Market design memorandum · 26 July 2026

Hedging corporate event risk inside a hierarchy

A prediction-market architecture in which liquidity concentrates in a small number of parametric benchmark contracts, and idiosyncratic exposure is bought back as basis on progressively more granular nodes. Built out in full for two families — pre-release content compromise and mass-tort litigation — and sketched for four more.

  1. The thesis in three numbers
  2. The generic architecture
  3. How granular is granular enough
  4. Family I — content compromise
  5. Family II — litigation
  6. Correlation as a traded quantity
  7. Four more families
  8. Contract mechanics & resolution
  9. Microstructure & capital
  10. Feasibility ranking
  11. What kills this

01The thesis in three numbers

Corporate event risk is not one risk. It is a systematic factor — a doctrine, a regulatory regime, an industry-wide vulnerability — multiplied by an idiosyncratic instance. Today you can only trade the two bundled together, through equity, and the bundling is catastrophically lossy.

~22,000×
Ratio of Meta's market-cap loss to the verdict that caused it
A ~$6M jury award on 25 Mar 2026 took $135bn off Meta's capitalisation the next day. Equity is not a hedge for legal risk; it is a lever with unknowable gearing.
+19%
Bayer's one-day move on a single Supreme Court holding
June 2026 FIFRA preemption ruling repriced ~65,000 pending Roundup claims simultaneously — the largest single-day gain since 2003. One node, one factor, the whole pool.
0.6bp / 35bp
Bid–ask on index CDS versus on a better tracker
CDX traded $13.7tn at 0.6bp; iBoxx TRS — materially lower tracking error to cash — traded $17bn at 35bp. Concentration of flow buys spread. Precision of the reference costs it.
The design consequence

Do not build a contract per exposure. Build a small set of imprecise, liquid benchmarks that capture the systematic factor, and let the residual trade as a quoted basis on granular nodes that nobody expects to be liquid. This is not a compromise — it is how the credit market, the retrocession market, and the cat-bond market all actually work.

02The generic architecture

Two orthogonal axes. Down the tiers is idiosyncratic decomposition — from regime to instance. Across each tier is a severity ladder — a bracket set on the loss metric. Every family below is an instantiation of this same grid.

The five-tier template. Tier names are generic; each family instantiates them differently. Cost figures are the modelled round-trip in the worked example of §03 and are indicative, not quoted markets.
TierWhat it pricesAnalogue in an existing marketLiquidity expectationVenue
T0 Regime / doctrineThe single factor that reprices every exposure in the family at once — an appellate holding, a statute, a rule finalisationDuration / the systematic factor in a one-factor credit modelCan be genuinely deep — every holder of the sector wants itOrder book
T1 Industry benchmarkAggregate industry loss or event count crossing a threshold. Parametric. Pays regardless of whose loss it wasIndustry loss warranty — "$50bn US wind." The single best analogue in the entire designThe Schelling point. All flow concentrates here by constructionOrder book, DMM obligations
T1b Sub-benchmarkThe same index sliced by vector or sector — the four-quadrant refinementState-weighted ILWs; CDX sector sub-indicesThinner but viable — this is where basis reduction is cheapestOrder book
T2 NameDoes this specific company suffer a qualifying event / record a qualifying chargeSingle-name CDS. Note: 13 daily counterparties versus 160 for the indexEpisodic. Quoted as a spread to T1b, not outrightBook + AMM backstop
T3 InstanceThis title, this docket, this deal, this PDUFA dateBespoke reinsurance; deal-contingent hedgesEffectively none. Assume zero resting liquiditySubsidised AMM only

The severity ladder is what makes it a hedge rather than a bet

An occurrence binary — "did it happen" — tells a hedger almost nothing about how much to buy. The fix is to put a bracket ladder on a loss metric at every tier, and read it as a discretised distribution. A digital's delta is the risk-neutral density at its strike (Breeden–Litzenberger), so the price difference between adjacent brackets is the probability mass in that bucket. One Underlying supports an arbitrary strike set; that separation — Underlying / Expiration Value / Payout Criterion — is the structural move that makes a ladder possible at all, and it is worth adopting verbatim from Kalshi's rulebook vocabulary.

The drafting rule that does the most work

Wherever possible, denominate the severity ladder in third-party procedural acts, not in the underlying harm. "Was the film's value impaired" is unresolvable. "Did the studio move the announced release date by ≥60 days" is a press release with a date on it. Every documented resolution scandal in this market's short history — a suit at a NATO summit, a mineral-deal agreement, a "credible" pregnancy announcement, a market on a leader leaving office who instead died — was an underspecified predicate, never a missing source.

03How granular is granular enough

This is the question the whole architecture turns on, and there is a real empirical answer. Cummins, Lalonde & Phillips (JFE 2004) tested index versus indemnity hedging across 255 Florida insurers — 93% of the state's insured residential property value. Going from one statewide index to four intra-state sub-indices was enough that firms in the three largest market-share quartiles could hedge "almost as effectively" with the index as with contracts settling on their own losses.

Four, not four hundred. Below is that logic run through a factor model of a studio's content-leak exposure, priced against a plausible cost hierarchy. The efficient frontier is not at the bottom of the tree.

Marginal variance removed per basis point of hedging cost

Each bar is the incremental efficiency of adding that tier to the hedge already in place. Higher is better. The sub-benchmark tier is the last one that pays for itself; the instance tier is a luxury good.

