Who Pays When a Liquidation Goes Bad: Insurance Funds, Backstops, and Socialized Loss
When a position closes below its bankruptcy price there is a hole. Trace one identical deficit through a CEX, a DEX perpetual vault, and a lending market.

On this page
- 1. The deficit is the only thing that matters after a liquidation fails
- 2. One position, one hole: the scenario used in every section below
- 3. Who fills the hole on a centralized order book?
- 4. Who fills the hole on a DEX perpetual?
- 5. Who fills the hole on a lending protocol?
- 6. The loss-allocation waterfall side by side
- 7. When does venue design turn one deficit into a cascade?
- 8. What this means for a position you already hold
- Conclusion
- Frequently asked questions
- Sources and further reading
Quick read
A liquidation that fills below the bankruptcy price leaves a hole, and every venue fills it differently. This lesson traces one identical two thousand dollar deficit through a centralized order book, a DEX perpetual vault, and a lending market, so you know who absorbs your loss and whether it can reach you.
What to remember
- A liquidation only becomes a venue problem when it fills below the bankruptcy price; the gap between the liquidation price and the bankruptcy price is the entire buffer the venue has to work with.
- A centralized exchange insurance fund is funded by liquidated traders, not by the exchange, because the surplus above the bankruptcy price on every well-executed liquidation is swept into it.
- On a DEX with a backstop vault, the deficit lands on the vault's depositors rather than on winning traders, which means the loss allocation depends on whether you are a trader or an LP.
- A lending protocol has no profitable counterparty to claw back, so bad debt lands on protocol reserves, on slashed stakers, or as a haircut across every depositor in that market.
- A correctly margined, profitable, solvent trader can still lose money to a venue's loss-allocation mechanism, so check the backstop design before you size a position on a new venue.
Almost everything written about crypto liquidations stops at the moment the position closes. The risk engine takes over, the collateral is gone, and the story ends. That is the interesting part only if you are the person being liquidated.
The financially interesting question starts one step later. Sometimes the position does not close at a price that covers the losses. There is a hole, denominated in real money, and somebody's balance goes down to fill it. That somebody is frequently not the trader who was liquidated, and on several venue designs it can be you, sitting on a solvent and profitable position that you never mismanaged.
This article is about the hole and the queue of people who fill it. For the mechanics of how a liquidation is triggered in the first place, the mark price that triggers it, and the liquidation-price formula, read crypto liquidations explained first. This piece assumes all of that and asks only one question: the position closed underwater, so who pays?
1. The deficit is the only thing that matters after a liquidation fails
Two prices define the whole problem. Your is where your equity reaches exactly zero. Your liquidation price sits above it, at the point where your equity has fallen to the maintenance margin. The venue does not wait until zero, because at zero it has nothing left to work with. It intervenes early and keeps the difference as working capital.
That difference is the venue's only buffer. Everything a venue does about bad debt is an attempt to close positions inside that band and never below it. The maintenance margin is not a fee and it is not a penalty. It is the budget the risk engine has to find a bid with.
When the close happens inside the band, the venue ends up with money left over. When the close happens below the bankruptcy price, the venue ends up short. That shortfall is the deficit, and it is the subject of the rest of this article. It is a genuinely different financial event from a normal liquidation: a normal liquidation transfers a trader's own money, while a deficit creates a claim on somebody who was not party to the trade.
2. One position, one hole: the scenario used in every section below
Every venue section below uses this same position and this same shortfall, so the comparison is like for like.
