Market design memorandum · 26 July 2026
A prediction-market architecture in which liquidity concentrates in a small number of parametric benchmark contracts, and idiosyncratic exposure is bought back as basis on progressively more granular nodes. Built out in full for two families — pre-release content compromise and mass-tort litigation — and sketched for four more.
Corporate event risk is not one risk. It is a systematic factor — a doctrine, a regulatory regime, an industry-wide vulnerability — multiplied by an idiosyncratic instance. Today you can only trade the two bundled together, through equity, and the bundling is catastrophically lossy.
Do not build a contract per exposure. Build a small set of imprecise, liquid benchmarks that capture the systematic factor, and let the residual trade as a quoted basis on granular nodes that nobody expects to be liquid. This is not a compromise — it is how the credit market, the retrocession market, and the cat-bond market all actually work.
Two orthogonal axes. Down the tiers is idiosyncratic decomposition — from regime to instance. Across each tier is a severity ladder — a bracket set on the loss metric. Every family below is an instantiation of this same grid.
| Tier | What it prices | Analogue in an existing market | Liquidity expectation | Venue |
|---|---|---|---|---|
| T0 Regime / doctrine | The single factor that reprices every exposure in the family at once — an appellate holding, a statute, a rule finalisation | Duration / the systematic factor in a one-factor credit model | Can be genuinely deep — every holder of the sector wants it | Order book |
| T1 Industry benchmark | Aggregate industry loss or event count crossing a threshold. Parametric. Pays regardless of whose loss it was | Industry loss warranty — "$50bn US wind." The single best analogue in the entire design | The Schelling point. All flow concentrates here by construction | Order book, DMM obligations |
| T1b Sub-benchmark | The same index sliced by vector or sector — the four-quadrant refinement | State-weighted ILWs; CDX sector sub-indices | Thinner but viable — this is where basis reduction is cheapest | Order book |
| T2 Name | Does this specific company suffer a qualifying event / record a qualifying charge | Single-name CDS. Note: 13 daily counterparties versus 160 for the index | Episodic. Quoted as a spread to T1b, not outright | Book + AMM backstop |
| T3 Instance | This title, this docket, this deal, this PDUFA date | Bespoke reinsurance; deal-contingent hedges | Effectively none. Assume zero resting liquidity | Subsidised AMM only |
An occurrence binary — "did it happen" — tells a hedger almost nothing about how much to buy. The fix is to put a bracket ladder on a loss metric at every tier, and read it as a discretised distribution. A digital's delta is the risk-neutral density at its strike (Breeden–Litzenberger), so the price difference between adjacent brackets is the probability mass in that bucket. One Underlying supports an arbitrary strike set; that separation — Underlying / Expiration Value / Payout Criterion — is the structural move that makes a ladder possible at all, and it is worth adopting verbatim from Kalshi's rulebook vocabulary.
Wherever possible, denominate the severity ladder in third-party procedural acts, not in the underlying harm. "Was the film's value impaired" is unresolvable. "Did the studio move the announced release date by ≥60 days" is a press release with a date on it. Every documented resolution scandal in this market's short history — a suit at a NATO summit, a mineral-deal agreement, a "credible" pregnancy announcement, a market on a leader leaving office who instead died — was an underspecified predicate, never a missing source.
This is the question the whole architecture turns on, and there is a real empirical answer. Cummins, Lalonde & Phillips (JFE 2004) tested index versus indemnity hedging across 255 Florida insurers — 93% of the state's insured residential property value. Going from one statewide index to four intra-state sub-indices was enough that firms in the three largest market-share quartiles could hedge "almost as effectively" with the index as with contracts settling on their own losses.
Four, not four hundred. Below is that logic run through a factor model of a studio's content-leak exposure, priced against a plausible cost hierarchy. The efficient frontier is not at the bottom of the tree.
