MM0
Launch
DOCS / RISK-MODEL

MM0 Risk Model

Version: 0.1 (Stage 0)

Market making with concentrated liquidity is, economically, selling volatility for fees. An LP position is short convexity: as price moves through the range it accumulates the falling asset and sells the rising one. MM0 cannot make this risk disappear. The risk model's job is to bound it, price it, measure it, and stop when it can't be measured.


1. Risk taxonomy

Risk Source Primary control Measured by
Divergence (impermanent) loss price moves through range width ∝ σ√T, deploy fraction by regime divergence = NAV − fees + costs − HODL
Adverse selection / toxic flow informed traders and arbitrageurs fill MM0 before price moves regime classification, markout monitoring, supervisor widening/defensive switch 5m / 60m markouts (bps) on every fill
Inventory risk accumulation of one side soft/hard bands, skewed ranges, bounded swaps, single-sided liquidity base share vs target
Gap / jump risk discontinuous moves through liquidity max deployment caps, DISLOCATED regime, EXTREME_VOLATILITY breaker 1-minute reference return
Liquidity risk external liquidity disappears LIQUIDITY_SHOCK regime (external ±2% depth vs 24h EMA) external depth
Reference risk stale / manipulated / missing oracle oracle freshness + deviation checks, bootstrap mode oracle age, venue/oracle deviation
Execution risk failed / substituted / front-run tx verification, re-simulation, slippage bounds, failure-rate breaker failures per hour
Venue risk exploit, pause reserve integrity monitor, pause detection, safe-mode withdrawal reserve balance / accounted liabilities
Token risk authority changes, hostile extensions preflight + continuous config monitoring config diff
Quote risk stablecoin depeg QUOTE_DEPEG breaker quote/USD
Operational risk AI / quant / RPC / DB down explicit degradation policy per mandate ledger events
Model risk σ or regime model miscalibrated conservative σ_eff = max(short, long), prior for new tokens, replay gate realized exit frequency vs predicted

2. Volatility estimation

  • Log returns of the reference price (independent oracle, not the execution pool), one per minute.
  • Two EWMA variances with half-lives of 60 minutes and 24 hours, both initialized from mandate.bootstrap.priorAnnualVol (default 150%). New tokens therefore start conservative and the prior decays as evidence arrives.
  • σ_eff = max(σ_short, σ_long): widening is fast and narrowing is slow.
  • Stale observations are skipped: when the oracle is stale, or the reference source switches, no return is recorded. Otherwise a frozen feed would fake a calm market.

3. Regimes and their effect

Regime Trigger (default) Width k (BALANCED) Deploy (BALANCED) Other
CALM σ < 40% 2.2 80%
NORMAL σ < 90% 2.5 75%
VOLATILE σ < 160% 3.0 55%
STRESSED σ ≥ 160% or acceleration 4.0 30% state → DEFENSIVE
LIQUIDITY_SHOCK external depth < 40% of EMA 4.0 15%
DISLOCATED 1m move > 8% or deviation > 1% 4.0 0 new EXTREME_VOLATILITY breaker → no new risk

Escalation is immediate. De-escalation requires 60 minutes of persistence.

4. Inventory controller

TARGET 50/50 → SOFT ±10pp → HARD_WARNING (within 5pp of hard) → HARD_BREACH (outside 25/75)
Status Response
SOFT_BREACH at the next re-range (≥ 12h since the last), skew the range center by g·(s−s*)·h so the over-held asset sits on the selling side
HARD_WARNING additionally, a bounded inventory swap toward the soft edge: ≤ maxActionSize, ≤ remaining turnover, impact ≤ 0.8 · maxPriceImpact, avg price within half the oracle-deviation band, fresh oracle only, executed only after full liquidity removal. Symmetric top-ups suspended.
HARD_BREACH INVENTORY_HARD_LIMIT breaker (DEFENSIVE, with 3pp hysteresis): deployment capped, liquidity only on the reducing side, risk engine forbids any accumulating-side add or swap

5. Loss limits: what they measure

A token-funded vault inherently holds its own token. If loss limits were measured on total NAV, an ordinary 10% dip in the token would trip a "10% max drawdown" even when market making lost nothing. Withdrawing liquidity in response doesn't reduce that exposure, since the vault still holds the base. It only removes liquidity at the moment the market most needs it. Stage 1 simulation showed exactly this: makers for volatile tokens tripped a manual-reset breaker early and sat out the rest of the month.

