Perps DEX vs CeFi: Market Structure in 2026
A perpetual position looks identical on both kinds of venue: a size, a leverage figure, an entry, a liquidation price and a funding payment every few hours. Underneath, two different machines are running, and they break in different places. This page takes them apart at the mechanism level — where matching physically happens, what a trader's counterparty resolves to when the venue is also the custodian, how the two liquidation engines rank and haircut the people on the other side, and how a mark price is assembled.
Introduction
The interface is a poor guide to the machine. A perpetual position on a centralised exchange and one on an on-chain venue present the same handful of numbers and respond to the same order types. The comparison usually offered on top of that surface — custodial against non-custodial, regulated against permissionless — is a preference framed as an analysis, and it skips the part that decides what happens to a position under stress. Where the regulatory question is real it turns on jurisdiction rather than architecture — a register lists venues of both kinds — and it is answered jurisdiction by jurisdiction.
The structural question is narrower and answerable: which entity performs each function, and what does it own while performing it. A perpetual venue has five. Something matches orders, something holds the collateral, something compiles the reference price, something decides when a position is no longer solvent and closes it, and something absorbs the residual when a closure lands below the point where the margin ran out.
On the centralised venue whose contracts are read below, all five sit inside one commercial group, with a single clause offering trade execution and custody from the same provider. On the on-chain venue examined here they are split across chain state, a community-owned vault and a validator set — while the reference price is still imported from centralised venues, which is the part no marketing page mentions.
Two properties survive that split, and both are shared rather than contrasted. Neither model margins against the price on the chart: solvency is computed from a constructed mark price built out of external references, which is why a position can close at a level the traded market never printed. On both sides, the definition of that number stays under someone's discretion while a position is open.
The residual is the second. When the fund set aside to absorb it runs out, both architectures reach for the profitable side of the same contract, ranking the traders holding it by profit scaled by leverage. What differs is the settlement price applied to those positions once they are selected. Three episodes documented outside the venues' own material test the machinery: a regulator's oracle-manipulation case arising from a 2022 attack on a now-defunct venue, a vault squeeze in March 2025 resolved by a validator vote rather than by a protocol rule, and the record liquidation cascade of October 2025.
What follows traces that distribution function by function, from each venue's own documentation rather than from third-party summaries. Three things are out of scope: this page recommends no venue, carries no trading strategy or leverage advice, and does not re-explain what a perpetual is or how funding is calculated — that groundwork sits in our complete guide to DeFi derivatives.
One convention runs throughout: where a venue's own documentation is the source of a claim, the page says so and treats it as that venue's characterisation rather than as established fact. Several of the sharpest findings below are places where a venue's documents disagree with each other.
Where matching happens, and why that used to be impossible
The constraint: order churn, not order flow
A central limit order book is not a queue of trades. It is a queue of messages, and most of those messages are quote updates rather than trades, as the makers supplying the visible depth reprice inventory against a moving reference. Hyperliquid's developer documentation gives the volume plainly: "A market making strategy can send thousands of orders and cancels in a second."
That is why on-chain order books were treated as unworkable for most of a decade. If every quote update is a transaction, a book pays a fee for every cancel, waits for a block to have any cancel take effect, and competes for inclusion with everything else the chain is doing. The same documentation states the conclusion directly: "Ethereum's design does not work for an onchain order book." Order flow, where each message carries economic intent worth a fee, is the workload a general-purpose settlement layer is priced for. Order churn, where most messages exist in order to be withdrawn, is not.
For a maker the consequence is direct: quoting carries inventory risk, and a book whose cancels are slow and expensive is not a slow book but a thin one. Note what the constraint does not say. It does not say a venue must be centralised to carry a book; it says a general-purpose settlement chain is the wrong substrate for one. Venue-level DeFi on such chains is a large market, covered in our guide to Layer 2 DeFi — what it does not contain is a high-churn book.
What a purpose-built chain changes
The alternative is to build a chain whose only job is being the venue. Hyperliquid describes itself as "a layer one blockchain (L1)" rather than a contract deployed on someone else's chain, secured by a consensus it calls HyperBFT and describes as "a variant of HotStuff consensus", where blocks "are produced by validators in proportion to the native token staked" — a detail that returns below, because it identifies who can override what.
The move that matters is where the engine sits. Matching is not a service beside the chain but part of the chain's state: the venue's core component "includes margin and matching engine state", and its documentation rejects the alternative in a sentence written for that purpose — "HyperCore does not rely on the crutch of off-chain order books." That is the venue's own characterisation, but it is unambiguous. Matching is the chain: "Every order, cancel, trade, and liquidation happens transparently with one-block finality inherited from HyperBFT." Trading actions are also gas-free, with gas applying to deposits rather than orders.