You are long 2 BTC at $100,000, a notional of $200,000, at 20x leverage, so you posted $10,000 of initial margin. The venue's maintenance margin rate for this tier is 0.5% of notional, which is $1,000.
| Price level | What it is | Your equity there | What it means for the venue |
|---|---|---|---|
| $100,000 | Entry | $10,000 | Nothing to do |
| $95,500 | Liquidation price | $1,000, equal to the maintenance margin | The risk engine takes over with a $1,000 budget |
| $95,000 | Bankruptcy price | $0 | The break-even point for the venue |
| $94,000 | The actual fill | Negative $2,000 | A $2,000 deficit that somebody must absorb |
Read the last two rows carefully. The gap between the liquidation price and the bankruptcy price is $500 per BTC, which across 2 BTC is exactly the $1,000 maintenance margin. That is the arithmetic identity behind the whole design: the maintenance margin is the price band the engine is allowed to lose while closing you.
Now suppose the market gaps. There is no fill between $95,500 and $94,000, and the position finally closes at $94,000. Total realized loss is $6,000 per BTC across 2 BTC, or $12,000, against $10,000 of posted margin.
The deficit is $2,000. That is 1% of the notional, 20% of your margin, and a 1.6% unfilled move past the liquidation trigger. Hold that number: it is the same $2,000 in every section that follows.
What this scenario actually tells you
The buffer is thin by construction, and whether it holds is decided by liquidity rather than by you. A 0.5% maintenance margin buys the venue half a percent of price, which is why maintenance margin rates rise steeply with position size on every venue that tiers them. The venue is not protecting itself from your leverage; it is protecting itself from the width of the gap it will have to trade through. Once the engine takes over you cannot influence the fill, and the only variables left are order-book depth and how many other accounts are closing at the same moment.
What you should do differently: stop thinking of the maintenance margin as money you lost and start thinking of it as the venue's premium against your gap risk. A venue offering a suspiciously thin maintenance margin at high leverage is either confident in its book depth or confident that somebody else will pay when it is wrong. The rest of this article is about telling those two apart.
3. Who fills the hole on a centralized order book?
On a centralized derivatives exchange, the $2,000 comes out of the insurance fund. The more useful question is where the insurance fund got the money.
The fund is paid for by liquidated traders
It comes from liquidations that went well. Suppose the same position had instead closed at $95,200, inside the buffer band. Your loss would be $4,800 per BTC, or $9,600, against $10,000 of margin. The extra $400 is the surplus above the bankruptcy price, and on a centralized venue it is swept into the insurance fund rather than returned to you.
OKX states the mechanism plainly: if a position "is closed out at a price better than the bankruptcy price, a surplus is generated," and "this excess margin or surplus profit is contributed directly to the Security Fund."
So the fund is a pool of maintenance margin collected from traders who were closed successfully, held in reserve to pay for traders who were not. Several venues add a clearance or liquidation fee on top of that, which flows to the same place. Venues may also seed a fund with their own capital at launch or top it up after an incident, and the help pages do not consistently say. What is documented across venues is the surplus channel, and the surplus comes from liquidated traders.
A growing fund is a calibration signal, not a profit signal
This is the part that gets misread. A rising insurance fund balance is regularly presented as evidence that an exchange is over-charging liquidated traders. The mechanics say something more specific.
Follow the surplus channel and growth on quiet days is the expected state rather than the suspicious one. A fund fed by the gap between the liquidation price and the bankruptcy price grows whenever the engine closes positions inside the buffer band, which is what happens on every ordinary trading day. The reserve it accumulates is what lets the engine exit difficult positions later without reaching for ADL. A fund that never grew would not be a fairer venue; it would be one with no capacity to absorb the next gap.
The useful reading of the balance is therefore directional, not absolute. Steady growth across normal conditions means maintenance margin rates are wide enough that typical liquidations close above the bankruptcy price, which is the buffer doing its job. Growth that never pauses even through volatile sessions is the case for over-charging: the margin is set generously relative to actual book depth, and liquidated traders are subsidizing more than the risk warrants. A sharp drawdown means the engine has been trading through gaps, and the venue's distance to its next backstop just shortened.
