Append-only record

The kill ledger

This is where the things that did not work are written down. A hypothesis the data refused, a measurement that failed its own completeness bar, a claim whose artifact went missing, an article whose finding did not survive — each one is recorded here, with the same visibility the registration had.Four entries stand in the ledger. They come from the engine’s own hypothesis registry — the instrument-building research programme, pre-registered before any test ran — and each was killed by criteria written down before the answer was known. The site’s own measurement programme, the Observatory battery, has registered nothing yet, so its side of this ledger is still empty; that distinction is kept explicit below rather than blurred into one comfortable number.

Ledger status4 ENTRIES
  • Engine-registry kills recorded here4
  • Registry denominator they report against19
  • Observatory pre-registrations postedNOT YET PUBLISHED
  • Observatory measurements publishedNOT YET PUBLISHED

The three lower rows are the upstream corpus, and they read the same on the methodology page for the same reason. The top row is this page’s own state: four engine-registry kills, listed below in full against a denominator of nineteen — and the two rows still reading NOT YET PUBLISHED are facts about the work rather than a stage of loading.

A research operation with no kill ledger is claiming a 100% hit rate

Nobody has a 100% hit rate. What a research operation without a kill ledger actually has is a record of its survivors, and a record of survivors is indistinguishable from a record of everything — which is precisely why it gets published in place of one.

The cost is not reputational, it is arithmetic. Every correction for multiple testing — the probability of backtest overfitting, the deflated Sharpe ratio — conditions on the number of things that were tried, and every one of them degrades into false reassurance when that number is understated. It is always understated, because memory is the default ledger and memory deletes failures preferentially. The sweep run and abandoned in an afternoon, the notebook deleted because it “didn’t work”, the thirty-second sanity check that was statistically a full trial: all of it vanishes, and what vanishes is exactly the denominator.

A kill ledger is not a sophisticated instrument. It is a timestamped list. The difficulty is behavioural — it is a record of one’s own failures, kept against one’s own incentive to forget them — which is why it so rarely exists, and why publishing the empty one first is the only version of this commitment that costs anything to make.

The term itself is defined in the glossary, alongside the discipline it pairs with: kill ledger and pre-registration. Registration records what a trial was supposed to be; this ledger records what became of it. Neither makes a result good. Together they make the evidence for it mean what it claims to mean.

FIG. 01MEASURED
A bracket labelled with the registry denominator spans four groups of cells: filled cells for hypotheses killed by their own criteria, outlined cells for those rejected at registration and never tested, dashed cells for those blocked on data that does not exist, and dimmed cells for those standing sealed. A note marks the successor that entered as a new entry, raising the denominator. Beneath, a timeline places each kill on the day it was recorded.

The denominator, accounted in full: nineteen registered, four killed by their own criteria, four rejected at registration and never tested, two blocked on data that does not exist, nine standing sealed. The successor that entered as a new entry raised the denominator rather than widening a dead one.

Accounting for the denominator establishes what was tried. It does not make any surviving hypothesis more likely to be true.

Sourcekill-ledger.json — the register, exported and hashedSHA-256Artifact digest, shortened for display:fcb4bdcf87…62a502VerifyDate2026-08-30

The figure's numbers, as a table. Both derive from the same exported register the digest above names.

Registry stateCount
KilledBy their own registered criteria4
Rejected at registrationNever tested, still counted4
BlockedOn data that does not exist2
StandingSealed until each returns a verdict9
Registry denominator19

What gets killed

Four classes of object can die into this ledger. The list is closed on purpose: a ledger whose scope is vague can absorb anything, which in practice means it absorbs the convenient things and nothing else.

