← BACK TO SITE VLADIMIR BICHEV
Interactive Research

Fat Tails
The Hidden Shape of Risk

The bell curve says an 8-sigma day in the S&P 500 should arrive once every three trillion years, which is roughly 216 times the age of the universe. I measured 8,437 trading days and found one every 5.6 years. Here is what that actually means, with four things you can play with.

August 10, 2026 Measurement and Backtest Vladimir Bichev

Add one person to the room

Pick a hundred people at random and measure their height. You already know roughly what you will get. Almost everyone between 1.5 and 2 metres, a couple of outliers, nothing that breaks the ruler. Now add the tallest man who ever lived. Robert Wadlow was 2.72 metres. Drop him into your sample and the average moves by about a centimetre.

Do the same with wealth. Pick a hundred people, write down what they own, then add one billionaire. The average does not move by a centimetre. It moves by a factor of a thousand, and every other person in the room becomes a rounding error.

Same operation, two completely different worlds. In the first world the crowd decides the average, and any single member is powerless to change it. In the second world one member decides the average, and you have no way of knowing in advance which member that will be.

Heights live in the first world. Wealth, city sizes, earthquake energy, war casualties, book sales, pandemic deaths and market returns all live in the second. School statistics teaches the first world very well, because the math there is clean and the answers converge. Most of the things that decide our lives are in the second one.

Visual 01  /  The Sampler
Two machines drawing random numbers side by side. Left is a bell curve (human height). Right is a power law (wealth). Each panel is scaled to its own tallest visible bar, which is why the right side keeps flattening itself every time a giant arrives.
lower = wilder. Wealth sits near 1.5
samples drawn per frame
Bell curve
biggest share of total
0%
Bell curve
biggest / average
0x
Power law
biggest share of total
0%
Power law
biggest / average
0x
Samples
drawn
0
Watch the two "biggest / average" numbers. On the left it parks around 1.4 and stays there forever, no matter how long you run it. On the right it keeps climbing, and every so often a single draw arrives that is worth more than everything before it combined. Nothing changed in the code when that happens. That is simply what the distribution does.

The important part of that visual is not the spike. It is the number underneath it. On the bell curve side, the ratio between the biggest sample and the average settles down and stops moving. You can run it for a million draws and learn nothing new. On the power law side the ratio never settles, because the sample that will define your dataset has not arrived yet.

In a bell curve world, more data makes you more certain. In a power law world, more data mostly tells you that you had not seen the big one yet.

Everything hangs on alpha

Fat-tailed things share a signature. The probability of seeing something bigger than x falls off like x raised to a negative power. That power is called the tail index, written α, and it is the single most useful number you can know about a risky thing. It answers "when this gets extreme, how extreme does it get".

That third bullet deserves a second read, because it quietly demolishes a lot of finance. Sharpe ratios, value at risk, position sizing off a volatility target, portfolio optimisation, and options pricing all take a standard deviation as an input and assume it means something. If α is below 2, that input is not a property of the asset. It is a property of how long you happened to look.

Visual 02  /  The Tail Plot (real data)
Every daily return since inception, divided by its own standard deviation, then plotted as "how often is a move at least this big". Both axes are logarithmic, which turns a power law into a straight line. Hover or tap anywhere on the chart.
drag to match the straight part of a curve
SPY α=3.03 BTC α=3.05 ETH α=3.18 XRP α=2.23 bell curve (falls off a cliff)
The bell curve is the line that dives off the bottom of the chart. The real assets are the ones that keep going in a nearly straight line. That gap between them, out at the right hand side, is every market crash in recorded history.

The measured α for SPY across both tails came out at 3.03. I want to be clear that I did not aim for that. I ran a Hill estimator over 8,437 daily returns and it landed on the inverse cubic law that Gopikrishnan, Plerou and Stanley published in 1999 from a completely different dataset. Bitcoin came in at 3.05 and Ethereum at 3.18, which is a pleasant surprise for assets people describe as lawless. XRP, with the shortest history and the most promotional cycles, measured 2.23.