Hedge stackρ to own lossResidual σCum. cost (bp)Δ var (pp)pp per bp
T0 Regime only0.3059.3%95.2%159.30.62
+ T1 Industry benchmark0.46922.0%88.3%2512.71.27
+ T1b Vendor-vector sub-index0.73053.2%68.4%6031.20.89
+ T2 Name node0.88979.1%45.7%18025.90.22
+ T3 Title node1.000100%0%65020.90.044
Factor loadings are assumed, chosen to reflect the Airbender post-mortem in which the dominant driver was a third-party vendor. Cost hierarchy is calibrated to the observed benchmark-versus-granular spread ratios in credit and retrocession, not to quoted markets. The shape is the finding; the levels are illustrative.
The result

The first three tiers buy 53% of the variance for 9% of the total hedge budget (60bp of 650bp). The last two tiers buy the remaining 47% for the other 91%. Marginal efficiency peaks at the benchmark and degrades 29-fold by the time you reach the instance node.

And this is before the liquidity penalty, which is not in the cost figures. A hedger who insists on the instance node is not just paying more — it is paying more for a contract that may have no bid at all.

04Family I — pre-release content compromise

The motivating case, and — as it turns out — the hardest one to actually build.

What happened

Sources: Hollywood Reporter, Variety, Slate, NickALive (Apr–Jul 2026). The $80M production figure is press-reported, not a company disclosure.
DateEvent
12 Apr 2026An X account posts minute-long clips of The Legend of Aang: The Last Airbender, then unreleased; >100,000 likes within 12 hours
13 Apr 2026Full-length version circulates. Film appears on Letterboxd's "popular this week." Counterfeit DVDs on eBay
Apr 2026Paramount investigation concludes the breach did not originate at Paramount. Source traced to Vision Media, a third-party awards-screening vendor. A 26-year-old is arrested in Singapore
Apr 2026Non-watermarked copies appear — defeating the forensic control the industry relies on
24–25 Jul 2026Paramount pulls forward from an October Paramount+ debut to a 25 July streaming premiere, and reinstates a limited theatrical run from 24 July
ongoingThe alleged actor names the forthcoming series Seven Havens as an intended future target

Why every existing hedge missed

Roughly $80M of production cost plus marketing was exposed, and the risk was distributed across at least five balance sheets — Paramount, Avatar Studios and backend participants, the vendor, the cyber and media E&O towers above each, and downstream, the exhibitors and the franchise itself. But the loss event occurred at a node no one's cover was written on. Paramount's cyber policy insures Paramount's network. The compromise was on a vendor's server. This is precisely the indemnity-trigger perimeter problem, and a parametric benchmark contract is immune to it: it pays on a measured industry event without asking whose server it was.

A hard statutory constraint, specific to this family

The severity ladder here cannot be denominated in box office. 7 U.S.C. §1a(9) excludes from the definition of "commodity" both onions and "motion picture box office receipts (or any index, measure, value, or data related to such receipts)," and §13-1(a) makes listing one a misdemeanour. Both provisions are live in the current Code.

The history is the more important lesson. In June 2010 the CFTC approved box-office futures for two exchanges, finding them "based on commodities, not readily susceptible to manipulation, and serv[ing] an economic hedging purpose." Dodd-Frank killed them by statute one month later, at the studios' urging, with drafting broad enough to foreclose the workarounds. The contracts never traded. Your legal analysis can be entirely correct and your product can still be legislated out of existence in thirty days if you create a public price signal an organised incumbent industry hates. For this family in particular, that is the dominant risk.

The hierarchy

T0Regime
Does a mandatory vendor-security certification standard (TPN or successor) become a condition of major-studio content delivery contracts by YE2027? / Does federal pre-release content protection legislation enact?
Source: Federal Register · MPA published standard · congress.gov. Who buys: anyone long the whole content complex.
T1CLX — Content Leak Index
Qualifying pre-release content compromise events across MPA member studios and the top six streamers in calendar year Y ≥ N
Underlying: event count published by a designated industry aggregator. This body does not exist and must be built — see §10.
Ladder: N ≥ 1 · ≥ 2 · ≥ 3 · ≥ 5 · ≥ 8
T1bCLX by vector — the four quadrants
(a) vendor / post-production chain · (b) studio internal network · (c) distribution & screener · (d) insider or physical
Paramount's realised exposure was almost entirely (a). A vector-weighted index is where basis reduction is cheapest — this is the Cummins–Lalonde–Phillips quadrant result applied.
T1bVendor-chain node — cross-family
Is any TPN-certified vendor publicly identified as the source of a qualifying compromise in year Y?
This node is shared with the cyber family (§07). Counterparty-chain risk is what actually detonated here, and it is a single factor across both taxonomies.
T2Name
Does Paramount Skydance suffer ≥1 qualifying content compromise event in FY2026?
Ladder on count: ≥1 · ≥2 · ≥3
T3Instance — occurrence
Is a full-length unauthorised copy of a named title publicly available ≥30 days before its then-announced premiere date?
Source: two of three named anti-piracy monitoring services, plus the announced date as of contract listing.
T3Instance — severity, on the studio's response
Release date advanced by ≥60 days · distribution model changed (streaming-only → theatrical or vice versa) · premiere occurs before a stated date · title withdrawn from award consideration
Source: company press release / 8-K, first print. Why: a leak's economic severity is unmeasurable and box-office-denominated ladders are illegal. The studio's response is a dated, unambiguous public act, and it is tightly correlated with severity. This substitution is the single most important drafting move in the family.