The performance figures are where a careless reading turns a true page into a false impression, so the qualifiers travel with the numbers. For an order placed from a geographically co-located client — the venue's own qualifier, not ours — the reported latency is a median of 0.2 seconds with a 99th percentile of 0.9 seconds. That is an infrastructure-path measurement, not a retail-path one. The design buys throughput and finality in one place and pays for it in generality: anything that halts the chain halts the venue.
Two order models, and who takes the other side
The centralised book: matching as a service
Both venue types in scope run a central limit order book, which is worth saying plainly because the on-chain venue is routinely filed under a category it does not belong to. OKX's terms of service, last updated on 24 July 2026, define the service more usefully than any marketing page: "An order matching platform that matches Users' orders ... according to pre-established criteria." Price-time priority there is contractual rather than conventional — "OKX carries out all Orders based on price-time priority" — and applies "irrespective of the entry method or user type".
Settlement is not a transfer: a matched trade is "settled by debiting and crediting the relevant balances of Assets in both parties' Accounts". Nothing moves. Two rows change in one ledger. The mechanical texture underneath is documented best by Deribit, where each instrument is a single serialised lane — "only one action can be processed at a time per order book" — and queue position behaves as an asset, since reducing an order's size means it "retains its time priority at that price level" while cancel-and-replace does not.
Who the trader's counterparty actually is
Here the centralised model is more complicated than its own summary, and the complication is written into the terms rather than hidden. OKX reserves the right to "act in more than one capacity ... including as trading venue operator, principal, market maker", and states separately that "Affiliated Market Makers may enter into Transactions with you as your counterparty". Neither clause is unusual for a venue of this type; both are worth reading slowly by anyone who assumed a matching platform only stands between two customers.
The clause carrying the most structural weight is duller than either. The same terms describe the service as "a platform for the trade execution of Orders and the custody of Digital Assets" — one provider, both functions. Every subsequent difference in this comparison, from the lien over margin to the discretion over withdrawals to the ability to change a mark-price input in real time, follows from that combination. The entity computing the liquidation price also holds the assets it liquidates.
The counterparty question itself does not resolve cleanly, and the absence of resolution is the finding. OKX's Middle East margin and derivatives agreement is unambiguous in one direction: "OKX shall not be a party to the contract", its role being "to match any Positions a User opens with another User". The global perpetual swap trading user agreement, last updated on 28 June 2026, names no counterparty entity at all — the product is "offered by the OKX entity on which you are onboarded as a customer". Which legal entity faces a trader is a function of where that trader onboarded.
The on-chain book: state, not service
On the on-chain venue the same question is answered by describing where the account lives. The perpetuals clearinghouse "is a component of the execution state on HyperCore", and it "manages the perps margin state for each address, which includes balance and positions". There is no account at a company holding a claim on pooled assets.
The venue also runs a protocol vault, the "Hyperliquidity Provider (HLP)", which provides liquidity and performs liquidations, and which the documentation states is "fully community-owned". Funding flows between traders rather than to the operator: "Funding is purely peer-to-peer and no fees are collected on the payments." The rate's construction is the subject of our page on perpetual funding rates. Four questions separate the models:
- Where price is formed. Orders against orders under price-time priority, in both models.
- What settlement is. A debit and a credit inside the venue's ledger on one side; a state transition with one-block finality on the other.
- Who the counterparty is. Contractually unresolved on the centralised model, which permits the venue to act as principal and an affiliated market maker to face the customer. The other trader on the on-chain model.
- What margining reads. Not the book, in either model. Both liquidate against a constructed mark price — the largest shared dependency between the two architectures.
Two liquidation engines, mechanism by mechanism
This section is about architecture, not about avoiding a liquidation. Note that our liquidation protection guide addresses lending collateral — health factors, loan-to-value ratios and over-collateralised borrowing. That is a different mechanism with different triggers and a different remedy, not a lighter version of this one.
Initial margin, maintenance margin, tiers
The two margin numbers do different jobs. Initial margin is what opening costs, defined by Bybit as "Initial Margin = Position Value / Leverage". Maintenance margin is what keeping costs — "the minimum amount of margin a trader must maintain" — and when unrealised loss drives the position's margin below it, "liquidation will be triggered".
The centralised venues compute the maintenance requirement from position size, using what Bybit calls a "tier-based calculation" collapsed into a shortcut with a deduction constant: "Maintenance Margin (MM) = (Position Value x MMR) - Maintenance Margin Deduction". Its published example puts a BTCUSDT position at or below 2,000,000 USDT of position value in a tier requiring 0.5 per cent, rising to 0.56 per cent at 2,600,000 USDT — and the tier is not fixed at entry, since "the system will automatically adjust the user's risk limit" as position value grows. Bybit is direct about the purpose, and it is not trader protection: when the insurance fund cannot cover losses, "it triggers the Auto Deleveraging (ADL) system".
