What if a ransomware attack locks up a top global custodian's assets?
Ransomware freezing a top-three global custodian blocks redemptions, collateral, and corporate actions — a tail operational shock that forces broad de-risking as trillions in safekept assets go dark. Rhymes with the 2017 NotPetya hit on Maersk and the 2023 ICBC Financial Services ransomware that disrupted US Treasury settlement for days. Forward angle: custody is concentrated in BNY/State Street/JPM — a single-point cyber failure has no quick workaround; the cleanest hedge is long vol and gold, not directional credit.
Every number ships with its receipt — the odds, the range, the precedents, and a public grade at Reality Check. The statistical machinery that produces it is proprietary.
The butterfly cascade
How this trigger trickles across markets, left → right — the root shock, its first‑order moves, then the ripple effects. Drag any node; tap a market for its real price history.
Resolution timeline — how this probability is moving
Our model's odds (electric blue) over time vs the market's (Polymarket, amber), from the past toward the Tail risk horizon. Each dot is a real macro event that nudged the probability — green pushed it up, red pushed it down. Tap a dot for the source. Loading the probability audit trail…
What it would mean
If this plays out, it is a risk-off shock. A ransomware strike on a top-three global custodian freezes trillions in safekept assets, blocking redemptions, collateral, and corporate actions. The trigger decomposes into signed root‑shocks — Credit spreads ▲ · Financial conditions ▲ · Risk appetite ▼ — which propagate through our causal graph to the markets below.