authored by Premmi and Beguène
The Market Keeps No Secrets
On March 11, 2026, Matt Levine’s Bloomberg column opened with the question currently haunting the $1.8 trillion private credit market. Should a software loan be marked at $100, the par value1 on the assumption the loan is performing and will be held to maturity, or $98, reflecting what the market will actually pay today? The column arrived against a seismic backdrop of events concerning the private credit market. JPMorgan was independently revaluing software loan portfolios in the midst of private credit funds gating redemptions. The scrutiny reached a crescendo with Boaz Weinstein’s Saba Capital offering to buy shares in Blue Owl’s private credit fund at a 33% discount to reported net asset value, thus making a public bet, backed by real money, that the marks are wrong. Two days after the column, Blue Owl urged investors to reject the offer, calling the portfolio “high-performing.” So the mark was saying one thing and the bid the opposite.
The column is witty and incisive, delivered with the usual Levine humor, until the discussion shifts facetiously to random number generators. Levine says he half-jokingly calls the stock market a random number generator for gambling, noting that while stock prices obviously reflect the market’s expectations about future earnings, the competitive nature and apparent efficiency of markets make the future path of a stock price look random to most people. He then quips that his joke might not be a joke after all and points to a paper2 from the Financial Cryptography and Data Security 2026 conference proposing that financial tick sequences3 could serve as a source of randomness for cryptographic applications. He ends with “So there you go, the stock market is a useful random number generator.”
The problem is it isn’t. The claim is broken for the same reason the private credit marks are wrong. In the private credit case, the valuation model works correctly given its assumptions. The model correctly answers “What is the loan worth if held to maturity and nothing goes wrong?” while the market is asking “What will the buyer pay today given that AI is disrupting software?” Similarly, the statistical tests, which the paper relies on, correctly answer “Is the sequence random in the sense of being free of detectable patterns?” while cryptographic applications ask “Is the sequence random in the sense of being unpredictable to an adversary with practical computational resources?” This requires not just that the sequence be free of detectable patterns but also that the adversary lack the information that determines it, so that he cannot predict it appreciably better than chance4. A sequence can be free of detectable patterns while the adversary holds the information that determines it, and then the absence of patterns proves nothing, for he predicts it not by finding patterns in the sequence but by computing it from the inputs he holds. Therefore, both the statistical tests and the valuation model produce correct outputs for the questions they are designed to answer. But both are being used to claim something broader, which is the same category error, twice over.
The paper relies on the NIST test suite, together with the Rabbit and Alphabit sub-batteries of TestU01, screening tools for candidate random and pseudorandom number generators. They ask whether the output of these generators, a binary sequence, is random, and answer by checking for specific statistical patterns such as frequency imbalances, correlations, or periodic structure. This is exactly the question that matters in finance and in cryptography, though for different reasons. In finance, a detectable structure in price movements means a tradable edge, whereas in cryptography, a generator whose output contains a detectable structure is one whose values can be predicted better than chance, which is the defining failure of that generator. The paper’s error is in using the answer to the statistical question to address a broader question, one that cryptography asks but the test suite cannot answer, namely whether a sequence is unpredictable to a real-world adversary, that is, one with practical computational resources. The absence of detectable structure alone does not answer this, and NIST’s own documentation says as much in its guidance. It states that the outputs of generators suitable for cryptographic applications “must be unpredictable in the absence of knowledge of the inputs.” This requirement presupposes that the adversary lacks knowledge of the inputs. The inputs are known to some observers and not others, and it is the adversary’s lack of this knowledge that makes the output unpredictable to him. Therefore, unpredictability is never a property of a sequence by itself, but relative to the observer. A generator whose inputs the adversary knows has nothing to make its output unpredictable to him, since knowing the inputs is enough to determine the output.
NIST adds that no battery of statistical tests can certify a generator for cryptographic use, because statistical testing is no substitute for cryptanalysis. The paper inverts this, describing the suite as “designed to evaluate the randomness of binary sequences and to ensure their suitability for cryptographic applications,” precisely the certification NIST says it cannot provide. This is because a statistical test examines only the output sequence, and so cannot detect whether an adversary holds the information needed to determine it. When the adversary holds that information, even if the output passes statistical tests because it lacks detectable structure, he can still predict it with certainty.