The on-chain venue does it differently, and the contrast is the cleanest here. Initial margin is "position_size * mark_price / leverage", and maintenance margin is a fixed proportion of it — "the maintenance margin is half of the initial margin at max leverage" — producing a per-asset band documented as "between 1.25% (for 40x max leverage assets) and 16.7%".
That band is not the whole story, and the difference is smaller than it looks. The on-chain venue tiers by position size too, using the same equation — its documentation introduces the tiered formula with the words "Like most centralized exchanges", and what follows is the expression quoted above with the variables renamed.
What differs is where the first boundary sits. On the centralised venues it is reached by positions an active trader can hold; on the on-chain venue the first step down in maximum leverage on its deepest market arrives in the hundreds of millions of dollars of notional. So the models are the same and the thresholds are not, which is why neither is generically safer: they fail at different sizes, and for a retail position only one of them has a tier boundary anywhere nearby.
The partial-liquidation ladder
Neither centralised venue closes a failing position in one action if it can avoid it. Bybit describes "a laddered approach to reduce the required maintenance margin and avoid full liquidation": first "the system cancels all orders that would increase the position size, freeing up margin"; then it partially closes "by submitting a Immediate-Or-Cancelled (IOC) order", stepping into a lower risk tier; and failing that, the position "will be liquidated and closed at the bankruptcy price" — the level "where there's no initial margin left". OKX runs the same three stages, targets the partial step at Tier 1, and charges a liquidation fee.
Two details cause most of the confusion a liquidated trader experiences. The trigger is the mark price and not the last traded price, so a candle on the chart may never touch the level at which a position closed. And partial liquidation is not a courtesy: Bybit describes the ladder as a way of avoiding full liquidation, and is simultaneously describing a mechanism that protects the insurance fund. The on-chain venue charges nothing for it — "unlike CEXs there is no clearance fee on liquidations".

Insurance funds and how they are drawn
An insurance fund is not a reserve set aside from profits but a running balance fed and drained by the liquidation engine: when a liquidation closes better than the bankruptcy price, "the trader's remaining margin will be added to the insurance fund", and when it closes worse, "the contract losses will be covered by the insurance fund".
Neither venue runs a single pool, and the boundaries are drawn along different axes. Bybit segregates by settlement currency — "the insurance fund pools for Inverse contracts, USDT contracts, and USDC contracts are separate" — then again by project risk into shared and isolated pools. OKX separates by business line and instrument. Both publish live balances, and the two figures are not comparable in the way a reader expects: one is a currency-level aggregate, the other an instrument-level balance, so a ratio between them is a category error rather than a ranking. The structure is the finding here; the balances themselves, with the date they were read, belong in our Bybit versus OKX comparison.
The fund's contractual character is franker than readers expect. OKX's Middle East agreement guarantees nothing, and says so: having called it "the segregated fund consisting of Virtual Assets", the agreement states that "OKX cannot guarantee that your losses will be protected." Residual liability stays with the trader — "you may lose more than you invest and you may owe such negative balances".
Auto-deleveraging and counterparty ranking
When the fund is not enough, the shortfall moves onto the profitable side of the same contract. Bybit's definition is the clearest: auto-deleveraging "works by automatically deleveraging profitable or highly leveraged positions on the opposite side". OKX frames it as terminal — "the final liquidation process deployed to protect the OKX security funds" — and Binance as "the final step in the liquidation process".
Each venue publishes a trigger threshold measured against its own fund over a recent window, and each publishes a level at which the process stops. The thresholds themselves are venue-comparative data and are tabulated, with their revision dates, in our Bybit versus OKX comparison. What matters architecturally is that the line exists and is disclosed: the queue is ordered by profit and leverage, so a trader is ranked by how well the position has done, not by anything they chose.
The ranking converges more than the genre suggests. Bybit states that "the ADL ranking is based on the leveraged return"; OKX ranks "based on the leverage PnL%", surfaced where "five lights indicate your position is ranked at the front of the ADL queue"; Binance uses "PNL Percentage * Effective Leverage". Different algebra, one idea: profit scaled by leverage. Being at a loss is not immunity either, since "positions that are at a loss may still be selected", and the closure bypasses the book, with OKX directly matching "with the highest-priority counterparty".
The genuine divergence is the settlement price, and it is the most citable structural difference here. OKX normally closes deleveraged positions "at the mark price at the time of matching", falling back to the bankruptcy price only when its fund is nearly exhausted. Binance closes "at the Bankruptcy Price of the liquidated order for the losing trader", and Bybit's full-closure step lands there too. Same queue, same ranking idea, different haircut on the counterparty pulled out of a winning position.
