> **Source:** https://permissionless.fi/en/21-liquidity-incentives
> From *Permissionless Finance* (Permissionless Finance: From Perpetual Futures to the On-Chain Global Market) by Eric Cheung. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).

# Chapter 21: The Public-Goods Dilemma and Incentive Design of Liquidity Governance

In July 2025, Hyperliquid, a decentralized perpetual futures exchange, recorded monthly trading volume of approximately $320 billion (corresponding to roughly $10 billion per day); the total value locked (TVL) in its HLP vault crossed $500 million by the end of 2025 (approximately $300 million to $400 million in July 2025; TVL figures are drawn from the DefiLlama hyperliquid-hlp dashboard, accessed June 2026) [1]. These figures signal that the on-chain central limit order book (CLOB) architecture now rivals centralized exchanges (CEXs) in execution efficiency. More importantly, they validate an entirely new paradigm of liquidity governance: through protocol rules and an automated vault mechanism, retail capital is converted directly into the deep liquidity that the market requires.

This democratization of liquidity provision has not come without cost, however. During the JELLY token attack of March 26, 2025, the rigidity of the HLP vault's algorithmic strategy forced it to passively absorb a short position with a notional value of approximately $15.3 million, and its maximum unrealized loss briefly reached approximately $13.5 million (the former is the notional size of the short position absorbed, the latter the peak unrealized loss; the two use different measurement bases) [1]. This extreme event reveals an inherent tension in liquidity-provision mechanisms between everyday efficiency and crisis resilience, which in turn frames the chapter's central question: how do different market architectures acquire liquidity through institutional design, and what vulnerabilities do these designs exhibit when confronting market volatility?

In the traditional architecture of centralized exchanges, liquidity is acquired through private agreements signed between the platform and a small number of professional market makers—in essence a classic principal-agent problem [2]. Under normal conditions, these contracts deliver very high liquidity quality; yet in extreme market conditions they dry up instantly, as market makers exercise their exemption rights and retreat en masse, falling into the public-goods dilemma discussed in Chapter 20 (the full mechanics of its information asymmetry, adverse selection, and moral hazard are detailed in Section 21.2).

By contrast, decentralized exchanges (DEXs)—exemplified by Hyperliquid—treat liquidity as a product that can be manufactured. Through an engineered architecture comprising a capital layer, a strategy layer, and a distribution layer, they produce liquidity directly on-chain and democratize its provision, allowing ordinary investors to participate passively in market making (the fundamental differences between this activity's risk-return profile and that of a traditional index fund are detailed in Section 21.4.1). While this approach eliminates centralized privilege and enhances transparency, it also introduces new dimensions of risk through the predictability of its algorithms and the rigidity that comes from a lack of human intervention during crises (the three-layer architecture is detailed in Section 21.3, and the reconstruction of returns and transfer of risk in Section 21.4).

Adopting the perspective of institutional economics, this chapter offers a systematic analysis of two sharply contrasting approaches to liquidity governance. The analysis begins with the principal-agent dilemma inherent in the centralized-exchange procurement model and its structural deficiencies. Building on this, it deconstructs the three-layer architecture of decentralized-exchange liquidity engineering and, using the HLP vault as an in-depth case study, examines the reconstruction of returns and transfer of risk that accompany the democratization of liquidity provision. It then evaluates the effectiveness of existing incentive mechanisms by quantitatively simulating the survival boundary of an independent market maker operating in an on-chain order book environment. Finally, a four-dimensional framework—effectiveness, incentive compatibility, transparency, and resilience—provides an analytical tool for comparing the relative merits of the two paradigms and their coexistence. After reading this chapter, readers will understand how market architectures differ in the way they allocate risk-bearing, distribute returns, and assign crisis responsibility, and will recognize how, within decentralized finance, code-driven liquidity infrastructure resolves the traditional crisis of trust while giving rise to new systemic vulnerabilities.

## 21.1 The core problem of liquidity governance

The analysis in Chapter 20 shows that the countercyclical nature of liquidity provision—liquidity contracts precisely when the market needs it most—produces a systemic tragedy of the commons. Building on this, this section distills the central tension of liquidity governance and refines Chapter 20's characterization of liquidity as a *quasi-public good* into that of a common-pool resource: under normal conditions it is approximately non-excludable, but during windows of stress it becomes rivalrous as order book depth is rapidly consumed. The section then surveys the two institutional responses that have emerged in crypto-asset markets and constructs a four-dimensional evaluation framework for systematic comparison.

### 21.1.1 The tragedy of the commons

As discussed in Chapter 20, the microstructure of crypto-asset markets contains a fundamental contradiction: the supply of and demand for liquidity are negatively correlated. Under normal conditions, market makers face relatively low adverse selection risk and are willing to supply ample liquidity. When an extreme event triggers sharp price swings and a surge in trading demand, however, market makers' risk exposure expands abruptly, and their optimal rational strategy is to withdraw quotes to protect their own capital. This phenomenon—in which liquidity vanishes precisely when it is needed most—is not merely the rational choice of individual agents but the root cause of systemic crises.

In decentralized exchanges, this phenomenon manifests as a classic tragedy of the commons. In economic terms, liquidity resembles a common-pool resource more than a pure public good: all traders benefit from a deep order book or an ample liquidity pool (non-excludability), yet once a limit order is consumed it no longer exists (instantaneous rivalry). Although market makers can repost quotes on a millisecond timescale, in extreme conditions quotes regenerate far more slowly than they are consumed, which makes the tragedy-of-the-commons framework fully applicable at high-frequency timescales and during periods of market stress. The costs and risks of providing and maintaining this resource are borne by individual liquidity providers. Capponi and Jia (2025) [3] show that on blockchain infrastructure, liquidity providers face a distinctive collective-action dilemma: the value that arbitrageurs extract from a liquidity pool is mutualized as a loss across all liquidity providers, whereas the transaction cost and time delay of withdrawing liquidity must be borne by each provider alone. Facing adverse market conditions, an individual liquidity provider has a strong incentive to retreat ahead of the others, and this individually rational run ultimately causes aggregate liquidity to collapse. To mitigate this adverse selection risk, liquidity providers typically adopt a more convex, defensive pricing curve, but doing so inevitably reduces capital efficiency under normal conditions.

The market cannot resolve this tragedy of the commons on its own. In the absence of a binding coordination mechanism, market makers fall into a prisoner's dilemma: if all of them maintain their quotes, the market may weather the crisis smoothly, but the moment any one begins to retreat, the adverse selection risk borne by those who remain rises exponentially. The empirical study by Anand and Venkataraman (2016) [4] confirms that under adverse market conditions, systematic withdrawal by market makers significantly degrades market quality and amplifies price volatility. How to overcome the limits of individual rationality—through external intervention or internal mechanism design—so as to guarantee a liquidity floor during crises therefore constitutes the central problem of liquidity governance. This problem bears not only on the survival of any single trading platform but also directly determines the level of systemic risk across the entire decentralized finance system.

### 21.1.2 Two institutional approaches

In response to the systemic failure of liquidity provision, crypto-asset markets have evolved two sharply contrasting institutional responses. Centralized exchanges primarily adopt a procurement model, acquiring liquidity services through private agreements signed with a small number of professional market makers. Under this model, the exchange plays the role of principal, using economic incentives—rebates, fee discounts, and privileged access to advanced APIs—to require market makers to fulfill quoting obligations under specified market conditions. The essence of this arrangement is to treat liquidity as a professional service that can be purchased from external suppliers.

In execution, however, the procurement model faces severe information asymmetry and moral hazard. An exchange can neither monitor a market maker's internal risk models and true intentions in real time nor fully verify whether the maker exerted its best efforts during a crisis. Alexander (2025) [5] notes that the design of market-maker incentives directly affects the liquidity and price stability of crypto assets, but that an ill-suited incentive structure can lead market makers to invoke exemption clauses and retreat legally under extreme conditions. This governance structure, grounded in bilateral contracts, can deliver very high market depth under normal conditions, yet it repeatedly proves fragile during tail-risk events. When a systemic shock strikes, the market maker's rational choice is to trigger the abnormal-market-conditions clause and suspend its quoting obligations—precisely at the moment the market needs liquidity most.

By contrast, decentralized exchanges exemplified by Hyperliquid have charted an institutional path built on an engineering model. This model abandons reliance on external suppliers and instead manufactures liquidity directly on-chain through protocol rules and smart contracts. Its core lies in decomposing liquidity provision into three programmable modules: capital aggregation, strategy execution, and revenue distribution. By establishing a public vault, the protocol allows any user to deposit assets and become a liquidity provider, thereby democratizing liquidity provision. A built-in algorithmic engine replaces the human market maker, automatically posting two-sided quotes on the order book according to preset logic. This paradigm shift transforms liquidity governance from a contractual game between people into code-driven systems engineering.

The engineering model eliminates the agent's discretion through hard-coded rules. Under normal market conditions, code execution is immune to emotion and will not withdraw quotes on the basis of sentiment or profit motive, thereby providing the market with a degree of floor liquidity (under extreme boundary conditions this execution logic may still be overridden by governance intervention; see Section 21.4.6). This rigidity, however, brings new challenges: an algorithm cannot process complex cross-market information as flexibly as a human market maker, and vault capital may suffer large directional losses in a one-sided market. In essence, then, the engineering model trades hard capital losses for the rule-verifiability of liquidity provision.

### 21.1.3 A four-dimensional evaluation framework

A systematic comparison of the two liquidity-governance paradigms requires a multidimensional evaluation framework—one that measures not only market quality under normal conditions but also system performance under extreme conditions. Specifically, an institutional design can be assessed along four dimensions: effectiveness, incentive compatibility, transparency, and resilience.

Effectiveness measures an institutional design's ability to supply ample, low-cost liquidity in normal markets. By bringing in top quantitative teams with advanced technology and deep experience, the procurement model typically achieves extremely narrow bid-ask spreads and enormous order book depth. By contrast, the engineering model—constrained by on-chain computing resources and algorithmic rigidity—is at present often slightly inferior in capital efficiency and pricing precision.

Incentive compatibility concerns whether the interests of individual participants remain aligned with the system's overall objectives. In the context of the tragedy of the commons, the central question is whether the mechanism can internalize the externality of liquidity withdrawal. The procurement model binds market makers through contractual obligations, but their profit-maximizing instinct keeps them searching for loopholes to evade those obligations. The engineering model, by tightly binding retail capital to protocol revenue, creates a shared-fate configuration of interests, yet incentive misalignment persists at the point where arbitrageurs extract value. In a CLOB environment, the mechanism of value extraction differs from that of an automated market maker (AMM) but is no less significant. Drawing on empirical evidence from traditional limit order book markets, Aquilina, Budish, and O'Neill (2022) [6] find that latency arbitrage accounts for roughly 33% of the effective bid-ask spread and imposes an implicit cost of about 0.5 basis points on each trade. Foucault, Kozhan, and Tham (2017) [7] define such fleeting arbitrage opportunities as *toxic arbitrage*, demonstrating that the speed advantage of high-frequency arbitrageurs, while improving price efficiency, systematically intensifies market makers' adverse selection risk. In crypto-asset spot markets, a spread decomposition based on Bitfinex data by Tiniç et al. (2023) [8] shows that adverse selection costs account for roughly 10% of the effective spread, with BTC exhibiting the highest inventory-cost share among all crypto assets. By selling a speed advantage to particular market makers through API privileges and colocation services, exchanges also entrench this value-extraction structure at the institutional level. Although Capponi and Jia (2025) [3] report a more extreme value-transfer ratio in the AMM setting (the median arbitrageur transfers 96% of profit to the infrastructure layer), the value-extraction mechanisms of AMMs and CLOBs differ fundamentally in nature: a CLOB market maker can actively cancel orders, and the value erosion it faces stems chiefly from latency arbitrage and information asymmetry, rather than from the passively borne losses and rebalancing costs of liquidity providers in an AMM.

Transparency reflects market participants' ability to observe the system's operating state and the enforcement of its rules. The procurement model rests on confidential agreements and undisclosed privileges, leaving ordinary traders unable to know a market maker's true obligations or the subsidies it receives. This information black box not only raises doubts about market fairness but also conceals latent systemic risk. The engineering model, by contrast, deploys all rules, parameters, and fund flows on the blockchain, achieving full open-sourcing and auditability. Any user can monitor the vault's asset position and the algorithm's execution logic in real time, and this informational symmetry is a precondition for building trustless liquidity infrastructure.

Resilience directly determines a system's ability to survive a severe shock. Resilience requires that a liquidity-provision mechanism function well not only when markets operate stably but also provide a solid floor at moments of crisis. The fragility of the procurement model lies in its dependence on commercial entities that possess free will—entities that, when faced with the threat of insolvency, will inevitably choose self-preservation. The engineering model, through deterministic algorithmic execution and the continuous locking of public capital, builds a liquidity base that is not driven by emotion. Although this rigidity can cause a vault to endure a substantial drawdown in a one-sided market, it objectively preserves a counterparty of last resort for the market.

Table 21-1 integrates these four dimensions into a unified evaluation matrix, listing for each dimension its core concern and the specific performance it requires in normal markets and in crisis markets. This framework serves throughout the remainder of the chapter as a comparative tool for systematically assessing the relative merits of the CEX procurement model and the DEX engineering model along each dimension.

| Evaluation dimension | Core concern | Required performance in normal markets | Required performance in crisis markets |
| :--- | :--- | :--- | :--- |
| Effectiveness | Transaction cost and depth | Extremely narrow spreads; low slippage on large orders | Maintain basic two-sided quoting |
| Incentive compatibility | Alignment of interests | Market-making returns exceed the opportunity cost of capital | Expected return from holding quotes exceeds the cost of default |
| Transparency | Degree of informational symmetry | Rules public; fund flows traceable | Risk exposures transparent; the liquidation process auditable |
| Resilience | Shock resistance | Adapt to everyday volatility; parameters adjust automatically | Avoid sentiment- or profit-driven discretionary withdrawal; keep any crisis intervention transparent and auditable |

**Table 21-1.** A four-dimensional framework for evaluating liquidity governance (Data source: constructed by the author; analytical framework adapted from Madhavan (2000) [9])

These four dimensions are not independent but mutually constraining: pursuing maximal effectiveness often requires sacrificing some transparency to protect a market maker's strategy secrets, while enhancing resilience may require accumulating redundant capital under normal conditions and lowering short-term capital efficiency. Whether procurement or engineering, then, each model is at bottom a trade-off among these four dimensions. The central direction for future innovation in liquidity governance is to preserve the transparency and resilience of the engineering model while gradually improving its effectiveness and incentive compatibility through more advanced algorithms and mechanism design.