When the fund cannot cover it
If the fund is exhausted or falls below its trigger, the venue moves to . Binance's liquidation documentation describes the step directly: when the insurance fund cannot cover the losses, "the matching engine will automatically liquidate the Bankrupt Positions and some opposing non-bankrupt trader's positions." OKX ties the trigger to a fund threshold rather than to full exhaustion, stating that ADL is triggered "when the present value of an applicable security fund drops significantly lower than a certain preset threshold."
That threshold detail matters more than it looks. It means ADL is not a last-microsecond emergency that only fires when the fund is empty. It is a state that can be entered while the fund still holds a balance, and the fund balance is therefore a live risk parameter for every profitable trader on the venue, not just an accounting curiosity. For how the queue is built, how positions are ranked, and how the haircut on a deleveraged position is calculated, see auto-deleveraging explained.
4. Who fills the hole on a DEX perpetual?
Take the identical $2,000 deficit onto a decentralized perpetual venue with a backstop vault. The waterfall has the same shape and a completely different set of people at the bottom of it. One calibration note before the comparison: Hyperliquid documents maintenance margin ranging from 1.25% to 16.7% depending on the asset's maximum leverage, so the buffer band is wider than the 0.5% used in our illustration. The width differs by venue and by asset. What happens below the band does not.
The vault is the counterparty of last resort
Hyperliquid runs order-book liquidations first, and falls back to a vault when they fail. Its documentation sets the fallback at a specific equity level: "if the account equity drops below 2/3 of the maintenance margin without successful liquidation through the book, a backstop liquidation happens through the liquidator vault." That vault is not a corporate balance sheet. It is "a component strategy of HLP," the protocol's community liquidity vault, and the docs are explicit that "the pnl stream from liquidations go entirely to the community through HLP, rather than to privileged market makers as on other venues."
Lighter's design is structurally the same with different naming. Its LLP takes over the positions of a margin-called account, and the liquidation fee, up to 1% when a user is filled better than the zero price, is sent to the LLP as the insurance fund.
So on these venues, the $2,000 hole is a $2,000 mark-down on the vault's net asset value. It is borne pro rata by whoever deposited, in proportion to their share. Nothing is taken from a winning trader.
Note the symmetry, because it is the point. On a centralized venue the surplus from a well-executed liquidation goes to a fund you cannot own and the deficit is eventually charged to profitable traders. On these DEX designs both legs point at the same pool: the vault receives the liquidation profit stream and the vault absorbs the liquidation losses. Whoever owns the upside owns the downside. Hyperliquid also notes that in a backstop liquidation "the maintenance margin is not returned to the user," which is the same surplus-capture rule applied for the vault's benefit rather than the exchange's.
The oracle is a distinct failure surface
A centralized exchange computes its own index price from its own chosen basket of spot venues and can adjust the calculation at will. A decentralized venue has to reach consensus on the trigger price, and that changes the failure modes.
Hyperliquid's documentation describes the construction: "the validators are responsible for publishing spot oracle prices for each perp asset every 3 seconds," each computed as "the weighted median of Binance, OKX, Bybit, Kraken, Kucoin, Gate IO, MEXC, and Hyperliquid spot mid prices," with the final clearinghouse price being "the weighted median of each validator's submitted oracle prices, where the validators are weighted by their stake."
That is a robust design, and reading it as a loss-allocation parameter rather than a pricing detail is what makes it useful:
- A publication cadence is a floor on staleness. Prices refresh every three seconds. In a fast move, three seconds of price change is three seconds of unhedged gap risk that lands somewhere, and it lands on the vault.
- The constituent set is a dependency list. The oracle is a median of named centralized spot venues. Disruption at several of them at once propagates into the liquidation trigger of a venue that is otherwise entirely on-chain.
- Consensus is a liveness requirement. The trigger price is produced by staked validators. Anything that degrades their ability to publish degrades the accuracy of every liquidation on the venue simultaneously, which is a correlated failure that a single-operator index does not have.
The transparency also cuts in your favor: you can read the exact basket and cadence before you deposit, which you cannot do for a centralized venue's internal index.