A cryptographic adversary isn’t sitting and looking at a sequence trying to spot a pattern. That’s what a statistical test does, and it does it tirelessly. Instead, the adversary asks questions that a statistical test does not. Can I see the inputs that generated it? Can I influence it?
The paper asks none of these questions. If it had, the answers would have been fatal to the premise that cryptographic randomness can be derived from stock market data. Every trade in a stock market is observable by all market participants, and so the data is public. If the sequence is derived from this data, then the information that determines it is available to every market participant, which makes it predictable to all of them and therefore random to none.
One might object that comprehensive real-time feeds are costly and colocated5 firms see prices microseconds before everyone else. But this confuses restricted access with cryptographic secrecy. Paid access to a public feed is not a secret because the prices form in public markets, are observable in principle by any participant, and a latency advantage of microseconds is bounded and decaying, shrinking over time as others catch up, not a durable secret the adversary lacks. Moreover, the trend in market structure runs the wrong way for the premise, too. On decentralized, on-chain venues the complete order book and trade history are public by construction, readable by anyone, with no feed to buy and no colocation edge to invoke. Security cannot rest on the hope that the adversary declined to pay for market data.
We might wonder why the public nature of the stock market data does not trouble the authors, when the publicness makes the data accessible to every market participant and hence useless as a secret. But a secret is needed only under the assumption that an adversary exists. The authors’ framework for constructing a source of randomness has no adversary because they understand randomness as the absence of specific patterns in a sequence that their statistical tests can detect, and not as the unpredictability of a sequence to an adversary. They ask whether the sequence resembles the output of a random number generator, never whether it is unpredictable to someone who holds the information that determines it, a question the public data would have answered against them, since that information is held by every market participant. In their world the publicness is no defect, for there is no one to exploit it. But the assumption is self-defeating. Randomness exists only in relation to an adversary, for a process is random only to one who lacks the information that determines its output and so cannot predict it, and a world with no adversary needs no secret, and so no unpredictability to protect it, and hence no cryptography at all. The very absence of an adversary that lets the authors overlook the publicness of the stock market data removes the reason for the randomness they labor to extract from it. This is why the misconception that stock market data can function as a source of cryptographic randomness is not an inadvertent error the paper commits but a fundamental impossibility.
Secrecy Lives in the Adversary’s Limits
On March 16, 2026, five days later, Matt Levine’s column returned to the subject of the stock market as a random number generator. A reader had written in to inform Levine of the historical precedent of using financial data to draw random numbers nearly a century before anyone thought to propose the stock market. That precedent was the Harlem numbers game, a private lottery that ran for decades in the 20th century, drawing its daily winning number from New York Clearing House totals, the published figures for money exchanged between the city’s banks each day. Not the stock market, Levine noted, but a similar idea.
It is a similar idea, and that is exactly the problem. The similarity ends with both the Clearing House totals and the stock prices being financial data. And for the purpose of serving as random number generators, they couldn’t have been more dissimilar. While the Clearing House totals worked as a random number generator, the stock prices cannot. And the reason the one succeeded is the very reason the other fails.
The intuition the comparison carries, the very intuition that misled the paper, is that unpredictability is a property of the financial data itself, sitting in the figures, there for anyone who knows how to draw it out. Where the numbers game read its winning number straight off the Clearing House totals, the paper works harder, aggregating its tick sequences until the patterns in them fade and what remains passes its statistical tests. For the numbers game, the totals worked. Here is public financial data, used every business day for a decade to produce numbers no one could guess, exactly what the paper now aims to do with stock prices. If it worked then, why not now?
It worked then for a reason that had nothing to do with the financial data and everything to do with the bettors. The numbers game’s winning number was, in the words of the period, drawn from a source with a reputation for being unfixable. A bettor in 1920s Harlem could not see the day’s bank clearances before they were posted, could not compute them in advance, and certainly could not move the aggregate flows of money between the banks of New York such that the winning number matched his wager. The winning number was unpredictable to him and beyond his influence, and that is the precise reason the Clearing House totals served as a source of randomness. The winning number was random not because it was drawn from the financial data. It was random only because the bettor lacked the means to foresee or affect it.