The part that should bother you

Here is the same information as a table, and it is the reason I spent two months on this. A "sigma" is one standard deviation of a daily move, so for SPY one sigma is about 1.17% and for Bitcoin about 3.49%. The bell curve column is what you get if you assume returns are normally distributed, which is the assumption sitting underneath most risk software ever shipped.

Daily move Bell curve says: once every SPY actual Bitcoin actual How wrong
3 sigma 1.5 years 3.7 per year 4.5 per year 5x too rare
4 sigma 63 years 1.6 per year 1.6 per year 103x
5 sigma 6,922 years every 1.4 years every 2.2 years 4,961x
6 sigma 2 million years every 2.2 years every 4.3 years 901,000x
8 sigma 3 trillion years every 5.6 years every 17 years 5 x 1011
10 sigma never, in any universe every 33 years every 17 years off the scale

Three trillion years is 216 times the age of the universe. The S&P 500 produces days like that roughly once per presidential term. The single largest day in my sample is October 13, 2008, when SPY rose 14.52%. That is an 11.6-sigma move, and a bell curve gives it a waiting time of 8.6 x 1027 years. You would need to run 600 million billion universes end to end to expect it once. It happened on a Monday.

Bitcoin's worst day, March 12, 2020, was a 37% drop and a 13.3-sigma event. The Gaussian waiting time for that one has 37 digits in it. If your risk model produces a number like that and you keep using the model, the number is not the surprising part.

Now look at the dates of the six largest days in 33 years of SPY: October 13 2008, March 16 2020, October 28 2008, October 15 2008, March 12 2020, April 9 2025. Five of the six arrive in two tight clusters. Whatever generates extreme days is clearly not rolling independent dice, and that turns out to be a second mechanism worth understanding on its own.

Why fat tails exist at all

So markets are wild. The interesting question is why. It would be easy to assume the answer is "because news is unpredictable", but that gets the shape wrong. Unpredictable news arriving at random gives you a bell curve, by the central limit theorem. Something else is going on.

In 1987 three physicists at Brookhaven found the mechanism, and they found it in a pile of sand. Bak, Tang and Wiesenfeld dropped grains one at a time onto a pile and measured the slides. Most grains did nothing at all. Some caused a small slip. Occasionally one grain took half the mountain down. The size distribution of those slides was a power law, and the striking part was that nobody tuned anything. The pile organised itself into a state where a single grain could cause any size of collapse. They called it self-organised criticality.

The forest fire version is even easier to feel. Trees grow at random. Lightning strikes at random. When the forest is sparse, a strike burns one tree and stops, because there is nothing nearby to catch. So the forest keeps thickening. At some density the trees connect up, and then a single strike can cross the entire map. The forest does not settle at a comfortable density. It settles exactly at the edge, because that is where growth and fire balance.

Visual 03  /  The Avalanche Machine
Two rules only. Trees grow in empty cells at random. Lightning hits a random cell and burns every tree connected to it. Nothing in here knows what a power law is. Watch the histogram on the right straighten into a line.
chance per empty cell, per step
rarer lightning = bigger fires
simulation steps per frame
Forest
density
0%
Fires
recorded
0
Largest fire
share of map
0%
Measured
tail index α
Give it twenty seconds. Two things happen without being asked. The density readout stops moving, because the forest parks itself at the critical point. And the histogram becomes a straight line across three decades, with a measured exponent around 1.3, which means most fires are a few cells and the total area burned is dominated by a handful of monsters. Turn lightning down to make the fires rarer and larger.

The same distribution shows up in earthquakes, where it is old enough to have a name. Gutenberg and Richter published it in 1944: for every magnitude 7 quake there are roughly ten magnitude 6s and a hundred magnitude 5s. Stress accumulates slowly along a fault, and the release comes in a spectrum of sizes with no characteristic scale. Nobody asks what a quake's "average" size is, because the question is not useful.

Markets have every ingredient. The slow buildup is leverage, crowded positions, correlated bets and rising confidence. The spark is whatever it happens to be that week. The connections are margin calls, stop losses, redemption requests and risk models that all say sell at the same moment. When a market falls 20% in a day, you are not looking at 20% worth of news. You are looking at a forest that was ready.