ADL still exists here
A vault is a finite pool, so it is not the end of the waterfall. Lighter's documentation is explicit that positions which would push the LLP below its threshold "are instead auto-deleveraged," and that ADL activates "when an account has a negative value and the LLP does not have enough capital to cover the losses of the bankrupt account." Hyperliquid documents auto-deleveraging as a separate mechanism that engages when an account value goes negative.
The practical consequence: choosing a DEX does not exempt you from ADL. It inserts one more absorber ahead of you in the queue.
5. Who fills the hole on a lending protocol?
Move the same $2,000 hole onto a lending market and two things change. Getting to the hole is far harder, and once you are in it there is nobody to claw back from.
This section is only about bad debt. For how a lending liquidation is triggered, over-collateralization, health factor, and the liquidation timeline, read DeFi lending explained. None of that is re-derived here.
Translating the scenario
The instrument has to change here, because a lending market cannot be levered 20x. What is held constant is the notional and the size of the hole: the same $200,000 of BTC and the same $2,000 shortfall at the end.
Same 2 BTC, same $100,000 entry, same $200,000 of collateral value. You borrow $150,000 of USDC, a 75% loan-to-value, against an 80% liquidation threshold. The position becomes liquidatable when the debt exceeds 80% of collateral value, which is when collateral falls below $187,500, which is BTC at $93,750.
For the protocol to end up $2,000 short, your collateral has to be worth $148,000 against $150,000 of debt. That is BTC at $74,000.
| Dimension | Perpetual at 20x | Lending at 75% LTV |
|---|---|---|
| Position | 2 BTC long, $200,000 notional | 2 BTC collateral worth $200,000, against $150,000 of debt |
| Trigger price | $95,500 | $93,750 |
| Price that produces a $2,000 hole | $94,000 | $74,000 |
| Unfilled move past the trigger required | 1.6% | 21% |
| Who acts to close it | The venue's own risk engine, automatically | A third-party liquidator, if it is profitable to act |
What this comparison actually tells you
Figure 1 puts the two buffers on one scale, because the ratio is the point and a table row understates it.
How far price must run past the trigger to open the same $2,000 hole
Both bars describe the identical deficit on the identical 2 BTC position. The only difference is the venue design.
Read the two bars as the same accident happening to the same position. The trigger fires at $95,500 on the perpetual and $93,750 on the loan; the hole opens at $94,000 and $74,000 respectively. The bar heights are the distance between those two pairs of numbers, expressed as a percentage of the trigger price, and the second bar is roughly thirteen times the first.
The lending buffer is roughly thirteen times wider, and that is the whole reason lending bad debt is rare. At the moment the loan becomes liquidatable, the collateral is still worth $187,500 against $150,000 of debt, a cushion of 25% of the debt. Erasing that cushion takes a further 21% fall with nobody clearing the position. On the perpetual venue the same hole opens after a 1.6% gap.
But the lending market's defense is slower and it is conditional. The perpetual venue closes you with its own engine, unconditionally, because it is protecting its own balance sheet. The lending protocol depends on an independent liquidator choosing to act, and that choice is economic. With a 5% liquidation bonus, repaying your full $150,000 debt requires seizing $157,500 of collateral, which exists only while BTC is above $78,750. Below that, the bonus is no longer fully payable and rational liquidators stop before the protocol is technically insolvent.
The failure mode is therefore different in kind, not just in size. A perpetual venue produces a deficit when the market gaps faster than the engine can trade. A lending market produces a deficit when nobody wants the collateral: an illiquid asset whose on-chain depth is thinner than the position, a gas spike that makes small positions unprofitable to clear, chain congestion, or an oracle that reports a price the collateral cannot actually be sold at. Speed is the perpetual venue's problem. Willingness is the lending market's.
What you should do differently: when you evaluate a lending market, do not read the LTV as the safety margin. Read the market depth of the collateral asset against the size of the largest positions in that market. A generous LTV on an asset with shallow liquidity is a thinner buffer than a conservative LTV on a deep one, regardless of what the health factor says.