To prevent confusion among the several numbered frameworks that follow, a brief map is useful. The four-dimensional framework—effectiveness, incentive compatibility, transparency, and resilience—is the evaluative backbone that runs through the entire chapter. The three-layer architecture—capital layer, strategy layer, and distribution layer—is the descriptive skeleton of the DEX engineering model. The five risk categories and three revenue engines that appear later in Section 21.4 are a further decomposition of the internal workings of the HLP vault. Three superficially similar binary contrasts must be kept distinct, because they compare different objects: the *two paradigms* refers to the two institution-level approaches of CEX procurement and DEX engineering; the *two routes* refers to the two submodels within a DEX, namely "protocol as market maker" and "protocol recruits market makers"; and the *active-passive dual track* refers to the two participant identities of the independent market maker and the vault participant. Each numbered framework can be mapped back onto the four-dimensional backbone.

## 21.2 The principal-agent model of CEX liquidity procurement

Within the microstructure of cryptocurrency markets, the relationship between a centralized exchange and its market makers forms the central axis of liquidity creation. This relationship is not a simple sale-and-purchase contract, however, but is deeply rooted in a principal-agent problem set within an environment of information asymmetry. As principal, the exchange's fundamental objective is to provide platform users with narrow bid-ask spreads, a deep order book, and stable liquidity under extreme market conditions. As agent, the market maker is motivated by profit maximization and risk minimization, which inevitably leads it, under certain market conditions, to take actions contrary to the exchange's overall interests. This section dissects the liquidity-procurement model of centralized exchanges and analyzes how market-maker agreements design incentives under the constraints of adverse selection and moral hazard.

### 21.2.1 Information asymmetry

Principal-agent theory provides an analytical framework for understanding the liquidity-procurement mechanism of centralized exchanges. Within this framework, the exchange delegates the task of liquidity provision to professional market-making firms but confronts a fundamental obstacle: it cannot fully observe, in real time, the true quality and intent of a market maker's conduct. This information asymmetry exists not only ex ante (before signing) but persists ex post (after signing) throughout the entire trading process.

Figure 21-1 presents the internal structure of this principal-agent relationship: information asymmetry manifests ex ante as adverse selection and ex post as moral hazard, and when extreme market conditions trigger the exemption clause, the two erupt simultaneously, causing liquidity to evaporate rapidly at the moment it is needed most.

![Figure 21-1](./images/fig-21-1-en.png)

**Figure 21-1.** The structure of the CEX principal-agent relationship (A conceptual structural diagram constructed by the author from principal-agent and microstructure theory; nodes and arrows denote mechanism relationships, not measured data; the adverse selection branch follows Glosten & Milgrom 1985 [2])

In classical microstructure theory, the principal risk a market maker faces is defined as adverse selection risk. Under the classical model proposed by Glosten and Milgrom in 1985, a market maker supplying liquidity cannot distinguish whether its counterparty is an informed trader holding private information or a noise trader who trades solely out of liquidity needs [2]. To compensate for the expected loss that necessarily arises when trading against informed traders, the market maker must set a bid-ask spread, the width of which is directly related to the proportion of informed traders in the market. Kyle developed this framework further in 1985, constructing a three-party dynamic model comprising a single informed insider, random noise traders, and competitive market makers, and showing that the informed trader hides its informational advantage by spreading trades over time, while market makers can absorb the market's information only gradually, through continuous price adjustment [10].

In the principal-agent relationship of a centralized exchange, however, the dimension of information asymmetry undergoes a profound inversion. Although the exchange possesses global order-flow data within its own platform, modern cryptocurrency market makers typically conduct high-frequency cross-market arbitrage across dozens of centralized and decentralized platforms at once, which makes the exchange the relatively *uninformed* party. Exploiting its cross-platform informational advantage and order-execution capability, a market maker can behave, on the surface, in ways that comply with the agreement on a single exchange while in substance pursuing strategies that may harm that exchange's long-term liquidity. This informational disadvantage is especially pronounced in cryptocurrency markets, because extreme fragmentation prevents any single platform from obtaining complete global price-discovery information, and the cross-platform data-aggregation capability of top market makers is precisely what constitutes their core competitive barrier.

This bidirectional information asymmetry gives rise to two classic economic problems. The adverse selection problem appears at the contracting stage: the exchange struggles to identify accurately which market makers possess the genuine ability to maintain quotes amid extreme volatility and which are merely speculators relying on simple statistical-arbitrage strategies to extract rebates in calm markets. The moral hazard problem appears after the agreement takes effect: a market maker may exploit its informational advantage and technical means to appear to fulfill its quoting obligations while using devices such as ghost liquidity to evade any substantive risk-bearing. In practice, ghost liquidity takes at least three distinct forms [11]. The first is quote flickering, in which extremely short-lived limit orders are canceled before they can be filled; this may be legitimate risk management or a deliberate display of phantom liquidity. The second is signal manipulation, in which only the best price level in a multi-tier order stack carries genuine trading intent while the deeper orders exist to fabricate order book depth. The third is cross-platform double-counting, in which the same source of capital posts orders on multiple platforms simultaneously, causing aggregate market liquidity to be systematically overestimated. The three carry entirely different implications for principal-agent analysis: the first is detectable through a cancellation-rate metric, the second requires dynamic analysis of multiple depth tiers, and the third lies beyond the monitoring reach of any single exchange. To meet these challenges, exchanges have had to design complex market-maker agreements that align the two parties' interests through finely calibrated incentive and constraint mechanisms.

### 21.2.2 The structure of the agreement

The market-maker agreement is the core contractual instrument through which a centralized exchange addresses the principal-agent problem. These agreements are generally not disclosed to the public, but by analyzing compliance filings made public by regulators such as the Commodity Futures Trading Commission (CFTC), together with prevailing industry practice, one can clearly outline their internal structure of interest exchange [12]. Every clause of a market-maker agreement is, in essence, an act of pricing and allocating risk for liquidity, an intangible asset.

As shown in Figure 21-2, the market-maker agreement distilled from public CFTC compliance filings rests on three pillars—obligations, compensation, and exemptions—with monitoring and enforcement mechanisms at the base forming a safeguard layer; the boundary of obligation drawn by the exemption clause is precisely the source of systemic fragility in extreme market conditions.

![Figure 21-2](./images/fig-21-2-en.png)

**Figure 21-2.** The clause structure of a market-maker agreement (A schematic of the three pillars—obligations, compensation, and exemptions—with the monitoring-and-enforcement safeguard layer at the base; not measured data; clauses drawn from the CFTC market-maker agreement filing [12] and Section 21.2.2 of the text)

The structure of the agreement generally rests on three pillars. The first is the obligations clause, the minimum behavioral baseline set by the exchange as principal. Typical obligations include a maximum-spread constraint, a minimum-depth requirement, and a strict uptime guarantee. An agreement might, for example, require the market maker to maintain continuous two-sided quotes for the life of the contract (the specific uptime threshold varies by exchange and reflects prevailing industry practice), to keep the bid-ask spread within a specified number of basis points, and to provide a minimum quantity of liquidity at the best bid and offer [12]. These quantitative metrics aim to ensure that retail investors can execute trades at a reasonable slippage cost for the vast majority of the time. In addition, to prevent market makers from manufacturing false prosperity through high-frequency cancellation strategies, some agreements impose strict caps on order lifetime or on the order-cancellation rate. On latency, agreements typically stipulate that a market maker's quote-update response time must fall below a specified threshold, so that stale quotes do not become an arbitrage tool for other traders during rapid market swings.

In return for bearing these obligations, the compensation clause forms the agreement's second pillar. A centralized exchange pays its liquidity-procurement costs mainly through the fee structure and technical privileges. On fees, the maker rebate is the central economic incentive. When a market maker's limit order is executed, it not only pays no trading fee but receives back a portion of the fee the exchange charges the taker. This negative-fee structure directly subsidizes the market maker's adverse selection costs and inventory risk [5]. On technology, exchanges commonly grant core market makers API privileges, including higher request rate limits, lower system latency, and in some cases a priority matching channel or a dedicated order-flow data feed. These privileges effectively transfer a system-level microstructure advantage to the market maker as an implicit subsidy. Some exchanges also extend inventory-financing facilities to top market makers, lending them digital assets held on the platform at very low interest rates, thereby lowering the makers' cost of capital and enabling them to maintain quotes across more trading pairs at once.

The agreement's third pillar—the exemption clause—reveals the fragility of this contractual relationship. Analysis of public market-maker agreements shows that a market maker's quoting obligations are automatically suspended under a range of circumstances, including a halt in the calculation of underlying market data, the absence of any direct underlying market from which to derive a price, a determination by the exchange that unforeseeable international financial or political-economic conditions have made accurate pricing impossible, and force majeure events such as war, natural disaster, or technical failure [12]. This clause design is reasonable in legal and operational terms, but it introduces structural risk: the moment an *abnormal condition* is triggered is often precisely the moment the market is undergoing violent price swings and demand for liquidity peaks.

Table 21-2 summarizes the core clauses of these three pillars and, from the perspective of principal-agent theory, annotates the specific function each clause serves in constraining market-maker behavior. The progression from the obligations clause to the exemption clause clearly displays the institutional logic by which risk-bearing is transferred, step by step, from the market maker to the exchange and the end user.

| Clause type | Core content | Principal-agent function |
| :---------- | :---------- | :--------------- |
| Maximum-spread constraint | Upper limit on the two-sided bid-ask spread (in basis points) | Limits the market maker's ability to pass adverse selection costs on by widening the spread |
| Minimum-depth requirement | Minimum quantity at each quote level | Prevents the market maker from offering token "paper liquidity" |
| Uptime requirement | Maintain continuous quotes for the life of the contract (specific threshold varies by exchange) | Ensures the temporal continuity of liquidity |
| Maker rebate | Negative-fee mechanism; fees rebated in proportion to volume | Compensates the market maker's adverse selection costs and inventory risk |
| API privileges | Priority channel; higher rate limits | Lowers the market maker's technical operating costs |
| Abnormal-market exemption | Suspends all obligations under extreme conditions | Transfers tail risk back to the exchange and users |

**Table 21-2.** Principal-agent function analysis of the core clauses of a market-maker agreement (Data source: CFTC market-maker agreement filing [12])

### 21.2.3 Adverse selection

Before a market-maker agreement is signed, the exchange faces a classic adverse selection dilemma. Because a market maker's true strategy, risk appetite, and capital depth are closely guarded commercial secrets, the exchange struggles to distinguish ex ante between the *high-quality* maker willing to bear risk amid volatility and the *low-quality* maker that merely harvests rebates in calm periods. If the incentives the exchange offers are too generous, they will inevitably attract a wave of high-frequency speculators bent on exploiting system loopholes; if the terms are too onerous, genuinely capable institutional market makers may exit for competing platforms with richer incentives. This dilemma is especially acute in cryptocurrency markets because, unlike the designated-market-maker system of traditional financial markets, a crypto exchange's market-maker program is usually non-exclusive: makers can operate on several platforms at once, so the exchange's screening mechanism perpetually faces the threat of cross-platform arbitrage.

To mitigate this adverse selection problem, leading centralized exchanges have developed a complex screening and dynamic-tiering mechanism. The first element is an entry barrier based on historical performance. Some top exchanges' market-maker programs, for example, require applicants to have met an extremely high trading-volume threshold over the preceding 30 days, taking this as an initial signal of capital strength and execution capability [13]. Such a high threshold effectively performs the role described in Spence's signaling model, because for a speculator lacking genuine market-making ability, the cost of fabricating such large and sustained volume is prohibitively high. At the same time, some exchanges require applicants to submit detailed strategy descriptions and risk-management frameworks and assess their system stability and emergency-response capability through in-depth interviews with the exchange's technical team.

Second, exchanges make wide use of a performance-based dynamic tiering system. Market makers are no longer treated as homogeneous liquidity providers but are sorted into tiers—typically ranging from ordinary to platinum or diamond—according to their actual performance over the preceding evaluation period. The assessment metrics include not only share of trading volume but also finer microstructure dimensions of liquidity quality, such as the proportion of time with orders posted within a specified depth, quote continuity during sharp volatility, the order-cancellation rate, and the stability of spread maintenance. A market maker's tier directly determines the rebate rate and level of API privileges it enjoys in the next period. This dynamic-game mechanism forces market makers to weigh long-term interests against short-term arbitrage. If a market maker responds to a bout of market turbulence by canceling orders en masse to avoid inventory risk, its rating in the system is swiftly downgraded, costing it future high-rebate privileges—a loss that often far exceeds what it avoided by canceling during that single crisis.

Although these screening mechanisms raise the overall quality of liquidity providers to some degree, they cannot eliminate adverse selection entirely. Because cryptocurrency markets are extremely fragmented, a market maker can readily engage in regulatory arbitrage across exchanges—dumping high-risk inventory onto platforms with weaker safeguards while maintaining only risk-free statistical-arbitrage strategies on the platform with the richest incentives. This cross-platform concealment of strategy keeps any single exchange's screening mechanism perpetually at an informational disadvantage. The more fundamental problem is that a market maker's *true capability* is itself a dynamic concept that shifts with the state of the market: a maker that excelled in the 2021 bull market may, amid the systemic deleveraging wave of 2022, be unable to maintain quotes because of capital depletion. The effectiveness of historical performance as a screening signal is often sharply diminished in the face of a structural market shift.

### 21.2.4 Moral hazard

If adverse selection is ex ante information asymmetry, moral hazard is the market maker's use of its informational advantage, after the agreement takes effect, to harm the principal's interests. In calm day-to-day markets, this moral hazard typically manifests as a proliferation of *ghost liquidity*. By placing large numbers of readily cancelable limit orders in the order book, a market maker superficially satisfies the agreement's minimum-depth and maximum-spread requirements and thereby legally captures the exchange's rebates and privileges. These orders, however, tend to carry extremely high cancellation rates: at the slightest anomaly in market price, or when a genuine taker order attempts to fill, this seemingly deep liquidity vanishes within milliseconds [11]. In substance, the market maker fulfills its paper obligations while refusing to bear any substantive adverse selection risk.

A moral hazard of greater consequence erupts during extreme market crises. When the market suffers a violent shock and volatility spikes, the exchange most needs its market makers to supply stable liquidity to cushion the price collapse. Yet it is precisely at this critical moment that the exemption clause in the market-maker agreement so often becomes the maker's basis for a legal retreat. Analysis of public market-maker agreements shows that a maker's quoting obligations are suspended once the exchange determines that *abnormal market conditions* exist or that an event has rendered accurate pricing impossible [12]. This power of determination is typically exercised unilaterally by the exchange, and the definition of *abnormal market conditions* is itself so vague that it leaves enormous room for interpretation on both sides.

This institutional design produces a structural contradiction: the market maker receives generous subsidies when the market least needs liquidity yet is legally released from its obligations when the market needs liquidity most. Academic research shows that even a tightly regulated designated market maker does not necessarily behave in ways beneficial to the market when confronting an extreme event akin to a *flash crash*. When high-frequency traders withdraw in unison, designated market makers can provide some cushion at first, but in the face of enormous inventory-devaluation risk and extreme information asymmetry they too will ultimately choose to widen spreads sharply or even cease quoting altogether [14]. In cryptocurrency markets, which lack the central bank's lender-of-last-resort support found in traditional financial markets, such collective liquidity withdrawal often triggers catastrophic cascading liquidations, amplifying what began as a localized price move into a systemic evaporation of liquidity.