History illustrates how randomness dissolves when its source falls within an adversary’s reach. When the New York Clearing House, irked that it had become synonymous with gambling, stopped posting its totals on December 31, 1930, the numbers game operators turned to a different public source, the totals paid out on horse races each day. And now what had kept the Clearing House totals safe, that no one could manipulate them, came apart, because a determined man could reach the figures a racetrack pays out. The gangster Dutch Schultz, who took over the Harlem numbers racket, did exactly to the racetrack payouts what no bettor could have done to the Clearing House totals. With a mathematician6 to pick the horses and size the bets, and Schultz’s money to place them, his men bet late and large at the track, and since a track’s payouts were computed from the wagers themselves, their money moved the very figures the winning number was drawn from. The same idea, public financial data as a source of random numbers, had been unfixable with one source and was corruptible with another, and nothing about the move from bank clearances to racetrack payouts changed the data’s statistical character. What changed was the adversary’s reach.
The stock market hands the modern adversary the very advantage that the bettor never had over the Clearing House and Schultz had only over the racetrack. The modern adversary is not a 1920s bettor waiting for the morning paper. He sees the prices the instant they form, and he has the capital to trade into them and push them toward the values that suit him. The numbers game only required the Clearing House to stay out of a bettor’s reach, and it did. The stock market must survive an adversary the Clearing House never had to face, one who can access and influence its prices. The numbers game faced bettors and held; it faced Schultz and broke; the stock market faces an adversary stronger than either, and there is nothing in the prices he cannot already reach.
The Cost of Being Public
The 2026 paper is the most recent entry in a research direction that has been attempting to extract cryptographic randomness from public market data for over fifteen years, originating with a 2010 paper proposing a stock-market-based cryptographic randomness beacon and extended by a 2025 paper analyzing the cost of manipulating a beacon of that kind. The premise that the stock market is a source of cryptographic randomness has been flawed from the start, and the three papers do not fail in three different ways. They fail at the same point, the market supplies no secret the adversary lacks, and they differ only in the type of machinery they build to compensate for that absence, a secret key in the first, a delay function in the second, and nothing in the most recent paper.
Why extract randomness from the market at all, when random number generators already exist? Because an ordinary generator produces a number but no evidence that the number came from the generator. Once a party publishes a value, no observer who did not watch it being generated can tell whether it was the generator’s output or a value the party simply chose and presented as the generator’s. This is not a problem when the party producing the value is also the party who suffers if it is not random. Whoever generates a key to protect his own secrets has every reason to generate it well, since a key an adversary can guess fails to protect whatever it was meant to, and that failure falls on its holder alone. So no one else need care whether it was truly produced at random. The difficulty arises only when a random value must instead be seen and trusted by everyone to have been produced honestly, that is, drawn at random and not chosen to favor someone, as in an online lottery. Here the party who publishes the winning number is not the party harmed by a dishonest draw, and his own assurance that the number was drawn at random does nothing for the players unless they can confirm it for themselves. What such applications need is randomness that is also publicly verifiable, a value that is drawn at random, and that anyone can confirm was not chosen by whoever published it.
One way to provide such a value is a randomness beacon, a public service that periodically publishes random numbers anyone can use. One such beacon is operated by NIST. It generates 512 bits of randomness from independent hardware random number generators every 60 seconds and publishes the result with a timestamp, a digital signature, and a hash of the previous value that chains all published values together. Anyone can retrieve the values and verify their authenticity. The values are generated from physical sources of randomness, where the information that determines them is inaccessible to all, and so, until the hardware fires, they are unpredictable to anyone, NIST included. Since the values are signed, timestamped, and hash-chained, they cannot be forged, backdated, or altered after publication, even by NIST itself.
Applications like online lotteries that require publicly verifiable randomness can use the beacon value, and every participant can independently confirm it was the value the beacon published. A lottery using the NIST beacon fixes its formula in advance and applies it to the published beacon value to produce the winning number; the operator therefore has no control over the winning number, for the value was NIST’s and the formula, once fixed, was no longer his to change. The beacon replaces the lottery operator’s trustworthiness with NIST’s trustworthiness.