Socialised loss and two allocation rules
State the vocabulary precisely, because it is muddled almost everywhere: auto-deleveraging and socialised loss are not two severities of one event. They are two allocation rules for the same residual. On Bybit, auto-deleveraging is the socialisation route rather than an alternative to it — when the fund cannot absorb the loss, "the profits from other traders' positions on the platform will be used". The fund's exhaustion is what causes socialisation, and auto-deleveraging is the instrument.
Deribit documents the other rule: a "deficit, that cannot be covered by the insurance fund, is redistributed", and it "would be proportionally distributed between the traders who made a profit that day", with a daily settlement at 08:00 UTC ring-fencing earlier sessions. As of that venue's statement of March 2025, "Deribit has never had an instance of socialised loss" — a claim dated by construction. The difference is distributional: one rule concentrates the residual on a few highly-ranked counterparties, the other spreads it across everyone who profited that day.
The on-chain venue uses the concentrating rule and states its purpose as a solvency guarantee: "Auto-deleveraging strictly ensures that the platform stays solvent." It also carries one invariant with no centralised equivalent in any document read for this page — "a user who has no open positions will not socialize any losses of the platform". On a centralised venue, exposure follows from the account rather than the position: OKX's terms describe a socialised claw-back that may "take a portion of your gain" when "OKX's security funds are not able to cover a User's losses". Framing auto-deleveraging as a centralised-exchange defect is nonetheless wrong: both architectures socialise unrecoverable losses onto profitable traders.
The on-chain keeper and oracle path
One term needs redefining. In most DeFi contexts a "keeper" is a scheduled bot that compounds a vault; in the perpetuals context it is a liquidator, an unprivileged actor competing to close somebody else's failing position for a profit. Failing positions are "first attempted to be entirely closed by sending market orders to the book", at full size, because "this allows all users to compete for the liquidation flow". The profit goes to whoever wins the race rather than to a desk with a relationship, which is why there is no clearance fee.
The backstop fires when the auction fails. If account equity drops below two thirds of the maintenance margin without a successful liquidation, "the trader's cross positions and cross margin are all transferred to the liquidator", and "the trader ends up with zero account equity". One clause is under-reported and is the sharpest single risk fact on the on-chain side: "During backstop liquidation, the maintenance margin is not returned to the user." The value lands with depositors, since "the pnl stream from liquidations go entirely to the community through HLP".
Three failure modes have no centralised analogue. The price that fires the sequence updates approximately once every three seconds, so the engine's resolution is bounded by the oracle's. Inclusion is contested on a general-purpose chain, where gas is a blind auction: per Ethereum's developer documentation, "if there's too much demand, users must offer higher tip amounts to try and outbid" other transactions. And chain liveness can fail outright: general-purpose chains have had sequencers stop relaying transactions under sustained load, which is a failure mode with no centralised analogue — a matching engine does not stop because its users are busy.
We are not naming an incident here, because the one we examined could not be confirmed at its source; the class is what matters, and no documented consensus halt for the venue named here was found either. For the chain-level comparison it belongs to, see our Layer 2 comparison.
The stress test that exercised all of this arrived on 10 October 2025, reported by CoinDesk as "the largest single-day liquidation event in crypto history by dollar value" — "over $1.23 billion in trader capital on Hyperliquid and $19 billion across the crypto market". A Bitwise portfolio manager's postmortem, quoted by the same outlet, records that "auto-deleveraging kicked in at some venues, forcibly closing part of profitable counter-positions", and reports "$300-plus spreads at times between Binance and Hyperliquid on ETH-USD" — the oracle surface becoming visible under load.
Custody, counterparty and what a trader owns
Who holds the margin, and under what lien
OKX's perpetual swap trading user agreement is specific about the security arrangement, and it is stronger than the word "deposit" suggests. The user grants a security interest over the margin in OKX's favour; all margin is held by OKX; that margin is subject to a general right of set-off; and the following clause takes "a continuing first priority security interest in, and a lien upon, all assets" in the margin account. Nothing there describes an insolvency. It describes the ordinary state of the relationship, with the lien live from the moment the account funds.
The terms of service fill in what holding means. Pooling is consented to at account opening — "you expressly agree to the pooling of your Digital Assets" — and no external safety net sits under it, since "digital assets of users are not protected by deposit protection or a deposit insurance scheme". Yet the same document affirms that the user "is the ultimate and effective legal and beneficial owner of any Digital Assets" in the account.
