XCore HFT / Trading Lab
PULSE: A passive fill can be bad news
Quantitative execution, market-microstructure, and risk-control research from XTRSK.
What this problem really is
Traders rarely lose money to the concept itself; they lose it to the gap between the concept and the plumbing that implements it. High fill rate is not proof of good execution if orders fill mainly before price moves against them.
A passive fill can be bad news. is easy to describe and harder to operate, and the gap between the description and the operation is where trading risk accumulates. The system becomes understandable when every transition is timestamped and every assertion is checkable against an independent record.
The mechanism should degrade predictably: when a dependency slows or disappears, the system should narrow its behaviour rather than invent a new one.
The mechanism is a sequence, not a single decision. Each stage consumes the output of the previous one, and a small error early in the chain is amplified by everything that follows.
Read the idea as a pipeline: observation, interpretation, permission, execution and reconciliation. The desk is only as strong as the weakest of those links on the day it matters.

How the mechanism works, step by step
1) Estimate volume ahead and cancellation dynamics. 2) Measure mid-price movement after each fill. 3) Calculate realised rather than quoted spread. 4) Segment results by imbalance, volatility and venue. 5) Compare missed fills with toxic fills.
The mechanism should degrade predictably: when a dependency slows or disappears, the system should narrow its behaviour rather than invent a new one.
The mechanism is a sequence, not a single decision. Each stage consumes the output of the previous one, and a small error early in the chain is amplified by everything that follows.
Read the idea as a pipeline: observation, interpretation, permission, execution and reconciliation. The desk is only as strong as the weakest of those links on the day it matters.
The second is a control that exists in configuration but not in behaviour. A limit that reads stale or unreconciled state is documentation, not protection.
A worked example with real numbers
Collecting a small spread nine times can be erased by one fill immediately before a large adverse move.
Where the cost is uncertain, use a conservative bound; an edge that survives only optimistic costs is not an edge.
A worked number is useful precisely because it can be wrong in public. If the arithmetic does not survive inspection, the strategy will not survive the market.
Keep the units explicit: currency, notional, size and time. Most apparent edge disappears in a unit conversion that nobody checked.
Recompute the example under a stress variant — wider spreads, thinner depth and slower acknowledgements — and see how much of the margin remains.

Where it breaks in live markets
The fourth is capacity. The same signal that earns a thin edge at small size consumes that edge through market impact as the order grows.
The fifth is the recovery path. A desk that can stop but cannot restart safely has only solved half of the problem it set out to solve.
The first failure mode is silent drift: the measurement that justified the strategy stops matching the conditions that produce it, and nobody is watching the difference between the two.
The second is a control that exists in configuration but not in behaviour. A limit that reads stale or unreconciled state is documentation, not protection.
The third is concentration. Several positions that look independent share a factor, a venue or a liquidity source, and the book quietly becomes one larger bet than the dashboard suggests.
The operating path, stage by stage
A compact checklist is: 1) calculate realised rather than quoted spread; 2) segment results by imbalance, volatility and venue; 3) compare missed fills with toxic fills.
Reconciliation closes the loop: the system compares intended exposure with confirmed exposure and refuses to continue on an unexplained gap.
The kill path must be independent of the components it is meant to stop, or it inherits their failure modes at exactly the wrong moment.
Log the decisions the system declined to take, not only the ones it took; rejected opportunities are the cleanest evidence about how the controls behave.
A rehearsed recovery is part of the operating path, not an afterthought once the incident has already started.

Controls that act before the damage
Use a three-level ladder. Level one warns and records; level two reduces size, frequency or participation; level three blocks new risk and invokes the rehearsed recovery path.
Every limit needs a named owner, an observable trigger and a tested response that does not depend on the component that failed.
Prefer several narrow, well-understood limits over one clever aggregate that nobody can explain under pressure.
A control that fires constantly is a design fault, while a control that never fires has not really been tested.
The sequence matters: warn, then reduce, then stop, with each step leaving a record that the next one can trust.

How to measure whether it is working
Set the review cadence before the pressure arrives, so the response becomes a decision rather than a reaction.
Measure the median and the tail separately. An acceptable average can conceal a loss distribution the account could not survive twice.
Record the reason for every rejection and every reduction, not only the outcomes. The audit trail is what lets operations reconstruct a decision without guessing.
Compare decision price, arrival price and realised fill. The gap between intention and execution is the most honest measure of what the system actually delivered.
Track the frequency and duration of abnormal states, not just their existence. A control that fires constantly is a design problem, not a safeguard.
Turning the idea into a daily routine
Start each session by confirming that the data, the clock and the venue state agree. Most model failures are really synchronisation failures discovered late.
Review the previous session against the same three questions: what was expected, what happened, and what was the largest unexplained gap.
Keep a short list of conditions that would make the desk stand down. A pre-committed exit is worth more than a clever entry.
Feed the review back into the limits. A control that never changes after new evidence is not learning from the market.
The portfolio view
The account experiences combined profit, loss and liquidity demand even when the models are monitored in separate dashboards.
Risk should aggregate across instruments and strategies before another order is allowed to consume scarce liquidity or margin.
Aggregate by risk factor rather than by strategy label, because two desks can easily be one position.
Ask what happens to the whole book if the shared dependency fails at the worst moment, then size for that day rather than for the average one.
Which assumption here is tested continuously in production, and which one is still trusted from the backtest?
About the research behind this lesson
The seminar frames electronic markets as price-time-priority queues. It separates queue value into spread capture versus adverse-selection cost and the option value of retaining a place in line.
Applied to this lesson: An order lifetime therefore cannot be based on elapsed time alone: the system must reassess whether its queue position, expected spread and adverse-selection risk still justify keeping the order alive.
Explore PULSE: System details
PULSE live account: Verify the live account on FX Blue
Live chat and updates: Telegram @xtrskhft
Source: High-Frequency Trading and Modern Market Microstructure
Educational content only. Trading leveraged products involves risk.
Chat with XTRSK
Chat ready
Start a chat and the XTRSK team will be notified immediately.