Events that breed

There is a second mechanism, and it is about timing rather than size. Earthquakes come with aftershocks. One event raises the probability of the next one, which raises the probability of the one after that. Alan Hawkes wrote the math for this in 1971, and his self-exciting process is now standard equipment in seismology, epidemiology, neuroscience and market microstructure.

The controlling number is the branching ratio. It is the average number of direct children each event produces. Below 1, every burst eventually dies out. At exactly 1, bursts sustain themselves indefinitely. Above 1 the system runs away. It is the same quantity epidemiologists call R nought, which is why the shape of a viral outbreak and the shape of a volatility cluster are cousins.

I fitted this to Bitcoin's extreme days. The branching ratio came out at 0.59. Read that as follows: of Bitcoin's violent days, roughly 59% are statistically the echo of previous violent days rather than the arrival of fresh information. The market is talking to itself more than half the time.

Visual 04  /  Echoes
Top lane is a self-exciting process, where each event makes the next more likely. Bottom lane is plain randomness tuned to produce exactly the same number of events on average. Same count, same long-run rate. Only the clumping differs.
0.59 is what I measured on Bitcoin. Try 0.9
how long each event stays contagious
Self-exciting
worst cluster
0
Plain random
worst cluster
0
Self-exciting
longest quiet
0
Plain random
longest quiet
0
Events
so far
0 / 0
Both lanes are tuned to the same long-run event rate, so anything that only counts events will call them equally risky. The top lane is the one that bankrupts you, because its events arrive together, and it pays for that with long stretches of calm that feel like safety. Watch the two "worst cluster" numbers instead of the totals.

This is why volatility clusters, and why "it has been quiet for a while" is not information about tomorrow. The quiet stretches in the top lane are not the system being safe. They are the system between bursts, and they are longer precisely because the events got packed together elsewhere.

From fascination to a spreadsheet

Reading about this is one thing. I wanted to know whether it held up in data I had fetched myself, on assets I could actually trade. So I built a research tool and made one rule for myself before starting: every parameter goes into a locked JSON file first, and I am not allowed to touch it after seeing results. Backtesting without that rule is a machine for generating flattering nonsense.

The dataset

  • 186 Coinbase USD pairs, daily bars, July 2020 to January 2026, filtered for at least 800 bars and $50k median daily volume.
  • 180 liquid US stocks plus SPY, daily, adjusted, July 2020 to August 2026.
  • SPY back to February 1993, which is 8,437 daily returns, plus VIX over the same window.
  • Bitcoin back to September 2014, 4,343 daily returns.
  • Every bar cross-checked against a second independent source before any of this ran, at 0.9975 daily return correlation. That check caught a field-order bug in my own ingest that had swapped the open and the low on 98% of my crypto bars.

The result was unambiguous, and slightly funnier than I expected. Here is every asset I measured, each one placed on the ruler by its own tail index:

Visual 05  /  The Census
One dot per asset, 366 of them, positioned by measured α. Lower means wilder. The dots stack up where assets pile onto the same value, so the shape of each row is the shape of that market's risk. Hover or tap a dot to see which asset it is.
α below 2, no stable volatility (177 assets) the cubic band (189 assets) thin enough for a bell curve (none)
Median
crypto α
1.70
Median
stocks α
2.25
Wildest
asset
0.99
Thin tailed
assets found
0 / 366
The interesting part of this chart is the empty half. Not one of the 366 assets reached even α = 3, and 177 of them sat below 2, where volatility has no stable value at all. Stocks are better behaved than crypto by a clear margin and still land nowhere near the region their own risk models assume. Bitcoin, at 1.99, is one of the tamer things on the exchange. These are right-tail measurements over the window every asset shares, which is why Bitcoin reads 1.99 here and 3.05 in the tail plot further up, where it gets its full history and both tails.

Two more numbers came out of the same run, and they are the ones that changed how I think about waiting for a crash.

Bitcoin contagion  /  Hawkes branching ratio
0.59
0  independent events 1.0  runaway
Roughly 59% of extreme days are echoes of earlier extreme days rather than fresh news. Below 1 the process eventually calms down. Above 1 it never does.
Trend persistence  /  share of assets above random walk
76%
Crypto 76%
Stocks 24%
Three quarters of crypto pairs showed mild persistence by detrended fluctuation analysis, against about a quarter of stocks. This was the one place crypto looked more tradeable than equities.

