t}\) [2512.01112].

## 2. ADL as sequential control and online learning

A distinct formalization treats each ADL episode as an online learning problem. In that model, an ADL round \(t\) occurs whenever a residual deficit
\[
D_t=\sum_{j\in L_t}(-e_{j,t}(p^{liq,exec}_{j,t}))_+>0
\]
is encountered after liquidation and insurance. The public-data state is
\[
s_t=(\mathcal P_t, D_t, W_t, u_t, \zeta_t),
\]
where \(\mathcal P_t\) is the set of active positions, \(W_t=\{i:\mathrm{PNL}_{i,t}>0\}\) is the winner set, \(u_{i,t}=(\mathrm{PNL}_{i,t})_+\) is winner \(i\)'s positive-PNL capacity, and \(\zeta_t\) denotes auxiliary market signals such as mark price and depth summaries. The venue chooses an action
\[
a_t=(B_t,x_t),
\]
with \(B_t\in[0,U_t]\), \(U_t=\sum_{i\in W_t}u_{i,t}\), \(x_t=(x_{i,t})_{i\in W_t}\), \(0\le x_{i,t}\le u_{i,t}\), and \(\sum_{i\in W_t}x_{i,t}=B_t\). Equivalently, the action is parameterized by a severity fraction \(\theta_t=B_t/D_t\in[0,1]\) and haircut fractions \(h_{i,t}=x_{i,t}/(u_{i,t}+\epsilon)\in[0,1]\) [2602.15182].

The per-round surrogate loss combines tracking error against the ex post benchmark severity with a penalty for burden concentration. Standard static regret,
\[
\mathrm{Reg}^{static}_T=\sum_t \ell_t(x_t)-\min_{x\in X}\sum_t \ell_t(x),
\]
dynamic regret,
\[
\mathrm{Reg}^{dyn}_T=\sum_t \ell_t(x_t)-\sum_t \ell_t(x_t^\star),
\]
and policy-class regret are then defined over comparator classes [2602.15182].

For the one-dimensional severity control problem, the loss reduces to
\[
\ell_t^\theta(\theta_t)=D_t\,|\theta_t-\theta_t^{needed}|,
\qquad
\theta_t^{needed}=\min\{1,B_t^{needed}/(D_t+\epsilon)\}.
\]
If the comparator path variation is
\[
P_T^\theta=\sum_{t=2}^T |\theta_t^\star-\theta_{t-1}^\star|,
\]
then projected OGD with step size \(\eta\) satisfies
\[
\mathrm{Reg}^{dyn,\theta}_T
\le \frac{1+2P_T^\theta}{2\eta}+\frac{\eta}{2}\sum_t D_t^2,
\]
and choosing
\[
\eta^\star=\sqrt{\frac{1+2P_T^\theta}{\sum_t D_t^2}}
\]
yields
\[
\mathrm{Reg}^{dyn,\theta}_T
\le \sqrt{(1+2P_T^\theta)\cdot \sum_{t=1}^T D_t^2}.
\]
The robustness statement is explicit: adversarial deficits \(D_t\) and adversarial price moves enter only through \(\sum D_t^2\) and \(P_T^\theta\), so worst-case regret scales with episode severity and variability [2602.15182].

This framework also formalizes a limitation of queue-based ADL. Queue policies correspond to extreme-point selections on the feasible polytope and are therefore discontinuous and non-Lipschitz in their scores; fixed queues can incur \(\Omega(T)\) regret or \(\Omega(T)\) variation in effective execution slope even under smooth underlying changes. A common misconception is that ADL queues merely encode operational priority. In this formulation, they are specific control laws with unfavorable worst-case sequential behavior [2602.15182].