Those statements do not conflict; together they define what a custodial claim is. The trader beneficially owns a share of a pool, and "users whose assets have been pooled may share in that shortfall". Access is discretionary too: withdrawal is a request rather than an action, and the venue "may also suspend withdrawals at such time we deem appropriate".
What a claim is worth when the venue fails
The abstract question has a concrete precedent. In the FTX bankruptcy, whether customer assets were customer property or property of the estate was not self-evident and had to be litigated by the customers themselves. When the plan was settled, digital-asset claims were converted to cash valued on asset prices rather than returned in kind. The position is not preserved, the asset is not returned, and the claim becomes a fiat number fixed at the moment of collapse — pledged and encumbered before the failure, converted and fixed after it.
One limitation belongs in the text rather than a footnote. Bybit is cited throughout for documented mechanism, read at source; its contractual documents were not retrievable in machine-readable form during this research, so no claim about who faces a Bybit user, or what happens to their margin on failure, appears above.
The on-chain answer, and what it does not say
On the on-chain venue, margin is not a balance at a company. It is execution state on the chain held against an address, and the collateral is natively minted on the venue's own layer one rather than bridged in — which retires a standard criticism, since the legacy Arbitrum bridge that most explainers still call the custody chokepoint now "holds less than 10% of the USDC supply on HyperCore".
What replaces custodial risk is not nothing. Blocks are produced by validators in proportion to stake, and exits run through that set, since "the L1 validators will sign and send the withdrawal request to the bridge contract". The trust boundary moved; it did not disappear. Nor is every balance instantly exitable: staking transfers carry "a 7 day unstaking queue", and liquidity-vault deposits a four-day lock-up.
The most useful finding here is an absence. The venue's published documentation, read in full, contains no claim of non-custody to cite — no sentence in which the protocol tells a user their funds are theirs, with the only self-custody language referring to third-party ecosystem wallets. This page therefore does not write "your funds are yours" about the on-chain model, because the venue does not. Account state is key-controlled, exits are validator-signed, and a user who logs in by email is issued a generated wallet whose private key they can export.
Two asymmetries survive an honest reading, and they run in opposite directions. The on-chain model's genuine advantage is the flat-account invariant combined with the absence of a pre-insolvency lien: a user with no open position socialises nothing by protocol rule, and no security interest sits over their collateral while they simply hold it. The centralised documents offer neither.
The centralised model's genuine advantage is a funded, disclosed, contractual backstop with a published balance. It carries an explicit no-guarantee, but it exists as an obligation of a commercial entity rather than the goodwill of a depositor pool. The on-chain backstop is a community vault that can itself be squeezed — and it was, in an episode covered next.

Oracle dependency and its manipulation surface
How a mark price is actually assembled
Everything in the liquidation section runs off a number neither book produces on its own. On the on-chain venue, publishing the oracle is a validator duty rather than a purchased data feed: validators are "responsible for publishing spot oracle prices ... every 3 seconds" for each perpetual asset. The input is external — a weighted median across eight constituent venues, seven of them centralised, with Binance carrying weight three, OKX and Bybit weight two each, and the remaining five weight one — then aggregated as "the weighted median of each validator's submitted oracle prices", weighted by stake.
The mark price sits on top as a median of three inputs, one of them a median of centralised-venue perpetual mid prices, and it is "used for margining, liquidations, triggering TP/SL, and computing unrealized pnl".
The venue's stated rationale is that the construction is "robust because it does not depend on hyperliquid's market data at all". The claim is narrower than it sounds — the venue's own book carries the least weight in the set rather than none — and it is simultaneously the admission. An on-chain venue whose mark price is deliberately independent of its own book is, by construction, dependent on the books of centralised venues. Non-custodial and price-independent are different properties, and a reader who changed venues to escape the first has not touched the second.
The centralised side builds the same kind of number for the same stated reason. Bybit describes a dual-price design adopted "to prevent traders from falling victim to market manipulations", with the standard construction given as "Mark Price = Median (Price 1, Price 2, Last Traded Price)", and a newer mechanism for thin and newly-listed symbols rolled out "starting from November 14, 2025, 10 AM UTC". Mark price against index price as the funding anchor is a separate question, handled in our funding-rate page.
The degradation condition is documented rather than inferred: if "the index price of any Spot exchange is abnormal or data cannot be obtained", then "the mark price will be calculated based on the last traded price". Note what that fallback does: an index built to resist manipulation abandons its external inputs precisely when they misbehave, and falls back to the single venue-local price it was designed not to trust. The venue also retains the right "to update the mark price selection criteria in real time".
What manipulation looks like structurally
The attack is not on the oracle. It is on the oracle's input set: an oracle that faithfully reports a manipulated market has not malfunctioned; it has done its job on corrupted inputs. Each episode below is a case study in that distinction: an enforcement action over alleged manipulation of the inputs feeding a defunct venue's oracle, and an on-chain squeeze in which the oracle itself worked correctly throughout.