Who eats it once it exists
Three answers, and they differ by protocol.
Protocol reserves. Compound III documents that "reserves are a balance of the base or collateral asset, stored internally in the protocol, which automatically protect users from bad debt," and that "each absorption is paid for by the protocol's reserves of the base asset." Reserves accumulate from the spread between what borrowers pay and what suppliers earn. As with the CEX insurance fund, the first absorber is a pool funded by the users of the same market.
Slashed stakers. Aave records the shortfall explicitly. Its Pool contract exposes a reserve deficit that represents the "current reserve deficit from undercollateralized borrow positions," and a function that "covers the deficit of a specified reserve by burning the equivalent aToken amount," callable only by the Umbrella module. Umbrella is described as "a modular, onchain risk management system that automates bad debt coverage for Aave v3 pools," and the bargain for stakers is stated without euphemism: "in return for earning rewards, stakers accept the possibility of slashing if a deficit arises on the specific pool and asset they have staked." Slashed assets go to the Aave Collector to cover the deficit.
Crucially there is a first-loss layer in front of the stakers. Aave calls it the , and documents a concrete instance: "USDT staking has a 100,000 USDT offset, meaning the Aave DAO covers the first 100,000 USDT of bad debt before any staker assets are affected." Our $2,000 hole sits comfortably inside that. The offset is the reason most real deficits never touch a staker.
A haircut across depositors. If neither reserves nor a staking module absorbs it, the shortfall stays in the market as an unbacked liability. Depositors do not receive a bill. The exchange rate between the interest-bearing receipt token and the underlying simply stops being fully honored, so the loss is expressed as everyone in that market being able to withdraw slightly less than the accounting says. It is socialized loss with no notification event, which is exactly what makes it easy to miss.
There is no clawback, because there is no counterparty
This is the structural difference between a lending deficit and a futures deficit, and it explains why ADL has no analogue here.
On a perpetual venue, every dollar a losing trader failed to pay was won by a specific opposing trader. The winner is identifiable, their profit is unrealized, and the venue can reach it. That is what auto-deleveraging is: an involuntary settlement against the person on the other side of the trade.
On a lending protocol, nobody made a symmetric profit from your loss. The lender who supplied the USDC you borrowed did not gain when your collateral fell. There is no counterparty position holding the missing $2,000, so there is nothing to close. The deficit can only be pushed onto capital that volunteered to stand behind the market: the treasury, the stakers, or the depositors themselves.
Curve's LLAMMA design attacks the same problem from the opposite end by removing the discrete event entirely, converting collateral continuously across a band of prices instead of at a single threshold, so there is no cliff to gap through and no moment at which a deficit is created; the cost is paid continuously instead, as covered in soft liquidations and LLAMMA.
6. The loss-allocation waterfall side by side
| Venue type | First absorber of the deficit | Next backstop when that is exhausted | Can it reach a solvent, profitable position? | Who owns the residual and the upside |
|---|---|---|---|---|
| CEX perpetual | Exchange insurance fund, built from liquidation surplus and clearance fees | Auto-deleveraging of opposing profitable positions | Yes. ADL closes a solvent, profitable trade against the bankrupt one | The exchange. Surplus above the bankruptcy price accrues to a fund you cannot hold |
| Hyperliquid | The HLP liquidator vault, which takes the position over below 2/3 of maintenance margin | Auto-deleveraging once account value goes negative | Yes. As a vault depositor by drawdown, and as a trader by ADL | Vault depositors. The liquidation pnl stream goes to the community through HLP |
| Lighter | The LLP, which takes over positions in ascending order of unrealized pnl | Auto-deleveraging for positions that would push the LLP below its threshold | Yes. LLP depositors first, then ADL for traders | LLP depositors. The liquidation fee of up to 1% is sent to the LLP |
| Aave | The DAO deficit offset, a stated first-loss amount per staked asset | Slashing of Umbrella stakers, then an unbacked liability in that market | No. There is no opposing position to close | The DAO and the stakers, via the reserve factor and safety incentives |
| Compound III | Protocol reserves of the base asset, which pay for each absorption | Discounted collateral sales that rebuild reserves; the residual stays as protocol bad debt | No. Suppliers are exposed, but they are not counterparties | The protocol, via the spread between borrow and supply interest |
Three readings are worth pulling out of that table.