The basis walk

A studio with $130M of at-risk value on a slate does not buy the title contract. Working up the efficiency table of §03: it buys T1 and the vendor-vector T1b in size — killing 53% of variance for 60bp — takes the name node if it prices near the model, and buys a small T3 sleeve only on the single highest-value title. The remaining ~21% residual variance is retained, deliberately, because eliminating it costs 470bp and 29× worse marginal efficiency.

And here is the deepest problem in the whole design

Paramount cannot buy the title-level contract in size without signalling that its release plan is fragile, and it cannot sell it at all without an insider-trading problem, because the studio is the party that determines the settlement fact. Any well-drafted rulebook bars Source Agency employees and MNPI holders from trading — which excludes exactly the party with the most hedging demand.

The resolution is that the granular leg is not for the issuer. The natural buyers of T3 are the counterparties whose exposure is real but who hold no inside information: completion-bond writers, backend participants, exhibitors, the cyber and E&O carriers above the tower, and the vendor's own insurers. The issuer trades the benchmark, where no single firm has material non-public information. The ecosystem carries the residual. Design the participant taxonomy accordingly.

05Family II — mass-tort and platform litigation

You asked whether to decompose by company or by lawsuit. The answer is neither.

Decompose by adjudicated proposition, then by track, then by name, then by docket

The covariance in a litigation pool is not generated by the defendant and it is not generated by the docket. It is generated by the shared legal propositions that many cases turn on at once — a preemption holding, a §230 ruling, an admitted expert, a statute. Bayer moved +19% on one Supreme Court holding that repriced 65,000 claims. Meta fell 6.8% and Alphabet 4.2% on the same ~$6M verdict, which mattered to neither company financially and to both as precedent. Organise the hierarchy along the factor structure, not the org chart.

Where this litigation actually stands

2,893
Cases pending in MDL 3047
N.D. Cal., Judge Yvonne Gonzalez Rogers; 3,068 filed to date. Plus JCCP 5255 before Judge Carolyn Kuhl in Los Angeles.
~800 + 42
School-district suits, and state AGs
Three structurally distinct tracks — personal injury, public nuisance, consumer-protection penalties — with different correlation structures and wildly different severity.
$20–50bn
Sell-side aggregate settlement range
JPMorgan and Goldman cited "unquantifiable tail risk" post-verdict. Four states' penalty demand ahead of the August 2026 Oakland trial is $1.4tn — a per-violation arithmetic Meta calls without analogue.
Jan 2026
Snap and TikTok settled — before the first verdict
Snap 22 Jan, TikTok 27 Jan, both confidential, both ahead of the KGM state trial. A dated, observable instance of bellwether signalling driving settlement.

A note on the verdict figure. Sources disagree: one reports $6M total in the Los Angeles KGM trial ($3M compensatory apportioned Meta 70% / Google 30%, plus $3M punitive), another reports $6.2M in compensatory damages. The distinction is immaterial to the argument — at either figure the market-cap response is four orders of magnitude larger than the award — but it is exactly the kind of ambiguity a contract's Payout Criterion cannot tolerate, which is itself the point of §08. Judge Kuhl declined to overturn the verdict in June 2026; post-trial motions and appeal are pending.

The hierarchy

T0Doctrine — where almost all the systematic risk lives
Does a federal appellate court hold that §230 bars design-defect claims against a platform, by date X? · Does SCOTUS grant certiorari on platform design liability by 2028? · Does a federal statute preempting state platform-design claims enact by 2028?
Source: PACER docket entry · Supreme Court order list · congress.gov. Who buys: any diversified holder of large-cap tech equity. This is the contract that does not exist and that everyone needs.
T1Pool benchmark
Aggregate publicly-disclosed resolution value across all youth-harm defendants ≥ $X by date Y
Source: defendants' own 10-K/10-Q loss-contingency disclosures plus court-approved settlement orders — public, dated, auditable, and already a legal obligation. This is the strongest Source Agency of any family in this memo.
Ladder: $5bn · $15bn · $30bn · $50bn · $100bn — bracketing the $20–50bn analyst range
T1bBy track — the answer to "by lawsuit or by company"
(a) personal injury MDL/JCCP · (b) school-district public nuisance · (c) state AG consumer-protection penalties · (d) follow-on securities and derivative suits
These are not the same risk. A $300k–$900k severe-injury claim and a $1.4tn statutory-penalty demand share a defendant and nothing else — different triggers, different caps, different correlation, different insurance response. Track is a more informative slice than defendant.
T2Name
Does Meta record cumulative charges ≥ $X for youth-harm matters through FY2027?
Settles on the 10-K, not on a finding of liability — a deliberate choice. It keeps the contract clear of the CEA's "activity unlawful under Federal or State law" prong, which the CFTC's June 2026 proposal leaves almost entirely undeveloped and which is the largest unresolved legal risk in this family.
Ladder: ≥$1bn · ≥$5bn · ≥$15bn · ≥$30bn
T3Instance
Is the KGM verdict affirmed on appeal? · Does the Oakland state-AG trial return a plaintiff verdict? · Does Meta resolve the 42-state action before verdict?
Source: PACER. Precedent exists — Kalshi already lists a specific company's DOJ antitrust case settling on pacer.uscourts.gov.