Another dimension of moral hazard lies in the market maker's active management of inventory risk. Under normal market conditions, a maker covers its adverse selection costs through high-frequency bid-ask spread income and controls its net inventory exposure through cross-platform hedging. When the market enters a one-sided trend, however, the maker's hedging costs rise sharply, and its quoting within the scope of its contractual obligations effectively becomes a compulsory absorption of losses. In this situation, the maker has a strong incentive to evade such passive risk-bearing by various means, including deliberately triggering the technical conditions of the exemption clause, applying to the exchange for a temporary waiver, or effectively exiting the market by widening spreads to an extreme. The root of this behavior is that the market-maker agreement never truly resolves the central paradox of liquidity provision: the cost of providing liquidity is highest precisely when the market needs it most.

### 21.2.5 Proprietary market making

When the procurement model fails in a crisis because of the exemption clause, many centralized exchanges do not stop at contractual adjustment but move to the opposite extreme: internalizing the market-making function. This section shows that this path likewise fails to resolve the principal-agent dilemma and instead introduces a more serious conflict of interest. Confronted with the unreliability of external market makers in a crisis, these exchanges adopt a more radical solution—building a proprietary market-making team or forming a deep equity-binding relationship with a particular market maker. On the surface, this model appears to eliminate the principal-agent problem entirely, since the principal (the exchange) and the agent (the market maker) become a single economic interest. Far from solving the problem, however, this internalization gives rise to a more serious structural conflict of interest.

When the exchange simultaneously plays the multiple roles of trade matcher, rule maker, and market participant, its proprietary market-making desk inevitably gains an absolute informational advantage over other participants. First, the proprietary desk can obtain global order-flow data with zero latency, including every client's hidden orders, stop-loss levels, and leverage-liquidation thresholds. Second, it enjoys physical-level minimum latency in the system architecture and may even hold priority-execution rights inside the matching engine itself. This extreme asymmetry of advantage creates the structural conditions for market manipulation in various forms. The regulatory frameworks of traditional financial markets—such as the U.S. Volcker Rule, that is, Section 619 of the Dodd-Frank Act—rest precisely on a keen awareness of this conflict of interest: the rule bars regulated banking institutions from short-term proprietary trading but grants an explicit exemption for genuine market-making activity. Its institutional essence is to require banks, at the same trading desk, to draw a strict line between client-driven market making and proprietary trading undertaken for the bank's own account, and to prevent proprietary trading from evading the ban under the guise of market making through conditions such as inventory caps and compensation design.

Historical experience shows that proprietary trading at cryptocurrency exchanges is often accompanied by serious compliance risk. Some platforms use proprietary accounts for wash trading, artificially inflating volume through matched trades between their own accounts to manufacture the illusion of a thriving market and attract retail investors [15]. In certain extreme conditions, an exchange's proprietary market-making desk may exploit its precise knowledge of clients' liquidation levels to deliberately launch a targeted price shock, force client positions into liquidation, and reap outsized profits amid the resulting volatility. Such conduct betrays the exchange's fundamental character as neutral market infrastructure and transforms the principal-agent problem from "the market maker deceiving the exchange" into "the exchange and market maker together deceiving the end user."

A deep equity-binding relationship between an exchange and a particular market maker produces a similar conflict of interest even short of full internalization. When a market maker holds equity in the exchange, or the exchange grants a particular maker exclusive information privileges unavailable to other participants, the relationship has in substance breached the boundary of a fair market, turning the entire platform into a rent-seeking instrument for a particular interest group.

### 21.2.6 Structural deficiencies

Taken together, the existing liquidity-procurement model of centralized exchanges suffers from structural deficiencies that are difficult to overcome. The root difficulty is that liquidity—a highly dynamic, state-dependent public good—cannot be effectively constrained and priced through a static, rigid bilateral contract.

Within the principal-agent framework, the exchange disciplines its market makers through complex incentive and penalty mechanisms yet can never break through the barrier of information asymmetry. Drawing on their technical advantage and cross-market vantage point, market makers can always find strategies that satisfy the letter of the agreement while minimizing their own risk. This space for compliance arbitrage is endogenous to the agreement's design, because any incentive mechanism based on observable metrics must confront Goodhart's law: once a metric becomes a control target, it ceases to be a good metric. When the exchange makes *uptime* and *spread width* its core metrics for evaluating market makers, the makers focus on excelling along those dimensions while relegating what truly matters—liquidity quality, that is, resilience under stress—to secondary importance.

The very existence of the exemption clause is, moreover, a fundamental admission of this contract's impotence before an extreme crisis. Each exemption clause is an implicit *insurance contract* that transfers tail risk from the market maker back to the exchange and the end user. And when the exchange internalizes this contradiction through proprietary market making, it falls into a still more serious conflict of interest, harming market fairness and transparency.

These structural deficiencies show that reliance on the contractual design and microstructure adjustments of centralized institutions alone cannot fundamentally resolve the problem of liquidity provision in cryptocurrency markets. So long as the market maker's profit motive diverges fundamentally from the exchange's character as a public platform, and so long as room for information asymmetry and regulatory arbitrage remains, this principal-agent-based procurement mechanism will remain in a fragile dynamic equilibrium. This predicament also provides the deep real-world backdrop for the rise of alternative liquidity-provision mechanisms in decentralized finance, such as the automated market maker: in an on-chain protocol, rules are encoded as immutable smart contracts, and liquidity providers' behavior is constrained by mathematics rather than by contract, which fundamentally alters the informational structure of the principal-agent relationship.

## 21.3 The three-layer architecture of DEX liquidity engineering

Unlike the CEX procurement model, decentralized exchanges treat liquidity as a product that can be manufactured through protocol mechanisms. Taking Hyperliquid as its prototype, this section deconstructs the capital layer, strategy layer, and distribution layer of this engineering approach and compares the two DEX liquidity routes.

### 21.3.1 The paradigm shift

The fundamental divergence between CEXs and DEXs in liquidity governance stems from differing conceptions of the nature of liquidity. As discussed in Section 21.2, a CEX treats liquidity as a *service* to be *procured* from external professional institutions through contractual constraints and fee rebates; its effectiveness depends heavily on a principal-agent relationship under information asymmetry [16], and it faces systemic risk when, under an extreme shock, market makers invoke the exemption clause to withdraw liquidity [17].

By contrast, a new generation of DEXs exemplified by Hyperliquid proposes a wholly different governance paradigm: treating liquidity as a product that can be *manufactured* through protocol mechanisms. From this engineering vantage point, liquidity is no longer the preserve of a few professional institutions but the systematic output of a decentralized protocol that converts raw material (retail capital) into a finished good (order book quotes) [3]. The core of this paradigm shift is to reconstruct market making—once dependent on human trust and private gamesmanship—as an automated process driven by smart contracts and algorithms. By establishing a transparent system of rules, a DEX reduces the moral hazard of the traditional model and democratizes liquidity provision [18]. The engineering approach does not eliminate the principal-agent problem, however; it changes its form and its distribution of risk. Under the vault model, depositors delegate their capital to protocol code rather than to a human market maker, and the focus of information asymmetry shifts from *the market maker's true intent is unobservable* to *the effectiveness and safety of the algorithmic strategy cannot be fully verified*. This transformation reduces the agent's discretion but introduces new dimensions of risk, including algorithmic rigidity, parameter governance, and smart-contract vulnerabilities.

In this engineering system, participants are redefined. On one side, ordinary investors can become indirect liquidity providers by injecting funds into the protocol's vault; on the other, technically capable independent market makers can still connect through the API to compete directly in the market. The two are not mutually exclusive but together form the foundational base and the elastic margin of the DEX liquidity ecosystem. By decoupling capital aggregation, strategy execution, and revenue distribution, this system design offers a structural alternative for resolving the public-goods dilemma of liquidity.

### 21.3.2 The capital layer

In the three-layer architecture of liquidity engineering, the capital layer is the power source of the entire system. Its core mechanism is the liquidity vault, which aggregates dispersed, small-scale retail funds into market-making capital with scale effects. In the traditional CEX model, a market maker must bring vast proprietary funds or raise institutional financing to meet the steep entry threshold, which turns liquidity provision into a highly concentrated oligopolistic game [19]. The vault mechanism breaks this barrier through smart contracts and democratizes the supply of capital.

Investors need only deposit stablecoins into the designated vault smart contract to receive token certificates representing their share of the pool. These funds no longer sit idle but are marshaled by the protocol as the underlying assets that support subsequent market-making activity. From the investor's perspective, the process resembles buying an index fund focused on a market-making strategy (the limits of this analogy are clarified in Section 21.4.1); from the protocol's perspective, the vault is a bridge between retail capital and professional market-making demand [20].

Vault design is not fixed; protocol developers must make trade-offs along several dimensions. A single-vault model, for example, maximizes the efficiency of capital utilization but readily transmits risk across assets when making markets in multiple assets; a multi-vault model lets investors target their exposure to the risk characteristics of different assets but may fragment liquidity. In addition, to maintain the stability of market-making capital, a vault typically introduces redemption limits or a capacity cap. These design details directly determine the capital layer's resilience under extreme market conditions, because allowing investors to withdraw funds without limit during a crisis would turn the vault itself into a fuse that accelerates a market collapse.

### 21.3.3 The strategy layer

The capital layer completes the aggregation of funds; the strategy layer is responsible for converting this static capital into dynamic two-sided quotes on the order book. In Hyperliquid's architecture, this conversion is performed automatically by a built-in market-making strategy engine. The engine is, in essence, an automated algorithm running at the protocol layer: it reads market data in real time, computes the optimal bid-ask spread, and posts the corresponding orders on the CLOB [21].

The strategy engine's core task is to balance the depth of liquidity supplied against the risk the market maker faces. Its key parameters include quote width, quote depth, inventory-management thresholds, and the ratio of capital allocated across assets. When the market is in a normal state, the engine keeps spreads relatively narrow to capture trading fees; when volatility spikes, it automatically widens spreads or reduces posted size to lower adverse selection risk [2]. Unlike the passive pricing curve of a traditional AMM, the strategy engine can actively manage inventory: by adjusting the asymmetry of its quotes, it steers order flow to work off one-sided risk exposure.

This "protocol as market maker" design makes the strategy engine functionally equivalent to a professional quantitative market-making team, yet its operating logic is driven entirely by open, transparent code. On-chain auditability eliminates the black-box operations of the traditional model and ensures fairness in execution. This transparency brings an endogenous paradox, however: publicly visible strategy parameters are easily reverse-engineered and gamed by high-frequency traders or maximal extractable value (MEV) searchers [22]. Moreover, because parameter changes typically must pass through a governance process, the strategy engine's response to a sudden black-swan event is often slower than that of a human-operated centralized market maker.

This architecture also involves a trust assumption that is easily overlooked. Hyperliquid currently uses a centralized sequencer to process trade instructions, and the sequencer controls the ordering and execution priority of orders. As a protocol-native component, the HLP strategy's order submission and execution path may enjoy priority, which is functionally similar to the API privileges in a CEX market-maker agreement. This fact means that the claim in Section 21.3.1 of delegation "to code rather than to a person" requires further qualification: although the strategy code is publicly auditable, it runs on sequencer infrastructure controlled by the core team. Trust is not eliminated entirely but shifted—from trust in an individual market maker's conduct to trust that the sequencer operator will not abuse its execution priority. As Hyperliquid advances the progressive decentralization of its sequencer, the strength of this trust assumption will gradually diminish; but at the current stage, it is inaccurate to describe HLP as a fully trustless liquidity-provision mechanism.

Beyond the capital, strategy, and distribution layers, the system as it actually operates also contains a risk-control layer that cuts across all three. The strategy engine's execution is not unconstrained; the protocol imposes multiple risk-control parameter limits on it, including a maximum position size for any single asset, a cap on the vault's overall net exposure, a maximum notional value per trade, and a leverage ceiling for specific asset classes. These constraints are not part of the market-making algorithm's internal logic but a safety boundary that sits independently above the strategy. The design quality of the risk-control layer directly determines the vault's ability to survive at boundary conditions: the core lesson of the JELLY and POPCAT incidents is not that the market-making strategy itself was flawed but that the risk-control parameters failed to effectively constrain extreme position concentration in long-tail assets at the position-building stage (the full mechanism by which this imbalance amplifies the vault's tail risk is detailed in Section 21.4.3).

### 21.3.4 The distribution layer

The final link in liquidity engineering is the distribution layer, which returns the revenue generated by market-making activity to the capital layer's participants fairly and transparently. In Hyperliquid's economic model, the fee-distribution module is the incentive hub that sustains the entire system over the long run. The vault's revenue comes mainly from two sources: first, the bid-ask spread and the share of trading fees captured when the strategy engine facilitates trades on the order book; and second, the liquidation penalties the vault earns by taking over defaulted positions when large-scale forced liquidations occur in the market [10].

These two revenue sources display marked complementarity across different phases of the market cycle. In a low-volatility normal market, market-making spreads and fees are the stable base of returns; in high-volatility or extreme conditions, although adverse selection risk increases market-making losses, a surge in liquidation penalties forms a powerful countercyclical hedge. The distribution module converts these net proceeds, in proportion to each investor's vault shares, into growth in the net asset value of those shares.

This mechanism builds a self-reinforcing incentive loop. Active trading generates fee revenue, which draws more retail capital into the vault; the vault's growing scale deepens the order book's liquidity, which in turn attracts more traders. Within this loop, the inflow of liquidation penalties enables the vault to replenish capital quickly after a crisis, strengthening its ability to take over the next round of liquidated positions [23]. By tightly binding liquidation management to market-making revenue, this design gives the protocol a stronger capacity for self-repair in the face of a systemic shock than a traditional CEX.

### 21.3.5 Overall operation

The preceding three subsections analyzed the internal logic of the capital, strategy, and distribution layers in turn; the core value of the three-layer architecture lies in their coordinated operation. Figure 21-3 places the system components of the three-layer architecture and their interactions in a single view, arranged top-down along the flow of funds, so that one can trace how capital moves and changes state across the layers.

![Figure 21-3](./images/fig-21-3-en.png)

**Figure 21-3.** The three-layer architecture of Hyperliquid's liquidity engineering (Data source: Hyperliquid protocol documentation [24])

The process begins when user A deposits USDC into the protocol's HLP vault. Once this capital enters the capital layer, it merges with the funds of many other users to form a large liquidity pool, and user A receives HLP share tokens representing their proportional contribution. The strategy layer then takes over this aggregated capital. According to preset algorithmic parameters, the market-making strategy engine assesses the current market's volatility and the balance between long and short forces and computes the optimal bid and ask prices and posted quantities. The engine converts these parameters into concrete instructions and posts buy and sell orders simultaneously on the on-chain CLOB.

When trader B submits a market buy order on the order book, the system matches it against a sell order posted by the strategy engine. Once the trade completes, trader B has paid a trading fee and the strategy engine has captured the bid-ask spread. At this point the flow of funds enters the distribution layer. The fee-distribution module aggregates the fee revenue and spread profit generated by this trade. If a liquidation of trader C occurs during this period, the liquidation engine intervenes and collects a liquidation penalty, and these funds likewise flow into the distribution module. Finally, following its rules, the distribution module adds the total proceeds proportionally to the vault's total assets; the net asset value of the HLP shares held by user A rises accordingly, completing the full loop from capital contribution to value capture.