The first absorber is almost always funded by the same users it protects. Insurance fund, LP vault, protocol reserves: all three are pools built from fees and surpluses taken from the market's own participants. No mainstream venue design has a genuinely external underwriter. The differences are about who holds the pool and who receives its profits in the good years, not about where the money originates.
Only futures venues can reach a winning trader. ADL exists on both CEX and DEX perpetuals and nowhere in lending, because it requires a symmetric counterparty. If you trade perpetuals anywhere, being correct is not a defense against loss allocation. Lending exposes you the other way round: on a perpetual venue you must hold an open position to be reachable, while on a lending market you are exposed by having deposited and gone away. That exposure is smaller and much less likely to fire, and it is also the one you are least likely to be monitoring.
7. When does venue design turn one deficit into a cascade?
A single $2,000 hole is a rounding error. The reason any of this matters is that the mechanisms which absorb deficits interact with the conditions that create them.
Forced flow arrives when the book is thinnest. The engine's liquidation orders are market orders, and they arrive during exactly the volatility that has already pulled market makers back. Deficit size is not linear in the price move; it is a function of how far the fill lands past the bankruptcy price, which is a function of depth. Halving the resting depth roughly doubles the distance the same forced size has to travel, so the deficit grows faster than the move that caused it. This is also why partial liquidation is a loss-allocation choice and not only a trader-experience one: closing the minimum size needed to restore maintenance margin puts less into a thin book, which means fills closer to the bankruptcy price and fewer deficits reaching the backstop at all.
ADL is an internal transfer, not more selling. This is widely misunderstood and worth being precise about. When the engine deleverages a profitable counterparty, the two positions are matched against each other and closed at the bankrupt position's price. Nothing hits the order book. ADL is brutal for the trader who is deleveraged and it does not, by itself, push the price further. The market impact of a cascade comes from the liquidation orders, not from the deleveraging that follows them.
Open interest tells you how much fuel exists; the backstop tells you who gets burned. A venue carrying large open interest at high leverage has more positions inside their buffer bands at any given price, and margin mode decides how big each forced sale is: a cross-margin account defends one position with its whole balance, so when it fails the engine is closing a larger aggregate position into the same thin book. Whether all that turns into an insurance fund drawdown, a vault drawdown, or an ADL wave is determined entirely by the design in section 6. See how crypto leverage works and cross versus isolated margin.
Oracle lag is a deficit generator specific to on-chain venues. A trigger price that refreshes on a cadence is stale between refreshes, and every unit of staleness is a unit of price the engine did not get to trade through. In a fast move, the cost of that lag is paid by the backstop vault.
8. What this means for a position you already hold
The reader payoff of everything above is one uncomfortable sentence: you can be right, correctly margined, and solvent, and still lose money to a mechanism that has nothing to do with your trade. There are exactly three ways it reaches you.
- As a perpetual trader, through ADL. Your winning position is closed early at the bankrupt position's price, and you lose the rest of the move you were right about.
- As a backstop vault depositor, through NAV drawdown. Every deficit the vault absorbs is a direct mark-down on your share, and it happens without any action on your part.
- As a lending market depositor, through slashing if you staked, or through a quiet haircut on what your receipt token is actually worth if you did not.
None of those three is a failure of your risk management. All three are consequences of a venue design you accepted when you deposited. So check the design before you size.
