Failure Lab · offline editionOne file · no network · nothing saved or sent
Trading deployment
Knight Capital, 1 August
New order-router code has to be live before the market opens. Choose how it ships to the servers, how it is switched on and what happens to old code. Then the opening bell rings, and you make one more call.
Prepared with AI assistance. Published by CyberNative AI LLC. Corrections: hello@cybernative.ai.
Quickstart for a 25-minute team session
- BeforePut the browser in full screen (F11, or Ctrl+Cmd+F on a Mac). Choose Run with a group, pick a timer length, then Start.
- 0–3 minRead the briefing aloud: role, constraints, evidence.
- 3–13For each decision: read the prompt, discuss, take an optional show of hands, record the group's choice. ← Back reopens the previous decision.
- 13–15Run the model on the group's choices.
- 15–23Compare with the record and work through the discussion questions. Each one cites a numbered source.
- 23–25Open the one-page summary, write the team's actions on it, then print it or save it as a PDF.
- Decisions
- Three before the open, one during it
- Record
- U.S. SEC order, Exchange Act Release No. 70694, 16 October 2013
Sources
Source registerU.S. SEC order, Exchange Act Release No. 70694, 16 October 2013 · tags S1–S6
Primary source
S1 — U.S. Securities and Exchange Commission, In the Matter of Knight Capital Americas LLC, Exchange Act Release No. 70694, File No. 3-15570, administrative order, October 16, 2013. Official SEC PDF.
References below are to Section III of the order and its numbered findings.
Register
- S1 — Incident date and scale: §III, ¶1. August 1, 2012; 212 retail parent orders; about 45 minutes; more than 4 million executions in 154 stocks; more than 397 million shares; approximate long and short positions; loss greater than $460 million. The specific findings in ¶17 give 4 million executions and a $460 million loss.
- S2 — RLP code, retained code, and flag: §III, ¶¶12–13, 15–16. The RLP change added code to SMARS; the Power Peg functionality was no longer used but remained present and callable; the new code reused its flag; one of eight servers missed the new code and retained the old code.
- S3 — Fill tracking and repeated child orders: §III, ¶¶14, 16. In 2005, the cumulative-share tracking function moved earlier in the SMARS sequence and the unused Power Peg code was not retested. When the eighth server received orders carrying the reused flag, its code sent child orders rapidly without regard to executions already received.
- S4 — Pre-open e-mails: §III, ¶19. Beginning around 8:01 a.m. ET, 97 automated BNET reject e-mails referencing SMARS and Power Peg were sent to personnel before the 9:30 a.m. open. The order says these messages were not designed as system alerts and generally were not reviewed.
- S5 — Removing the new code worsened the incident: §III, ¶27. Knight removed the new RLP code from the seven servers that had received it correctly; the order says this led additional parent orders to activate Power Peg on those servers, like on the eighth.
- S6 — Controls and response procedures: §III, ¶¶21, 26–27. The order found inadequate SMARS output monitoring, no procedures to halt SMARS in response to its own aberrant activity, no written SMARS deployment procedures, and no supervisory incident-response procedures to guide employees.
Source/spec distinctions
- The task brief describes a manual copy to all eight servers. The order says deployment began in stages and that one technician did not copy the new RLP code to one of eight servers (§III, ¶15); it does not say that every server was deployed by hand. The UI labels manual copy as a decision option and models a missed per-server copy, while this register preserves the narrower historical wording.
- The brief requests a 9:30 to 10:15 timeline. The order reports an approximately 45-minute incident and identifies 9:30 a.m. as the market open; 10:15 is a derived endpoint, not an exact stop time stated in the order.
- The introduction says Knight lost more than $460 million (§III, ¶1). The detailed impact finding reports a $460 million loss (§III, ¶17). The reveal uses the introduction's greater-than figure.
- The order does not name a particular kill-switch device. The UI states only that the order found no procedures to halt SMARS in response to aberrant activity and no incident-response procedures to guide employees (§III, ¶¶21, 27).
Simulation boundary
The eight-server counterfactual, order counter, animation pace, choice costs, and the outcomes of safe choices are illustrative model behavior. Historical figures and events are attributed to the cited findings. The simulation does not claim a counterfactual firm outcome.
Licence
MIT licence and noticeCovers the original Failure Lab software and documentation only. Third-party excerpts and linked records are excluded.
The MIT licence applies only to the original software and documentation created for Failure Lab by CyberNative AI LLC. Third-party material, including attributed excerpts reproduced in these files and linked inquiry, regulatory and postmortem records, is excluded from that grant and remains subject to its respective rights. The source registers identify the publishers and cited passages. No source PDF or complete third-party record is bundled.
MIT License Copyright (c) 2026 CyberNative AI LLC Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.