Figure 21-4 presents the full end-to-end flow of this trade lifecycle, in which every link is executed automatically by smart contracts without human intervention.

![Figure 21-4](./images/fig-21-4-en.png)

**Figure 21-4.** The end-to-end flow of funds: user deposit → order book quoting → revenue distribution (Data source: Hyperliquid protocol documentation [24])

### 21.3.6 Two routes

As the decentralized CLOB has developed, two sharply contrasting models of liquidity governance have emerged so far. The model exemplified by Hyperliquid's HLP vault may be called "protocol as market maker." Under this model, the protocol not only provides the trading infrastructure but also directly operates a built-in market-making engine. Its core advantages are control over liquidity and higher resilience during crises. Because the strategy engine is hard-coded, its execution logic is unaffected by market sentiment: under normal conditions it quotes continuously according to its rules and does not withdraw orders on the basis of sentiment or profit motive, thereby providing the market with a rule-verifiable liquidity floor (under extreme boundary conditions this logic may still be overridden by governance intervention; see Section 21.4.6) [25].

The contrasting model, exemplified by dYdX v4, is "protocol recruits market makers." In this architecture, the protocol concentrates on building a high-performance on-chain matching engine and leaves liquidity provision entirely to external, independent market makers. To attract these professional firms, the protocol typically designs complex token-incentive programs and a tiered fee-rebate structure [26]. This model can deliver very high liquidity quality under normal conditions, because external market makers possess more advanced hardware and greater flexibility in adjusting their strategies.

The fundamental difference between the two lies in their distribution of risk and their governance structure. The "protocol as market maker" model socializes strategy risk (such as an algorithmic bug or a parameter error), spreading it across all vault participants, while lowering the entry threshold to a minimum and achieving full democratization. The "protocol recruits market makers" model, by contrast, isolates risk inside independent professional firms, but its liquidity provision still faces a principal-agent dilemma similar to that of a CEX: when the market collapses, token incentives are often insufficient to offset the market makers' inventory losses, and liquidity evaporates in an instant [27]. These two routes are not strictly opposed; future DEX architectures are more likely to converge—using a built-in vault to provide a base of antifragile liquidity while introducing external market makers through incentives to raise overall market efficiency.

## 21.4 Case study: the HLP vault

The HLP vault is the archetypal product of the liquidity-engineering paradigm, converting professional market-making activity into a standardized yield instrument that ordinary investors can access. This section examines it in depth along five dimensions: positioning, returns, risk, historical performance, and governance.

### 21.4.1 Index-style investing

The evolutionary history of financial products is a history of democratization—of turning institutional privilege into mass-market products. In traditional equity markets, index funds and exchange-traded funds (ETFs) aggregated retail capital and turned passive investing from a complex, institution-only operation into a standard product that ordinary investors could access at will [28]. This paradigm shift not only lowered the barrier to investment but also reshaped market microstructure, making passive capital an important cornerstone of market liquidity. In the context of decentralized derivatives exchanges, the HLP vault in the Hyperliquid protocol represents a similar structural innovation. The vault turns participation in perpetual futures market making—a highly specialized, capital-intensive activity—into a yield product that any user can access permissionlessly [29]. More precisely, this mechanism is a structured instrument for capturing a liquidity risk premium: it aligns with the democratizing logic of index funds along the dimension of lowering the barrier to market-making participation, yet it differs fundamentally from index investing in its risk-return profile. Its essence lies in using protocol-level engineering to fully automate the fundraising, strategy execution, and revenue distribution of market-making activity.

In terms of mechanism design, the HLP vault is not a simple pool of funds but an autonomous agent capable of system-level economic behavior. Once users deposit dollar-pegged stablecoins into the vault, the protocol's built-in engine takes over this capital and executes a two-sided quoting strategy simultaneously across all perpetual futures pairs on the platform [30]. This feature of diversified market making across many contracts closely parallels the logic of a traditional index fund that buys a weighted basket of constituent stocks. Liquidity providers need neither expertise in quantitative trading nor low-latency infrastructure; in effect, they delegate the right to formulate strategy and manage risk to the protocol code [31]. In this process, a vault share becomes, in essence, a new asset class representing passive exposure to the profit pool of the entire exchange's market making.

Analogizing market-making activity to index investing, however, requires clarifying the fundamental difference in their risk-return profiles. The traditional index investor is a bearer of market risk whose returns derive from the long-run appreciation of asset prices; the vault's liquidity provider, by contrast, is a seller of liquidity insurance in market microstructure. A market maker's core profit comes from capturing the bid-ask spread and from funding rate arbitrage, and these returns compensate it for bearing adverse selection risk and inventory risk [32]. When users deposit funds into the vault, they are not buying a market trend but systematically selling liquidity. This role reversal means that the vault's net asset value does not depend directly on crypto assets' bull-bear cycle but is instead closely tied to the market's volatility characteristics, trading volume, and the degree of participation by competing market makers. Thus, although this structured capture of a liquidity risk premium democratizes the form of participation, it far exceeds traditional passive-investment instruments in the complexity of its risk assessment. From the perspective of behavioral finance, analogizing the vault to an *index fund* carries a framing-effect risk: to a retail investor, *index fund* connotes low risk, long-term holding, and passive diversification, whereas a vault depositor actually bears adverse selection risk, the risk of a nonlinear inventory blowup, and whale-manipulation risk. Its return distribution, moreover, exhibits a negative skew and fat tails quite unlike those of index investing.

### 21.4.2 Sources of return

The HLP vault's return structure is not a one-dimensional linear sum but is driven jointly by three independent engines with distinct cyclical characteristics. This multi-engine design is the core reason the vault can maintain a relatively stable net asset value across different market states.

The first return engine is market-making spread income, the most basic profit source of all market-making activity. In a normal market, the vault's strategy engine continuously posts buy and sell limit orders on the order book to earn the tiny difference between bid and ask prices [33]. Because the vault's capital is large and can provide liquidity across all trading pairs at once, these high-frequency, thin-margin trades accumulate over a vast base to form the vault's principal source of returns in low-volatility periods. Spread income is highly sensitive to market conditions, however. When volatility spikes, a one-sided market causes the maker's posted orders to be swept through repeatedly and inventory to accumulate rapidly on the unfavorable side; spread income then not only falls sharply but may even turn negative [34].

The second return engine is the protocol fee share. As a protocol-native vault, the HLP vault enjoys a special right to a share of revenue, capturing a fixed proportion of traders' fees on the platform [35]. The distinguishing feature of this income stream is that it is decoupled from the actual performance of the market-making strategy and driven purely by the platform's total trading volume. In economic terms, it can be viewed as a *participation reward* the protocol pays the vault for providing base liquidity. When the market turns highly volatile, market-making spread income comes under pressure, but the surge in trading volume drives the fee share up markedly, thereby hedging the potential losses of the market-making strategy to some degree.

The third return engine is liquidation penalties and the management of defaulted positions. In a leveraged trading market, when a trader's margin ratio falls below the maintenance-margin requirement, the position is forcibly liquidated and charged an additional liquidation penalty [36]. This income stream requires distinguishing two components of quite different natures. In a normal market, the penalties generated by a large number of small, dispersed liquidations constitute risk-controlled fee income with low correlation to the vault's inventory risk. In extreme conditions, however, the large penalties triggered by a whale's liquidation or by cascading liquidations are entirely different in nature: as the vault collects these penalties, it is forced to take on an enormous directional position, so that liquidation-penalty income and inventory risk are amplified in the same instant. This *poisoned yield* means that the net effect of liquidation penalties as a return engine depends heavily on subsequent market movements: if the price reverts, the vault both collects the penalty and realizes an inventory gain; if the price continues to move away, the penalty income falls far short of offsetting the inventory loss. The JELLY incident is a textbook case of the latter.

Figure 21-5 depicts the relative contribution shares of these three return engines across three states: the normal market, the high-volatility market, and the extreme crisis. Liquidation penalties become the core support for net asset value during the extreme-crisis phase and can partially offset market-making losses under certain conditions; but this compensation is ex post, uncertain, and heavily dependent on the speed of the market's reversion, and it should therefore not be understood as a natural countercyclical hedge.

![Figure 21-5](./images/fig-21-5-en.png)

**Figure 21-5.** The cyclical characteristics of HLP's three return engines (Conceptual illustration: the relative contribution shares of the three engines are derived from mechanism analysis, not measured profit and loss; the mechanism follows Hyperliquid Protocol vaults [29], supplemented by the HLP security glossary entry [35]; on-chain profit-and-loss data for the vault can be queried through DefiLlama and Hyperliquid's official vault dashboard)

The combination of these three engines builds a subtle internal hedging mechanism. In a normal market, the market-making spread provides stable positive cash flow; in a high-volatility market, the rise in the fee share offsets the decline in the spread-capture rate; and in an extreme crisis, the explosive growth of liquidation penalties becomes the key buffer that absorbs inventory losses. This nonlinear feature of the return structure gives the vault's net-asset-value curve a resilience distinct from that of a single market-making strategy.

### 21.4.3 Risk exposure

Although the multi-engine return structure provides an intrinsic risk buffer, the essential nature of liquidity provision means the vault cannot be immune to systemic risks in market microstructure. Pooling capital and entrusting it to automated strategy execution in fact exposes liquidity providers to five distinct categories of risk.

The first is adverse selection risk. In the order book model, a market maker perpetually faces the predicament of trading as counterparty to traders who hold an informational advantage. When the market price makes a genuine move, the maker tends to sell too low or buy too high, and this structural loss caused by information asymmetry is termed the adverse selection cost [8]. Because the vault's strategy is driven by public code and its position is fully transparent on-chain, its quoting logic is readily predicted and gamed by high-frequency arbitrageurs and MEV searchers, so its adverse selection exposure is amplified (the full analysis of this transparency paradox is detailed in Section 21.4.6).

The second is the nonlinear blowup of inventory risk. The vault makes markets in dozens of perpetual futures pairs at once, and under normal conditions the independent fluctuations of different assets achieve a statistical diversification of inventory risk [37]. In cryptocurrency markets, however, cross-asset correlations tend to converge sharply toward one under extreme conditions. When the entire market suffers a macro shock, the vault may accumulate one-sided inventory in the same direction across all trading pairs at once. This synchronized deterioration of multidimensional inventory causes the diversification effect to fail in an instant, pushing the vault into a state of severe capital depletion. If the one-sided market persists longer than the vault's strategy-adjustment cycle, the paper loss turns into an irreversible, substantive loss of capital.

The third category is extreme-event and whale-manipulation risk. Unlike a centralized-exchange market maker, which can actively sever its connection to the system at any time through human intervention, the protocol vault's automated nature means it cannot subjectively refuse a trade. This *always-on* property, while providing a liquidity floor, also makes the vault a potential target for malicious manipulation. If a trader with vast capital exploits the mechanical nature of the vault's quote depth to deliberately engineer an extreme price dislocation in a poorly liquid long-tail asset—forcing the vault to buy at the top or dump at the bottom—the vault's capital will be rapidly depleted [38]. Such attacks exploit the rigid weakness of the vault's strategy in responding to irrational trading behavior and constitute the largest source of the vault's tail risk.

The fourth category is mark-price and oracle-deviation risk. HLP's liquidation engine relies on the mark price to trigger forced liquidations, and the mark price is computed from an exponentially smoothed moving-average component of the spot index prices from several external exchanges together with the basis (the funding rate is a function of the basis between the mark price and the index price, not an input to the mark-price calculation; see Chapter 14). In a normal market, the mark price is highly consistent with the tradable price on the platform, but under extreme conditions the two can diverge significantly. The key attack step in the JELLY incident exploited precisely this mechanism: by manipulating the price of the JELLY token on an external spot exchange, the attacker drove the mark price on the Hyperliquid platform far from the actual tradable price, causing the vault to take on a position based on the distorted mark price and to incur an enormous unrealized loss. This risk is especially pronounced in low-liquidity assets, because the capital required to manipulate an external spot market is disproportionate to the asset's open interest on the perpetual futures platform.

The last is strategy and algorithm risk. The vault's operation depends heavily on a preset matrix of parameters and code logic. Parameter settings—such as quote width, depth allocation, and the inventory-skew coefficient—must adapt to an ever-changing market microstructure. If the market state shifts fundamentally while the strategy parameters are not updated in time through the governance process, the vault's quoting will deviate from the optimum and cause a continuous drain of funds [39]. At a deeper level, smart-contract security is the foundational risk of all on-chain financial infrastructure: any vulnerability in the vault contract, the strategy contract, or the oracle price-feed contract could allow funds to be extracted directly or cause the strategy engine to execute erroneous instructions. The largest fund-loss events in the crypto industry's history (such as cross-chain bridge attacks) all stemmed from security flaws at the contract layer rather than the strategy layer, and this risk is further amplified in the cross-chain liquidity layer discussed in Section 21.6.4.

These five risk categories are not evenly distributed across all market states. Figure 21-6 presents, in matrix form, how the severity of each risk category evolves across three market environments—normal, high-volatility, and extreme crisis; strategy and contract risk runs through all market states and is difficult to hedge with a capital buffer.

![Figure 21-6](./images/fig-21-6-en.png)

**Figure 21-6.** The HLP five-category risk-exposure matrix (Conceptual illustration: the severity of the five risk categories across three market states is derived from microstructure theory, not a quantitative score; theoretical basis: Tiniç et al. 2023 [8] and Fournier & Jacobs 2020 [37]; severity references the HLP vault's historical drawdown events, as of June 2026: the March 2025 ETH whale-liquidation event with a loss of approximately $4 million, the March 2025 JELLY token attack with a maximum unrealized loss of approximately $13.5 million [1][57], and the November 2025 POPCAT manipulation event with approximately $4.9 million in bad debt [38][58])

### 21.4.4 Historical performance

Empirical analysis of the vault's historical performance is important for testing the effectiveness of its mechanism. Since the vault went live, its net-asset-value curve has recorded not only the profitability of the market-making strategy across different market cycles but also the fragility boundary of the protocol architecture in the face of extreme shocks.