  • A registered hypothesis the data refused. The ordinary case. A hypothesis was declared in advance with the result that would count as failure, the test ran, and the failure arrived. The hypothesis dies and the entry records it — including where the failure was uninteresting, because an uninteresting failure is still a trial and still counts against the denominator.
  • A pre-registered measurement that failed its completeness bar. Every registration fixes a minimum sample below which the honest null publishes instead of a number. Where the sample cannot reach that bar and no further collection will fix it, the measurement is killed rather than quietly re-run with a lower bar. Lowering a completeness bar after seeing the sample is not a repair; it is the thing the bar was set to prevent.
  • A claim that lost its artifact. A published number is only as good as the artifact it can be recomputed from. Where the artifact cannot be produced — lost, unreproducible, or never actually hashed — the claim comes off the site. It is not softened, not re-hedged, not left standing with a caveat. The claim dies and the entry says which artifact went missing.
  • An article whose finding did not survive. A research article whose finding is overturned — by later data, by a recomputation, or by someone else’s work — is retracted with the original text preserved verbatim, and the kill is appended beside it. The error stays readable above the correction, because a record that shows only the corrected version proves nothing about the process that corrected it.

What does not belong here

  • An honest null is not a kill. A measurement that ran correctly and returned “insufficient sample” or “no effect distinguishable from noise” is a result. It publishes as a result, on the receipt page that owns it, and recording it as a death would inflate this ledger with successes.
  • An amendment is not a kill. A registration corrected before data contact is appended to, with its original text intact and its reason stated. The hypothesis is still alive; only its declaration changed, visibly.
  • A rename, a refactor or a typo fix is not a kill. Nothing died. Padding a ledger of failures with clerical events is the same evasion as leaving it empty, performed with more effort.

The entry schema

Every entry carries the same five fields, in the same order:date · what was killed · the pre-registration it belonged to · why it died · what replaced it, if anything. No field is optional, and no field takes a blank — an absent successor is written as an absent successor.

date

The UTC date the kill was recorded — written at the moment of death, not reconstructed later for an audit.

A ledger assembled afterwards is a memoir. Contemporaneity is the whole difference between the two.

what_was_killed

The object that died, named precisely enough to look up: a hypothesis, a measurement, a published claim, or an article.

A kill described in general terms cannot be checked, and an admission nobody can check is not an admission.

registration

The pre-registration the dead object belonged to, cited by its reference so the kill can be read against what was declared.

Without the registration an entry is an anecdote. With it, the kill is legible against a promise made before the answer was known.

why_it_died

The reason, stated in the terms the registration fixed in advance: the threshold crossed, the completeness bar missed, the artifact that could not be produced.

A reason composed after the fact can be shaped to flatter. Quoting the registration is what stops that.

replaced_by

What took its place — or the explicit statement that nothing did.

“Nothing replaced it” is the most informative value this field takes, so it is written out rather than left blank.

Two rules govern the ledger

Append-only

An entry, once written, is never edited and never removed. If an entry is itself wrong, the correction is a new entry that names the entry it corrects, and the original stays where it is, readable, above the correction. A ledger that can be edited is a ledger of survivors with extra steps: the single capability that would make it worthless is the capability to take something out of it.

Visibility parity

A kill publishes exactly as loudly as the registration did. Same surface, same feed, same index, same prominence — if a hypothesis was registered on the research feed, its death goes out on the research feed. The asymmetry between how loudly a finding is announced and how quietly it is withdrawn is where most of the published record goes wrong, and parity is the only rule that closes it.

Both rules were written while the ledger was still empty and there was nothing yet to be tempted by. That ordering is deliberate: a rule published before the first entry binds; the same rule published after it is a description of whatever was already done.

The ledger

FIG. 02MEASURED
Two panels from one kill entry. A grid of parameter cells with the agreeing cells filled, stopping one short of the requirement marked on a tally beneath; beside it, a two-point plot of conditional intensity falling from its first published endpoint to its second as parameters tighten, joined by a dashed line labelled endpoints only.

How a hypothesis dies: one entry from the ledger below, rendered. The cluster-coherence filter fell one agreeing cell short of its pre-registered requirement, and the conditional intensity decayed monotonically as parameters tightened — the fingerprint the registration said would fail it. The working, in full, is row H-011.