But can we trust NIST?7 🤔
Though the values are generated from genuine sources of randomness, one must trust that NIST’s hardware works as claimed, that NIST has not been compromised, and that NIST publishes the value its process produced rather than one it chose. The beacon does not remove the need for trust; it moves that trust from the lottery operator to NIST, and provides verifiability only that NIST published the value, not that NIST generated it at random rather than choosing it.
This is why researchers proposed using market data, which appears to provide exactly what a randomness beacon needs. The prices are public, so anyone can recompute the published value from the prices and confirm the published value follows from them, and the prices are taken to be unpredictable, for no one can forecast tomorrow’s prices today, so the prices seem to supply the randomness too. But the appearance is misleading.
What the market actually lacks comes into view only against what cryptographic security requires. Cryptographic security rests on an asymmetry of information between the legitimate parties and the adversary. The legitimate parties hold a secret the adversary does not, and they use it to protect whatever they must from him, the protection holding precisely because defeating it requires the secret, which he lacks. The adversary cannot defeat the protection by trying every possible secret, because that would demand a computation he cannot complete, a search through a space too vast to exhaust or the inversion of a function, neither of which admits a known shortcut, so the protection stands against any such computationally bounded adversary, the only kind in existence.
For a value to be a secret to the adversary, it must elude him at every stage of its genesis and ever after: unknowable before it is formed, unobservable as it is formed, and undisclosed thereafter. Randomness secures the first, making the value unpredictable; concealment secures the other two, making it a secret. A beacon, however, exists to publish its value, and so surrenders the third condition by design. What remains is that the adversary must be unable to learn the value before it is published, neither predicting it in advance nor observing it as it forms, for once published it is public to all, which is the beacon’s entire purpose.
Public market data fails every one of these three requirements, and fails them all for a single reason. Market prices are the continuous result of trading, and trading is how information, whether private or public, enters the prices. Whatever a trader privately knows, he can profit from only by trading on it, and the trade impounds what he knew into the price for all to see. The market is, by its very function, a dissolver of secrets. The prices are therefore knowable before they settle, observable as they settle, and disclosed publicly once they have, so they are no secret on any of the three counts. And their formation is steerable throughout, because moving the prices is not solving a computationally intractable problem, it is only a matter of money. Hence the prices carry no secret, their determinant being public to all; and against manipulation they are shielded by nothing more than money. An economic barrier is not a bound on computation, and neither failing leaves any room for cryptographic security.
Each of the three papers nonetheless takes the public prices for a source of randomness. Because they are not, each must supply from elsewhere the randomness the prices were assumed to provide, or supply none at all. The 2010 paper supplies it with a key, a secret held by the beacon’s operator. Its construction combines the public closing prices8 with that key, producing each trading day a value anyone can confirm was computed from those prices and that key, yet that no one lacking the key could have produced. The value is thus unpredictable to an adversary who holds the prices but not the key. Had the prices been a source of randomness, no key would have been needed; the key is there precisely because they are not, and it carries the whole of the security the prices were supposed to supply. The prices serve only for public verifiability, letting anyone confirm the value was computed from them, not that they were the genuine closing prices, for the auction that sets them is run by the exchange, on order flow only the exchange sees. And even were the prices genuine, they cannot establish that the value was produced at random, for the randomness comes from the key, and the check shows only that the value follows from the key, not that the key was drawn at random rather than chosen by the operator.
A secret key owned by an operator must be trusted in two ways: that it was drawn at random, so no adversary can predict the outputs, and that it has never leaked, for the same key underlies every published value, and a single leak compromises every one of them. This trust is more exacting than the one a beacon drawing on a true source requires. Each value such a beacon publishes is generated independently of the rest, so a lapse corrupts only a particular value and the rest are unaffected. A beacon resting on a secret key affords no such isolation. The beacon drawing on a true source of randomness fails only when its operator acts dishonestly, choosing a value instead of drawing it at random; the one resting on a secret key requires no such act, for the key can leak from an honest operator and compromise every value the beacon has published or ever will, with nothing in the record to show the leak occurred. Worse still, there is a party for whom such a leak would be decisive. The closing prices are set by the exchange, which holds them before they are public, so an exchange that came to hold the key would possess both the prices and the key before the beacon published, and could compute the value in advance, which is the very thing a beacon exists to prevent.