Marginal variance removed per basis point of hedging cost
Each bar is the incremental efficiency of adding that tier to the hedge already in place. Higher is better. The sub-benchmark tier is the last one that pays for itself; the instance tier is a luxury good.
| Hedge stack | ρ to own loss | R² | Residual σ | Cum. cost (bp) | Δ var (pp) | pp per bp |
|---|---|---|---|---|---|---|
| T0 Regime only | 0.305 | 9.3% | 95.2% | 15 | 9.3 | 0.62 |
| + T1 Industry benchmark | 0.469 | 22.0% | 88.3% | 25 | 12.7 | 1.27 |
| + T1b Vendor-vector sub-index | 0.730 | 53.2% | 68.4% | 60 | 31.2 | 0.89 |
| + T2 Name node | 0.889 | 79.1% | 45.7% | 180 | 25.9 | 0.22 |
| + T3 Title node | 1.000 | 100% | 0% | 650 | 20.9 | 0.044 |
The first three tiers buy 53% of the variance for 9% of the total hedge budget (60bp of 650bp). The last two tiers buy the remaining 47% for the other 91%. Marginal efficiency peaks at the benchmark and degrades 29-fold by the time you reach the instance node.
And this is before the liquidity penalty, which is not in the cost figures. A hedger who insists on the instance node is not just paying more — it is paying more for a contract that may have no bid at all.
The motivating case, and — as it turns out — the hardest one to actually build.
| Date | Event |
|---|---|
| 12 Apr 2026 | An X account posts minute-long clips of The Legend of Aang: The Last Airbender, then unreleased; >100,000 likes within 12 hours |
| 13 Apr 2026 | Full-length version circulates. Film appears on Letterboxd's "popular this week." Counterfeit DVDs on eBay |
| Apr 2026 | Paramount investigation concludes the breach did not originate at Paramount. Source traced to Vision Media, a third-party awards-screening vendor. A 26-year-old is arrested in Singapore |
| Apr 2026 | Non-watermarked copies appear — defeating the forensic control the industry relies on |
| 24–25 Jul 2026 | Paramount pulls forward from an October Paramount+ debut to a 25 July streaming premiere, and reinstates a limited theatrical run from 24 July |
| ongoing | The alleged actor names the forthcoming series Seven Havens as an intended future target |
Roughly $80M of production cost plus marketing was exposed, and the risk was distributed across at least five balance sheets — Paramount, Avatar Studios and backend participants, the vendor, the cyber and media E&O towers above each, and downstream, the exhibitors and the franchise itself. But the loss event occurred at a node no one's cover was written on. Paramount's cyber policy insures Paramount's network. The compromise was on a vendor's server. This is precisely the indemnity-trigger perimeter problem, and a parametric benchmark contract is immune to it: it pays on a measured industry event without asking whose server it was.
The severity ladder here cannot be denominated in box office. 7 U.S.C. §1a(9) excludes from the definition of "commodity" both onions and "motion picture box office receipts (or any index, measure, value, or data related to such receipts)," and §13-1(a) makes listing one a misdemeanour. Both provisions are live in the current Code.
The history is the more important lesson. In June 2010 the CFTC approved box-office futures for two exchanges, finding them "based on commodities, not readily susceptible to manipulation, and serv[ing] an economic hedging purpose." Dodd-Frank killed them by statute one month later, at the studios' urging, with drafting broad enough to foreclose the workarounds. The contracts never traded. Your legal analysis can be entirely correct and your product can still be legislated out of existence in thirty days if you create a public price signal an organised incumbent industry hates. For this family in particular, that is the dominant risk.
A studio with $130M of at-risk value on a slate does not buy the title contract. Working up the efficiency table of §03: it buys T1 and the vendor-vector T1b in size — killing 53% of variance for 60bp — takes the name node if it prices near the model, and buys a small T3 sleeve only on the single highest-value title. The remaining ~21% residual variance is retained, deliberately, because eliminating it costs 470bp and 29× worse marginal efficiency.
Paramount cannot buy the title-level contract in size without signalling that its release plan is fragile, and it cannot sell it at all without an insider-trading problem, because the studio is the party that determines the settlement fact. Any well-drafted rulebook bars Source Agency employees and MNPI holders from trading — which excludes exactly the party with the most hedging demand.