As of October 2025, the HLP vault's cumulative profit and loss was approximately $121.8 million, corresponding to a total return of about 50% (over the period) and a full-cycle annualized compound growth rate of about 42% (data from the DefiLlama hyperliquid-hlp dashboard, on an all-time cumulative profit-and-loss basis, accessed June 2026; the total return uses the vault's average assets under management over the period as the denominator, and the 42% annualized figure is significantly inflated by an early low-base effect, as qualified below). On this basis, only 6 of the 64 observation weeks recorded a negative return, with an average weekly return of about 0.84%. This performance fits the classic profile of a high-frequency market-making strategy: accumulating returns through thin-margin trades with a very high win rate. The smoothness of the net-asset-value curve is broken at certain points, however, by sharp downward gaps. On March 12, 2025, a whale deposited $4.3 million in margin to build a 50x-leveraged ETH long position (notional value approximately $200 million to $230 million) and then deliberately withdrew the margin to trigger liquidation, forcing the HLP vault to absorb the closing liquidity of approximately 113,000 ETH at an extremely unfavorable price, causing a direct loss of approximately $4 million [36]. Just two weeks later, on March 26, in the JELLY token attack, the attacker exploited the thin liquidity of a long-tail asset and manipulated the spot price across platforms, forcing the vault's short position to a maximum unrealized loss of approximately $13.5 million [1][57]. The POPCAT manipulation event of November 2025 further exposed the vault's fragility in the face of market manipulation: through a fake buy wall and flash cancellations, the attacker caused approximately $4.9 million in bad debt [38][58]. Although liquidation penalties and fee income partially offset these losses after the fact, the deep drawdowns in net asset value faithfully reflect the systemic cost the vault bears as a lender of last resort. In favorable liquidation events, the vault can likewise earn significant gains; for example, the forced liquidation of a $700 million BTC long position on February 1, 2026, brought the vault a single-day profit of approximately $15 million (data for this event are from KuCoin [38] and Longbridge [59] reports of February 2026 and the Hyperliquid vault dashboard, accessed June 2026). This profit event deserves symmetric attention within a risk-analysis framework, however: it shows that HLP had taken on an enormous directional position at that moment, and had the BTC price moved by an equal magnitude in the opposite direction, the vault could have suffered a loss of comparable size. This event reflects the level of risk concentration permitted by the vault's risk-control parameters more than any superiority at the strategy level.

Several important qualifications are needed in interpreting the performance data above. The 42% annualized compound growth rate is significantly inflated by a low-base effect: the vault's early assets under management were far smaller than in later periods, so the high early return rates contributed disproportionately to the full-cycle compound growth rate. As assets under management grew from approximately $150 million at the end of 2024 to a peak of approximately $512 million in May 2025 (the size curve is a single-source estimate, with specific figures pending verification against DefiLlama and official dashboard historical data), the expected return per unit of capital was noticeably diluted: the full-year return for 2024 was about 50%, whereas the per-unit-capital annualized return in 2025 fell back markedly (estimates across sources and measurement bases range from roughly 10% to 22%, the differences arising mainly from whether fees are deducted, whether token incentives are counted, and differing statistical windows). Moreover, the observation period covered a strong phase of the crypto market, and market-making strategies generally perform well in an environment of high trading volume and moderate volatility. The presence of liquidation-penalty income makes the vault functionally long market volatility, and the roughly $15 million single-day profit event noted above shows that the vault bears a significant directional risk exposure—which is in tension with the characterization in Section 21.4.1 of the vault as "not depending directly on crypto assets' bull-bear cycle."

From the perspective of attack-surface analysis, although the JELLY and POPCAT incidents both resulted in financial losses for the vault, their attack vectors differ in essence. JELLY was a liquidity-exhaustion attack: the attacker built a large short position and deliberately triggered a self-liquidation, forcing the vault to take on the entire position as counterparty, and then amplified the vault's unrealized loss through cross-platform spot manipulation. After the JELLY incident, the protocol implemented risk-control measures such as lowering the maximum leverage and adding position-opening limits. The POPCAT incident eight months later, however, used a different attack vector—creating a price illusion with a fake buy wall and then flash-canceling—which was market manipulation rather than liquidity exhaustion, a category the JELLY-era fixes did not cover. The systemic weakness both incidents exposed is that HLP's quote depth in long-tail assets is severely disproportionate to the scale of externally manipulable capital.

Figure 21-7 marks the key market events over the course of the vault's net-asset-value evolution, revealing how external shocks map into profit-and-loss fluctuations in the internal capital pool.

![Figure 21-7](./images/fig-21-7-en.png)

**Figure 21-7.** The HLP net-asset-value curve (illustrative trajectory) with key events annotated (The net-asset-value curve is an illustrative trajectory with an initial value of 1.0; the shape of the curve references Hyperliquid's official vault dashboard and DefiLlama [29] and is not a day-by-day measured series; the timing, direction, and amount of the four overlaid key events are measured, as of June 2026: the March 2025 ETH whale liquidation with a loss of approximately $4 million [36], the March 2025 JELLY attack with a maximum unrealized loss of approximately $13.5 million [1][57], the November 2025 POPCAT manipulation with approximately $4.9 million in bad debt [38][58], and the February 2026 whale liquidation with a single-day profit of approximately $15 million; event sources are given in Section 21.4.4 of the text [59])

Further return-attribution analysis (based on inference from the protocol mechanism, lacking direct verification from on-chain itemized profit-and-loss data) suggests that the dynamic switching of profit composition across market states may be the key to the vault's sustained long-run profitability. In a normal market of moderate volatility, the mechanism implies that bid-ask spread capture contributes the bulk of the positive returns, reflecting that the vault's pricing algorithm should be reasonably competitive at handling ordinary order flow. When the market enters a high-volatility quadrant, however, the return structure reverses markedly. The contribution of market-making spreads shrinks sharply, while the fee share driven by surging trading volume and the liquidation penalties triggered by large-scale liquidations become the core pillars supporting net asset value.

Figure 21-8 provides a quantitative breakdown of the vault's return attribution under two typical market environments.

![Figure 21-8](./images/fig-21-8-en.png)

**Figure 21-8.** HLP return-attribution breakdown (Conceptual illustration: the return-attribution shares for the two scenarios are derived from mechanism analysis, lack direct verification from on-chain itemized profit-and-loss data, and are not a measured decomposition; the primary anchor for the attribution is the Hyperliquid vault dashboard and DefiLlama revenue line items [29])

This dynamic return-compensation mechanism explains why the vault can quickly repair its net asset value after a deep drawdown. It shows that the protocol-level distribution-rule design—internalizing fees and liquidation penalties as vault revenue—is in essence a systematic cross-subsidy for liquidity providers who bear tail risk. Strip away this non-market-making income, and the long-run viability of an automated strategy that relies on spread capture alone in the on-chain environment would be greatly diminished.

### 21.4.5 Comparison with traditional products

Comparing the liquidity vault of a decentralized protocol with innovative products in traditional financial markets helps locate its coordinates within the broader financial spectrum. In traditional finance, although ETFs greatly popularized passive investing, direct participation in market-making activity was always regarded as an institution-only domain. More recently, some structured products have used derivatives packaging to offer retail investors exposure resembling market-maker returns (such as short-volatility strategies or covered-call funds), and such products may be loosely termed *market-making ETFs* [40].

The HLP vault differs markedly from such traditional products in its underlying logic. Traditional structured products typically simulate market-maker returns by executing complex option strategies in over-the-counter markets or on derivatives exchanges, and their operation is entirely a black box to investors, who see only the final change in net asset value and cannot see through to the underlying position distribution and execution details. The protocol vault, by contrast, achieves genuine on-chain transparency. Every order the vault posts, every fill, every inflow and outflow of funds, and its real-time inventory state are publicly queryable on a block explorer [31]. This extremely transparent information structure significantly reduces the information asymmetry between manager and investor found in traditional finance (though, as Section 21.4.6 notes, transparency itself does not eliminate information asymmetry entirely but shifts it into a strategy-level disadvantage in predictability).

In entry threshold and intermediation cost, the protocol vault displays the efficiency advantage of a decentralized architecture. Traditional products, constrained by strict regulatory frameworks, often require very high minimum subscription amounts and charge steep management fees and performance fees. The protocol vault, through smart contracts, achieves zero-threshold fundraising and zero management fees [29]. After deducting network friction costs, returns are distributed to liquidity providers strictly in proportion. This disintermediated profit-distribution model raises the efficiency of capturing market-making returns to a level traditional finance can scarcely reach.

Innovation comes with limitations that cannot be ignored, however. Traditional structured products, though costly and opaque, are backed by strict regulatory endorsement and well-developed investor-protection mechanisms; when a product faces extreme risk, a clear path of legal recourse exists. The protocol vault, by contrast, operates in an unregulated, crypto-native environment, where the principle that code is law means liquidity providers must bear all technical risks and economic losses themselves. Moreover, traditional products typically provide standardized risk metrics (such as a value-at-risk (VaR) calculation), whereas the protocol vault currently lacks a unified risk-assessment framework, making it difficult for ordinary investors to gauge their true level of risk exposure accurately.

### 21.4.6 Governance dilemmas

As a piece of code-driven, community-funded financial infrastructure, the protocol vault faces a series of complex trade-offs at the governance level. These dilemmas arise from a fundamental contradiction between the vault's public-good character and the strategic secrecy it needs to survive in a competitive market.

The foremost conflict is the transparency paradox. From the liquidity provider's standpoint, extreme transparency is the foundation of trust; they need to know exactly how their funds are being used. In a zero-sum trading market, however, strategic transparency often amounts to an exploitable weakness. When the vault's quoting logic, inventory thresholds, and rebalancing frequency are public to the entire network, professional quantitative teams can readily construct targeted counter-strategies—front-running the vault before it adjusts its position, or imposing a liquidity squeeze when the vault is forced to close out [8]. This adverse selection cost created by transparency is ultimately borne by the liquidity providers. The protocol must therefore find a fragile balance between "reassuring investors" and "preventing arbitrage by counterparties."

Another core dilemma is the locus of control over parameters. Although the vault's strategy engine runs automatically, its core parameters (such as the spread multiplier and inventory tolerance) still require human setting. Handing control over parameters entirely to the core team would in effect degrade the vault into a centrally managed black-box fund, betraying the original intent of decentralization. But entrusting parameter adjustments to a decentralized autonomous organization (DAO) through token voting would leave the vault unable to respond in time to a rapidly shifting market microstructure, given the lengthy governance process [39]. Under extreme conditions, a delay of a few minutes in adjusting a parameter can mean losses of millions of dollars. This tension between "decentralizing control" and "maximizing execution efficiency" is a governance challenge shared by all on-chain automated market-making protocols today.

The dilemma over parameter control is especially acute in extreme events. The emergency handling of the JELLY incident in March 2025 revealed a phenomenon of "crisis governance reversion": when the vault faced an unrealized loss of approximately $13.5 million that threatened the safety of the entire vault's roughly $230 million in assets (the vault's assets under management at the end of March 2025, when the JELLY incident occurred), Hyperliquid's validators voted in an emergency to forcibly settle all JELLY positions at $0.0095 (far below the then-prevailing market price of about $0.50) and delisted the token from the platform. This intervention is functionally equivalent to the manual risk-control intervention of a CEX and stands in inherent tension with the engineering positioning of delegation "to code rather than to a person" in Section 21.3.1. From the perspective of institutional analysis, DEX liquidity engineering today in fact operates in a hybrid mode: governed by code rules under normal conditions, reverting to human discretion in a crisis. This arrangement has its counterpart in traditional finance—for example, a central bank follows policy frameworks such as the Taylor rule under normal conditions but exercises emergency discretion in a crisis. But the analogy also exposes a legal uncertainty: if the protocol claims to be decentralized, a validator vote that unilaterally alters the terms of a trade may constitute breach under contract law; if it concedes that a centralized decision-making entity exists, that entity may face legal charges of market manipulation. The boundary of legitimacy for crisis governance reversion is an unresolved institutional gap in DEX governance architecture today.

The vault mechanism also faces an existential threat distinct from market-microstructure risk: legal-characterization risk. The HLP vault aggregates retail capital, manages it uniformly through an algorithmic strategy, and distributes returns in proportion to shares—a structure that may satisfy all four prongs of the Howey test under U.S. securities law: an investment of money (depositors inject USDC), a common enterprise (funds are pooled into a single pool), an expectation of profit (depositors expect to earn returns through market-making activity), and reliance on the efforts of others (returns depend on the protocol code and the core team's strategy settings). In most jurisdictions, such a structure could be deemed a collective investment scheme or a fund product. If vault shares were classified as securities, the protocol would face the compliance requirement of registering as an investment company or fund manager, which would fundamentally alter the viability of the DEX liquidity-engineering model, because the permissionless participation, zero management fees, and instant global access described in Section 21.3 would all be difficult to sustain under the current securities-regulatory framework.

In addition, an endogenous conflict exists between liquidity providers' redemption rights and the vault's system resilience. To ensure the free entry and exit of funds, a vault typically allows users to redeem their capital at any time after a very short lock-up period [29]. When the market suffers an extreme crisis and the vault faces a severe drawdown, however, investors' flight to safety often triggers a large-scale wave of redemptions. This procyclical withdrawal of capital not only weakens the vault's ability to take over liquidated positions but also forces the strategy engine to close out and realize positions when liquidity is at its worst, entering a negative feedback loop of "NAV decline → capital redemption → forced liquidation → further NAV decline." Unlimited redemption rights thus in fact constitute the vault's principal source of systemic risk in extreme states. How to design a reasonable exit mechanism (such as a dynamic redemption fee or crisis-period withdrawal limits) that both protects investors' interests and preserves the vault's capital-buffer capacity is a pressing question for liquidity governance.

### 21.4.7 Division of labor among vaults

As decentralized derivatives exchanges expand in scale, an architecture in which a single vault bears all liquidity responsibilities gradually exposes a problem of internal cross-contamination of risk. A market-making strategy pursues high-frequency, low-volatility, stable returns, whereas liquidation takeover involves low-frequency, high-volatility, tail-risk exposure. Mixing these two lines of business, with their sharply different risk-return profiles, in the same capital pool leaves liquidity providers unable to allocate precisely according to their own risk preferences. A natural conception of architectural evolution to address this is to introduce specialized division of labor, stripping the liquidation function out of the market-making vault to form an independent liquidation liquidity provider (LLP) vault [41]. This division of labor, however, is a matter of mechanism design and evolutionary conception rather than current deployment: as of June 2026, Hyperliquid's official documentation shows that its liquidator vault remains a constituent strategy of HLP rather than an independent, firewall-isolated vault standing alongside HLP [29]; the analysis below should accordingly be understood as a conceptual exploration of specializing the liquidation function.

This division-of-labor architecture achieves an economic isolation and repricing of risk. HLP concentrates on two-sided order book quoting in normal markets, earning returns by capturing the bid-ask spread and a share of trading fees; its risk exposure is concentrated mainly in ordinary adverse selection and short-term inventory fluctuations, suiting risk-neutral investors who seek relatively stable cash flow. The LLP vault, by contrast, serves specifically as the protocol's lender of last resort, taking over defaulted positions when traders are forcibly liquidated and compensating itself for the extreme market risk it bears by collecting liquidation penalties. This design attracts investors with a higher risk tolerance who are willing to endure long periods of idle capital in exchange for capturing the crisis premium.

Figure 21-9 illustrates the division of labor in this conception between the HLP market-making vault and the LLP vault: HLP handles two-sided order book quoting in normal markets, with income drawn mainly from market-making spreads and fees; the LLP vault focuses on taking over defaulted positions at moments of crisis, earning returns through liquidation penalties; and a risk-isolation firewall between the two ensures that the shock of the liquidation flow is not transmitted to the inventory balance of the market-making strategy.