06Correlation as a traded quantity

Do lawsuits correlate with each other? Yes — strongly, and asymmetrically. The design answer is not to estimate the correlation and price around it. It is to make correlation itself the instrument.

What drives ρ up

  • Shared doctrine. One preemption or §230 holding binds every case in the pool
  • One judge, one record. An MDL concentrates Daubert and discovery rulings into single decisions
  • Bellwether signalling. The KGM verdict changed the settlement value of every case — which is why Snap and TikTok settled two months before it
  • A shared expert bench and a shared scientific literature
  • Common legislative exposure and a common insurance market
  • Shared upstream node — one ingredient supplier, one vendor, one active molecule

What keeps ρ down

  • Individual causation. A specific plaintiff's own history is irreducibly idiosyncratic
  • Venue and jury pool
  • Defendant-specific documents. Meta's internal research is not Snap's
  • Balance sheet and appetite. Two defendants facing identical law settle at different numbers
  • Insurance tower depth and attachment
  • Restructuring optionality — a divisional-merger or Chapter 11 path is available to some defendants and not others

Tranche the basket

List Nth-to-event contracts on a defined basket — here {Meta, Alphabet, ByteDance, Snap}, each with a marginal probability of an adverse resolution event in the window. Under a one-factor Gaussian copula, the tranche prices are a direct, monotone read on correlation. The chart is the whole argument.

Nth-to-event price versus asset correlation

Four-name basket, each name at a 45% marginal probability. As correlation rises the first-to-event gets cheaper and the all-four gets dearer — they are opposite correlation exposures written on identical underlying risk.

1st-to-event 2nd-to-event 3rd-to-event All four
Asset ρ1st-to-event2nd-to-event3rd-to-eventAll four
0.050.8950.6000.2550.050
0.200.8510.5770.2890.082
0.400.7900.5520.3260.133
0.600.7210.5290.3590.192
0.800.6370.5030.3920.268
One-factor Gaussian copula, 400,000 simulations per point, marginal probability 45% per name. Over this range the all-four contract multiplies 5.4× while the first-to-event falls 29% — the senior tranche is the correlation instrument. Correlation here is an asset correlation in the latent factor, not a correlation of outcomes.
Why this solves the problem rather than restating it

A defendant hedging its own case buys the equity tranche. First-to-event is dominated by idiosyncratic risk — it is what a single company with a single exposure actually needs, and it gets cheaper as the market's correlation estimate rises.

A diversified holder of tech equity buys the senior tranche. All-four is nearly pure doctrine risk — the systematic factor, stripped of any individual company's facts. It is the cheap, high-convexity hedge against "the law turns against the whole industry."

Both trade against the same collateral pool, and correlation is discovered rather than assumed. An observed 18¢ print on the all-four contract implies an asset correlation of 0.56 — that is a base-correlation read, and it is a number no one can observe today at any price.

The corollary: never price a conjunction as a product of marginals

"Acquired" ∧ "premium >30%" ∧ "closes within six months" are massively positively correlated. Independence pricing systematically underprices positively-correlated conjunctions and gets picked off by anyone who understands the dependence — this is exactly why correlated parlays were historically prohibited in sports betting, and why a two-leg NFL parlay at 2.64:1 against a true 3:1 carries a 12% haircut from independence pricing alone. Sportsbooks absorb this with a fat margin. A prediction market cannot, because the margin is what destroys the price-as-probability property. Price marginals and conjunctions jointly off one cost function so that correlation is a traded quantity, not an assumption.

07Four more families

Same grid, different instantiation. Each card gives the tiers, the Source Agency, and — most importantly — the family's distinctive correlation structure, because that is what determines whether tranching or bracketing is the right second axis.

M&A / deal break — the family with the strongest legal precedent and the smallest gap

The CFTC's own precedent list, recited in its 2010 box-office approval and requoted in its June 2026 proposal, includes "Company-Specific Merger and Acquisitions" among event contracts approved before 2010. Kalshi lists deal contracts today. So the question is not whether it is listable — it is whether a binary adds anything to merger arbitrage, which is already a functioning implicit deal-completion market.

It does, because the merger spread is a bundle. Implied completion probability is P = (Pmkt − Pbreak) / (Pdeal − Pbreak), and Pbreak — the unaffected price — is unobservable and contestable:

Same market price, same deal price, three views of the downside. The spread cannot distinguish "the deal is riskier" from "the standalone is worth less."
Assumed break priceImplied P(close)
80 (optimistic standalone)70.0%
72 (base case)78.6%
65 (pessimistic standalone)82.9%

12.9 percentage points of the "implied probability" are pure assumption, and the spread also carries timing, financing, borrow cost, and the acquirer's own beta. A binary quotes the probability directly.