The resolution is that the granular leg is not for the issuer. The natural buyers of T3 are the counterparties whose exposure is real but who hold no inside information: completion-bond writers, backend participants, exhibitors, the cyber and E&O carriers above the tower, and the vendor's own insurers. The issuer trades the benchmark, where no single firm has material non-public information. The ecosystem carries the residual. Design the participant taxonomy accordingly.
You asked whether to decompose by company or by lawsuit. The answer is neither.
The covariance in a litigation pool is not generated by the defendant and it is not generated by the docket. It is generated by the shared legal propositions that many cases turn on at once — a preemption holding, a §230 ruling, an admitted expert, a statute. Bayer moved +19% on one Supreme Court holding that repriced 65,000 claims. Meta fell 6.8% and Alphabet 4.2% on the same ~$6M verdict, which mattered to neither company financially and to both as precedent. Organise the hierarchy along the factor structure, not the org chart.
A note on the verdict figure. Sources disagree: one reports $6M total in the Los Angeles KGM trial ($3M compensatory apportioned Meta 70% / Google 30%, plus $3M punitive), another reports $6.2M in compensatory damages. The distinction is immaterial to the argument — at either figure the market-cap response is four orders of magnitude larger than the award — but it is exactly the kind of ambiguity a contract's Payout Criterion cannot tolerate, which is itself the point of §08. Judge Kuhl declined to overturn the verdict in June 2026; post-trial motions and appeal are pending.
Do lawsuits correlate with each other? Yes — strongly, and asymmetrically. The design answer is not to estimate the correlation and price around it. It is to make correlation itself the instrument.
List Nth-to-event contracts on a defined basket — here {Meta, Alphabet, ByteDance, Snap}, each with a marginal probability of an adverse resolution event in the window. Under a one-factor Gaussian copula, the tranche prices are a direct, monotone read on correlation. The chart is the whole argument.
Nth-to-event price versus asset correlation
Four-name basket, each name at a 45% marginal probability. As correlation rises the first-to-event gets cheaper and the all-four gets dearer — they are opposite correlation exposures written on identical underlying risk.
| Asset ρ | 1st-to-event | 2nd-to-event | 3rd-to-event | All four |
|---|---|---|---|---|
| 0.05 | 0.895 | 0.600 | 0.255 | 0.050 |
| 0.20 | 0.851 | 0.577 | 0.289 | 0.082 |
| 0.40 | 0.790 | 0.552 | 0.326 | 0.133 |
| 0.60 | 0.721 | 0.529 | 0.359 | 0.192 |
| 0.80 | 0.637 | 0.503 | 0.392 | 0.268 |
A defendant hedging its own case buys the equity tranche. First-to-event is dominated by idiosyncratic risk — it is what a single company with a single exposure actually needs, and it gets cheaper as the market's correlation estimate rises.
A diversified holder of tech equity buys the senior tranche. All-four is nearly pure doctrine risk — the systematic factor, stripped of any individual company's facts. It is the cheap, high-convexity hedge against "the law turns against the whole industry."
Both trade against the same collateral pool, and correlation is discovered rather than assumed. An observed 18¢ print on the all-four contract implies an asset correlation of 0.56 — that is a base-correlation read, and it is a number no one can observe today at any price.
"Acquired" ∧ "premium >30%" ∧ "closes within six months" are massively positively correlated. Independence pricing systematically underprices positively-correlated conjunctions and gets picked off by anyone who understands the dependence — this is exactly why correlated parlays were historically prohibited in sports betting, and why a two-leg NFL parlay at 2.64:1 against a true 3:1 carries a 12% haircut from independence pricing alone. Sportsbooks absorb this with a fat margin. A prediction market cannot, because the margin is what destroys the price-as-probability property. Price marginals and conjunctions jointly off one cost function so that correlation is a traded quantity, not an assumption.
Same grid, different instantiation. Each card gives the tiers, the Source Agency, and — most importantly — the family's distinctive correlation structure, because that is what determines whether tranching or bracketing is the right second axis.
