Resolution criteria
This market is conditional on a single cyber incident causing $15 billion (USD) or more in total economic damage to the United States. If no such incident occurs before December 31, 2030, this market will resolve to N/A.
To resolve this market, the following criteria must be met:
Damage Threshold: A single cyber incident (whether a malicious cyberattack or a systemic IT/software-induced failure) must result in an estimated $15B+ in U.S. economic damage. This figure will be determined based on official assessments from U.S. federal agencies (e.g., CISA, FBI, or DHS) or a consensus of reputable economic and cyber-risk modeling firms (e.g., Lloyd's, Swiss Re) reported by major financial news outlets (e.g., Bloomberg, Reuters, The Wall Street Journal).
Target Sector: The winning option will correspond to the primary target or initial vector of the compromise, categorized using the Cybersecurity and Infrastructure Security Agency (CISA) critical infrastructure sector classifications:
critical utilities (electric grid, water, oil/gas pipelines): Targets within the CISA Energy, Water and Wastewater Systems, or Dams sectors.
internet/telecom: Targets within the CISA Communications or Information Technology sectors.
financial system: Targets within the CISA Financial Services sector.
other (includes transportation & supply chain): Targets within any of the other 11 CISA critical infrastructure sectors (e.g., Transportation Systems, Healthcare and Public Health, Critical Manufacturing) or multi-sector supply chain compromises.
In the event of ambiguity regarding the primary target, the market creator will resolve the market based on the sector designated as the primary point of failure or compromise in official federal investigative reports.
Background
While major historical events like the 2021 Colonial Pipeline ransomware attack, the 2024 Change Healthcare breach, and the 2024 CrowdStrike IT outage caused significant operational halts, none individually crossed the $15 billion threshold in direct U.S. economic losses. However, cyber risk modeling continuously warns of systemic events—such as a prolonged cloud service provider failure, a coordinated attack on the healthcare sector, or deep compromises of the electric grid—that could easily exceed tens of billions of dollars in macroeconomic damages.
By framing the targets around CISA's 16 official critical infrastructure sectors, this market aims to objectively track where the most economically devastating vulnerabilities lie.