The authors add the key, by their own account, to guard against manipulation, for even were an adversary to force the closing prices to whatever values he chose, he could not produce the output without the key. Yet the guard exposes a confusion at the center of the proposal. Since the randomness comes from the key, manipulating the prices changes nothing, for an adversary who sets every price still cannot compute a value that requires the key he lacks. The manipulation they take such pains to guard against was never a danger to a scheme whose security lives in the key, and the effort they spend defending against it betrays that they took the prices for the source of randomness when that source was the key all along.
The 2025 paper rests on the same premise and the same closing prices, but the machinery it adds is different, a verifiable delay function (VDF) in place of a key. A VDF requires a fixed number of sequential steps to evaluate, steps that no amount of parallel hardware can collapse, so that its output cannot be obtained until a set span of time has passed, and it produces alongside the output a short proof by which anyone can confirm the output is correct without repeating the computation. So the output is slow to produce and, given the input and the proof, quick to verify. Its purpose is to withhold the output from an adversary for a chosen interval.
Such a function has a genuine use, but not as a randomness beacon built from stock market prices. Its place is the distributed beacon, where the randomness originates not with one operator but with many parties, each contributing a value, the output formed from all of them together, so the result is unpredictable as long as a single contributor supplies a genuinely random value. If the last to reveal is adversarial, seeing the others’ values before he commits his own, he can evaluate the output for one candidate contribution after another, and submit the one whose result serves him best. The VDF forecloses this last-reveal attack. By making the output slow to compute, it ensures the last revealer cannot learn what his choice would produce before the window to submit has shut, so he must commit blindly and the manipulation is prevented. The VDF works here for two reasons: the attack runs through computation, since he must compute the output to choose his value, and he is bound by a deadline, the instant he must commit, past which he can no longer act.
The authors of the paper transpose the last-reveal defense onto the market. They picture an adversary who, in the seconds before the market close, computes the beacon outputs that various manipulations would yield and then trades to force the prices toward his preferred output. They propose to thwart this attack with the VDF, setting its delay so that computing the output extends past the closing time, leaving him unable to learn which manipulation to perform while the market is still open. The transposition mistakenly assumes this attack is like the last-reveal attack the VDF defends against. In both, the adversary waits until the last moment and uses what he then knows to steer the output his way. But the two differ at the root, in whether the adversary’s input is secret from him, and this is what the VDF’s defense turns on. In the distributed beacon the last revealer’s input is the others’ values, and these are secret from him until they reveal, so he cannot compute the output until the reveal, his computation forced into the interval before he must commit his own value, which the VDF defeats by making the computation outlast the interval. In the market the adversary’s input is the prices, and the prices are public, secret from no one. He need not wait for the true closing prices, for he can take any price vector he likes and compute its output whenever he wishes, even days ahead, then trade toward a price vector whose output suits him, at any time before the close and not only in its final seconds. His computation was never confined to the last moment, because nothing was ever kept from him, so the delay set to outlast that moment defeats nothing. The deadline the VDF exploits was a creature of the secret, and here there is no secret.
The authors do not dispute that the adversary precomputes, and rest their defense on the market drifting far enough from the precomputed target during the delay imposed by the VDF that forcing the prices back requires billions in capital and loses millions to slippage9, by their own estimate. To make a cryptographic security guarantee, the authors would have to show that forcing a chosen output requires a computation no known method completes in feasible time. They cannot, for the output is fixed by the closing prices, and the closing prices are fixed by trading, so forcing the output is a matter of trading and not of computation. What stands in the adversary’s path is therefore not an infeasible computation but only the expense of the trading, and it is that expense the authors are left to offer as security.