The CFTC's own precedent list, recited in its 2010 box-office approval and requoted in its June 2026 proposal, includes "Company-Specific Merger and Acquisitions" among event contracts approved before 2010. Kalshi lists deal contracts today. So the question is not whether it is listable — it is whether a binary adds anything to merger arbitrage, which is already a functioning implicit deal-completion market.
It does, because the merger spread is a bundle. Implied completion probability is
P = (Pmkt − Pbreak) / (Pdeal − Pbreak), and
Pbreak — the unaffected price — is unobservable and contestable:
| Assumed break price | Implied P(close) |
|---|---|
| 80 (optimistic standalone) | 70.0% |
| 72 (base case) | 78.6% |
| 65 (pessimistic standalone) | 82.9% |
12.9 percentage points of the "implied probability" are pure assumption, and the spread also carries timing, financing, borrow cost, and the acquirer's own beta. A binary quotes the probability directly.
Correlation structure: single-factor and regime-driven — deals break together when the enforcement posture changes. A tranched basket of the twenty largest pending deals separates regime exposure from single-deal risk using exactly the machinery of §06.
Two things make this the family to build first. The Source Agency is a gift: SEC Item 1.05 turned corporate breach disclosure into a dated, filed, machine-readable public act. And the gap is real and acknowledged by the market itself — cyber ILS has scaled but has not solved the benchmark problem.
| Tranche | Size | Expected loss | Spread | Multiple |
|---|---|---|---|---|
| Class A | $120M | 0.82% | 7.00% | 8.54× |
| Class B | $100M | 1.31% | 9.13% | 6.97× |
| Class C | $60M | 2.05% | 10.63% | 5.18× |
Note the trigger: indemnity, not industry loss. The largest, most sophisticated cyber ILS programme in the market still cannot use a benchmark, because no credible cyber industry-loss index exists. That is the hole this family fills. And the pricing gives you a real risk-premium anchor: a benchmark binary on an 0.82%-probability event should be expected to trade near 7¢, not 0.8¢ — a 5–8.5× multiple on expected loss is what this risk clears at today. Any hedger should size on that basis, and any market designer should stop expecting tail binaries to trade at fair value.
Correlation structure: highly non-linear and concentrated on shared infrastructure. Not a single factor — a dependency graph. Tranche by shared upstream provider rather than by sector, or the basket will badly understate the joint tail.
The best Source Agencies of any family: the FDA Enforcement Report and the NHTSA recall database are both public, structured, dated, and already machine-readable. The difficulty is elsewhere.
Correlation structure — the one that breaks the single-factor model. Recall correlation is bipartite: brands on one side, suppliers on the other, connected by a sparse graph. Two competitors with no commercial relationship are perfectly correlated if they buy from the same plant. A one-factor copula is the wrong tool; the basket must be defined on the supplier node. This is also why hedging demand is concentrated in relatively few firms, which is a liquidity problem.
Today this is hedged with a straddle across the PDUFA date, which is a poor instrument: it pays for two-sided volatility the hedger does not want, bundles the approval with everything else about the company, and — critically — cannot express label scope at all, which is where most of the commercial value actually sits.
Kalshi already lists named-CEO departure contracts. The design work is entirely in the predicate.
A liquid market on "does the CEO depart" hands the board a financial payoff contingent on firing the CEO, and hands an activist a cheaper way to profit from agitating for it than buying the stock. ILWs manage exactly this by triggering on an index the buyer cannot influence. Apply the same rule: self-referential nodes belong at index level only. A sector turnover index is benign. A single-name node held in size by anyone inside the company is not.
Every documented failure in this market has been a predicate failure, not a source failure. The mechanics below are the ones that empirically prevent it.
Adopt a four-type separation as abstract types in a stable rulebook, then instantiate them in per-contract terms documents:
Then five clauses that are individually boring and collectively decisive: a first-print rule (revisions and amendments never reopen settlement); a formula-based silence fallback rather than a committee; a hard outer expiry regardless of source behaviour; settle-at-last-fair-price as the void substitute; and ex-ante clarification only, which clears the order book when published so a clarification cannot silently reprice existing exposure.
