· via dev.to (home feed)
Knight Capital lost $440M in 45 minutes because one server missed a deploy
A dev.to retelling of the SEC's Knight Capital order traces how a manual deploy that reached seven of eight servers let long-dead 2003 code fire off millions of errant trades.

On August 1, 2012, market-making firm Knight Capital lost roughly $440 million in about 45 minutes of trading. A dev.to retrospective, built on the SEC's 2013 enforcement order against the firm (Release No. 34-70694), walks through how it happened: no intrusion, no rogue trader, just old software that was never removed, a manually run deployment that missed a machine, and a stream of warnings nobody was reading.
The router at the center
According to the account, Knight handled roughly a tenth of all trading in US-listed stocks during 2011 and 2012. A core piece of its infrastructure was SMARS, an automated router that took large "parent" orders, split them into smaller "child" orders, and dispatched those to exchanges. A counter inside SMARS tracked cumulative fills and signaled when a parent order was complete and child orders should stop. That counter matters to everything that follows.
Retired code that never left
SMARS contained a legacy capability called Power Peg, which Knight had stopped using in 2003 without deleting the code. In 2005 the fill counter was relocated to a different part of the codebase; Power Peg was never retested afterward, so it no longer knew where to look to determine that an order was finished. When the NYSE launched a new retail program effective August 1, 2012, Knight wrote new SMARS code for it. Rather than introducing a fresh flag to activate the feature, the developers reused the flag that had once triggered Power Peg, on the assumption that the old code would be replaced everywhere.
A manual deploy that missed a machine
Beginning July 27, 2012, a technician copied the new code onto SMARS' eight servers by hand, spread over several days. Seven servers received it; the eighth did not, and kept running the version with Power Peg. The dev.to piece notes that no second person reviewed the deployment, and that the SMARS team, unlike other groups at Knight, had no written procedure requiring one.
97 messages with no reader
From 8:01 a.m., before the open, a Knight system began emailing a group of employees about SMARS orders tagged with the error "Power Peg disabled." By 9:30 a.m. it had sent 97 of them. They were not designed as actionable alerts, and per the SEC record cited in the article nobody generally read them, even though they named the exact fault.
45 minutes of runaway orders
When trading opened, customer orders arrived carrying the reused flag. The seven updated servers executed the new retail code correctly. The eighth invoked Power Peg, whose counter check failed, so it kept emitting child orders regardless of fills. Other parts of Knight's setup knew the parent orders were complete, but that information never fed back into SMARS. The result, per the article: 212 customer orders turned into roughly 4 million executions across 154 stocks, totaling more than 397 million shares. Staff could see a position piling up past a $2 million account limit in a risk tool, but the tool only displayed numbers to humans. It was not connected to the order system, raised no automated alarm, and could not cut anything off.
The rollback that spread the bug
Engineers concluded the new code was at fault and removed it from the seven servers where it was working. Orders still carried the reused flag, so all eight servers then woke Power Peg.
The bill
By the time it stopped, Knight held about $3.5 billion in stock it had never intended to buy and had sold roughly $3.15 billion it did not own. The firm initially estimated the damage at $440 million; the SEC later put it above $460 million. In 37 stocks, prices moved more than 10 percent with Knight doing most of the volume. Investors injected $400 million five days later to keep the firm alive, it merged with a rival within a year, and the SEC fined it $12 million for lacking the risk controls required under its market access rule.
Why it matters
The story endures because no single decision looked reckless on the day it was made, and that is the uncomfortable part. The lessons the article draws apply to any production system, well beyond finance. Delete dead code, because disabled code is still callable. Never reuse a flag across features, since old paths become reachable in ways nobody is thinking about. Automate deployments and have every instance report the version it runs, so an eighth server cannot hide. Build the kill switch before you need it, because stopping machine-speed damage should not depend on first understanding the bug. And treat an alert nobody reads as noise, because 97 ignored messages drowned out the one signal that mattered.
- #deployment
- #incident-postmortem
- #legacy-code
- #trading-systems
- #software