Rendering a kill establishes how the criterion fired. Only the two published endpoints of the intensity decay are drawn; the dashed line between them asserts nothing about the path.

Sourcekill-ledger.json — the register, exported and hashedSHA-256Artifact digest, shortened for display:fcb4bdcf87…62a502VerifyDate2026-08-30

Six columns: date, what was killed, registration, recorded in, why it died, replaced by. Scroll sideways if they do not all fit.

The kill ledger: for each killed object, the date it was recorded, what was killed, the pre-registration it belonged to, why it died, and what replaced it. Four entries, all from the engine’s hypothesis registry.
DateWhat was killedRegistrationRecorded inWhy it diedReplaced by
2026-06-24S-001 — salience-zone retrodiction: do high-salience levels pre-mark the origination points of range-expansion days?S-001 · registered pre-data; this run was the corpus’s first data contact, which closed the registry’s amendment window permanentlyaccumulated-null-ledger.md row 11 — the registry seed still reads Status: REGISTERED for S-001Origination-level salience enrichment −0.042, 95% CI [−0.127, +0.042] — spans zero. The salience score failed its first retrodictive exam, by its own registered kill criterion.Nothing. The score’s prior weakened and the hypotheses that depend on it inherit that, reported rather than buried.
2026-06-24H-010 — HADEYS: do ADR-normalised liquidation-footprint zones predict behaviour on future revisits?H-010 · ◆ primary endpoint frozen at registration; evaluated against matched point-in-time control cohorts, walk-forwardaccumulated-null-ledger.md row 10 — the registry seed still reads Status: REGISTERED for H-010Revisit effect −63.5 raw price units vs matched controls, 95% CI [−146.40, +17.92] — spans zero across 3 event-count folds, at q = 0.05 against a registry denominator of 18.H-012, a tighter-footprint variant — registered as a NEW entry (raising the denominator to 19) rather than by widening the dead one. H-012 died too, and carries its own entry in this ledger.
2026-06-29H-011 — ACTIVE_DISLOCATION: wide spread with elevated quote rate at a breach as the signature of a structural liquidation trapH-011 · registered 2026-06-23 with ◆ designated; killed six days later by the pre-registered coherence machineryhypothesis-registry-seed.md — Status: KILLED (2026-06-29 forensic audit), Rev 3.0Failed the cluster-coherence filter: 7 of 12 adjacent parameter cells shared the primary’s sign and magnitude, against a required 8. Conditional trap intensity decayed monotonically (+0.83 → +0.27) as parameters tightened — the fingerprint of generic range-bound mean-reversion, not a structural trap. Killed on the conservative reading of single-pair evidence, which is the direction that only ever removes a thesis.Nothing. A successor may enter only as a new registered entry; the frozen sibling hypothesis stands registered and untested.
2026-07-23H-012 — HADEYS tighter footprint: shallower penetration with stronger reversal as a higher-confidence liquidation fingerprintH-012 · registered post-H-010 as a new entry; evaluated only on clean pairs — the EUR, GBP, CAD and CHF crosses were excluded as burnedhypothesis-registry-seed.md — Status: KILLED (2026-07-23), Rev 3.1The confidence interval spans zero on every clean pair evaluated — six of six (e.g. AUDUSD −2.5 [−92.5, +86.3]; NZDUSD +12.3 [−89.4, +114.7]). Tightening the footprint did not produce an edge.Nothing.

The receipts behind the rows

The evaluated kills trace to served, content-hashed result documents in the engine repository. The digests are printed here so the rows above are pinned to something a rewrite would break; the documents themselves publish with the data licence, which awaits ratification — a digest without its file is a promise, and it is stated as one.