Blue Capital Re wrote an aggregate ILW incepting January 2017. The index revised Hurricane Irma upward in August 2020, triggering the contract, and it paid $3.1M nearly three years after the event. Industry loss indices have no fixed development period — four months for one storm, two years for another. Any benchmark contract in this design must hard-code a resolution cutoff, or the settlement tail is unbounded.
| Family | Primary Source Agency | Character | Verdict |
|---|---|---|---|
| Litigation | PACER docket entries; 10-K/10-Q loss contingencies; court-approved settlement orders | Exists; dated; audited; legally compelled | Ready |
| Cyber | SEC 8-K Item 1.05 and subsequent periodic filings | Exists; machine-readable; frequently amended | Ready with first-print |
| Recall | FDA Enforcement Report classification; NHTSA campaign records | Exists; structured; third-party; objective | Ready |
| Approval | FDA approval letter, Drugs@FDA, the published label | Exists; binary; scheduled in advance | Ready |
| M&A / key person | Termination and Item 5.02 8-Ks; agency press releases; HSR annual report | Exists; already used by listed contracts | Ready |
| Content compromise | None. An industry aggregator must be built. | Would need contributor data from competitors who have every incentive not to disclose | Blocked |
That last row deserves emphasis, because it inverts the intuition this memo started from. The motivating case is the least buildable family. The comparison is instructive: Japan's ILW market was described as "impaired" for years purely because loss estimates were unreliable, and only became tradable once an index provider built a credible one. Index credibility is a precondition for the benchmark existing at all — and building it here means persuading rival studios to contribute compromise data to a public count. That is a governance problem, not a market design problem, and it is the binding constraint on this family.
The CEA lets the Commission find a contract contrary to the public interest if it "involves" activity unlawful under any federal or state law. The June 2026 proposal develops that standard almost entirely through gaming and says essentially nothing about the unlawful-activity prong — no definition, no examples, no treatment of indictments or verdicts. That is an open risk. The mitigation is already in the market: Kalshi's Live Nation antitrust contract settles on a PACER docket entry, so the payout turns on a court's procedural act, not on whether the company violated the Sherman Act. Every litigation node in §05 is drafted the same way, and the T2 name node deliberately settles on a 10-K charge rather than a liability finding.
A parametric payout escapes insurance regulation — no material interest requirement, so it is not an insurance contract — but invites the gaming argument. An indemnity payout escapes the gaming argument and lands in fifty-state insurance licensing. A swap is statutorily not insurance and may not be regulated as such by any state. The ILW market resolved this in production by running both forms out of separate legal entities — one for the insurance form, one for the derivative form — and by bolting a token ultimate-net-loss warranty onto the insurance form purely so it clears the accounting scope exception. Copy the structure, not just the vocabulary.
Fully-collateralised binaries are zero-coupon instruments, so Pyes +
Pno = e−rT < 1. Two consequences, both severe for a family of
6-to-24-month corporate events:
| Horizon | Fair price of a true 50% contract | YES + NO | Wedge |
|---|---|---|---|
| 1 year | 48.04¢ | 96.08¢ | 3.92pp |
| 2 years | 46.16¢ | 92.31¢ | 7.69pp |
| 3 years | 44.35¢ | 88.69¢ | 11.31pp |
Worse, the wedge is asymmetric in capital terms. Selling the NO side of a 3¢ longshot ties up 97¢ of collateral to earn 3¢ gross — a 3.09% return on capital, below the risk-free rate, before fees. Nobody supplies that, so longshots stay structurally overpriced, and this is a mechanical generator of favourite-longshot bias entirely separate from any behavioural story. Paying a coupon on posted collateral (one venue pays roughly EFFR less 50bp on mark-to-market value, ~3.13% currently) lifts that same trade to 6.22% and makes the tail supplyable. For a corporate-event market this is not a marketing feature; it is a precondition, and it is doubly load-bearing for conditional nodes, where most collateral is eventually refunded having earned nothing.