Steps
Find out what absorbs a deficit before you fund the account
Open the venue's own documentation and identify the first absorber by name: an insurance fund, a named LP vault, or protocol reserves. If the documentation does not say, that is your answer. A venue that cannot describe its backstop in writing has not thought about it harder than you have.
Check whether the backstop is a pool you could be inside
On a CEX the fund is the exchange's and you cannot hold it. On a DEX with a vault, the backstop is a product you may already be deposited in through a yield position. Confirm you are not simultaneously the trader and the underwriter on the same venue, because a bad hour hits you twice.
Find the ADL trigger condition, not just the ADL rules
There is a difference between a venue that deleverages only when the fund is empty and one that deleverages when the fund crosses a threshold. The second is a materially higher probability of being deleveraged. Then check your queue position indicator on the venue itself.
Read the oracle or index construction for the specific asset
Identify which spot venues feed the price that triggers your liquidation and how often it updates. A long-tail asset priced off two thin venues has a far worse deficit profile than a major priced off eight deep ones, on the same platform at the same nominal leverage.
Size against the backstop, not just against your stop
A stop-loss protects you from the price. It does not protect you from the loss-allocation mechanism, which fires after your position is gone or, in the ADL case, while it is still winning. A thin or undocumented backstop is a reason to carry less size there, independent of the trade. Re-check after any violent session, because backstop capacity is consumed even when every published parameter looks identical.
Conclusion
A forced liquidation is not one financial event. It is two, and the second one is the one nobody explains.
The first is the closing of a trader's position, which is settled entirely out of that trader's own collateral and ends there most of the time. The second happens only when the fill lands below the bankruptcy price, and it creates a claim on somebody who was not in the trade. The gap between the liquidation price and the bankruptcy price is the entire buffer standing between the two, and it is thin on purpose: on our worked position, a 1.6% unfilled move past the trigger was enough to turn a clean liquidation into a $2,000 hole.
Where that hole goes is decided by venue design and nothing else. A centralized exchange fills it from an insurance fund built out of the maintenance margin of previously liquidated traders, and reaches for the profits of winning traders when the fund runs low. A DEX with a backstop vault fills it from the vault's depositors, who also collect the liquidation profits in the good weeks; the loss lands on people who chose to underwrite rather than on people who happened to be right. A lending protocol has no counterparty to reach at all, so bad debt falls on the treasury, on slashed stakers, or as a silent haircut across every depositor in that market.
The same $2,000 requires a 1.6% gap on the perpetual venue and a 21% unfilled fall on the lending market, which is why lending bad debt is rare, and the two fail for different reasons: the perpetual venue cannot trade fast enough, while the lending market cannot find anyone who wants the collateral at a price the bonus supports.
The practical conclusion is narrow and worth acting on. Before you size a position on a venue, find out what absorbs a deficit there, whether that absorber is a pool you might already be sitting in, and what condition triggers the step beyond it. You control your leverage and your stop. You do not control the queue, and the queue is where a correct trade can still cost you money.
Frequently asked questions
Momentarily it can, and most venues then reset it. Binance documents an automated negative balance clearance that uses the Futures Insurance Fund to cover the deficit in the trader's account and absorb the losses to the extent possible, subject to eligibility conditions. You are not normally pursued for the shortfall, which is precisely why the backstop has to absorb it instead.
No, and confusing the two is expensive. A derivatives insurance fund only covers deficits from bankrupt futures positions on that venue. It does not cover a hack, an insolvency, a withdrawal freeze, or the loss of your spot balance, and it is not a government-backed deposit scheme. Custody assurance is a separate question answered by reserve attestations, not by the insurance fund balance.
Only from the price, and only in one direction. A stop-loss reduces the chance your own position ever reaches the liquidation engine. It does nothing about auto-deleveraging, which closes a position that is winning, and nothing about a vault or depositor haircut, which reaches capital you are not actively trading at all. These are exposures to a venue's design rather than to a price level.