One hypothesis died here, which I am recording because a research note that only reports confirmations is a sales brochure. I expected preferential attachment, the rich-get-richer effect that generates power laws in network sizes, to show up as trailing winners continuing to win. It did the opposite. The top decile of trailing performers had negative mean forward returns at both 20 and 60 day lookbacks. Whatever produces fat tails in crypto prices, momentum ranking is not the way to harvest it.

Three ideas, three answers

The premise held everywhere I looked, so the obvious next move was to turn it into money. If returns are power-law distributed, then a handful of trades should carry everything, and the textbook response is to cut losers fast and let winners run. That is a Donchian breakout, and it is roughly what trend followers have done since the 1970s.

Attempt 1: ride the winners

Buy 40-day breakouts, trail a stop at the 10-day low, risk 1% of equity per position, and only trade when the index is above its 200-day average. The power-law signature showed up exactly as predicted: a 24.7% win rate on crypto and profits concentrated in a few positions. One Zcash trade carried a large share of the entire crypto result, which is the distribution doing precisely what section I said it would do, in my own account statement.

It made money. It also lost badly to doing nothing. Crypto daily came out around 5.4% a year after realistic Coinbase taker fees of 60 basis points per side, against roughly 50% a year for simply holding Bitcoin over the same window. Stocks came out at 6.7% a year against 17.7% for holding SPY. The weekly version was a net loser at every fee tier I tested.

Attempt 2: short the cascades

This was the idea I was most excited about, because it follows directly from the forest fire. If crashes are avalanches, find the dry forest. I built a three-step fragility ladder: price below its 200-day average, then also below a falling 50-day average, then a shock day of at least 1.5 sigma on top. The third rung fires on only 1.8% of days.

As a crash detector it works. The probability of a 10% or worse drop over the next 15 trading days goes from 1.2% unconditionally to 5.3% when the ladder is fully armed. Over 30 days it goes from 3.0% to 11.2%. That is a real, sizeable, four-fold lift in tail risk, measured out of sample against a locked definition.

As a short signal it is a disaster. The mean forward 15-day return when fully armed is +1.11%, which is higher than the +0.69% unconditional average. Fragility makes the distribution wider in both directions, and the right side is where the rebounds live. Shorting it lost money in both markets and finished in the bottom decile against 500 random-timing placebo campaigns matched on trade count and holding period. On SPY the sleeve scored at the 7.2nd percentile of random. On Bitcoin, the 2.6th.

Being right about the tail and wrong about the middle is still being wrong. The gates found the risk correctly and the risk was symmetric.

Attempt 3: buy the insurance instead

If you know a crash is more likely but not which direction the median goes, the correct instrument is an option. You cap the loss at the premium and keep the convexity. So I priced 21-day puts on SPY using VIX as the implied volatility input, with a skew adjustment, and measured what came back per dollar spent.

Buying blind returned 0.57 per dollar of premium. Buying only when the ladder was armed improved that to 0.76. Both are below 1, so both lose money over time. The reason is written into the pricing: VIX averages 19.5 across the sample and about 30 on armed days. The option market can see the dry forest as clearly as my gates can, and it charges for the view.

There is also a timing problem worth stating plainly. The ladder needs a 200-day average break to arm, which makes it a confirmation tool. It armed 44 trading days after the March 2000 peak, and 27 days after the October 2007 peak. It caught 2011 and 2020 within 7 days, because those crashes were fast. Slow bear markets are already well underway before it notices.

The scoreboard

What I tried Result Benchmark Verdict
Measure the tails
366 assets
0 thin-tailed
median α 1.70 crypto, 2.25 stocks
Bell curve CONFIRMED
Crash detection
fragility ladder, SPY
P(−10% in 15d) 1.2% → 5.3% Unconditional base rate CONFIRMED
Long breakouts
crypto daily, 227 trades
5.4% a year BTC hold: ~50% LOST TO DOING NOTHING
Long breakouts
stocks daily, 195 trades
6.7% a year SPY hold: 17.7% LOST TO DOING NOTHING
Short the cascade
SPY, 62 trades
−$4.5k, 39% hit rate 7.2nd percentile vs random REJECTED
Short the cascade
Bitcoin, 41 trades
−$4.6k, 32% hit rate 2.6th percentile vs random REJECTED
Buy puts when armed
SPY, VIX-priced 21d
0.76 back per $1 1.00 = breakeven REJECTED
Sell puts, scale by fragility
SPY, 401 trades
0.49% a year SPY hold: 10.9% WORKS, NOT WORTH IT
Momentum ranking
trailing winners, crypto
negative forward returns Preferential attachment HYPOTHESIS DIED