  • a418dcee2a21e3232ccb03831eeb583af9f705daa673380bf2f72abf6394f1e7 — H-010 ◆ result document (effect −63.5, CI [−146.40, +17.92], 3 folds, q = 0.05, denominator 18).
  • 5ce7fad2ea2662a4ef1a6ea8b7e70757c8cbf4b462e89f194ca3e0ab844beac6 — S-001 validation result document (enrichment −0.042, CI [−0.127, +0.042]).
  • c9c9e4e0397330f2d852f49ae20f7bbc77a4b43e0d56af71d8d0f97d269b9e34 — the first-data-contact corpus artifact behind the S-001 run, the file whose evaluation closed the registry’s amendment window for good.

The denominator, accounted for in full

A kill count without its denominator is a marketing figure. The registry holds nineteen entries, and every one is accounted for here:

  • Four killed — the rows above, each by its own pre-declared criteria.
  • Four rejected at registration, never tested — and still counted. A sub-second sweep-velocity trigger, rejected because a conflated retail quote feed cannot support sub-second premises: its quote rate partially measures the broker’s conflation policy under load, not the market. Any premise requiring the broker-manipulation mechanism to be true, rejected as unfalsifiable with available data. Sweep-trigger-moment prediction, rejected in advance — the data that could support it does not exist in this corpus, and registering the rejection forecloses the idea being backfilled later under a different name. And dynamic latent-state hypothesis gating, rejected as silent recalibration formalised. Rejections sit in the denominator because deciding not to test something is also a decision made about the hypothesis space.
  • Two blocked on data that does not exist yet — one on a sentiment surface the current ingestion cannot carry, registered anyway, in the registry’s own words, “so nobody ‘finds’ sentiment data by relaxing provenance standards”; one on a second journaled venue feed not yet acquired.
  • Nine standing — seven registered hypotheses, one registered model and one descriptive study, frozen and awaiting their corpus gates. Their premises are sealed here until each returns a verdict: parameter grids and endpoints are timestamped in the registry, and publishing a live premise would be showing the market an experiment mid-run. The deal this ledger makes is the verdict and the premise together, whichever way it lands.

Two disciplines make those rows worth more than their count. Kills report against the registry denominator at the time of evaluation — 18 and 19 above, never the tests we liked — and dead entries stay in the file, so the denominator never shrinks when a hypothesis dies. And the burned-pair rule: the H-012 evaluation excluded every EUR, GBP, CAD and CHF cross because earlier exploration had touched that data. Contaminated pairs are excluded from evaluation forever, which is the burned-door lesson applied to data rather than to agents.

The Observatory side is still empty

The entries above are engine-registry kills — research that shaped the instruments. The site’s own measurement programme, the Observatory battery, has its own lifecycle and its own side of this ledger, and that side has no entries for the honest reason: nothing has been pre-registered on this site yet. Four things happen in order, and that side of the ledger cannot move before the first of them:

  1. A methodology is written, content-hashed and registered before any data is touched.
  2. Point-in-time data is collected and hashed at ingest.
  3. The registered battery runs against it, with no parameter changed after the fact.
  4. Something fails — and the failure is written here the day it happens.

Step one has not happened for the Observatory. No site-side pre-registration is posted, so that side of the ledger has nothing upstream of it to record. When the first battery registration publishes, it becomes capable of dying here too.

The engine entries above set the standard the Observatory now has to meet: its kills will publish with the same visibility as its registrations, against the same kind of honest denominator, and an operation that then never kills anything has said something about itself either way.

The registry that will produce these entries as a service — pre-registration, trial accounting, the ledger itself — is the Epistemic Harness. I am its first subject rather than its first customer, and the record of what it finds on me will be this page.

Cite This Article

Hadal Instruments. (2026). The Hadal kill ledger. Hadal Instruments. https://hadalinstruments.com/kill-ledger/ Version 6b8bb31, 2026-08-30.

Version 6b8bb31 identifies the commit that last changed this page in Hadal's content repository. That repository is not public, so the identifier does not resolve externally — it is published so a citation pins one specific state rather than a moving page. To obtain the exact version cited, use the press and research route. The ledger is this page plus its entry data, so its version is the most recent change across both — it moves when an entry is added even though the surrounding text is unchanged.