MM0 therefore separates the two:

  • Market-making loss = unit NAV relative to a unitized HODL benchmark of the same deposits (rel = unitPrice / hodlUnitPrice). This captures what market making itself lost: divergence, adverse selection, rebalancing and transaction costs. It is flow-neutral (a deposit does not move it; see the test).
    • Daily loss (maxDailyLoss): from the UTC day start. A breach trips MAX_DAILY_LOSS: DEFENSIVE for the rest of the day, plus no new risk.
    • Drawdown (maxDrawdown): from the relative high-water mark. A breach trips MAX_DRAWDOWN: CIRCUIT_BREAK, safe-mode withdrawal, manual reset.
  • Absolute drawdown (maxAbsoluteDrawdown, the token's beta included) is a capital-preservation backstop. A breach trips MAX_ABSOLUTE_DRAWDOWN, which means DEFENSIVE (deployment capped) with auto-clear. Both drawdowns are published on the maker page.

Loss limits bound further risk-taking. They cannot cap losses on liquidity that's already deployed when a gap occurs. In the −90% stress scenario, the BALANCED maker lost about 58% versus about 45% for a 50/50 HODL. That gap is LP convexity: its bid-side liquidity bought base on the way down. Projects must understand this before funding a maker. The create-maker flow states it under CAPITAL AT RISK.

6. Circuit breakers

Breaker Severity Clears
ORACLE_STALE no new risk auto, 5 min after recovery
ORACLE_DEVIATION circuit break auto, 30 min
MAX_DAILY_LOSS (market-making, vs HODL) defensive next UTC day
MAX_DRAWDOWN (market-making, vs HODL) circuit break manual
MAX_ABSOLUTE_DRAWDOWN defensive auto, 60 min
EXTREME_VOLATILITY no new risk auto, 60 min
ABNORMAL_POOL_STATE no new risk auto, 15 min
UNSUPPORTED_TOKEN_CHANGE circuit break manual
INVENTORY_HARD_LIMIT defensive auto, 15 min after 3pp recovery
EXECUTION_FAILURE_RATE no new risk auto, 60 min
VAULT_INVARIANT HALT manual
VENUE_SECURITY_INCIDENT circuit break manual
QUOTE_DEPEG circuit break auto, 60 min

Breakers stop NEW risk. They never market-sell the vault. Circuit-break safe mode is the mandate's predefined WITHDRAW_TO_VAULT (a non-trading removal) or HOLD_POSITIONS.

7. Degradation policy

Component down Policy
AI supervisor quant continues within the mandate only if safeMode.quantOnlyWhenSupervisorDown (BALANCED/ACTIVE default true, CONSERVATIVE false). Otherwise no new risk.
Quant engine no new risk. Existing positions held. Safe-mode withdrawal still works (it is built by the maker, not the strategy).
Oracle no new risk (bootstrap without an oracle only if the mandate allows it, never with swaps)
RPC transactions fail → failure-rate breaker. Oracle unreadable → stale breaker.
Database / indexer Stage 3+: maker state is reconstructible from the chain + ledger. The maker refuses to act on a vault it can't reconcile.

8. Stress results (Stage 1, synthetic)

npm run stress runs 22 scenarios: ±shocks (−20/−50/−90/+500%), depeg, volume collapse/20×, liquidity migration, pool exploit, oracle stale/divergence, RPC outage, tx failures, priority-fee spike, inventory hard limit, freeze/mint authority changes, venue pause, supervisor down (two policies), quant down, and vault tamper. Each must pass the generic invariants (ledger integrity, approved instruction kinds only, no self-trade, accounting identity, and a ledger-replay proof that no risk-increasing action ran under a blocking condition) plus scenario-specific expectations. All pass at this version. The suite asserts safety, not profitability.

9. Known limitations / open items

  • Driftless lognormal assumptions underestimate tail exits. Stage 2 must measure realized vs predicted exit frequency.
  • Markout data feeds the supervisor, but there is no quantitative "toxicity regime" yet (Stage 2).
  • The synthetic venue has no dynamic fee. Real DLMM variable fees partially compensate LPs in volatility, so the model is conservative there.
  • SOL-quoted makers (volatile quote) need USD-denominated risk limits. V1 targets stable-quoted pairs.