T0Regime
Second-request rate for US deals >$1bn in FY2027 ≥ X% · Are the merger guidelines revised by date Y?
Source: FTC/DOJ annual HSR report · Federal Register.
T1Deal-break count index
≥ N announced US deals with equity value >$5bn terminated without closing in calendar year Y
Ladder: N ≥ 1 · ≥ 3 · ≥ 5 · ≥ 8 · ≥ 12
Source: termination 8-Ks against a published index constituent list fixed at listing.
T1bBy reviewing agency and by sector
FTC vs DOJ vs CFIUS vs sectoral regulator; tech / healthcare / energy / financials
T2Named deal, with a timing ladder
Does the ABC/XYZ merger close by 31 Mar / 30 Jun / 30 Sep / 31 Dec?
The timing ladder is the discretised distribution of the closing date — the thing merger spreads express worst, because a wide spread on a slow deal and a narrow spread on a risky deal are observationally similar.
T3Cause of death
Terminated following: a second request · a filed DOJ/FTC complaint · financing failure · shareholder vote failure · an asserted MAC · CFIUS
Source: the termination 8-K plus the agency's own press release. This is the decomposition deal-contingent hedges price implicitly and nobody can trade explicitly.

Correlation structure: single-factor and regime-driven — deals break together when the enforcement posture changes. A tranched basket of the twenty largest pending deals separates regime exposure from single-deal risk using exactly the machinery of §06.

Cyber & data breach — the best combination of feasibility and genuine gap

Two things make this the family to build first. The Source Agency is a gift: SEC Item 1.05 turned corporate breach disclosure into a dated, filed, machine-readable public act. And the gap is real and acknowledged by the market itself — cyber ILS has scaled but has not solved the benchmark problem.

Beazley's PoleStar Re 2026-1, upsized to $280M across three tranches — fourth takedown under the programme. Attachment $1bn, per-occurrence, through end-2028.
TrancheSizeExpected lossSpreadMultiple
Class A$120M0.82%7.00%8.54×
Class B$100M1.31%9.13%6.97×
Class C$60M2.05%10.63%5.18×

Note the trigger: indemnity, not industry loss. The largest, most sophisticated cyber ILS programme in the market still cannot use a benchmark, because no credible cyber industry-loss index exists. That is the hole this family fills. And the pricing gives you a real risk-premium anchor: a benchmark binary on an 0.82%-probability event should be expected to trade near 7¢, not 0.8¢ — a 5–8.5× multiple on expected loss is what this risk clears at today. Any hedger should size on that basis, and any market designer should stop expecting tail binaries to trade at fair value.

T0Systemic single points of failure
Does a single cyber event cause ≥$X of aggregate insured loss? · Does a named hyperscaler region suffer >Y hours of unavailability? · Is a top-five identity provider compromised?
The Change Healthcare / CrowdStrike class of event. This is the node that a diversified corporate treasury actually wants and cannot buy.
T1Cyber industry loss index
Aggregate insured cyber loss in year Y ≥ $X
Ladder: $1bn · $5bn · $10bn · $20bn — anchored to PoleStar's $1bn attachment and the ILW rungs
T1bBy vector and by sector
Ransomware · third-party/supply-chain · cloud outage · data exfiltration; financials / health / industrial / media
The supply-chain sub-index is the shared node with the content family (§04) — Vision Media was a vendor breach. Cross-family factors should be listed once, not twice.
T2Name
Does Company X file an Item 1.05 8-K materiality determination in FY2026?
First-print rule is critical here — Item 1.05 filings are frequently amended, and a contract that reopens on amendment has an unbounded settlement tail.
T3Severity ladder
Disclosed remediation cost ≥ $X in a subsequent 10-Q · operational disruption ≥ N days · regulatory penalty imposed
Source: the company's own subsequent periodic filing. Self-referential, but the filing is an audited legal obligation, which is the strongest available discipline.

Correlation structure: highly non-linear and concentrated on shared infrastructure. Not a single factor — a dependency graph. Tranche by shared upstream provider rather than by sector, or the basket will badly understate the joint tail.

Product recall & safety — excellent sources, awkward correlation

The best Source Agencies of any family: the FDA Enforcement Report and the NHTSA recall database are both public, structured, dated, and already machine-readable. The difficulty is elsewhere.

T0Enforcement intensity
Class I recall count in FY2027 ≥ N · NHTSA opens ≥ N new defect investigations · a named agency's inspection cadence crosses a threshold
T1Sector recall index
Recall events, or units affected, by sector in year Y ≥ N
Sectors: food · pharma · medical device · automotive · consumer durables
T1bBy supply-chain node — the distinctive slice
Does any recall in year Y trace to a named upstream supplier, contract manufacturer, or active ingredient source?
This is where the family's correlation actually lives. One contaminated ingredient recalls across forty brands simultaneously.
T2Name
Does Company X announce ≥1 Class I recall in FY2026?
Source: FDA Enforcement Report classification / NHTSA campaign number. Objective, third-party, dated.
T3Instance escalation ladder
Units affected ≥ N · recall expanded after initial announcement · consent decree entered · import alert issued · facility placed under warning letter
The escalation ladder matters more than the initial event: most recall cost is in the expansion, not the announcement.

Correlation structure — the one that breaks the single-factor model. Recall correlation is bipartite: brands on one side, suppliers on the other, connected by a sparse graph. Two competitors with no commercial relationship are perfectly correlated if they buy from the same plant. A one-factor copula is the wrong tool; the basket must be defined on the supplier node. This is also why hedging demand is concentrated in relatively few firms, which is a liquidity problem.

Regulatory approval and key person — the two cleanest binaries, already partly listed

Approval (FDA as the worked case)

Today this is hedged with a straddle across the PDUFA date, which is a poor instrument: it pays for two-sided volatility the hedger does not want, bundles the approval with everything else about the company, and — critically — cannot express label scope at all, which is where most of the commercial value actually sits.