![Figure 21-9](./images/fig-21-9-en.png)

**Figure 21-9.** The division-of-labor architecture of HLP and LLP (Schematic: the division of labor and risk isolation between HLP and an independent liquidation vault is a matter of mechanism design and evolutionary conception; as of June 2026, Hyperliquid's liquidator vault is a constituent strategy of HLP rather than an independent vault [29]; theoretical basis: Chitra 2025, Autodeleveraging [41])

Specialized division of labor not only meets differentiated demand on the capital side but also produces a marked synergy at the level of strategy execution. Under the single-vault model, when cascading liquidations occur in the market, the enormous flood of defaulted positions instantly breaks the inventory balance of the market-making strategy, forcing the engine to stop quoting or even to take orders in the opposite direction to close out—draining order book depth at precisely the moment the market needs liquidity most. Once an independent liquidation vault is introduced, defaulted positions are isolated and taken over, and the market-making vault's inventory state is spared the direct shock of the liquidation flow. This isolation mechanism lets the market-making strategy keep running normally for longer under extreme conditions, thereby raising the systemic resilience of the entire exchange's liquidity supply. The risk-isolation effect of the division-of-labor architecture may fail in an extreme tail event, however. When the whole market suffers a one-sided move that triggers cascading liquidations, the liquidation vault is forced to take on a large volume of same-direction positions at the same time that the HLP market-making vault is accumulating inventory in that same direction through normal market making; the profit and loss of the two vaults then become highly positively correlated under extreme conditions, and the diversification effect disappears exactly when it is most needed. This resonance risk within the system is directly related to the countercyclical nature of liquidity discussed in Chapter 20, and mitigating it requires introducing directional constraints at the vault-design level (such as a hedging requirement for the liquidation vault) or a time-delay mechanism (such as delaying the takeover of liquidated positions to avoid a short-term price shock).

Through capital aggregation, automated strategy execution, and specialized risk isolation, the protocol vault mechanism accomplishes a deep deconstruction and reshaping of the traditional market-making model. It demonstrates that in a decentralized network, complex financial-intermediation services can be transformed into transparent protocol rules. Yet engineering liquidity provision does not eliminate risk; it changes the form of its distribution. In the market's future evolution, this new kind of delegation relationship—one that takes code as the agent—must still withstand the stress test of more extreme cycles.

## 21.5 A survival simulation for the independent market maker

The core goal of liquidity engineering is to convert dispersed capital into continuous two-sided quotes through protocol rules. Within this architecture, the vault represents a passive route to participation, allowing ordinary users to delegate their funds to the protocol's strategy engine. The on-chain central limit order book, however, also allows independent market makers to connect directly through the API and run their own strategies. These two modes of liquidity provision are complementary in microstructure terms. To assess the effectiveness of the protocol's incentives in attracting active market makers, this section simulates the operation of a mid-sized independent market maker on the Hyperliquid platform, quantifies its risk-return structure, and explores its boundary of profitability under different market scenarios.

### 21.5.1 Simulation setup

Assessing a market maker's ability to survive requires a parameter system consistent with the features of the on-chain environment. The parameter settings below are calibrated against empirical ranges in the public literature: the volatility assumption references the empirical range of roughly 60%–75% for the annualized realized volatility of BTC perpetual futures [42]; the spread and adverse selection ratios reference the BTC perpetual futures order book microstructure data reported by He et al. (2022) [43] (an average bid-ask spread below 0.05 basis points and a price impact below 0.3 basis points for a $500,000 order; the basis-point convention here follows the original paper's definition of relative spread, and readers should note the conversion between basis points and percent when citing) as well as the adverse selection decomposition of the effective spread in Tiniç et al. (2023) [8]; and the funding rate distribution references the BIS working paper by Schmeling et al. (2023) [44]. The simulation is intended to provide an illustrative analysis rather than a precise quantitative forecast, and the specific figures vary significantly across market cycles and platforms. This simulation constructs the profile of a typical mid-sized independent market maker with an initial capital of $750,000, focused mainly on perpetual futures pairs of mid-cap crypto assets (such as ETH or SOL). The market maker employs a classic inventory-management strategy, and its infrastructure has an order-execution latency of between 200 and 500 milliseconds. This latency is upper-middle for the on-chain environment; although it cannot rival the microsecond-level colocated execution of a traditional centralized exchange, it is sufficient to maintain competitive quotes on most decentralized limit order books.

The strategy parameters directly determine the market maker's behavior on the order book. The base two-sided spread is set at ±3 basis points, a width that provides effective liquidity while preserving a basic profit margin for the maker. On order depth, the maker maintains $50,000 to $100,000 of posted size on each side of the book. Inventory management is the core of the market-making strategy: when the absolute value of one-sided inventory exceeds $200,000, the strategy engine triggers a quote-skewing mechanism that adjusts the asymmetry of the bid-ask spread to attract offsetting orders and push inventory back toward neutral. In addition, to guard against extreme tail risk, when short-term market volatility exceeds three standard deviations, the strategy automatically suspends two-sided quoting and enters a risk-averse state.

The market-environment assumptions abstract real historical data into three typical scenarios. The normal market occupies about 65% of trading time and is characterized by steady volatility and randomly distributed order flow. The high-volatility market accounts for about 25% and usually accompanies macroeconomic data releases or major industry events; it is characterized by a pronounced one-sided price trend and a markedly narrowed effective spread. The extreme-crisis scenario, though only 10% of the time, typically manifests as liquidity exhaustion and a liquidation cascade and is the critical period that tests a market maker's ability to survive. These three scenarios form the base environment for the revenue and cost calculations that follow. The 10% probability assigned to the extreme scenario is based on the empirical frequency of the 2024–2025 crypto perpetual futures market, in which roughly 10% of trading weeks saw an extreme event with intraday volatility above 5%. Sensitivity analysis shows that as the frequency of tail events rises, the market maker's expected annualized return converges rapidly toward breakeven (the specific critical value is illustrative only and depends on the parameter settings), which reflects the decisive influence of tail-risk pricing on any judgment of profitability.

### 21.5.2 The revenue side

An independent market maker's revenue has three main components, which differ in stability and predictability. The first source is the liquidity-provider rebate offered by the protocol. To attract market makers, many decentralized exchanges adopt a maker rebate—awarding a fee bonus for orders that provide liquidity and are ultimately filled [5]. This income is relatively stable, and its size depends directly on the maker's average daily volume and the rebate rate the protocol sets. In the simulation, this income is treated as the maker's unconditional base return and forms the first line of defense in covering fixed operating costs.

The second source is bid-ask spread capture, the most central way a traditional market maker profits. By quoting both a bid and an ask, the maker earns the difference on two-sided fills. The theoretical spread does not equal the return actually captured, however. The capture rates and loss rates below are all calibrated values for this simulation, not empirical observations. In a normal market, the relatively high randomness of order flow typically keeps the maker's effective spread-capture rate between 40% and 60%. This rate measures the share of orders filled on both sides (the gross capture rate); after deducting adverse selection costs and operating friction, the net profit margin is about 0–30%. When the market turns highly volatile, the strengthening one-sided trend often leaves the maker able to fill only passively on the unfavorable side, and the effective capture rate falls sharply to 20%–30%. In an extreme crisis, with the market in a one-directional wave of large-scale selling or buying, the maker can barely achieve two-sided matching, and the spread-capture rate approaches zero.

The third profit-and-loss component is net funding rate income. The funding rate is the core mechanism used to anchor the spot price in perpetual futures markets, with longs and shorts periodically exchanging payments according to the price deviation [43]. For a market maker, this income is highly random. Strictly speaking, the funding rate should be classified as a conditional profit-and-loss item tied to inventory direction rather than a pure revenue item: a neutral market maker's net funding rate income is close to zero when its long and short positions are roughly balanced, and it becomes a stable source of income only when the maker holds a systematic directional tilt—at which point the maker also bears directional risk [44]. Its sign depends on the product of the maker's current inventory direction and the direction of the funding rate. If the maker holds inventory opposite to the market's dominant trend, it usually receives a positive funding rate payment; otherwise it must pay. Research shows that in certain market environments, funding rate arbitrage can itself constitute an independent profit strategy [45]. In a pure market-making strategy, however, funding rate income tends to be one of the more volatile components of the profit-and-loss statement and cannot serve as a stable profit expectation.

### 21.5.3 The cost side

While pursuing the revenue above, the market maker must bear costs and risks along several dimensions. The adverse selection loss is the maker's principal implicit cost. When a trader with an informational advantage enters the market, the maker often fills against it at an unfavorable price, after which the market price moves adversely and the maker incurs a paper loss [46]. In the on-chain environment, because all trade data and smart-contract states are publicly visible, the maker's quoting intent is more easily exploited by high-frequency arbitrageurs or MEV searchers. The adverse selection loss rate for on-chain market making is therefore typically higher than at a traditional centralized exchange. In a normal market, this loss accounts for about 30%–40% of the theoretical spread; in a high-volatility scenario, about 60%–80%; and in an extreme scenario, it may exceed 100%, meaning the maker loses substantively on every fill.

Inventory-fluctuation loss is the second core cost. In the course of providing two-sided quotes, a market maker inevitably accumulates one-sided positions. Until inventory reverts to neutral, these positions are fully exposed to market price fluctuations [47]. The simulation shows that inventory-fluctuation loss is significantly positively correlated with the volatility of the underlying asset and with the maker's average inventory-holding time. In a market with a strong one-sided trend, the maker tends to accumulate a large volume of disadvantaged positions, and the effectiveness of the inventory-management mechanism is severely tested. If the price deviates faster than the quote-skewing strategy can attract offsetting orders, the maker faces enormous unrealized losses.

In addition, the market maker must bear the friction costs and institutional costs of on-chain execution. Although some appchains or layer-2 networks significantly lower the per-trade fee, the cumulative execution cost remains a non-negligible expense for a maker that must update its quotes at high frequency. Institutional costs include the infrastructure investment needed to sustain around-the-clock operation and the special risk premium that may arise in a decentralized protocol, such as an unexpected loss from an anomalous triggering of the liquidation engine. These fixed and semi-fixed costs further raise the maker's profitability threshold.

### 21.5.4 Scenario analysis

Substituting the revenue and cost elements above into the three specified market scenarios yields the results in Figure 21-10: in the normal market the net-asset-value curve rises smoothly; in the high-volatility scenario, profit and loss alternate around the zero axis with markedly greater variance; and in the extreme-crisis scenario the net asset value falls sharply—vividly displaying the asymmetry of tail risk.

![Figure 21-10](./images/fig-21-10-en.png)

**Figure 21-10.** Profit-and-loss simulation for an independent market maker: three scenarios (Data source: Monte Carlo simulation; the volatility parameters are calibrated against the empirical range of 60%–75% for the annualized realized volatility of BTC perpetual futures [42], the adverse selection ratio against the effective-spread decomposition reported by Tiniç et al. 2023 [8], and the funding rate distribution against the BIS working paper [44])

In a normal market, the maker can serve effectively as a liquidity intermediary. Here the randomness of order flow keeps two-sided fills relatively balanced, and spread capture is sufficient to cover adverse selection losses and execution costs. The simulation shows that in this scenario the maker's combined average daily return reaches 0.05%–0.15% of its capital, and the net-asset-value curve trends steadily upward. This indicates that in a calm market environment, the protocol's incentives and the maker's profit motive achieve good incentive compatibility.

When the market enters the high-volatility scenario, the maker's profit structure deteriorates markedly. The formation of a one-sided trend quickly unbalances inventory, and the adverse selection loss rate climbs to 60%–80% of the theoretical spread. Although rising trading volume may bring more rebate income, this increment is often insufficient to offset the paper losses caused by inventory fluctuations. At this stage, the maker's average daily return oscillates violently around the breakeven line, and the variance of the net-asset-value curve increases significantly. The maker's core task shifts from pursuing profit to controlling risk, and the strategy centers on how to clear disadvantaged inventory quickly through aggressive quote-skewing.

In the extreme-crisis scenario, market microstructure fractures. Large-scale one-directional orders flood the order book, the maker's effective spread-capture rate drops to nil, and the adverse selection loss far exceeds 100%. More seriously, in an environment of liquidity exhaustion the inventory-management mechanism fails completely, and the maker cannot find a counterparty willing to take the other side. The simulation shows that in this scenario the maker faces a significant single-day loss and the net-asset-value curve drops sharply. This asymmetric tail risk is precisely the fundamental reason many independent market makers choose to cancel their quotes and exit the market in the early stage of a crisis.

### 21.5.5 The profitability boundary

A market maker's ability to survive is highly sensitive to several microstructure parameters. As shown in Figure 21-11, a sensitivity analysis of four parameters in turn—capital size, base spread, market volatility, and competitive intensity—can delineate the profitability boundary of an independent market maker in the on-chain environment, which also indirectly reflects the lower bound of the protocol's incentive effectiveness.

![Figure 21-11](./images/fig-21-11-en.png)

**Figure 21-11.** Sensitivity analysis of the profitability boundary (Data source: numerical calculation; model parameters are given in Section 21.5.1; the trade-off between fill probability and adverse selection references the empirical study of Binance BTC perpetual futures by Albers et al. 2025 [48])

Capital size is the foundation of a market maker's risk-bearing capacity. The analysis shows a nonlinear positive relationship between capital size and the annualized return. A smaller capital base means the maker more easily hits its risk limits when inventory becomes unbalanced and is thus forced to close out at unfavorable prices. Only when capital size exceeds a certain threshold (about $500,000 in the simulation) (this refers to total capital, including margin and operating reserves; at an initial margin rate of 5%–10%, it can support a notional market-making position of roughly $5 million to $10 million, and the simulation covers only a single mid-cap trading pair) can the maker cover its fixed costs while retaining enough of a cushion to absorb the short-term drawdowns of a high-volatility market.

The base spread directly determines the maker's gross margin. Given an adverse selection probability, too narrow a spread makes the expected return on each trade negative and traps the maker in structural losses. Yet the spread is also tightly constrained by market competition. Rising competitive intensity forces makers to narrow their quotes to compete for fills, compressing profit margins across the whole industry [49]. As the number of active makers grows, each maker's share of order flow shrinks and the profitability boundary shifts upward, requiring superior execution efficiency or lower operating costs for a maker to survive.

Market volatility is the most active exogenous variable affecting the profitability boundary. Moderate volatility helps increase trading volume and opportunities for spread capture, but once volatility exceeds the strategy model's tolerance ceiling, inventory risk is amplified exponentially. The sensitivity analysis clearly displays the trajectory of returns decaying rapidly as volatility rises. This means the protocol's incentives must be able to provide extra risk compensation during high-volatility periods; otherwise a rational independent market maker will inevitably choose to exit, causing liquidity provision to fracture exactly when it is most needed.