No. It inserts one more absorber ahead of you. Hyperliquid's liquidator vault and Lighter's LLP take deficits before ADL is reached, but both venues document auto-deleveraging as the mechanism once the vault cannot cover a bankrupt account. Lighter states that positions which would push the LLP below its threshold are auto-deleveraged instead.
Yes, and both major protocols have a route. Aave's Pool exposes a function that covers a reserve's deficit by burning the equivalent aToken amount, callable only by the Umbrella module, so a recorded deficit can be retired rather than carried forever. Compound III rebuilds reserves by letting liquidators buy seized collateral at a discount, a path that is disabled once reserves reach their governance-set target.
Over-collateralization gives the buffer, but independent liquidators decide whether it is defended, and they only act when the bonus is worth taking. In practice bad debt concentrates in two places: long-tail collateral whose on-chain depth is thinner than the position, and dust positions where gas costs more than the bonus is worth. The protocol does not reverse the loan; it records the shortfall as a deficit on that reserve.
Usually not. If reserves and any staking module do not absorb the shortfall, it stays as an unbacked liability in that market. The exchange rate between your interest-bearing receipt token and the underlying simply stops being fully honored, so you can withdraw slightly less than the accounting suggests. It is socialized loss with no notification event.
None fully removes it, but the exposures differ. A perpetual venue can reach a winning position through auto-deleveraging on both centralized and decentralized designs. A lending market cannot reach a borrower's counterparty at all, so a pure spot lender's exposure is limited to reserves, staking, and depositor haircuts. The lower-exposure choice is not a better venue, it is a different product.
Sources and further reading
Primary venue and protocol documentation opened and verified for the claims above:
- OKX — Understanding OKX's Security Fund
- OKX — Introduction to Auto-deleveraging (ADL)
- Binance — Futures Liquidation Protocols
- Hyperliquid Docs — Liquidations
- Hyperliquid Docs — Protocol vaults (HLP)
- Hyperliquid Docs — Auto-deleveraging
- Hyperliquid Docs — Oracle
- Lighter Docs — Liquidations and the LLP insurance fund
- Aave Docs — Umbrella
- Aave Docs — Pool contract, reserve deficit functions
- Compound III Docs — Liquidation
Also opened, and useful as further reading, but not the basis of any claim above:
- dYdX Docs — Liquidations, which states that profits and losses from liquidations are taken on by the insurance fund
- Coinglass — Liquidation data, an aggregate liquidation tracker for judging whether a session was large enough to have consumed backstop capacity
This article is educational and is not financial advice. All position sizes, prices, margin rates, loan-to-value ratios, and deficit figures above are illustrative examples constructed to show the mechanism, not live venue parameters or market data. Insurance fund balances, maintenance margin tiers, ADL trigger thresholds, deficit offsets, liquidation bonuses, and reserve targets are set by each venue or by protocol governance and change frequently. Verify current parameters in each venue's own documentation before you deposit or open a position.
Related coins
Keep learning
Recommended next reads based on this lesson.
- Auto-Deleveraging (ADL) Explained: When the Exchange Closes Your WinnerHow the ADL queue is ranked, what price your position is closed at, why the settlement gap matters less than the forced exit, and how to read the indicator on your position row.
- How Exchanges Build the Index Price: The Basket Behind Your LiquidationEvery venue builds its index from its own basket of spot exchanges, with its own rule for what to do when one of them dislocates. Work through the published methodologies at Binance, Bybit, OKX and Deribit, and see why the same position carries a different liquidation price on each.
- Reading Liquidations as a Contrarian Signal: When the Forced Seller Is FinishedWhat crypto liquidation data actually reports, why aggregate totals understate reality, and when a long flush is a setup rather than a headline.
- Are Longs and Shorts Symmetrical? The Structural Asymmetries of Each SideLongs and shorts share one payoff rule but not one risk profile. What is genuinely symmetric, and the four asymmetries that decide how you size each side.