T0Regime
CDER novel approvals in CY2027 ≥ N · agency on-time action rate ≥ X% · does a named review pathway survive reauthorisation?
T1By therapeutic area and pathway
Approval rate for a stated cohort of pending applications in a therapeutic area / review designation
T2Named application
Does Company X's NDA/BLA receive an approval action on or before its PDUFA goal date?
Source: FDA approval letter / Drugs@FDA, first print. Add a distinct node for action taken but not approval — a complete response letter is a different event from a delay.
T3Label-scope ladder — the real prize
Approved for the full requested indication · boxed warning imposed · REMS required · narrower population than requested · accelerated rather than full approval
Objectively resolvable from the published label, and completely inexpressible in an options straddle. This is the clearest case in the whole memo of a granular node that has no existing substitute.

Key person

Kalshi already lists named-CEO departure contracts. The design work is entirely in the predicate.

T1Turnover index
S&P 500 CEO departures in CY2027 ≥ N, by sector
T2Name
Does the named individual cease to serve as CEO of Company X, for any reason, by date D?
The phrasing is load-bearing. A market framed on a leader "leaving office" collided with that leader dying and produced the most notorious settlement dispute in the industry's short history. Draft for exhaustion, and settle on the 8-K Item 5.02.
T3Cause ladder — with a residual bucket
Resignation · termination without cause · termination for cause · health · death · departure within 90 days of a restatement or enforcement action · other
Every cause ladder must be exhaustive and must have an explicit "other," or you have written the same bug again.
Reflexivity is acute in this family

A liquid market on "does the CEO depart" hands the board a financial payoff contingent on firing the CEO, and hands an activist a cheaper way to profit from agitating for it than buying the stock. ILWs manage exactly this by triggering on an index the buyer cannot influence. Apply the same rule: self-referential nodes belong at index level only. A sector turnover index is benign. A single-name node held in size by anyone inside the company is not.

08Contract mechanics and resolution

Every documented failure in this market has been a predicate failure, not a source failure. The mechanics below are the ones that empirically prevent it.

The rulebook layer

Adopt a four-type separation as abstract types in a stable rulebook, then instantiate them in per-contract terms documents:

Then five clauses that are individually boring and collectively decisive: a first-print rule (revisions and amendments never reopen settlement); a formula-based silence fallback rather than a committee; a hard outer expiry regardless of source behaviour; settle-at-last-fair-price as the void substitute; and ex-ante clarification only, which clears the order book when published so a clarification cannot silently reprice existing exposure.

Resolution date ≠ event date ≠ expiry

Blue Capital Re wrote an aggregate ILW incepting January 2017. The index revised Hurricane Irma upward in August 2020, triggering the contract, and it paid $3.1M nearly three years after the event. Industry loss indices have no fixed development period — four months for one storm, two years for another. Any benchmark contract in this design must hard-code a resolution cutoff, or the settlement tail is unbounded.

Source Agency quality by family — the real feasibility constraint

Settlement infrastructure, ranked. Where a source already exists as a legal obligation on a third party, the family is buildable. Where it must be created, the family is a data business first and a market second.
FamilyPrimary Source AgencyCharacterVerdict
LitigationPACER docket entries; 10-K/10-Q loss contingencies; court-approved settlement ordersExists; dated; audited; legally compelledReady
CyberSEC 8-K Item 1.05 and subsequent periodic filingsExists; machine-readable; frequently amendedReady with first-print
RecallFDA Enforcement Report classification; NHTSA campaign recordsExists; structured; third-party; objectiveReady
ApprovalFDA approval letter, Drugs@FDA, the published labelExists; binary; scheduled in advanceReady
M&A / key personTermination and Item 5.02 8-Ks; agency press releases; HSR annual reportExists; already used by listed contractsReady
Content compromiseNone. An industry aggregator must be built.Would need contributor data from competitors who have every incentive not to discloseBlocked

That last row deserves emphasis, because it inverts the intuition this memo started from. The motivating case is the least buildable family. The comparison is instructive: Japan's ILW market was described as "impaired" for years purely because loss estimates were unreliable, and only became tradable once an index provider built a credible one. Index credibility is a precondition for the benchmark existing at all — and building it here means persuading rival studios to contribute compromise data to a public count. That is a governance problem, not a market design problem, and it is the binding constraint on this family.

Two structural choices worth copying wholesale

Settle on procedural acts, not on conduct

The CEA lets the Commission find a contract contrary to the public interest if it "involves" activity unlawful under any federal or state law. The June 2026 proposal develops that standard almost entirely through gaming and says essentially nothing about the unlawful-activity prong — no definition, no examples, no treatment of indictments or verdicts. That is an open risk. The mitigation is already in the market: Kalshi's Live Nation antitrust contract settles on a PACER docket entry, so the payout turns on a court's procedural act, not on whether the company violated the Sherman Act. Every litigation node in §05 is drafted the same way, and the T2 name node deliberately settles on a 10-K charge rather than a liability finding.

Two legal forms, two entities

A parametric payout escapes insurance regulation — no material interest requirement, so it is not an insurance contract — but invites the gaming argument. An indemnity payout escapes the gaming argument and lands in fifty-state insurance licensing. A swap is statutorily not insurance and may not be regulated as such by any state. The ILW market resolved this in production by running both forms out of separate legal entities — one for the insurance form, one for the derivative form — and by bolting a token ultimate-net-loss warranty onto the insurance form purely so it clears the accounting scope exception. Copy the structure, not just the vocabulary.