### 21.5.6 Active versus passive

Having assessed the independent market maker's survival, the analysis now turns to the route by which an ordinary user deposits funds directly into the protocol vault (passive participation). These two modes of liquidity provision differ fundamentally in source of return, risk control, and barrier to participation. As shown in Table 21-3, the independent market maker has full autonomy over its source of return and risk control, able to adjust its strategy dynamically according to the market state or even to retreat; the vault participant, by contrast, delegates these decisions entirely to the protocol code, gaining a much lower technical barrier and a relatively smooth return curve at the cost of losing the flexibility to exit actively during a crisis.

| Dimension | Independent market maker (active) | Vault participant (passive) |
| :--- | :--- | :--- |
| Source of return | Fully self-controlled; depends on the maker's own strategy for spread capture and rebates | Controlled uniformly by the protocol engine; shares in aggregate fees and liquidation penalties |
| Risk control | Dynamically adjusted; can suspend quoting or retreat at any time | Passively borne; constrained by protocol parameters and a withdrawal cooldown |
| Technical barrier | Very high; requires low-latency infrastructure and quantitative R&D capability | Very low; participation requires only an on-chain transfer |
| Expected return | Highly dispersed; may earn excess profit or face severe loss | Relatively smooth; reflects the market-average market-making return |
| Behavior in a crisis | Tends to cancel quotes to avoid unknown tail risk | Strategy rigidity keeps capital continuously exposed, providing floor liquidity |

**Table 21-3.** Risk-return comparison of the independent market maker and the vault liquidity provider (Data source: protocol documentation and inference from microstructure theory [50][51]). Note: this table is organized along the "active-passive participant identity" axis; its "source of return" and "risk control" correspond to the effectiveness and incentive-compatibility dimensions of the four-dimensional framework in Section 21.1.3, and "behavior in a crisis" corresponds to the resilience dimension

From an economic perspective, these two models are not simple substitutes but form complementary layers of the on-chain liquidity ecosystem. The independent market maker represents "elite-tier liquidity": through refined algorithms and very low latency, it provides the tightest bid-ask spreads in normal markets and dominates the price-discovery process. Because it has full autonomy, however, its liquidity provision tends to prove fragile in an extreme crisis.

By contrast, vault participants pool long-tail capital to form "base-tier liquidity." Although the protocol engine's strategy may be less sharp than that of a top independent market maker, its core feature is the rule-verifiability of code execution. Under normal market conditions, vault capital still maintains quotes according to established rules, providing the market with an indispensable liquidity floor. This "active-passive" dual-track architecture lets a decentralized exchange pursue everyday efficiency while gaining a degree of systemic resilience.

### 21.5.7 Judging effectiveness

On the basis of the simulation above (a single-agent profit-and-loss simulation on the independent-market-maker side) and the vault analysis in Section 21.4, a comprehensive judgment can be made of the protocol-level liquidity incentives. Assessing the effectiveness of an incentive mechanism requires distinguishing two different goals: *attracting* and *retaining*.

On attraction, economic incentives such as rebates and fee shares prove markedly effective in normal markets. As long as the protocol can offer a stable expectation of trading volume, the clear financial return is enough to overcome the initial technical barrier and friction costs of an independent market maker entering the on-chain environment. The simulation data confirm that, under reasonable parameter settings, an active market-making strategy can achieve a capital return exceeding the risk-free rate, which explains why an emerging decentralized exchange can amass considerable order book depth in a short time.

On retention, however—especially in the face of an extreme market crisis—financial incentives alone are often insufficient to offset the potential losses. When the expected value of adverse selection losses and inventory risk exceeds the marginal utility of the rebate, the rational maker's sole optimal solution remains retreat. This means traditional incentives cannot fundamentally resolve the public-goods dilemma of liquidity provision. Against this backdrop, the protocol vault mechanism reveals its distinctive structural value. The vault exists not to beat independent market makers on efficiency but to provide the market with a compulsory crisis buffer by fixing a market-making obligation onto a portion of capital. The conclusion this section's single-agent simulation can directly support is only that independent market makers tend to retreat in an extreme crisis. The claim that "the vault's floor liquidity absorbs concentrated selling pressure, reduces independent market makers' one-sided inventory risk, and thereby induces them to stay" is a theoretical inference not yet proven by this simulation; testing it would require a multi-agent simulation or empirical data that incorporate the interaction between the vault and independent market makers. Under this mechanism hypothesis, the presence of floor liquidity could improve the survival environment for independent market makers and induce some that had planned to retreat to stay instead, thereby enhancing the stability of the entire market microstructure at the macro level.

## 21.6 Comparison and coexistence of the two paradigms

The preceding sections analyzed the internal logic of CEX procurement and DEX engineering in turn. This section places the two paradigms within a unified analytical framework for systematic comparison, discusses the substantive meaning of liquidity democratization, and looks ahead to the two paradigms' coexistence and future trends.

### 21.6.1 Systematic comparison

The central problem of liquidity governance is how to sustain market makers' willingness to participate across different market states. Centralized and decentralized exchanges take sharply different institutional paths to this problem. A centralized exchange *procures* liquidity from professional institutions through bilateral private agreements, whereas a decentralized exchange exemplified by Hyperliquid *engineers* the supply of liquidity through smart contracts and a vault mechanism. The two paradigms display systematic differences along dimensions such as normal-market liquidity quality, crisis resilience, transparency, and barrier to entry.

The quality of liquidity in a normal market is the foremost indicator of market-microstructure efficiency. Through strict capital thresholds and market-making obligation clauses, a centralized exchange can screen for top market makers with high-frequency trading capability and maintain extremely narrow bid-ask spreads and deep order books on major pairs; a decentralized exchange, constrained by on-chain settlement latency and algorithmic rigidity, can usually attain only a medium-to-high level of normal-market liquidity quality [16]. This difference often reverses under extreme conditions, however: a centralized exchange's agreements generally contain an abnormal-market-conditions exemption that allows market makers to withdraw quotes amid violent volatility, intensifying market fragility just when liquidity is needed most; a decentralized exchange's protocol-level market-making vault, by contrast, quotes continuously according to preset rules and does not retreat on the basis of subjective judgment, providing the market with a liquidity floor—though this may still be overridden by governance intervention under extreme boundary conditions.

Table 21-4 consolidates the analysis above into a systematic comparison of the two paradigms across six core dimensions. CEXs and DEXs exhibit a complementary distribution of strengths across several dimensions: the CEX is superior in normal-market liquidity quality and crisis-response speed, while the DEX holds structural advantages in transparency and barrier to entry; and the difference between them in crisis liquidity resilience—that a CEX's market makers may legally retreat whereas a DEX's vault will not withdraw its orders—constitutes the core finding of this chapter's analysis.

| Dimension | CEX procurement | DEX engineering (Hyperliquid type) |
| :--- | :--- | :--- |
| Normal-market liquidity quality | Very high | Medium-to-high |
| Crisis liquidity resilience | Falls sharply (retreat + exemption) | Has a floor, but can be overridden by governance intervention |
| Transparency | Very low | Very high |
| Barrier to entry | Very high | Low |
| Conflict of interest | Severe | Lower but present |
| Crisis-response speed | Fast (human intervention) | Slow (rule rigidity) |

**Table 21-4.** Systematic comparison of CEX procurement versus DEX engineering (Data source: Aquilina et al. (2024) [16] and protocol-mechanism analysis). Note: this table is a projection of the four-dimensional framework of Section 21.1.3 along the "CEX vs. DEX" axis—"normal-market liquidity quality" corresponds to effectiveness, "crisis liquidity resilience" and "crisis-response speed" correspond to resilience, "transparency" matches the dimension of the same name, and "conflict of interest" corresponds to incentive compatibility; "barrier to entry" is an incremental dimension of this table relative to the four-dimensional framework

On transparency and conflict of interest, a centralized exchange's principal-agent model contains inherent information asymmetry. As rule maker and referee—sometimes even competing directly in the market through a proprietary market maker—the exchange's dual role gives rise to a serious conflict of interest. A decentralized exchange, by contrast, encodes all rules in smart contracts, with strategy parameters and fund flows fully visible on-chain, greatly reducing the cost of trust [3]. This high transparency also brings the risk of the algorithm being gamed, however, and in the face of an unknown crisis, rule rigidity makes its response far slower than a centralized exchange's human intervention.

### 21.6.2 The democratization of liquidity

The engineering paradigm of decentralized exchanges has not only changed how liquidity is produced but also structurally advanced the *democratization of liquidity*. This concept is not mere marketing rhetoric but comprises three interwoven dimensions: democratization on the supply side, democratization of information, and democratization of risk-bearing [52].

Democratization on the supply side breaks professional market makers' monopoly on market-making returns. In the traditional architecture, market making requires a very high capital threshold and complex infrastructure, and ordinary investors can only be consumers of liquidity (takers) who pay the spread. Through the liquidity-vault design, a decentralized exchange lets any user holding assets inject funds proportionally, aggregating retail capital into institutional-grade market-making capital. This mechanism allows ordinary participants to capture returns at the market-microstructure level, achieving a shift in identity from consumer to producer.

Democratization of information seeks to weaken the informational privilege among market participants. A centralized exchange often provides particular market makers with better order-flow data or lower latency through premium interfaces, and this opaque allocation of privilege intensifies the market's adverse selection risk. In the on-chain order book model, all order-submission, matching, and settlement data are publicly queryable, and the strategy engine's parameters are disclosed through the governance process. Although this high degree of transparency erodes the excess profit that comes from an informational advantage, it significantly reduces the systemic crisis of trust caused by information asymmetry (as noted in Section 21.3.3, privileges such as the on-chain sequencer's execution priority have not been eliminated entirely) [53].

Democratization of risk-bearing is an inevitable result of the liquidity-vault mechanism. A professional market maker usually must bear extreme inventory risk and price-fluctuation risk alone, whereas the vault mechanism spreads these risks, by share, across all liquidity providers. This risk-diversification effect raises the system's capital-carrying capacity under normal conditions but conceals a deep cost. Retail liquidity providers often lack the ability to price complex market-making risks and are easily drawn by high yields into underestimating the tail risk of extreme conditions. At the same time, because setting the strategy parameters requires a high degree of expertise, governance power may ultimately concentrate in a few core developers, diverging at the decision-making level from the original intent of full democratization.

### 21.6.3 The pattern of coexistence

The two paradigms of liquidity governance are not absolute substitutes but display marked complementarity across different asset classes and market states. The evolution of market structure suggests that centralized procurement and decentralized engineering are forming a pattern of coexistence based on comparative advantage.

In trading major assets (such as Bitcoin and Ethereum), the centralized exchange—by virtue of its very high efficiency and low-latency advantage in normal markets—still dominates price discovery. Professional market makers can maximize profit on these highly liquid assets and therefore have a strong incentive to participate in a centralized exchange's liquidity procurement. When the market suffers an extreme shock that causes professional market makers to retreat en masse, however, the decentralized exchange's protocol-level vault takes on the function of supplying floor liquidity. Its non-retreating character may cause paper losses in the short run, but it provides a last-resort floor for the price continuity of the entire crypto market. This combination of everyday quality and a crisis floor constitutes the complete resilience of the market structure for major assets.

For long-tail assets, the divergence between the two paradigms is more pronounced. Because long-tail assets have high volatility and unstable trading demand, professional market makers face very high inventory risk and adverse selection costs and are often unwilling to provide liquidity services for them on a centralized exchange. Here the engineering advantage of the decentralized exchange comes fully into play. Through permissionless vault creation and community-driven capital aggregation, a long-tail asset can quickly cross the cold-start threshold of bootstrapping liquidity [3]. In this setting, the decentralized mechanism fills the void that centralized capital is unwilling to enter and becomes the only effective path to price discovery for an innovative asset.

The analysis above rests on an implicit assumption: that the liquidity systems of the CEX and the DEX operate independently, so that their complementarity still holds under extreme conditions. In real markets, however, several channels of risk transmission exist between the two systems and may cause the complementary structure to fail synchronously at the moment it is most needed. The same market maker often operates on both Binance and Hyperliquid, sharing a capital pool and risk limits. When the CEX side suffers a large loss, the maker may be forced to withdraw liquidity from the DEX side at the same time to satisfy its overall risk-control requirements, forming a cross-platform liquidity contagion. More critically, a CEX market maker's triggering of the exemption clause to exit and a redemption run by DEX vault depositors may be set off synchronously by the same macro event (such as systemic deleveraging or a regulatory shock). During the FTX collapse of November 2022, DEX trading volume surged briefly while order book depth likewise contracted sharply, providing an empirical precedent for this kind of resonant failure. The coexistence of the two paradigms is therefore more accurately described as a *conditional complementarity*: complementarity holds under moderate market stress but may fail on both sides during a systemic liquidity shock.

Moreover, as regulatory frameworks gradually clarify, compliance considerations will further entrench this divergence. Centralized exchanges will increasingly tend to serve institutional clients and regulated assets, and their liquidity-procurement agreements will become more standardized and legalized; decentralized exchanges will continue to serve as liquidity infrastructure for borderless, censorship-resistant assets, relying on cryptographic engineering to sustain their distinctive niche.

### 21.6.4 Future trends

The evolution of the microeconomics of liquidity has not stalled. As the technology matures and market depth increases, three emerging trends are reshaping the frontier of decentralized liquidity engineering.

AI market-making agents are sharply lowering the technical barrier for independent market makers. Traditional high-frequency market-making strategies require a large quantitative team and expensive computing resources, whereas a new generation of automated algorithmic models can adaptively adjust quoting parameters and inventory-management strategies through machine learning [54][55]. The spread of such intelligent tools will let more small and mid-sized quantitative teams, and even individual developers, connect to decentralized order books as independent market makers, supplementing the more flexible "elite-tier liquidity" beyond the protocol vault. In the four-dimensional framework, this trend mainly improves the effectiveness dimension, converging the DEX's normal-market liquidity quality toward the CEX standard.

Building a cross-chain liquidity layer acts directly on two dimensions: effectiveness and incentive compatibility. At present, liquidity is fragmented across numerous isolated blockchain networks and specific protocols, resulting in low capital utilization. A new generation of cross-chain aggregation architectures schedules liquidity across networks through standardized messaging and asset-locking mechanisms [56]. Once this underlying interoperability is fully realized, a liquidity vault will be able to allocate capital dynamically based on the real-time yields of each chain, evolving from a market maker in a single market into a liquidity provider for the global market.

The rise of the liquidity-as-a-service model is breaking the traditional binding of signed contracts. In this model, liquidity is no longer an appendage tied to a specific exchange but is abstracted into an independent resource that can be called through a standardized interface. A project team or an emerging trading platform no longer needs to conduct cumbersome bilateral negotiations with market makers but instead *rents* the market-making depth it needs directly from a decentralized liquidity network. This modular architecture for liquidity provision not only greatly lowers the startup cost of a new market but also marks liquidity's transformation from a passively procured service into programmable, composable financial infrastructure. In the four-dimensional framework, the liquidity-as-a-service model improves both transparency (a standardized interface replaces private agreements) and resilience (a modular architecture allows rapid switching among liquidity sources), but its incentive compatibility depends on whether the pricing mechanism can accurately reflect the true cost of liquidity across different market states.