## 3. Risk-based optimization and the water-filling benchmark

A separate line of work casts ADL as an expected-loss minimization problem. In the single-asset isolated-margin case, the exchange must re-absorb an aggregate short exposure \(Q>0\). The remaining short accounts \(i=1,\dots,n\) have position \(q_i\ge 0\), entry price \(p_i^{(e)}>0\), and posted margin \(m_i\ge 0\). At reference price \(p_\tau>0\), an ADL allocation is \(x=(x_1,\dots,x_n)\) satisfying \(0\le x_i\le q_i\) and \(\sum_i x_i=Q\), where \(x_i\) is the quantity forcibly bought back from account \(i\). Post-ADL equity at a future close-out price \(p>0\) is
\[
e_i(x_i,p)=q_i(p_i^{(e)}-p)-x_i(p_\tau-p)+m_i.
\]
The exchange’s loss at terminal price \(p_T\) is
\[
\mathrm{loss}(x,p_T)=\sum_{i=1}^n[-e_i(x_i,p_T)]_+.
\]
Under risk neutrality, the optimization problem is
\[
\min_{x\in\mathbb R^n}
\E\Bigl[\sum_{i=1}^n (-e_i(x_i,p_T))_+\Bigr]
\quad\text{s.t.}\quad
0\le x_i\le q_i,\;\sum_i x_i=Q.
\]
[2603.15963]

The key state variable is post-ADL leverage,
\[
\ell_i(x_i)=\frac{p_\tau (q_i-x_i)}{E_i},
\qquad
E_i=e_i(x_i,p_\tau)=q_i(p_i^{(e)}-p_\tau)+m_i>0.
\]
The paper proves that, under a risk-neutral expected-loss objective, the unique optimal allocation is the unique solution of
\[
\min_{x:\,\sum x_i=Q,\;0\le x_i\le q_i}\;\max_{1\le i\le n}\ell_i(x_i).
\]
Hence the policy minimizing expected exchange loss is exactly the policy minimizing the maximum leverage among participants. The closed-form solution is the water-filling, or leverage-draining, rule
\[
x_i^\star=\Bigl(q_i-\frac{E_i}{p_\tau}t^\star\Bigr)_+,
\]
where the leverage threshold \(t^\star\) is the unique root of
\[
\sum_{i=1}^n \Bigl(q_i-\frac{E_i}{p_\tau}t\Bigr)_+=Q.
\]
Operationally, positions are reduced first for the most highly levered accounts, and leverage is progressively equalized [2603.15963].

The benchmark has several structural properties. It is distribution-free in the sense that \(x^\star\) depends only on \((q_i,E_i,p_\tau,Q)\) through the root equation. It is wash-trade resistant because round trips at prices \(\le p_\tau\) preserve \(E_i\). It is Sybil resistant because splitting an account into subaccounts never reduces the total buyback it must absorb. It is path-independent, formally \(F_{Q_1+Q_2}=F_{Q_2}\circ F_{Q_1}\). The paper further states an axiomatic uniqueness result: leverage priority together with path independence uniquely characterize the water-filling rule among monotone ADL maps [2603.15963].

In the multi-asset cross-margin case, the problem becomes genuinely multi-dimensional. Introducing asset-level shadow prices \(\lambda\in\mathbb R^d\) yields a separable dual decomposition:
\[
\phi_i(\lambda)=\min_{x_i\in[l_i,u_i]}
\{\E[\sigma_i(x_i,p_T)]+\lambda^T x_i\},
\]
and the exchange chooses \(\lambda^\star\) by maximizing
\[
g(\lambda)=-\lambda^TQ+\sum_{i=1}^n \phi_i(\lambda).
\]
This decouples an \(n\times d\) decision problem into \(n\) low-dimensional subproblems plus a \(d\)-dimensional outer search. Under a one-factor price model, the rule again becomes a clipped water-filling policy, now in factor-adjusted leverage rather than naive gross leverage. The explicit observation is that naive gross leverage can be misleading because it ignores hedging within portfolios [2603.15963].