A fee proportional to p(1−p) is theoretically right — that is exactly the market maker's
per-contract variance — but it means buyers of sub-10¢ contracts lose more than 60% of their money to
fees. Corporate tail events live at 1–5¢. The high strikes on a severity ladder, which are precisely
the catastrophe protection a hedger needs, are the least economic to trade under the standard schedule.
This needs an explicit carve-out: a flat or capped fee in the tail, or a minimum-tick regime, accepting
worse maker economics there in exchange for the ladder being usable at all.
Every venue with real volume uses an order book; automated market makers are bootstrap technology. So: benchmarks on a book with designated market makers and maker rebates that actually work, and the long tail on a cost-function maker with a promotion rule — graduate a node to the book once cumulative volume crosses a threshold. A logarithmic scoring rule is the right family for the tail specifically because of its locality: a conditional trade on a child node leaves the parent's price unchanged, which is the mathematical foundation of any hierarchy. And its subsidy is bounded and sub-additive, so granular nodes can be quoted off the same capital that supports the benchmark rather than splitting fixed order flow.
| b | Move | Shares | Cash cost to mover | Max operator subsidy |
|---|---|---|---|---|
| 5,000 | 10¢ → 20¢ | 4,055 | $589 | $3,466 |
| 25,000 | 10¢ → 20¢ | 20,273 | $2,945 | $17,329 |
| 25,000 | 3¢ → 6¢ | 18,114 | $785 | $17,329 |
| 100,000 | 10¢ → 20¢ | 81,093 | $11,778 | $69,315 |
A 260-node tail at b = 25,000 carries a worst-case total subsidy of roughly
$4.5M. That is a cheque a serious operator can write, and it is the single clearest argument for
running the granular tier on a subsidised maker rather than hoping for organic two-sided flow.
Quote T3 as a spread to T2, and T2 as a spread to T1b — never as independent outright prices. This is the index-skew mechanism, and it is what keeps the granular legs tethered to the benchmark. The precedent is unambiguous: a sub-denominated contract on an identical reference at a fixed integral ratio thrives (micro futures are now 40% of one exchange's equity index volume), while a differently-referenced contract with no linking mechanism dies. One exchange delisted a micro FX contract explicitly for "lacking fungibility" with its standard contract. When single stock futures were relaunched in July 2026, the design was 55 names and two expiries with a basis-trade mechanism built in from day one — against a predecessor that listed 12,500 symbols and died.
Index-versus-constituent arbitrage in credit persistently fails to close, on leg count, clearing asymmetry, and capital charges — regulation alone moves the breakeven by ~84bp. And industry-index cat bonds traded at a widening premium to other trigger types for four straight years on nothing but supply and demand. A non-zero basis is what compensates makers for warehousing granular risk. You may not want to arbitrage it to zero.
Scored on four axes. The ordering is not the ordering of intellectual interest.
| # | Family | Source | Value-add | Liquidity | Legal risk | Read |
|---|---|---|---|---|---|---|
| 1 | Cyber | Strong | Large | Medium | Low | Best combination. Item 1.05 gives a clean source; the leading cyber cat bond is still indemnity-triggered at $1bn, which is the gap. Start here. |
| 2 | Litigation | Strong | Very large | Medium | High | $20–50bn of exposure with no hedge in existence, and the tranche structure is genuinely novel. But the unlawful-activity prong is undeveloped and the doctrine nodes are the longest-dated and worst-calibrated. |
| 3 | Approval | Strong | Moderate | Good | Low | Dates are known in advance, which concentrates flow naturally. Straddles already work for the binary; the label-scope ladder is the real unmet need. |
| 4 | M&A | Strong | Small | Good | Very low | Highest feasibility, lowest value-add — explicit CFTC precedent and live listings, but merger arb already does most of this. The timing ladder and cause-of-death decomposition are the additive parts. |
| 5 | Recall | Strong | Moderate | Thin | Low | Excellent sources, real gap, but hedging demand sits in few firms and bipartite supplier correlation resists the standard basket machinery. |
| 6 | Content compromise | None | Large | Thin | High | The motivating case and the hardest build: no index exists, the hedger population is small and mostly conflicted, and a statutory ban on a closely adjacent measure sits one drafting error away. |
Six failure modes, roughly in order of how likely they are to be the actual cause of death.