The last one deserves a note. Selling insurance rather than buying it is the historically paid side of this trade, and it did produce a positive return across 401 positions. It produced 0.49% a year with a 5.4% maximum drawdown, which is a savings account with homework and a short position in the exact tail this whole project exists to respect. Scaling the size by my fragility gates helped in 2008 and hurt in 2020, and went slightly negative on a 2019-onward holdout. I am not going to pretend that is a strategy.

Standard caveats, because they matter: the crypto universe has total survivorship bias since delisted pairs are absent from my database, the stock list is today's index membership rather than point-in-time, idle cash earns nothing in my backtest, and the options work uses VIX as a proxy for a real chain. Each of those flatters the results rather than harming them.

What the ruler is good for

I went looking for an edge and came back with a ruler. That is a worse outcome commercially and a better one intellectually, so here is what the ruler is good for.

Position sizing is where fat tails actually pay you. If α is below 2, the volatility number in your risk system is not a property of the asset, it is a property of your sample length. Every risk limit derived from it should be read as a floor rather than an estimate. The practical version: assume the worst move you have seen is not the worst move you will see, and size so that it does not end you. Most blowups I have read about were not wrong about direction. They were correctly positioned and too large.

Anything you can see, the market can price. My fragility gates found real risk. VIX at 30 on those same days means the options market had found it too, and had already marked up the insurance to the point where buying it was a losing proposition. The gates still have a use as a reason to cut size, which costs nothing and does not require anyone to sell you a mispriced option.

The convexity was in the holding. Across every test I ran, on two asset classes and 33 years of index data, owning the fat-tailed thing beat every attempt I made to time it. Fat tails cut both ways, and the right tail of a market that trends upward is where the returns are. Every timing package I built spent some of its life in cash, and that is exactly the period the distribution rewards.

The honest summary

The mathematics is real, well established, and confirmed in every dataset I touched. Zero of 366 assets were thin-tailed. Crash probability genuinely quadruples when the fragility ladder arms. Bitcoin's extreme days genuinely breed more extreme days at a rate of 0.59.

None of that gave me a trading edge. Every strategy I built on top of it underperformed holding the asset, and two of them lost money outright. The gap between "this model describes reality" and "this model makes money" turned out to be the entire project.

What I would want before touching this again: real option chains rather than a VIX proxy, a point-in-time universe with delisted names included, and a pre-registered holdout that a strategy has to clear before I am allowed to like it. Until then, the useful output of two months of work is a ruler, a locked parameter file, and the knowledge that my worst day is still ahead of me.

Where this comes from

  • 1944Gutenberg & Richter, Frequency of Earthquakes in California. The original power law of catastrophe.
  • 1963Mandelbrot, The Variation of Certain Speculative Prices. The paper that told finance its bell curves were wrong, sixty years ago.
  • 1971Hawkes, Spectra of Some Self-Exciting and Mutually Exciting Point Processes. The branching ratio in Visual 04.
  • 1987Bak, Tang & Wiesenfeld, Self-Organized Criticality. The sandpile.
  • 1992Drossel & Schwabl, Self-Organized Critical Forest-Fire Model. The exact two rules running in Visual 03.
  • 1999Gopikrishnan, Plerou, Amaral, Meyer & Stanley, Scaling of the Distribution of Fluctuations of Financial Market Indices. The inverse cubic law my SPY measurement landed on.
  • 2007Taleb, The Black Swan. The height and wealth comparison in section I is his, and it is still the clearest way to explain the difference.
  • 2015Bacry, Mastromatteo & Muzy, Hawkes Processes in Finance. How branching ratios get fitted to real order flow.