A trading desk choosing a venue, or a compliance officer answering a regulator's questionnaire, usually gets the same non-answer: "we have surveillance." The questions that matter are narrower. What patterns is the venue looking for, on what data, and who is watching the watcher? The abusive patterns are named in rulebooks and statute; the detection methods are not equally rigorous; and onchain data answers a smaller question than most counterparties assume.

The patterns surveillance is built to catch

Every major regime names roughly the same conduct under slightly different labels. Four patterns cover most of it.

Wash trading

Wash trading is self-dealing, or coordinated dealing between related parties, that creates the appearance of volume or price discovery where none exists. It is distinct from, though it sometimes runs alongside, the paid market-making arrangements covered separately on this site, where the issue is disclosure of compensation rather than fabricated volume. On 9 October 2024 the US Attorney's Office for the District of Massachusetts announced charges against eighteen individuals and entities, among them the firms Gotbit, ZM Quant, CLS Global and MyTrade, following an operation in which the FBI created its own token, NexFundAI, and agents posed as its promoters. The SEC filed a parallel civil action the same day against three of those firms and nine individuals, alleging trading bots that "generated quadrillions of transactions and billions of dollars of artificial trading volume each day" with no economic purpose. Those are allegations and settlements involving those specific parties, and carry no implication about any other firm.

Spoofing and layering

Spoofing places orders with no intention of executing them, to move the visible order book, then cancels them once the price has moved. Layering does the same with a stack of orders at multiple price levels. Both are named directly in venue rulebooks: Coinbase's published trading rules define market manipulation to include front-running, wash trading, spoofing, layering, churning and quote stuffing. The mechanics are the same as in equities and futures, which is why the CFTC's long-running spoofing docket in traditional derivatives remains the closest analogue for how a crypto derivatives venue is expected to detect the pattern.

Ramping

Ramping, sometimes called price positioning, is a sequence of aggressive orders designed to push a thinly traded instrument through several price levels quickly, creating a false impression of demand that other participants, or their algorithms, follow. It sits inside the broader category of market manipulation that both MiCA's Title VI and the FCA's proposed cryptoasset regime prohibit, rather than being a separately named offence, and it is most visible in low-liquidity tokens around a listing or a promotional push.

Insider dealing on listings and unpublished information

The clearest crypto precedent so far concerns a venue's own employee rather than a token issuer. In July 2022 the SEC and the Department of Justice charged a former Coinbase product manager, his brother and an associate with trading ahead of Coinbase's listing announcements between June 2021 and April 2022, for alleged gains of more than $1.1 million. The case matters because it is not about a token's fundamentals. It is about who inside a venue knows a listing decision before the market does, and what they do with it.

How a venue actually detects these patterns

Detection is order-book and account-level analysis, not blockchain analysis. A surveillance system ingests every order, cancellation, modification and execution, tags accounts and, where it can, beneficial owners, and runs pattern logic across linked accounts and linked venues: rapid layering in a thin book, correlated buying and selling between related accounts, order-to-trade ratios that spike inside a specific announcement window. Vendors selling into this market describe the same shape of problem. Solidus Labs markets cross-venue detection of "cross-product spoofing, price pressure, and latency arb" across spot, derivatives, onchain and offchain markets, which should be read as a vendor describing its own product rather than as evidence of what any particular exchange runs. The raw material is trading activity, and the hard part is linking accounts that are deliberately kept looking unrelated.

What onchain data adds, and what it does not

Institutions that ask whether you cannot simply look at the chain are asking the wrong question for most of these patterns. As this site has set out in detail, a block explorer reliably shows that a quantity of an asset moved between addresses with a valid signature. It does not reliably show who controls those addresses. A July 2026 evaluation of the multi-input heuristic, the clustering method most widely used to turn Bitcoin addresses into "entities", tested it against ground-truth address-to-entity mappings supplied by European crypto-asset service providers: dataset-level recall was 0.71, but measures assessing the full clusters returned precision of 0.36 and recall of 0.44, with near-complete failure for some services. For wash trading or layering run through related but unlinked accounts, that is exactly the gap that matters. Onchain data can suggest coordinated movement, but confirming common control still needs off-chain evidence, such as identity records or exchange account linkage, that the venue or the regulator holds.

Onchain data earns its place elsewhere: tracing where proceeds went once manipulation is established, and corroborating a pattern where accounts are already suspected. The EU rules treat the two as complementary rather than alternative. The technical standards under MiCA require monitoring of orders and transactions whether conducted on-chain or off-chain, and monitoring of the functioning of the distributed ledger itself, including consensus mechanisms.