The regulator-named precedent is historical and belongs to a defunct venue. In an action the CFTC's own subtitle described as the "First CFTC Oracle Manipulation Case on 'Decentralized Exchange'", the agency alleged that on 11 October 2022 a trader "unlawfully misappropriated over $110 million in digital assets" from Mango Markets by taking large leveraged positions on both sides of one instrument, then "artificially pumped up the price of MNGO" "on three digital asset exchanges that were the inputs for the 'oracle,' or data feed", and borrowing against "the artificially inflated value of his swaps as collateral". Those are the regulator's allegations rather than this page's assertions. The collateral-side version of that attack is a different mechanism, treated in the lending context; the perpetuals version targets a mark price that triggers liquidations.
The on-chain episode worth studying is more recent, because the venue's oracle worked correctly throughout. On 26 March 2025 a trader combined a short position on the venue with on-chain spot buying, and the resulting liquidation left the community vault holding the inherited short. Its "unrealized PNL temporarily stood at negative $13.5 million", as CoinDesk reported.
The response was not a mechanism firing but a decision being taken: "the validator set convened and voted to delist JELLY perps", and the position was resolved by "settling it at $0.0095 as opposed to $0.50 that was being fed to oracles". Restitution came from a foundation's discretion rather than a protocol rule. Read that alongside the same vault having "an extremely profitable day" during the October 2025 cascade: the architecture that let a community-owned vault harvest a record cascade is the one that let a single trader hand it a $13.5 million short.
Mitigations, and the discretion that remains
Real mitigations exist and they are structural rather than promissory. The first is redundancy of inputs: medians at two layers, so that corrupting one constituent moves the result far less than it moves the constituent. The second is explicit bounds — on its index-style perpetual instruments the on-chain venue restricts the reference to "at most 4 times the one month average mark price" and caps the mark price at three times the eight-hour moving average. A bound of that kind does not prevent manipulation; it caps the payoff.
The third is update cadence. This venue pushes a fresh price on a fixed roughly three-second interval, whereas the general pattern for on-chain data feeds elsewhere is event-driven: a new aggregation round starts when off-chain values "deviate by more than the defined deviation threshold from the onchain value", or "after a specified amount of time from the last update". Those are different staleness profiles, and staleness is the window an attacker needs.
What no mitigation removes is discretion. On the centralised side, a contractual right to update mark-price selection criteria in real time means the definition of the number that liquidates a trader can change while they hold the position. On the on-chain side, a stake-weighted validator set voted a market out of existence mid-incident and settled it away from its own oracle, after which a foundation decided who was made whole. The override was relocated, not removed.
Fees, rebates, withdrawal and settlement finality
Rebates are the book's funding mechanism
On a book, the fee schedule is a two-sided price: the venue charges the side consuming depth and pays the side supplying it, because without paid suppliers there is no depth to consume. Rebates are therefore not a loyalty discount but the book's funding mechanism, and how each venue gates access to the paid side says more than the headline rate does.
The two centralised venues compared here have made opposite choices about it. On OKX the maker fee turns negative partway up a public ladder, so any account can reach the paid side by trading enough. On Bybit the public ladder stops at zero, and negative maker pricing exists only inside an institutional programme where "all applications and upgrades are reviewed on request".
That is a difference in who may be paid to supply depth, not in what depth costs. Both venues reserve the right to change these terms — Bybit's own wording is "to change, modify, or increase the Trading Fee Rate" — so the rungs matter less than the gate. Venue-level fee tiers, funding intervals and margin modes are compared in our Bybit and OKX comparison.
The on-chain venue starts at 0.045 per cent taker and 0.015 per cent maker, with the maker fee reaching zero above 500 million dollars of 14-day volume. Its rebate gate diverges structurally: rebates are conditioned on share of maker volume rather than absolute size, from minus 0.001 per cent above a 0.5 per cent share to minus 0.003 per cent above 3.0 per cent. A dollar ladder rewards a maker for being large; a share ladder rewards one for being important to that specific book. Fees also go elsewhere: they "are entirely directed to the community (HLP, the assistance fund, and deployers)" — the protocol's own description of its economics rather than an audited fact.
Withdrawal: a request against a signature
The exit is where the two custody models become tangible. On the centralised model, withdrawal is a request the venue may decline, suspend or delay, and the ultimate failure case is the fiat-fixed claim described above. On the on-chain model the exit is a cryptographic operation with a documented trust boundary, since the validator set signs the withdrawal request through to the bridge contract — a different dependency, since it does not require a company's cooperation, but not the absence of one.
