Skip to main content
A market order asks for immediate execution at whatever the book offers. Taken literally that is dangerous: in a thin or fast-moving book, “whatever the book offers” can be far from the price you saw. Intention does not submit market orders literally. Every market order is converted into a limit order with a protective price bound, computed at submission. It still takes liquidity immediately — but it stops at a price rather than sweeping through the book without limit.

Three bounds, strictest wins

The bound is the most conservative of three independently derived prices.
Your slippage tolerancebest ask × (1 + s) for a buy, best bid × (1 − s) for a sellDefaults to 10%, settable from 0.01% to 10%. The one you control.
The market’s price bandno order may rest or execute outside itProtects the market, not you — and rejects rather than lapsing if no index is available for the block.
The worst price your size would reachderived from the depth your order would actually consumeThe bound the quoted touch price does not show you.
The strictest of the three
The limit price actually submittedlowest of the three for a buy, highest for a sell
For a buy, the bound is the lowest of the three; for a sell, the highest. Each closes a different gap, and none of them is sufficient alone.

Your slippage tolerance

buy bound=best ask×(1+s)sell bound=best bid×(1−s)\text{buy bound} = \text{best ask} \times (1 + s) \qquad \text{sell bound} = \text{best bid} \times (1 - s) Tolerance defaults to 10% and can be set anywhere from 0.01% to 10%. This is the bound you control, and it expresses a simple instruction: do not fill me worse than this far from the touch.

The market’s price band

Every market enforces a band around its reference price, and no order may rest or execute outside it. This applies to market orders too — your tolerance cannot push a fill beyond what the market allows anyone. This is the bound that protects the market rather than you. Without it, a large market order into a vacuum could print a price that then feeds into other systems. The band is evaluated against both the mark and the index price, and a market that has a band configured will reject rather than fall back if no index is available for the block — a configured protection is not allowed to lapse silently. The width is per-market configuration, held as price_limit_ppm with a two-segment refinement in price_limit_x_ppm and price_limit_y_ppm. Read them from the contract specification rather than from this page.

A worked example

You submit a market buy for 4,000 USDC of ETH into this book: The engine walks down, spending until the budget is gone:
  • Level 1 takes 1,000, leaving 3,000
  • Level 2 takes 1,503, leaving 1,497
  • Level 3 has 2,008 available but only 1,497 is left, so it fills partially: 1,497 ÷ 50,200 = 0.0298207 ETH
You end with 0.0798207 ETH at an average of 50,112.30 — not the 50,000 at the top of the book. The difference is slippage, and it is a function of your size against this depth, not a fee. The bound the engine derives is the price at the deepest level it had to reach, which is what turns your market order into a limit order at that price.

The worst price your size would reach

Before submitting, the book is walked to the depth your order size would consume, and the price at the deepest level reached becomes a bound. This is the subtle one, and it addresses a case the other two miss. Your tolerance is measured from the touch, which says nothing about whether the book is deep enough to fill you anywhere near it. Walking the book to your actual size converts how far from the touch into where this specific order would actually end up.

What this means for you

Your order may not fully fill. If the book runs out of liquidity within the bound, the remainder is cancelled rather than filled at a worse price. A partial fill on a market order is the protection working, not a failure. A tighter tolerance means more unfilled orders. Setting 0.01% on a volatile market will frequently return partial fills or nothing at all. The default of 10% is loose because being unfilled is often worse than a few basis points of slippage — but it is loose, and in a thin market 10% is a real amount of money. Size matters more than tolerance. Because the third bound is derived from your size, a large order is bounded by the book’s actual depth regardless of how generous your tolerance is. Splitting a large order is the reliable way to reduce impact — see TWAP and Scale orders.
This conversion happens at submission, using the book as it stands then. Between submission and execution the book can move. The bound protects you from sweeping through depth that was never there; it does not freeze the market.

Checking before you submit

The bound is computable from public data, so a client can show you the expected fill price and the worst case before you commit. That is worth doing on any order large relative to the visible book — the difference between the touch and the worst reachable price is exactly the number a market order hides.
Slippage protection bounds the price, not the outcome. In a fast move, an order that would have filled comfortably can come back partially filled or empty, leaving you without the position you intended at the moment you most wanted it. Protective intent is better served by conditional orders with an explicit trigger than by market orders with a wide tolerance.

Where to go next

Order types

Limit orders, time-in-force, and what each does with an unfilled remainder.

Order book

Reading depth, and why the touch price is not the fill price.

TWAP

Splitting a large order across time to reduce impact.

Markets

Per-market price bands and tick sizes.