Three different things called "surveillance"

Counterparties often collapse three distinct functions into one word.

A venue's own surveillance is the platform's internal monitoring of the orders and accounts on its own book, run because its rulebook and licence require it, and reported to its own compliance function and, where a suspicion arises, to a regulator.

A shared utility pools order or trade data across several venues to catch patterns that never surface on a single book, such as an actor wash trading the same instrument on several platforms at once. Solidus Labs has described building a multi-exchange data consortium for that purpose. A shared utility widens what any single venue can see, but it depends entirely on which venues join and what they agree to share, so the question to ask is which venues are actually in the pool, not whether the product exists.

A regulator's own monitoring is independent of what a venue chooses to report. It includes market data, blockchain forensics tools bought from vendors, and a formal reporting channel. In the EU that channel is Article 92 of MiCA, which requires persons professionally arranging or executing transactions in crypto-assets to monitor for market abuse and report a reasonable suspicion to their national competent authority, on a template set out in the technical standards. These three layers do not automatically talk to each other, and a venue passing its own surveillance audit says nothing about whether it participates in a shared utility, or how a regulator would detect the same conduct independently.

The obligations by regime, and their actual status

Status matters more than headline dates here. A rule adopted is not a rule in force, and the permissions side of the same picture is set out separately on this site.

IOSCO published eighteen policy recommendations for crypto and digital asset markets as a final report on 16 November 2023. Recommendation 9 states that market surveillance for crypto-asset markets should provide a level of protection similar to traditional markets, and that surveillance requirements should be instituted to detect and report suspicious transactions whether on-chain or off-chain. Status: recommendations to national regulators, not law in any jurisdiction on their own.

In the EU, MiCA's Title VI market abuse regime, covering insider dealing, unlawful disclosure of inside information and market manipulation in crypto-assets, applied from 30 December 2024. Commission Delegated Regulation (EU) 2025/885, the technical standards under Article 92, was published in the Official Journal on 22 August 2025 and entered into force on 9 September 2025. It requires documented monitoring arrangements proportionate to the business, human analysis alongside automated alerting, five-year records of both the analysis and the reasons for filing or withholding a report, regular staff training, and annual audit. ESMA published its final report on guidelines for competent authorities on preventing and detecting market abuse under MiCA on 20 March 2025. Status: in force.

In the UK, the FCA consulted on a dedicated Market Abuse Regime for Cryptoassets, MARC, in CP25/41, published on 16 December 2025 and closing on 12 February 2026, and set out final rules in policy statement PS26/9 on 30 June 2026. Firms may apply for authorisation between 30 September 2026 and 28 February 2027, and the authorisation requirement itself comes into force on 25 October 2027. Status: adopted, not yet applying. A UK venue today therefore operates ahead of any dedicated statutory market abuse regime for cryptoassets.

In the US there is no single crypto-specific market abuse statute. Enforcement runs through existing securities and commodities fraud law, case by case. The October 2024 action against the market-making firms addressed wash trading sold as a service to token issuers; the 2022 Coinbase listings case addressed insider dealing on a venue's own listing decisions. Status: case-by-case enforcement under general fraud and manipulation law, not a codified crypto market abuse regime.

Self-regulating venues sit alongside all of this. CME Group's Market Regulation department conducts trade, position, account and market surveillance across its four designated contract markets, which are CFTC-registered and carry self-regulatory responsibilities, and each of those rulebooks contains rules against abusive trade practices. Its crypto futures sit inside that same structure. That is a venue obligation on top of CFTC oversight, not instead of it.

What to ask a venue to evidence

Diligence here is a matter of separating claims from evidence. A short list is enough to tell them apart.

  • The rulebook provisions that name wash trading, spoofing, layering and manipulation, rather than a marketing description of "surveillance".
  • Whether surveillance runs on the venue's own trading data alone or through a cross-venue utility, and which other venues are in that pool.
  • What off-chain identity data backs any onchain attribution the venue relies on, since clustering alone cannot establish common control.
  • Which regulator receives its suspicious activity reports, under which regime, and from what date that regime has actually been in force rather than adopted or consulted on.
  • How it monitors and discloses employee access to non-public listing decisions, since that channel, not a token's public trading, is what the 2022 Coinbase case turned on.

None of this is tax, legal, accounting or investment advice. A specific venue relationship should be assessed with counsel who can read the actual rulebook and licence conditions rather than the public description of them.