The withdrawal cost is this page's cleanest freshness lesson, and the finding is a disagreement rather than a number. The venue's own documentation contradicts itself. Its API reference still states a one-dollar withdrawal fee and roughly five minutes to settle, hedging the figure in the same sentence with "at the time of this writing". Its user-facing onboarding page carries neither number, saying instead that "depending on the withdrawal chain and method, there may be small gas fees". Meanwhile USDC is now natively minted on the venue's layer one, and the legacy bridge the old figure assumed holds under 10 per cent of supply. Every affiliate write-up still repeats the one-dollar, five-minute, Arbitrum-bridge line as though it were current.
Settlement finality is the last piece, and the two models mean different things by the word. On the on-chain venue, "every order, cancel, trade, and liquidation happens transparently with one-block finality", and because trading actions are gas-free that finality is not rationed by a fee market. On the centralised venue, a fill is final the instant the venue records the debit and the credit in both accounts — final in exactly the sense that the venue's own ledger is authoritative. One is a property of a distributed state machine, the other of a company's books.
Conclusion
The useful comparison was never custodial against non-custodial. It is a question about how five functions are distributed. On the centralised model documented here, one commercial group matches the orders, holds the margin under a first-priority lien, compiles the reference price and reserves the right to change its inputs in real time, operates the liquidation engine and manages the fund absorbing the residual — while at least one of its own agreements declines to say who the counterparty is. On the on-chain model those functions sit in chain state, a community-owned vault and a stake-weighted validator set, and the reference price is still assembled from centralised-venue quotes with Binance, OKX and Bybit carrying the heaviest weights.
Two advantages are genuinely one-sided and deserve saying without hedging. The on-chain model offers a flat-account invariant with no contractual equivalent found in this research — a user holding no position socialises nothing — and it places no security interest over collateral during normal operation. The centralised model guarantees nothing while funding a disclosed backstop with a published balance, which is an obligation of a commercial entity rather than the goodwill of a depositor pool; the on-chain equivalent is a vault that can be squeezed, and was, for 13.5 million dollars in a single episode.
What is not one-sided is most of what the genre treats as decisive. Both socialise unrecoverable losses onto profitable traders, ranking them on essentially the same index. Both retain a discretionary override. And both liquidate against a constructed reference rather than the traded price, which is why a position can close at a level the chart never printed on either kind of venue.
Three questions carry most of the analytical weight. Which entity holds the collateral, and does anything sit over it before a failure? What is the reference price built from, and what does it degrade to when an input misbehaves? And when the fund runs out, who is selected, on what ranking, and at which settlement price? The habit worth carrying away is smaller than any of it: check a venue's technical documentation against its marketing, and check both against their dates. The sharpest findings on this page were disagreements, and none needed a source outside the venues themselves.
Sources
- Hyperliquid — protocol documentation: consensus and matching-engine state, the co-located latency figures, margining and liquidation mechanics, the community vault, oracle and mark-price construction, fees and withdrawals.
- OKX — terms of service, updated 24 July 2026: the order-matching definition, price-time priority, the multiple-capacity and affiliated-market-maker clauses, the combined execution-and-custody clause, and pooling.
- OKX — perpetual swap trading user agreement, updated 28 June 2026: the security interest over margin, the right of set-off, the first-priority lien, and the unresolved counterparty entity.
- OKX — Middle East margin and derivatives trading agreement: the venue not being a party to the contract, the segregated insurance fund with its explicit no-guarantee, and the contractual auto-deleveraging thresholds.
- OKX — security fund, tiered margin and liquidation documentation: fund segregation, the three-stage liquidation sequence, the ADL thresholds effective 6 March 2025, and mark-price settlement.
- Bybit — margin, risk limit, liquidation, insurance fund, ADL, mark price and fee documentation: the margin formulas, tiered MMR, the laddered liquidation sequence, bankruptcy pricing, fund segregation, ADL ranking, the dual-price mark construction with its fallback, and the fee ladders.
- Deribit — order management best practices: per-instrument order-book serialisation and the time-priority behaviour of size reduction against cancel-replace.
- Deribit — insurance fund and socialised loss system: the session-wide socialisation rule, the 08:00 UTC settlement boundary, and the never-socialised statement dated to March 2025.
- Binance — auto-deleveraging documentation: ADL as the final step after the insurance fund, its ranking formula, and bankruptcy-price settlement.
- US CFTC — press release 8647-23, Mango Markets action: the regulator's allegations for the 11 October 2022 sequence. Allegations, not findings, and the venue is defunct.
- CoinDesk — the 10 October 2025 liquidation event and the March 2025 vault squeeze: the scale of the October cascade, the attributed postmortem on ADL firing across venues, and the JELLY episode.