## 21.7 Chapter summary

Chapters 19 through 21 together build a complete analytical framework for understanding the problem of liquidity provision. This chapter has examined two sharply contrasting governance responses: the CEX liquidity-procurement model and the DEX liquidity-engineering model. The former forms a principal-agent relationship by signing private agreements with market makers; it is efficient and flexible under normal conditions, but the adverse selection and moral hazard bred by information asymmetry erupt in concentrated form during periods of extreme volatility, when market makers invoke the exemption clause to retreat legally—shedding their supply obligation precisely when the system needs liquidity most. The latter, exemplified by Hyperliquid's HLP vault, uses a three-layer architecture of capital, strategy, and distribution layers to turn liquidity provision into a protocol-native automated process, lowering the barrier to entry; it does not eliminate the principal-agent problem, however, but transforms it into a new kind of trust relationship between depositors and protocol code, introducing new dimensions of risk such as algorithmic rigidity, parameter governance, and smart-contract vulnerabilities.

The core finding of this chapter is that the distinctive governance value of the DEX engineering model is not superior efficiency but the verifiability and ex post auditability of its execution rules. Under normal market conditions, the strategy engine executes deterministically according to preset rules and does not withdraw orders on the basis of sentiment or profit motive; but the JELLY and POPCAT incidents show that under extreme boundary conditions, the protocol may still override code execution through governance mechanisms such as a validator vote. This hybrid mode of "code governance in normal times, human discretion in crises" resembles a CEX's human intervention in its outcome, but its process is transparent and auditable on-chain—and this difference, rather than "the determinism of execution," constitutes the true distinction between the two models. Within the four-dimensional framework of effectiveness, incentive compatibility, transparency, and resilience, CEX procurement and DEX engineering form a complementary market structure: the former provides efficient elite liquidity under normal conditions, and the latter provides resilient floor liquidity in a crisis.

As the paradigms of liquidity production and governance evolve, the market's central tension gradually shifts from how to maintain order book depth to how to cope with sharp swings in asset prices. A market maker's inventory risk, the liquidation engine's throughput capacity, and the preservation of vault capital all ultimately depend on the system's ability to price and absorb volatility. When liquidity provision becomes a test of endurance against extreme price movements, a microstructure analysis of volatility itself becomes an unavoidable subject—and this lays the groundwork for the discussion of volatility and derivatives pricing in Part Eight.

## References

[1] Binance Square (community submission; author Louis Wang / Biteye Core Contributor; not an institutional Binance Research report). (2025). *In-depth research on Hyperliquid: The DeFi legend from zero to trillion*. Accessed June 2026. https://www.binance.com/en/square/post/28571815431049

[2] Glosten, L. R., & Milgrom, P. R. (1985). Bid, ask and transaction prices in a specialist market with heterogeneously informed traders. *Journal of Financial Economics*, *14*(1), 71–100. https://doi.org/10.1016/0304-405x(85)90044-3

[3] Capponi, A., & Jia, R. (2025). Liquidity provision on blockchain-based decentralized exchanges. *The Review of Financial Studies*, *38*(10), 3040–3085. https://doi.org/10.1093/rfs/hhaf046

[4] Anand, A., & Venkataraman, K. (2016). Market conditions, fragility, and the economics of market making. *Journal of Financial Economics*, *121*(2), 327–349. https://doi.org/10.1016/j.jfineco.2016.03.006

[5] Alexander, A. (2025). The impact of market-making incentives on crypto liquidity & price stability. *SSRN Electronic Journal*. https://ssrn.com/abstract=5143194 https://doi.org/10.2139/ssrn.5143194

[6] Aquilina, M., Budish, E., & O'Neill, P. (2022). Quantifying the high-frequency trading "arms race." *The Quarterly Journal of Economics*, *137*(1), 493–564. https://doi.org/10.1093/qje/qjab032

[7] Foucault, T., Kozhan, R., & Tham, W. W. (2017). Toxic arbitrage. *The Review of Financial Studies*, *30*(4), 1053–1094. https://doi.org/10.1093/rfs/hhw103

[8] Tiniç, M., Sensoy, A., Akyildirim, E., & Corbet, S. (2023). Adverse selection in cryptocurrency markets. *Journal of Financial Research*, *46*(2), 497–546.

[9] Madhavan, A. (2000). Market microstructure: A survey. *Journal of Financial Markets*, *3*(3), 205–258. https://doi.org/10.1016/s1386-4181(00)00007-0

[10] Kyle, A. S. (1985). Continuous auctions and insider trading. *Econometrica*, *53*(6), 1315–1336.

[11] Delphi Digital. (n.d.). *What is ghost liquidity?* https://members.delphidigital.io/learn/ghost-liquidity

[12] Commodity Futures Trading Commission. (2025). *Market maker agreement: North American Derivatives Exchange (Nadex) d/b/a Crypto.com Derivatives North America* (CFTC org-rules filing, 2025-01; agreement text is the September 2022 version). https://www.cftc.gov/sites/default/files/filings/orgrules/25/01/rules01022513031.pdf

[13] Binance. (2019). *Introducing the Binance Market Maker Program*. https://www.binance.com/en/support/announcement/detail/360034573691

[14] Bellia, M., Christensen, K., Kolokolov, A., Pelizzon, L., & Renò, R. (2022). *Do designated market makers provide liquidity during a flash crash?* (SAFE Working Paper No. 270). Leibniz Institute for Financial Research SAFE.

[15] Chainalysis. (2025). *Market manipulation: Suspected wash trading*. https://www.chainalysis.com/blog/crypto-market-manipulation-wash-trading-pump-and-dump-2025/

[16] Aquilina, M., Foley, S., Gambacorta, L., & Krekel, W. (2024). Decentralised dealers? Examining liquidity provision in decentralized exchanges. *Bank for International Settlements Working Papers*, No. 1227. https://bis.org/publ/work1227.pdf

[17] Biais, B., Foucault, T., & Moinas, S. (2015). Equilibrium fast trading. *Journal of Financial Economics*, *116*(2), 292–313. https://doi.org/10.1016/j.jfineco.2015.03.004

[18] Hasbrouck, J. (2007). *Empirical market microstructure: The institutions, economics, and econometrics of securities trading*. Oxford University Press.

[19] O'Hara, M. (2015). *Market microstructure theory*. John Wiley & Sons.

[20] Malinova, K., & Park, A. (2024). Learning from DeFi: Would automated market makers improve equity trading? *SSRN Electronic Journal*. https://ssrn.com/abstract=4531670

[21] Sim, J. Y., Chun, H., & Park, J. (2025). Toward unified liquidity in cryptocurrency markets: A comparative survey and architectural perspective. *International Journal of Advanced Smart Convergence*, *14*(2), 33–45.

[22] Daian, P., Goldfeder, S., Kell, T., Li, Y., Zhao, X., Bentov, I., ... & Juels, A. (2020). Flash boys 2.0: Frontrunning in decentralized exchanges, miner extractable value, and consensus instability. *IEEE Symposium on Security and Privacy (SP)*, 910–927. https://doi.org/10.1109/sp40000.2020.00040

[23] Klages-Mundt, A., & Minca, A. (2021). (In)Stability for the blockchain: Deleveraging spirals and stablecoin attacks. *Cryptoeconomic Systems*, *1*(2). https://cryptoeconomicsystems.pubpub.org/pub/klages-mundt-blockchain-instability https://doi.org/10.21428/58320208.e46b7b81

[24] Hyperliquid Foundation. (2025). *Hyperliquid documentation*. https://hyperliquid.gitbook.io/hyperliquid-docs/

[25] Foucault, T., Kadan, O., & Kandel, E. (2013). Liquidity cycles and make/take fees in electronic markets. *The Journal of Finance*, *68*(1), 299–341.

[26] dYdX Foundation. (2023). *v4 deep dive: Rewards and parameters*. https://www.dydx.xyz/blog/v4-rewards-and-parameters

[27] Colliard, J. E., & Foucault, T. (2012). Trading fees and efficiency in limit order markets. *The Review of Financial Studies*, *25*(11), 3389–3421. https://doi.org/10.1093/rfs/hhs089

[28] Braun, B. (2016). From performativity to political economy: Index investing, ETFs and asset manager capitalism. *New Political Economy*, *21*(3), 257–273.

[29] Hyperliquid. (2023). *Protocol vaults*. https://hyperliquid.gitbook.io/hyperliquid-docs/hypercore/vaults/protocol-vaults

[30] Hyperliquid. (2023). *Hyperliquidity Provider (HLP): Democratizing market making*. https://medium.com/@hyperliquid/hyperliquidity-provider-hlp-democratizing-market-making-bb114b1dff0f

[31] Chitra, T., Diamandis, T., Sheng, N., Sterle, L., & Yusubov, K. (2025). Perpetual demand lending pools. *arXiv preprint arXiv:2502.06028*. https://arxiv.org/abs/2502.06028 https://doi.org/10.48550/arXiv.2502.06028

[32] Gornall, W., Rinaldi, M., & Xiao, Y. (2025). Perpetual futures and basis risk: Evidence from cryptocurrency. *SSRN Electronic Journal*. https://ssrn.com/abstract=5036933

[33] Stoikov, S., & Sağlam, M. (2009). Option market making under inventory risk. *Review of Derivatives Research*, *12*(1), 55–79. https://doi.org/10.1007/s11147-009-9036-3

[34] Hendershott, T., & Seasholes, M. S. (2007). Market maker inventories and stock prices. *American Economic Review*, *97*(2), 210–214.

[35] Zealynx. (2026). *Hyperliquidity Provider (HLP)*. Blockchain Security Glossary. https://www.zealynx.io/glossary/hyperliquidity-provider

[36] WisdomTree Prime. (2025). *The great whale slap: How a whale offloaded \$4M in losses to Hyperliquid's HLP vault*. https://www.wisdomtreeprime.com/blog/the-great-whale-slap-how-a-whale-offloaded-4m-in-losses-to-hyperliquids-hlp-vault/

[37] Fournier, M., & Jacobs, K. (2020). A tractable framework for option pricing with dynamic market maker inventory and wealth. *Journal of Financial and Quantitative Analysis*, *55*(5), 1667–1698. https://doi.org/10.1017/s0022109019000462

[38] KuCoin. (2026). *Maximizing the liquidation alpha: How Hyperliquid's HLP vault converts whale losses into liquidity provider yield*. https://www.kucoin.com/news/articles/maximizing-the-liquidation-alpha-how-hyperliquid-s-hlp-vault-converts-whale-losses-into-liquidity-provider-yield

[39] Fan, S., Min, T., Wu, X., & Cai, W. (2023). Towards understanding governance tokens in liquidity mining: A case study of decentralized exchanges. *World Wide Web*, *26*(3), 1181–1200.

[40] Chinco, A., & Sammon, M. (2024). The passive-ownership share is double what you think it is. *Journal of Financial Economics*, *157*, 103860. https://doi.org/10.2139/ssrn.4188052

[41] Chitra, T. (2025). Autodeleveraging: Impossibilities and optimization. *arXiv preprint arXiv:2512.01112*. https://doi.org/10.48550/arXiv.2512.01112

[42] Catania, L., & Grassi, S. (2022). Forecasting cryptocurrency volatility. *International Journal of Forecasting*, *38*(3), 878–894. https://doi.org/10.1016/j.ijforecast.2021.06.005

[43] He, S., Manela, A., Ross, O., & von Wachter, V. (2022). Fundamentals of perpetual futures. *arXiv preprint arXiv:2212.06888*. https://doi.org/10.48550/arXiv.2212.06888

[44] Schmeling, M., Schrimpf, A., & Todorov, K. (2023). Crypto carry. *BIS Working Papers No. 1087*. https://www.bis.org/publ/work1087.pdf

[45] Werapun, W., Karode, T., Suaboot, J., Arpornthip, T., & Sangiamkul, E. (2025). Exploring risk and return profiles of funding rate arbitrage on CEX and DEX. *Blockchain: Research and Applications*. Advance online publication.

[46] Ho, T., & Stoll, H. R. (1981). Optimal dealer pricing under transactions and return uncertainty. *Journal of Financial Economics*, *9*(1), 47–73. https://doi.org/10.1016/0304-405x(81)90020-9

[47] Cartea, Á., Drissi, F., & Monga, M. (2025). Decentralised finance and automated market making: Execution and speculation. *Journal of Economic Dynamics and Control*, *177*, 105134.

[48] Albers, M., Cucuringu, M., Howison, S., & Shestopaloff, A. Y. (2025). The market maker's dilemma: Navigating the fill probability vs. post-fill returns trade-off. *arXiv preprint arXiv:2502.18625*. https://arxiv.org/abs/2502.18625 https://doi.org/10.48550/arXiv.2502.18625

[49] Malamud, S. (2017). Decentralized exchange. *American Economic Review*, *107*(5), 282–287.

[50] Xu, J., Paruch, K., Cousaert, S., & Feng, Y. (2023). SoK: Decentralized exchanges (DEX) with automated market maker (AMM) protocols. *ACM Computing Surveys*, *55*(11), 1–50. https://doi.org/10.1145/3570639

[51] Mohan, V. (2022). Automated market makers and decentralized exchanges: A DeFi primer. *Financial Innovation*, *8*(1), 20. https://doi.org/10.1186/s40854-021-00314-5

[52] Krekel, W. P. (2025). *Tokenized, decentralized, democratized? Market microstructure and exchange innovation in digital asset trading* [Doctoral thesis, Macquarie University].

[53] Bruegel. (2023). *Decentralised finance: Good technology, bad finance*. Bruegel Policy Brief.

[54] Addy, W. A., Ajayi-Nifise, A. O., Bello, B. G., Tula, S. T., Odeyemi, O., & Falaiye, T. (2024). Algorithmic trading and AI: A review of strategies and market impact. *World Journal of Advanced Engineering Technology and Sciences*, *11*(1), 258–267.

[55] Dou, W. W., Goldstein, I., & Ji, Y. (2025). AI-powered trading, algorithmic collusion, and price efficiency. *NBER Working Paper No. 34054*. https://www.nber.org/papers/w34054 https://doi.org/10.3386/w34054

[56] Han, Y., Wang, C., Wang, H., Yang, Y., & Wang, X. (2024). A study of blockchain-based liquidity cross-chain model. *PLOS ONE*, *19*(6), Article e0302145. https://doi.org/10.1371/journal.pone.0302145

[57] CoinDesk. (2025). *Hyperliquid delists JELLYJELLY after vault squeezed in $13M tussle*. Accessed June 2026. https://www.coindesk.com/markets/2025/03/26/hyperliquid-delists-jellyjelly-after-vault-squeezed-in-usd13m-tussle

[58] CoinDesk. (2025). *Peak degen warfare: Alleged POPCAT manipulation hits Hyperliquid with $4.9M loss*. Accessed June 2026. https://www.coindesk.com/markets/2025/11/13/peak-degen-warfare-alleged-popcat-manipulation-hits-hyperliquid-with-usd4-9m-loss

[59] Longbridge. (2026). *Hyperliquid vault HLP profited approximately $15 million in the liquidation of the "1011 insider whale"*. Accessed June 2026. https://longbridge.com/en/news/274395379
