Research · Risk Philosophy

Selling Volatility: The Loss You Name Before You Take It

HORIZON September 07, 2026 · CRYNOMAD Research Note

Methodology notes — Volatility Income

HORIZON is our volatility income strategy: multi-leg, defined-risk option structures on BTC, delta-hedged with futures, held to expiry. It is in real-time paper validation, now running the second generation of its specification against live quotes. No capital has been deployed to it.

That last sentence is why this note exists. The interesting question about a premium-harvesting book is never whether it earns in a calm month — almost everything does. The interesting question is what ends it, and whether the answer was designed in before the first order or discovered afterwards.

Where the premium comes from in the first place is a separate question, and we covered it in an earlier note on the design. This one is about what we think kills the design, and what we do about each.

The geometry decides the method

Selling volatility produces a return stream with a specific shape: many small, frequent gains punctuated by rare, fast, large losses. The losses do not arrive on a schedule, and the interval between them is usually longer than the window that feels long enough to judge the strategy in.

Two consequences follow, and they split the work in half.

The first is familiar: the controls have to be structural — properties of the position itself — rather than judgments made while the tape is moving. A control that requires someone to act correctly during the worst hour of the year is not a control.

The second is less often stated: the measurement has to be engineered as carefully as the strategy. If the interesting outcomes are rare, then almost everything you observe is the uninteresting part, and small biases in how you record it will dominate what you conclude. Most of our recent work on HORIZON has been on that second half.

Failure mode 1 — A loss you cannot name

The classic way to destroy a volatility income book is to sell an option whose worst case cannot be stated at entry. It looks efficient for a long time, because the premium collected is real and the tail is theoretical — until it isn't.

Our answer is a constraint rather than a forecast. Every position is a defined-risk structure — an iron condor — whose maximum loss is fixed by its own construction before it is opened. We give up premium to buy that ceiling, deliberately. A stop-loss is a plan that depends on liquidity being there when you need it, which is exactly when it isn't. A bounded structure is a plan that doesn't depend on anything.

Worth being precise about what the bound covers: it is a property of the option structure. The futures hedge alongside it is path-dependent and carries no such ceiling, which is exactly why the next two sections are about the hedge and about measurement. Naming the bounded part honestly is what makes the unbounded part visible.

The structure is then held to expiry, with no discretionary close along the way. That rule costs us optionality, and we keep it anyway, because the same escape hatch that lets you take a good exit is the one that lets a bounded position become a judgment call in the worst hour. The bound was the plan; being able to abandon it mid-life would mean we never really had one.

Failure mode 2 — A hedge that means something different at every size

A raw option position carries two entangled exposures: sensitivity to direction and sensitivity to volatility. We want the second. So the book is delta-hedged with futures — and the hedge is triggered by how far exposure has drifted, not by a clock, because hedging on a clock buys precision nobody needed with transaction cost everybody pays.

The part worth stating is how the tolerance is expressed. It scales with the size of the position rather than being a fixed absolute quantity. An absolute tolerance is a different strategy at every account size: unnecessarily tight when the book is small, quietly loose when it is large, with nobody ever having decided that it should change. Normalizing it makes hedge intensity a property of the design instead of a side effect of how much capital happens to be in the account. That change was one of the differences between our first and second generation.

What we refuse to do is treat either side of the hedging trade-off as free, or to widen the tolerance because hedging has been annoying lately. The tolerance is a parameter of the system, not a mood.

Failure mode 3 — Marking to a price nobody will trade with you at

In a book of multi-leg positions, the most expensive lie available is the mark.

A position can be valued at a screen price and unwound only by crossing a spread on every leg. Those are different numbers, and the difference is not noise — it is a real cost that has simply not been paid yet. A book that looks flat on the screen can be meaningfully worse the moment you actually try to leave, and a research record built on screen prices will show an edge that partly consists of an exit nobody took.

So we carry two numbers rather than one: the live mark, and what it would cost to actually unwind at the prices we would have to pay. The gap between them is recorded as a stated limitation next to every reading rather than netted away, and validation prices exits on the unfavourable side rather than at the midpoint. When the gap runs wider than we assumed, our first hypothesis is that the assumption was wrong — not that the market was unusual that day.

Failure mode 4 — A backtest that quietly knows the future

Option backtests are unusually easy to fool yourself with, and the failures are rarely dramatic enough to notice. Three we found in our own apparatus, and fixed rather than argued with:

Information the strategy could not have had. An earlier version of our simulation priced decisions using a window that included data from after the decision moment. Per trade it is small. In aggregate it is structural, and it points in the flattering direction every time. The pricing path was rebuilt so that every input is one the live system would already have had at the instant it acted.

The simulator and the live system were not doing the same thing. In the first generation, the entry timing the backtest assumed and the entry timing the live engine used were not the same. Two systems, one name, one set of conclusions drawn from both. Reconciling them is unglamorous work with no upside in the story and an unbounded downside if skipped.

An input that was not pinned. One of our validation pipelines was choosing its market-data file automatically, by taking the largest matching file in a directory. That worked, right up until the day it would have silently stopped working. The input is now pinned by name and verified by checksum, and the build fails rather than substituting something plausible.

None of those three came from the strategy. All three came from the apparatus around it. In our experience that ratio is normal, which is the argument for spending research time on the apparatus.

Deciding before you can be tempted

Every run here carries a pre-registration: the evaluation window, the decision rule, and what would count as failure are written down and locked before the observation period opens. Then the engine is left alone for the duration.

Both halves matter. A stopping rule invented after the drawdown is not a stopping rule, it is a negotiation with yourself — and a rule the author can edit mid-run is the same negotiation with extra steps.

The same principle governs how the record is kept. When the specification changed materially between generations, we did not splice the old and new observations into one longer curve. We don't restart the clock to escape a bad stretch, and we don't join two different things together to make a track look longer than it is.

What we don't do

Why the quiet tape is the dangerous one

The regime in which a volatility book looks best is the regime in which its risk controls look most expensive. Bounded structures cost premium. Hedging costs spread. Capacity limits cost size. Every one of those bills is paid during the calm, and every one of them pays out during a period nobody gets to schedule.

Sizing decisions made in a quiet market, against a quiet market's evidence, are how short-volatility books arrive at the event oversized. So the sizing question is answered against the stress record instead, and capacity is treated as a hard constraint of the design rather than a number to revisit when the strategy is working — a book whose returns assume it can always get filled has a ceiling, whether or not anyone has written it down.


HORIZON is in real-time paper validation. VOLCANO, our market-neutral strategy, is live; GLACIER, our delta-neutral carry strategy, is in paper validation. We do not manage client assets. Strategy overviews and current stages: crynomad.ai/strategies. Performance data is shared individually with qualified investors on request.

Performance data is shared individually with qualified investors on request — never published. Explore the strategy lineup on the strategies page.

← All research notes

This is an informational research note, not investment advice or a solicitation. Nothing here is a recommendation to buy, sell, or trade any instrument. Cryptocurrency trading carries significant risk, including the total loss of capital.