## 4. Impossibility results and mechanism classes

The mechanism-design treatment begins from three asymptotic desiderata for a family of policies \((\pi_n)\): solvency, fairness, and revenue. Solvency is encoded by \(\sum_t R_t(\pi_n)=O_p(1)\) and \(\sup_t \Pr[R_t>0]<1\). Fairness is expressed through bounded moral hazard using the metrics
\[
\mathrm{PTSR}_n=\E[\omega_n/D_n],\qquad
\mathrm{PMR}_n=\E[\omega_n/\Delta_n],
\]
where \(\omega_n=\max_i e_{i,T}\), \(D_n=\sum_i(-e_{i,T})_+\), and \(\Delta_n=\max_i(-e_{i,T})_+\). Revenue is written as
\[
\mathrm{LTV}_n(\pi)=\Phi_n(\pi)-\mathcal D_n(\pi)\ge c_R\,\Phi_n^{\max},
\]
with \(\Phi_n\) total fee revenue and \(\mathcal D_n\) diversion to insurance. Under heavy-tail and LLN/EVT assumptions, no static policy can satisfy solvency, fairness, and revenue simultaneously [2512.01112].

The trilemma is proved by showing that each pair of desiderata asymptotically excludes the third. From fairness, total haircut must be \(B_n=O(b_n)=o(n)\), so severity vanishes. From solvency plus fairness, fee diversion must increase until net venue revenue becomes negative. From solvency plus revenue, severity must remain order one, forcing moral-hazard ratios to collapse. From fairness plus revenue, residual shortfall remains order \(n\), violating solvency. This suggests that ADL mechanism design is not a search for a universally “correct” policy, but a choice of which objective is relaxed and by how much [2512.01112].

Constructively, the literature decomposes ADL into “how much?” and “who pays?” For severity, the mechanism classes include a static cap \(\theta_t=\bar\theta\), exponential back-off \(\theta_t=\theta_0\alpha^{k_t}\), and Online Mirror Descent with convex loss
\[
f_t(\theta)= -\lambda\,\theta D_t+\mu\,(D_t-\theta D_t)_+
+\nu\,(\theta D_t-\sum_i w_{t,i})_+^2.
\]
For allocation, the classes include queue policies based on a PNL\(\times\)leverage ranking score, pro-rata haircuts proportional to equity, Risk-Aware Pro-Rata (RAP) with weights \(\rho_i=\ell_{i,T}g(\ell_{i,T})\), and joint vector mirror-descent policies over \((\theta_t,h_t)\) [2512.01112].

These classes admit sharp distributional comparisons. Pro-rata is described as the unique minimizer of any convex aggregate disutility under Schur-convex or submajorization criteria, whereas queue allocation is the unique maximizer of moral-hazard concentration. In this sense, queue-based and pro-rata mechanisms are not merely different operational conventions; they occupy opposite ends of the concentration spectrum [2512.01112].

## 5. Empirical evidence from the October 10, 2025 Hyperliquid stress episode

One empirical study reconstructs the Hyperliquid event from 21:16 to 21:27 UTC using public fills. In that replay there are \(T=16\) ADL rounds and total liquidation of approximately \(\$2.103\) billion. Holding fixed \(D_t\), \(W_t\), \(u_t\), \(p^{bk}\), and the market path, and allowing only severity and allocation to vary, the realized comparator variation is \(\widehat P_T^\theta=7.06\), which yields an instance-calibrated upper envelope
\[
\mathcal B_{inst}=\sqrt{(1+2\cdot 7.06)\cdot \sum_t D_t^2}\simeq \$129.7\text{ M}.
\]
Under this calibration, Hyperliquid’s production queue attains total objective \(L^1(\text{queue})=\$64.86\) million, or about \(50.0\%\) of the bound, with dollar overshoot \(O(\Delta)=[H_t-B_t^{needed}]_+\) summing to approximately \(\$45.0\)–\(\$51.7\) million across a markout-horizon sweep. Integer pro-rata achieves \(\$3.40\) million, or \(2.6\%\) of the same bound, with overshoot approximately \(\$3.0\) million; vector mirror descent attains \(\$4.41\) million, or \(3.4\%\); and the min-max ILP oracle reaches \(\$0.106\) million, well below \(1\%\) [2602.15182].

A second empirical study analyzes the “Black Monday” cascade on Hyperliquid from 21:16 to 21:28 UTC. It reports 161 assets, roughly \(\$2.1\) billion liquidated in 12 minutes, 40 distinct ADL clusters on-chain, approximately 34,983 individual fills, and approximately 19,337 wallets. In that dataset, the aggregate deficit is approximately \(\$304.5\) million, while the server-reported ADL queue applied a budget of \(\$705\) million, overshooting by \(\$630\) million, approximately \(8\times\) the real shortfall. Winners lost \(\$705\) million, survivors absorbed \(\$230\) million net, and the reported moral-hazard metrics are \(\mathrm{PTSR}\approx 0.04\) and \(\mathrm{PMR}\approx 0.07\) [2512.01112].