The box-office precedent is the template and it is unambiguous: the agency approved the contracts on the merits, and an organised industry got Congress to override it inside thirty days, with drafting broad enough to kill the workarounds. A public price on "will this company lose its case" or "will this film leak" creates a signal that well-organised incumbents will fight. The binding risk is legislative, it arrives faster than litigation, and no amount of correct legal analysis defends against it.
2,893 pending cases is not 2,893 contracts. The evidence against proliferation is overwhelming and current: single-name credit default swaps have roughly 13 counterparties active on a given day versus 160 for the index; fewer than 3% of over a thousand corporate reference entities average more than ten trades a day; the single-stock futures venue that listed 12,500 symbols died, and its best full year was about two days of one index-futures complex. Most damningly, auto-generated combinatorial contracts on a live venue today show literally zero volume, zero open interest and zero resting liquidity — mechanically enumerating a product space produces contracts nobody trades.
Build small. Six families, four sub-benchmarks each, five strikes. And monitor depth, not spread — quoted spread is a lagging indicator of a fragmenting market, depth breaks first, and tipping accelerates roughly sevenfold once share crosses the threshold.
This is structural, not incidental. The party with the most demand for a granular corporate-event hedge is usually the party that determines the settlement fact. Any credible rulebook bars Source Agency employees and MNPI holders from trading, which excludes them by construction. The three partial answers: settle only on already-public third-party acts; push the issuer's hedging to the benchmark tier where no single firm holds material information; and let the ecosystem — insurers, participants, counterparties, suppliers — carry the granular tier. None of the three is complete, and a pre-cleared, disclosed, volume-capped hedging programme on the model of a 10b5-1 plan is probably required.
A market on a CEO's departure pays a board for firing them. A market on whether a company settles pays plaintiffs' counsel for a particular litigation posture. Industry loss warranties handle this precisely by triggering on an index the buyer cannot move — which is a design rule, not an accident: self-referential nodes belong at index level only, and granular nodes must settle on third-party acts. Where a node is unavoidably self-referential, the discipline has to come from the source being an audited legal filing.
Across 1,787 markets and half a million transactions, calibration degrades measurably with horizon — reasonably good near expiry, significantly biased for distant events, with realised frequency of 15.3% at a 20¢ price. Corporate events are 6-to-24-month horizons, and the T0 doctrine nodes — the most valuable contracts in this whole design — are the longest-dated and therefore the worst-calibrated. Mitigations are partial: pay interest on collateral, report the normalised implied probability rather than the raw price, and quote a term structure of nodes so the short end disciplines the long end, rather than listing one distant binary.
There is a documented case of exactly the feedback loop this design must avoid: a Treasury-adjacent futures contract went from ~2 million contracts a year to under 10,000 — a 99.5% collapse — because delivery options let the deliverable set drift away from the risk hedgers actually held, and the authors found hedging effectiveness fell in parallel with volume. Rising basis risk drives hedgers out, which kills liquidity, which raises basis risk. It is positive feedback, not a one-shot design error. The defence is to measure realised hedging effectiveness on the benchmark continuously and treat a decline in it as an existential signal, not a marketing problem.
Two closing observations, both slightly against the grain of the brief. First, the family that inspired this — pre-release content compromise — is the least buildable of the six, because no loss index exists and the studios have no incentive to create one; the framework survives the finding, but the first product should be cyber. Second, the most valuable single contract in the entire design is not a granular one. It is a T0 doctrine node — "does the appellate court hold X" — which is cheap to list, needs no index infrastructure, has an unimpeachable Source Agency in the docket, and is the only instrument that would let a diversified holder separate legal-regime risk from everything else it owns. That contract does not exist, and nothing in the law appears to prevent it.