An expense is not a barrier unless it exceeds what the adversary stands to gain, and the paper never makes that comparison, setting aside for future work, by its own account, the analysis that would weigh cost against payoff. But the billions the authors report are not even what the attack costs him. The capital is not spent but committed, held in the positions the manipulation requires and recovered when they are unwound, so what he loses is the slippage, and the cost of carrying the capital while it is committed, a fraction of the sum reported. And against that fraction stands a gain the paper allows may be arbitrarily large, because an adversary who can force the result can wager on it in advance, holding options and other derivatives that pay out on the very outcome he has chosen to bring about, so his winnings are not risked but assured, and bounded only by how much he cares to stake. The cost is bounded and the winnings are not, so there is a prize that clears any wall the expense can build. The prize need not be money at all, for an adversary who would fix a public lottery or swing an election weighs the result against ends no dollar can bound, and the economic frame secures nothing against him.
The economic barrier the beacon’s construction creates can only be raised by tuning the two quantities it offers, the length of the delay and the number of stocks the beacon draws on, and the paper’s own results price them both. Lengthening the delay, the one quantity the VDF exists to set, gives the market more time to drift and so raises what the adversary must spend to force the prices back, but only on the average day, and he does not attack on the average day; the authors’ model lets him watch and strike whenever the drift is small, and on those days, by their own results, the delay’s length scarcely matters. Every stock the beacon draws on is another price the adversary must force back, so the expense climbs only in proportion, five times the stocks for five times the expense. Cryptographic security is not bought in proportion. Each bit the defender adds to the secret costs him the same trivial increment, while each doubles the adversary’s search. So the smallest step the defender takes doubles the adversary’s climb. The delay commands no such rate, because doubling its steps doubles the honest evaluators’ wait as surely as the adversary’s, and worse, they pay that wait every day, while the adversary pays it once, on the day he elects. So neither quantity could ever have bought security at cryptography’s price, for that price is paid with a secret, and the beacon holds none.
That a VDF defeats the last-reveal attack but fails against the market manipulator reveals what such machinery can and cannot do. Cryptographic machinery of this kind does not create randomness; it preserves the randomness it is given and extends its reach. A VDF preserves randomness across time, holding an output that inherits the randomness of its input out of reach of any computationally bounded adversary until an interval has passed from the moment he has the input. Because each step of the computation takes the result of the step before it, the steps must be done in order, and running many machines in parallel produces the output no sooner, for parallelism speeds work by dividing it, and a chain in which each step needs the previous one cannot be divided. The VDF’s security is the assumption that no computation he can carry out yields the output appreciably sooner than the interval. A pseudorandom generator preserves randomness across length, stretching a short random seed into a long string that no computationally bounded adversary can distinguish from a truly random one. Because the seed is far shorter than the string it produces, the seeds are far fewer than the strings of that length, and the outputs they yield are only a sparse few of all the strings of that length, so a truly random string almost never falls among the outputs while a generated one always does; but to decide whether the string before him is generated or truly random, the adversary would have to compute the output of every seed, and there are too many seeds for that. The generator’s security is the assumption that no computation he can carry out tells the two apart appreciably better than guessing. Neither preserves randomness against an unbounded adversary, but that adversary does not exist. Neither originates the randomness it works upon; the security of what each produces rests on the randomness of the secret it was given, never on the machinery itself. If a VDF or PRG is given a public input, a value the adversary already holds and so no secret at all, it preserves nothing, for there was never any randomness in it to preserve. Where the 2010 paper supplied the missing secret with a key, the 2025 paper reaches for machinery that can only preserve a randomness it presupposes and never provides. It guards an empty vault.
Under the 2010 construction the exchange was dangerous on a single condition. Were it to come by the secret key, it could compute the value in advance. The 2025 construction needs no key at all. Its published value is a function of the closing prices alone, the very prices the exchange computes and holds first, in an auction of its own, closed to inspection, whose result is not official until the exchange has cleared it. Foreknowledge of the value was, in the 2010 construction, a power gated by the key; in this one it is granted by the design.
And the delay, the construction’s one remaining defense, runs its clock from each party’s own start, and the exchange starts first. The delay holds only from the moment a party has the input, and runs its interval from there; the exchange has the input first, so its interval opens first and expires first. The delay withholds the output from every party in turn, and the exchange’s turn comes first, before the aggregators that relay the prices, and before the public that waits on them. By the time the prices reach the rest and their intervals begin, the exchange’s interval, begun earlier on prices of its own making, may already have run out.