09Microstructure and capital

Pay interest on collateral, or the tail will not be priced

Fully-collateralised binaries are zero-coupon instruments, so Pyes + Pno = e−rT < 1. Two consequences, both severe for a family of 6-to-24-month corporate events:

At 4%. Report implied probability as Pyes/(Pyes+Pno), never as the raw price — the raw price carries a systematic downward bias equal to the wedge.
HorizonFair price of a true 50% contractYES + NOWedge
1 year48.04¢96.08¢3.92pp
2 years46.16¢92.31¢7.69pp
3 years44.35¢88.69¢11.31pp

Worse, the wedge is asymmetric in capital terms. Selling the NO side of a 3¢ longshot ties up 97¢ of collateral to earn 3¢ gross — a 3.09% return on capital, below the risk-free rate, before fees. Nobody supplies that, so longshots stay structurally overpriced, and this is a mechanical generator of favourite-longshot bias entirely separate from any behavioural story. Paying a coupon on posted collateral (one venue pays roughly EFFR less 50bp on mark-to-market value, ~3.13% currently) lifts that same trade to 6.22% and makes the tail supplyable. For a corporate-event market this is not a marketing feature; it is a precondition, and it is doubly load-bearing for conditional nodes, where most collateral is eventually refunded having earned nothing.

The fee schedule fights the design

A fee proportional to p(1−p) is theoretically right — that is exactly the market maker's per-contract variance — but it means buyers of sub-10¢ contracts lose more than 60% of their money to fees. Corporate tail events live at 1–5¢. The high strikes on a severity ladder, which are precisely the catastrophe protection a hedger needs, are the least economic to trade under the standard schedule. This needs an explicit carve-out: a flat or capped fee in the tail, or a minimum-tick regime, accepting worse maker economics there in exchange for the ladder being usable at all.

Order book for benchmarks, subsidised maker for the tail

Every venue with real volume uses an order book; automated market makers are bootstrap technology. So: benchmarks on a book with designated market makers and maker rebates that actually work, and the long tail on a cost-function maker with a promotion rule — graduate a node to the book once cumulative volume crosses a threshold. A logarithmic scoring rule is the right family for the tail specifically because of its locality: a conditional trade on a child node leaves the parent's price unchanged, which is the mathematical foundation of any hierarchy. And its subsidy is bounded and sub-additive, so granular nodes can be quoted off the same capital that supports the benchmark rather than splitting fixed order flow.

Liquidity as an explicit budget line. b is the scoring-rule parameter; the cost of moving a node from 10¢ to 20¢ is linear in it, which makes "how many dollars must an informed trader commit to move this node" a design choice rather than an accident.
bMoveSharesCash cost to moverMax operator subsidy
5,00010¢ → 20¢4,055$589$3,466
25,00010¢ → 20¢20,273$2,945$17,329
25,0003¢ → 6¢18,114$785$17,329
100,00010¢ → 20¢81,093$11,778$69,315

A 260-node tail at b = 25,000 carries a worst-case total subsidy of roughly $4.5M. That is a cheque a serious operator can write, and it is the single clearest argument for running the granular tier on a subsidised maker rather than hoping for organic two-sided flow.

Three capital mechanisms, all of them necessary

  1. Structural consistency in the pricing layer. Price the tree off one cost function whose price space encodes the constraints — child ≤ parent, siblings sum to parent — so inconsistency is unrepresentable rather than merely arbitrageable. Trees are the one combinatorial case known to be tractable; general Boolean conjunctions are #P-hard.
  2. Conversion, so mutually-exclusive sets are capital-efficient. A NO on any outcome converts atomically into a YES on every other. Include placeholder slots for outcomes not known at listing — corporate event sets are genuinely open-ended ("acquired by ___").
  3. Collateral netting across legs. A trader shorting every child of a parent must not be charged n× collateral. Required collateral = total investment less guaranteed minimum payout. Failure to net across the tree is the single largest capital-efficiency killer in a nested design.

Quote the basis, not the outright

Quote T3 as a spread to T2, and T2 as a spread to T1b — never as independent outright prices. This is the index-skew mechanism, and it is what keeps the granular legs tethered to the benchmark. The precedent is unambiguous: a sub-denominated contract on an identical reference at a fixed integral ratio thrives (micro futures are now 40% of one exchange's equity index volume), while a differently-referenced contract with no linking mechanism dies. One exchange delisted a micro FX contract explicitly for "lacking fungibility" with its standard contract. When single stock futures were relaunched in July 2026, the design was 55 names and two expiries with a basis-trade mechanism built in from day one — against a predecessor that listed 12,500 symbols and died.

But do not assume the basis mean-reverts

Index-versus-constituent arbitrage in credit persistently fails to close, on leg count, clearing asymmetry, and capital charges — regulation alone moves the breakeven by ~84bp. And industry-index cat bonds traded at a widening premium to other trigger types for four straight years on nothing but supply and demand. A non-zero basis is what compensates makers for warehousing granular risk. You may not want to arbitrage it to zero.

10Feasibility ranking

Scored on four axes. The ordering is not the ordering of intellectual interest.