- Ethereum — gas and fees documentation: the blind-auction character of inclusion and the per-block base-fee adjustment limit.
- Chainlink — decentralised data model documentation: the deviation-threshold and heartbeat update triggers, used only to contrast update cadences with a fixed-interval push design.
Frequently asked questions
- Is a perpetual futures DEX non-custodial?
- The published documentation of the on-chain venue examined here makes no non-custodial claim, so this page describes the mechanism rather than repeating a slogan. Perps margin is held as execution state on the chain, keyed to an address rather than to an account at a company, and collateral is natively minted on the venue's own layer one. Exits are not unilateral: a withdrawal completes when the validator set signs the request through to the bridge contract, and blocks are produced by validators in proportion to the native token staked. Two details complicate the binary further: an email login issues a generated wallet whose private key the user can export, and some balances are not instantly exitable.
- Does auto-deleveraging only happen on centralised exchanges?
- No. Both architectures socialise losses they cannot otherwise recover, by reaching for the profitable side of the same contract. Bybit describes it as automatically deleveraging profitable or highly leveraged positions on the opposite side, and both OKX and Binance call it the final step in the liquidation process. The on-chain venue states that auto-deleveraging strictly ensures the platform stays solvent. The honest difference is disclosure and predictability rather than existence, plus one invariant the centralised documents do not offer: on the on-chain venue, a user who holds no open positions socialises nothing at all.
- Does an on-chain perpetual escape centralised price discovery?
- No, and the venue's own documentation is the source. Validators publish a spot oracle price for each perpetual asset roughly every three seconds, and the input is a weighted median of eight constituent venues, seven of them centralised, with Binance carrying weight three, OKX and Bybit weight two each and the remainder weight one. Those submissions are then combined into a stake-weighted median. The mark price sits on top as a median of three inputs, one of them a median of centralised-venue perpetual mid prices, and it performs margining, liquidations and stop triggering. Custody and price dependence are separate properties: moving custody on-chain does not move price discovery with it.
- Who is my counterparty on a centralised perpetual exchange?
- It depends on which legal entity the account was opened with, and at least one governing document declines to resolve it. OKX's global perpetual swap trading user agreement, last updated on 28 June 2026, says the product is offered by the OKX entity on which the user is onboarded as a customer, without naming that entity. Its separate Middle East agreement is explicit in the other direction: the venue shall not be a party to the contract, and its role is to match positions one user opens with another user. Two things hold regardless of entity — the venue may act in more than one capacity, including as principal and market maker, and an affiliated market maker may enter into transactions with a user as that user's counterparty.
- What happens to my margin if a centralised venue fails?
- The pledge comes first and the shortfall second. Before any failure, OKX's perpetual swap agreement has the user grant a security interest over the margin, holds all margin at OKX subject to a general right of set-off, and takes a continuing first-priority security interest and a lien upon all assets in the margin account. The terms of service record that assets are pooled by consent at account opening, that no deposit insurance scheme applies, and that users whose assets have been pooled may share pro rata in a shortfall. What that resolves to has a precedent: under the FTX plan, digital-asset claims were converted to cash rather than returned in kind, and whether customer assets were customer property at all had to be litigated.
- Why did I get liquidated at a price the chart never printed?
- Because liquidation is triggered by the mark price, not the last traded price, and the two are deliberately different numbers. Bybit describes its dual-price design as a way to prevent traders falling victim to market manipulation, with the standard mark price built as the median of price one, price two and the last traded price. The on-chain venue does the same with a different median, updated roughly every three seconds. A mark price built from external references will sit away from a thin local book precisely when that book is being pushed, which is the point of the construction. It has a documented failure edge too: Bybit states that if the index price of any spot exchange is abnormal or the data cannot be obtained, the mark price is calculated on the last traded price instead.
- What does a perpetual exchange insurance fund guarantee?
- Nothing, and the venues say so in the same documents that describe it. OKX's Middle East agreement guarantees nothing: it calls the insurance fund a segregated fund and the first backstop for negative balances, then states that OKX cannot guarantee losses will be protected, and that a user may lose more than they invest and may owe the negative balance. The fund is not a static reserve either: it is fed by liquidations that close better than the bankruptcy price and drained by those that close worse. Nor is it one pool — Bybit segregates by settlement currency and then by project risk, while OKX segregates per business line and again per underlying and currency. Comparing a single headline balance across two venues is therefore a category error rather than a measurement.
← Back to Crypto Investing Blog Index
Financial Disclaimer
This content is not financial advice. All information provided is for educational purposes only. Cryptocurrency investments carry significant investment risk, and past performance does not guarantee future results. Always do your own research and consult a qualified financial advisor before making investment decisions.