The NIST beacon asked the public to trust one operator in one act, that the value it published was generated at random, not chosen. This beacon asks the public to trust that the exchange’s auction, closed to inspection, formed the prices honestly, and that every digit was carried faithfully from the auction, through the third-party aggregators the authors say the beacon must read the prices from, to the published value, when by the authors’ own observation a single digit’s difference selects an entirely different result. The numbers game ran on this same chain of trust, its figures formed by institutions and carried by reporters, and history recorded where the chain gave. No bettor could move the figures, for the flows between New York’s banks were not his to trade, and the institutions that could move them had nothing to win from moving them; so when the game was attacked, it was attacked at the one joint within reach: the newspapers that carried the figures were bribed. Against manipulation, the authors offer the closing auction10 as a defense, a blind auction, they note, in which the manipulator cannot ensure a specific outcome. But the blindness that hinders an outside manipulator is no obstacle to the exchange, which does not manipulate the auction from without but conducts it from within, and sees its result because it produces it. And the authors concede they have not analyzed the closing auction either, leaving its dynamics, by their own account, to future work, while resting the beacon’s security on the prices the auction produces. Where the 2010 design kept one secret, the key, this one keeps none. The closing prices are secret from no one, and the exchange holds them before anyone, for the prices are made there.
The 2026 paper adds no machinery to compensate for the market’s missing secret. The 2010 construction supplied a key and the 2025 construction a delay, each doing, in its design, the work of the secret the prices do not hold. And machinery is the least of what is missing, for the 2026 paper supplies no construction at all, no deterministic function fixed in advance that maps the prices to a published value. The earlier constructions, though they lacked the secret, defined exactly how the published value is computed: the 2010 value from the closing prices and the key, the 2025 value from the delay function run on the closing prices. In each, the value follows from the prices under a rule the operator commits to beforehand, and anyone may check that it does, since the 2010 value verifies against a published public key and the 2025 value against the delay function itself. The operator chooses nothing at publication, because any value but the right one fails the check. The 2026 paper fixes no such rule, and so there is no value the prices are meant to yield, nothing to compute and therefore nothing to check. It takes the tick sequence of some stocks and reduces it to bits, each tick compared with the one before it, the direction of the price change recorded as a bit, and where the price repeats, nothing recorded. Then it spaces the compared ticks further and further apart until the patterns its chosen tests detect have faded. What remains, it calls random. But nothing in what remains is hidden from anyone. The trades are public and the procedure is public, so the adversary holds every tick the bits are built from and knows how they are built, and can compute every sequence for himself. A sequence anyone can compute is unpredictable to no one.
Nor does the paper fix which stocks, over which period, at what level of aggregation. And these cannot be fixed, for by its own results the level at which the patterns fade shifts from stock to stock and month to month; the tests disagree, a sequence random to one and not to another; and the most heavily traded stocks resist at every level, so the paper sets them aside and keeps only the stocks that pass. What this describes, though the paper does not say so, is a search and not a method, for the stock, the period, the level are all free to choose and the one fixed instruction is to keep what passes.
Then the three choices are all an adversary lacks. He holds the prices, he knows the procedure; once he knows the stock, the period, the level, he has the value. So whatever unpredictability the published value has rests on those choices alone, and they would have to be made at random, for a choice made any other way can be guessed; and randomness is what the paper set out to produce, not consume. The source of randomness requires randomness the source does not have. Whatever cannot be foreseen in the published value entered through the choosing, and none of it came from the closing prices.
The market’s prices were sought for their publicness. The construction being public too, anyone could run it on the prices himself and compare his result with the published value, so no other value could be passed off as the one the prices had yielded. The prices were taken to be unpredictable as well. They are not, and cannot be, in the sense cryptography requires. They may well be unpredictable to a forecaster, for no one knows tomorrow’s prices today, but the adversary cryptography guards against does not forecast; he computes the value from prices he already holds, or steers the prices to a value that suits him, or simply holds them before anyone else, as the exchange does, for the prices are made there. The publicness that was the whole reason to go to the market is the reason it holds no secret, for what everyone can see is secret from no one, and what is secret from no one is unpredictable to no one. The prices were never the secret; they were the check. The randomness, assumed all along, was never there.