Build order. Value-add is the size of the gap versus instruments that already work; legal risk weights the unresolved unlawful-activity prong and the box-office precedent.
#FamilySourceValue-addLiquidityLegal riskRead
1CyberStrongLargeMediumLowBest combination. Item 1.05 gives a clean source; the leading cyber cat bond is still indemnity-triggered at $1bn, which is the gap. Start here.
2LitigationStrongVery largeMediumHigh$20–50bn of exposure with no hedge in existence, and the tranche structure is genuinely novel. But the unlawful-activity prong is undeveloped and the doctrine nodes are the longest-dated and worst-calibrated.
3ApprovalStrongModerateGoodLowDates are known in advance, which concentrates flow naturally. Straddles already work for the binary; the label-scope ladder is the real unmet need.
4M&AStrongSmallGoodVery lowHighest feasibility, lowest value-add — explicit CFTC precedent and live listings, but merger arb already does most of this. The timing ladder and cause-of-death decomposition are the additive parts.
5RecallStrongModerateThinLowExcellent sources, real gap, but hedging demand sits in few firms and bipartite supplier correlation resists the standard basket machinery.
6Content compromiseNoneLargeThinHighThe motivating case and the hardest build: no index exists, the hedger population is small and mostly conflicted, and a statutory ban on a closely adjacent measure sits one drafting error away.

11What kills this

Six failure modes, roughly in order of how likely they are to be the actual cause of death.

1 — Political risk, not regulatory risk

The box-office precedent is the template and it is unambiguous: the agency approved the contracts on the merits, and an organised industry got Congress to override it inside thirty days, with drafting broad enough to kill the workarounds. A public price on "will this company lose its case" or "will this film leak" creates a signal that well-organised incumbents will fight. The binding risk is legislative, it arrives faster than litigation, and no amount of correct legal analysis defends against it.

2 — Liquidity does not arrive, and the failure is quiet

2,893 pending cases is not 2,893 contracts. The evidence against proliferation is overwhelming and current: single-name credit default swaps have roughly 13 counterparties active on a given day versus 160 for the index; fewer than 3% of over a thousand corporate reference entities average more than ten trades a day; the single-stock futures venue that listed 12,500 symbols died, and its best full year was about two days of one index-futures complex. Most damningly, auto-generated combinatorial contracts on a live venue today show literally zero volume, zero open interest and zero resting liquidity — mechanically enumerating a product space produces contracts nobody trades.

Build small. Six families, four sub-benchmarks each, five strikes. And monitor depth, not spread — quoted spread is a lagging indicator of a fragmenting market, depth breaks first, and tipping accelerates roughly sevenfold once share crosses the threshold.

3 — The hedger is the insider

This is structural, not incidental. The party with the most demand for a granular corporate-event hedge is usually the party that determines the settlement fact. Any credible rulebook bars Source Agency employees and MNPI holders from trading, which excludes them by construction. The three partial answers: settle only on already-public third-party acts; push the issuer's hedging to the benchmark tier where no single firm holds material information; and let the ecosystem — insurers, participants, counterparties, suppliers — carry the granular tier. None of the three is complete, and a pre-cleared, disclosed, volume-capped hedging programme on the model of a 10b5-1 plan is probably required.

4 — Reflexivity and moral hazard

A market on a CEO's departure pays a board for firing them. A market on whether a company settles pays plaintiffs' counsel for a particular litigation posture. Industry loss warranties handle this precisely by triggering on an index the buyer cannot move — which is a design rule, not an accident: self-referential nodes belong at index level only, and granular nodes must settle on third-party acts. Where a node is unavoidably self-referential, the discipline has to come from the source being an audited legal filing.

5 — Long-horizon miscalibration hits exactly the valuable nodes

Across 1,787 markets and half a million transactions, calibration degrades measurably with horizon — reasonably good near expiry, significantly biased for distant events, with realised frequency of 15.3% at a 20¢ price. Corporate events are 6-to-24-month horizons, and the T0 doctrine nodes — the most valuable contracts in this whole design — are the longest-dated and therefore the worst-calibrated. Mitigations are partial: pay interest on collateral, report the normalised implied probability rather than the raw price, and quote a term structure of nodes so the short end disciplines the long end, rather than listing one distant binary.

6 — The basis-risk death spiral

There is a documented case of exactly the feedback loop this design must avoid: a Treasury-adjacent futures contract went from ~2 million contracts a year to under 10,000 — a 99.5% collapse — because delivery options let the deliverable set drift away from the risk hedgers actually held, and the authors found hedging effectiveness fell in parallel with volume. Rising basis risk drives hedgers out, which kills liquidity, which raises basis risk. It is positive feedback, not a one-shot design error. The defence is to measure realised hedging effectiveness on the benchmark continuously and treat a decline in it as an existential signal, not a marketing problem.


Two closing observations, both slightly against the grain of the brief. First, the family that inspired this — pre-release content compromise — is the least buildable of the six, because no loss index exists and the studios have no incentive to create one; the framework survives the finding, but the first product should be cyber. Second, the most valuable single contract in the entire design is not a granular one. It is a T0 doctrine node — "does the appellate court hold X" — which is cheap to list, needs no index infrastructure, has an unimpeachable Source Agency in the docket, and is the only instrument that would let a diversified holder separate legal-regime risk from everything else it owns. That contract does not exist, and nothing in the law appears to prevent it.