🔒 4 more in the full analysis
Receive retail stock orders from brokerages, split large orders into smaller orders, route them across the market to seek the best prices, fill the orders, and earn the spread.
Full plans for 1 idea. Inquire for details →
Searchable transcript of The most expensive software bug in history... — Fireship (05:19). Search for a phrase, then click its timestamp to jump straight to that moment in the video.
Captions sourced from the original video on YouTube, published by Fireship. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.
00:00 It seems like every week now we're seeing security incidents happening that would have made mainstream news just a few years ago. The big ones lately have been the North Korean hackers who Trojan horse taff the JavaScript ecosystem, the open AI model that committed a felony to get answers to a benchmark and that time Anthropic accidentally open source cloud code at 4 a.m.
00:17 via an npm source map. But sometimes it's good to remember that even before AI, the software has always been held together with duct tape and the poverty of open- source maintainers. And there's no better example of this than the damage one company managed to do to itself 14 years ago this month with organic human retardedness. In about 45 minutes on a random Wednesday, Night Capital, who at one time was responsible for 10% of all stock trading happening in the United States, a lost $440 million and 4 months later was
00:44 sold for parts. In today's video, we'll look into what caused the most expensive software bug in history, and learn how to lose $10 million in a minute with this one weird trick. It is August 27th, 2026, and you're watching the Code Report. In 2012, while the rest of us were planking on gas station roofs and awaiting the Mayan apocalypse, the Night Capital was quietly operating as the biggest market maker on Wall Street as it processed $20 billion in trades every day.
01:11 If you remember back to the GameStop, Robin Hood saga from a few years ago, Night Capital was basically the citadel of its time. Whenever an ape like you or me would buy a stock from a brokerage like Erade, that the brokerage didn't actually execute the trade themselves. Instead, they'd often pass it off to Knight, who would fill the order and pocket the spread.
01:26 At its core was a system called SM, which was an order router that took large orders and chop them up into smaller orders to fill them across the market at the best prices. It was fast, reliable, and more importantly, it printed money for over a decade. Then, in the summer of 2012, the New York Stock Exchange decided it was sick of watching firms like Knight ski off all the retail orders before they ever reached the actual exchange.
01:49 So, it created something called the retail liquidity program, which was essentially its own version of Knight's business model designed to get orders back with slightly better prices. The SEC approved it in June with a go live date of August 1st. And because Knight was ironically also one of the exchange's biggest customers, they were forced to implement it.
02:08 So, that's what they started to do. And like any large financial institution responsible for the livelihood of hardworking bluecollared Americans, they did it with dignity and grace. Just kidding. They did it in the most lazy way possible. At the time, deep in the SMARS codebase was an old feature flag that hadn't been used since 2003, but it was never deleted.
02:26 Flipping the flag would trigger a test function called power peg, which would execute a bunch of buy orders so Knight could watch how a stock's price would respond. And since the whole point was to push prices around, it was designed to buy aggressively at the current market price with zero concern for getting a good deal. But when the engineers in 2012 needed to switch on the new retail liquidity program rather than create a feature flag, they just reused the old power peg one and swapped out the logic behind it.
02:52 And they would have gotten away with it if this code was only running on a single server or if they had any DevOps on the team or if it hadn't been for those meddling kids in their dog. But I assume none of those were true. Back then, their deployment strategy took inspiration from the Pony Express and that they'd have a guy manually copy code changes to their eight servers across several days.
03:11 Unfortunately, while deploying the retail liquidity change, they hit one of the two hardest problems in computer science, and only seven out of the eight servers got the update. Then, on August 1st, 2012, when Knight flipped the feature flag, seven of their servers processed orders correctly, while the eighth one woke up Power Peg from its 9-year hibernation, and it got to work on its DGEN strategy of buying high and selling low.
03:32 Knight immediately noticed something was up, but as you can imagine, someone who gets themselves into the situation is unlikely to have a good way of getting themselves out of it. And so they panicked, assumed the problem was in their new code, and rolled back the seven healthy servers, which meant now all eight were running Power Peg. And to be honest, that feels like a suitable name for what the market was doing to them.
03:50 In the 45 minutes it took them to figure out the issue and flip the feature flag back, they had executed 4 million trades across 154 stocks and were now the proud owner of a new $7 billion position. And there was even a random penny stock called Wizard Software Corporation that went from $3 to $14 for no reason at all. When the dust settled, Knight was down over $440 million and its stock had dropped 75% in 2 days.
04:15 But 4 months later, it was acquired by its competitor, GitKo. And in 2017, another financial services firm called Virtue absorbed what was left. The good news, though, is that we definitely learned our lesson in the software industry, and nothing bad ever happened again. And that's why you need to know about Hyper Agent, the sponsor of today's video.
04:32 Maintaining a popular open- source date library is mostly just three people drowning in a thousand GitHub issues about daylight savings. So, my co-maintainers and I hired a team of agents to keep it alive. When a new issue comes in, one agent labels it and reproduces the bug, then hands it off to another that hunts down the fix and opens a draft pull request.
04:50 They work around the clock across every time zone we're asleep in and only ping a human when it's time to actually approve a merge. Every maintainer shares the same agents. So once you teach them how your project works, nobody has to teach them twice. And with support for DeepS and the top openweight model, even the AI maintaining your open source project can stay open source. Try it out and grab your free credits at the link below. This has been the code report. Thanks for watching and I will see you in the next one.