The Error the Market Cannot Correct
We will address only the cryptographic, economic, probabilistic, and market microstructure11 errors in the essays that follow. The private credit error is bigger, and the market is correcting it in real time. 😱 A bid can correct a mark, but no bid arrives to correct a category error.
The cryptographic errors in these papers are visible only against a precise account of what cryptographic security requires, what randomness is, and what statistical tests actually measure. We turn to each in order in our next essay.
Footnotes
- Par value is a loan’s full face amount, the sum the borrower owes at maturity; a loan marked at par is valued as if it will repay in full. ↩︎
- The paper was posted to arXiv as “Emergence of Randomness in Temporally Aggregated Financial Tick Sequences” and presented at Financial Cryptography and Data Security 2026 under the title “Ultra-high frequency random beacons from financial tick sequences.” ↩︎
- A tick is an individual trade as it executes, recorded with its price, size, and timestamp; a tick sequence is the series of these trades, as opposed to prices sampled at fixed intervals such as daily closes or one-minute bars. ↩︎
- “Better than chance” refers to the baseline probability of success, which depends on the distribution of outcomes. For a uniform distribution over n outcomes, that baseline is \frac{1}{n}. For a non-uniform distribution, it is the probability of the most likely outcome. “Better than chance” means exceeding this baseline. Bias raises the baseline, for the adversary’s blind guess succeeds more often against a biased source, and so each draw’s outcome is less uncertain to him. But the bias tells him only which outcome is more frequent, not which one any single draw will yield, and since the legitimate party knows the same bias, it gives the adversary no informational advantage. ↩︎
- Colocation places a trading firm’s servers in the same data center as the exchange’s matching engine, so it receives market data and sends orders microseconds faster. ↩︎
- The mathematician was Otto “Abbadabba” Berman, Schultz’s calculator. Schultz’s racket took the players’ bets and paid everyone who had bet on the winning number, so its payout each day depended on how many players had chosen that number. Berman computed, as the races ran, which late bets would steer the closing figures to a number few had chosen, and Schultz’s men placed them. ↩︎
- In 2013, it was revealed that NIST had published a pseudorandom number generator standard, Dual_EC_DRBG, that was designed with a backdoor attributed to the NSA. NIST subsequently withdrew the standard. The question of trusting NIST is not hypothetical. ↩︎
- The closing price is the official price assigned to a stock at the end of the trading day, the single reference value the exchange publishes once the market closes. It is not merely the last trade but the price set by the closing auction. A great deal rests on it. A fund’s net asset value, the per-share worth of a mutual fund or ETF, is computed from the closing prices of the stocks it holds, so its reported value each day is the sum of its holdings marked at their closes. An index level, the figure quoted as where the market closed, is computed from the closing prices of its constituents. And many derivatives settle on the close, an expiring option paying out or not according to where its underlying finished. Because so much is determined by it, the closing price is a frequent target of manipulation, traders pushing it to lift a fund’s stated value or to swing a derivative’s payoff. ↩︎
- Slippage is the loss a trader incurs by moving a price against himself. Buying drives the price up as the order fills, so he pays progressively more than the price at which he began; selling drives it back down, so he receives progressively less. The capital laid out is recovered when the position is unwound, but this difference, lost on the way in and again on the way out, is not. ↩︎
- The closing auction (closing cross) is the exchange’s end-of-day mechanism that collects all orders seeking to execute at the close and clears them at the single price matching the most volume. The exchange runs the auction, and participants do not see the full closing order book as it clears, so the clearing price cannot be independently recomputed. ↩︎
- Market microstructure is the study of how trades execute and how prices form at the level of individual transactions. It is concerned with order arrival, the order book, and the bid-ask spread, the difference between the highest price a buyer will pay and the lowest a seller will accept. ↩︎































