The same study evaluates counterfactual mechanisms. A smart queue capped at \(\$304\) million eliminates overshoot but still concentrates burden, leaving residual \(R\approx \$222\) million. Exponential back-off with \(\alpha\approx 0.8\) holds overshoot below \(\$1\) million, leaves \(R\approx \$218\) million, achieves \(\mathrm{PTSR}\approx 0.6\), and retains approximately \(35\%\) of winner PNL. Mirror-descent severity yields \(R\approx \$217\) million, negligible overshoot, and winners keep approximately \(38\%\) of PNL. Levered pro-rata yields \(R\approx \$216\) million and winners keep approximately \(45\%\) of PNL. Joint vector MD yields overshoot approximately zero, \(R\approx \$217\) million, winners keep approximately \(48\%\) of PNL, and best long-term revenue retention [2512.01112].

Because these studies use different replay assumptions, objectives, and calibrations, their quantitative outputs should be read as model-specific evaluations rather than interchangeable measurements. What is common across them is the direction of the comparison: production queue mechanisms overutilize ADL relative to optimized severity-and-allocation rules [2602.15182].

## 6. Implementation, trade-offs, and open directions

The implementable controllers proposed in the literature are lightweight. Severity can be controlled by vector mirror descent or by simple adaptive step-size OGD on \(\theta\); allocation can be continuous pro-rata in \(O(n)\) time or an integer-lot ILP solved in milliseconds; and the required inputs \(D_t\), \(u_{i,t}\), and prices are observable in real time on most venues. These constructions are explicitly described as not relying on discretionary overlays or external capital injections [2602.15182].

The main trade-offs are also explicit. Execution-price estimation remains a driver of ex post severity failure: under a linear impact model \(p^{liq,exec}(q)=p^{mark}\mp \alpha_t q\), estimation error in \(\alpha_t\) produces an ex post severity shortfall
\[
V_T=\sum_t [B_t^{needed}-H_t]_+,
\]
and OGD on \(\alpha_t\) controls this only up to an order bound \(O(Q^2[\alpha_{\max}\sqrt T+P_T^\alpha])\). At the policy level, \(\lambda_{fair}/\lambda_{track}\) tunes the fairness-versus-solvency-tracking tension. Convex allocation rules such as pro-rata sacrifice some queue seniority incentives, while queue policies preserve a strong priority structure at the cost of concentration and discontinuity. Replay-based evidence also assumes a fixed market path, whereas full equilibrium feedback through market-maker response and order-book resiliency remains to be integrated [2602.15182].

Risk-based ADL generalizes naturally to cross-margin and multi-asset portfolios, where exposure reduction must be allocated across correlated books using shadow prices and, in one-factor settings, factor-adjusted leverage [2603.15963]. Mechanism-design work adds further operational recommendations: monitor heavy-tail scale \(b_n\) and average deficit \(\mu_- n\); size buffers using the newsvendor rule \(K^\star=\VaR_{1-r/\kappa}(D)\); decouple scalar severity control from allocation; publish code or cryptographic commitments of the policy; monitor PTSR and PMR as real-time indicators; and consider extensions such as confidential ADL, joint clearing and ADL, and adversarial multi-round threat models [2512.01112].

A persistent misconception is that ADL is simply an exchange-specific liquidation queue. The current literature treats it more narrowly and more rigorously: as a constrained control problem over residual losses, as a risk-allocation problem over levered survivors, and as a mechanism whose desirable properties are mutually incompatible in the large. Within that framework, the central technical questions are no longer whether ADL can be avoided once residual shortfall exists, but how severity is chosen, how burden is allocated, and which objective—solvency, trader fairness, or venue revenue—is allowed to degrade.

Source: https://www.emergentmind.com/topics/auto-deleveraging-adl