Identifying market manipulation in digital assets: why your surveillance stack was built for the wrong market
the UK Market Abuse Regulation (MAR) as onshored, the FCA's proposed market abuse regime for cryptoassets within the crypto roadmap (consultation stage, with the broader cryptoasset regulatory perimeter expected to go live in 2027), SYSC surveillance and systems-and-controls requirements, and the suspicious transaction and order reporting obligations under MAR 7A.
Legacy surveillance assumes stable identity, market hours, a few venues and familiar instruments — none of which hold in crypto. The systems most firms run were designed around four assumptions: that participants can be identified, that trading happens inside a defined day, that the number of venues stays manageable, and that instruments behave in ways decades of precedent have taught us to read. Crypto breaks all four. Participants sit behind wallet addresses, the market never closes, liquidity fragments across dozens of venues and into on-chain protocols with no order book at all, and some manipulation techniques have no equivalent in any market that came before. An equity-tuned stack misses key crypto typologies while the firm believes it has coverage.
Some crypto manipulation is the old playbook on a new venue, and these are the techniques a traditional surveillance team can extend to cover, given the effort.
Wash trading, trading with yourself to manufacture the look of volume and interest, is endemic in crypto for a structural reason. Many venues run weak identity checks, so operating dozens of accounts and trading between them all day costs almost nothing. In a regulated equity market, faking volume at scale is hard because the participants are known. On a crypto venue with thin know-your-customer controls, one actor runs the whole crowd. The signals are familiar to anyone who has done trade surveillance: buy and sell ratios that stay perfectly balanced over long stretches, trades clustering at price levels that ignore the wider market, volume that doesn’t move price the way real volume does. What’s harder is the scale and the anonymity, which make any of it difficult to pin on a single actor.
Spoofing and layering, placing orders you mean to cancel to fake supply or demand, have adapted to crypto’s 24/7, multi-venue structure. A manipulator shows large visible orders on a major exchange to move sentiment, then executes the real trade on a smaller venue, coordinating across platforms in a way single-venue surveillance cannot see. What defeats legacy tools is the 24/7, cross-venue structure the technique now runs on.
Pump-and-dump schemes found their natural home in crypto because the coordination infrastructure is built in. Organised groups on Telegram and Discord assemble thousands of members, often with tiered access: VIPs who paid for early entry get advance word of which token will be pumped and when. That tiering builds layered information asymmetry. The organisers and VIPs buy first, the wider group pumps the price, and the latecomers supply the exit liquidity. Social-media coordination has scaled up a long-standing scheme.
The harder category is manipulation that doesn’t exist in traditional markets at all, because it depends on how blockchains work. These typologies have no equity analogue, so an equity-tuned system won’t catch them.
Maximal extractable value, usually shortened to MEV, is manipulation at the level of how transactions get ordered into blocks. A traditional rulebook forbids a broker from jumping ahead of a client order. On a public blockchain, the validators who assemble transactions into blocks can, in many designs, order those transactions however they like to maximise their own profit. That opens the door to front-running, where a validator or a searcher sees a pending trade and places its own ahead of it; sandwich attacks, where orders go in both before and after a victim’s trade to capture the price movement it causes; and back-running, all of it executed at the consensus layer rather than on any exchange. This is manipulation built into the infrastructure itself, and catching it means watching the mempool, the pool of pending transactions, not an order book.
Flash loan attacks are unique to blockchain and have no direct equivalent in traditional finance. A flash loan lets an actor borrow an enormous, uncollateralised sum inside a single blockchain transaction, on the one condition that it’s repaid before that same transaction ends. An attacker borrows millions, uses the capital to move the price on a thin venue or to feed a false price into a protocol’s price oracle, profits from the distortion through some other protocol, and repays the loan, all atomically, in one transaction that either completes in full or reverts entirely. It has no traditional analogue — no collateral, no overnight risk. Detecting it means reading smart-contract interactions and oracle dependencies, which is a different discipline from trade surveillance.
Effective surveillance in digital assets comes from integrating three data streams that traditional surveillance never had to combine.
The first is on-chain intelligence. Because activity happens on public ledgers, a surveillance function can cluster wallet addresses to link accounts that look separate, track token flows between wallets and contracts, watch specific smart contracts for the patterns that precede an exploit, and monitor the mempool for the ordering behaviour that signals MEV extraction. None of this data exists in traditional markets, and it is the foundation of crypto surveillance rather than an add-on.
The second is off-chain analytics, the part that looks most like traditional surveillance: order book analysis, volume profiling, and above all cross-venue correlation, because so much crypto manipulation is coordinated across platforms that watching any single venue misses it. The third is external signals: monitoring social-media mentions, tracking the influencers and channels that drive pump-and-dump coordination, and correlating news and social activity against price and volume moves. A pump-and-dump shows up in social data before it’s obvious in the price, so surveillance that ignores the social layer misses the lead signal.
How mature a surveillance capability is comes down to how deep that integration runs. At the foundational stage, a firm runs basic trade surveillance, some on-chain monitoring, and social alerts as separate streams. A more sophisticated one correlates across venues, applies machine learning to recognise manipulative behaviour patterns, watches the mempool for MEV, and manages its alerts in one place. An advanced one maps networks of related manipulators, uses predictive analytics, and tests its own detection against simulated attacks. Most firms entering this space are at the foundational stage; the FCA’s roadmap points to higher expectations.
Detection is only half the obligation. Under MAR, firms that arrange or execute transactions have to identify and report suspicious orders and transactions through suspicious transaction and order reports, and the crypto regime will carry an equivalent expectation into digital assets. So a surveillance function isn’t finished when it produces an alert. It needs a workflow that turns alerts into decisions and, where warranted, into reports the regulator can act on.
A credible workflow runs in stages. Initial triage filters the noise, because crypto surveillance throws off a high volume of alerts and most are benign volatility. Context gathering pulls the on-chain, off-chain and social data together for the flagged event, so the analyst looks at the whole picture rather than one venue. Pattern analysis tests the event against known manipulation typologies. Cross-source correlation is usually where a genuine case is made or dismissed, because, as the worked example below shows, the proof tends to live in the combination rather than any single stream. Documentation matters as much as detection: a suspicion recorded without its supporting evidence is one the firm can’t later defend having held, or having reported. Where manipulation is confirmed or strongly suspected, the firm needs escalation protocols covering any trading response, the regulatory report, and a feedback loop that sharpens the detection rules so the same pattern surfaces faster next time.
A tool without an investigation workflow leaves the alert as the output, which isn’t enough. The obligation runs to the investigation decisions, reports and audit trail, not just the alert. A surveillance capability with no documented investigation and escalation workflow produces warnings that no one has been made responsible for acting on.
There is a governance dimension to crypto manipulation that traditional market abuse work tends to understate. The firm isn’t only a potential detector of manipulation. It can be an unwitting participant in it, or its direct victim. A firm that provides liquidity, executes client orders, or runs trading strategies on-chain can find its own activity used as the exit liquidity in a pump-and-dump, its trades sandwiched by MEV extractors, or its smart-contract interactions drained by a flash loan attack. Those aren’t abstract market-integrity concerns. They’re direct financial and conduct risks to the firm and its clients.
This is why the risk-management and surveillance obligations under SYSC aren’t only about spotting other people’s manipulation. They are about understanding the firm’s own exposure as a victim, and making sure the firm’s own activity could never be read as taking part in it. A firm running automated strategies on public blockchains has to know whether those strategies could front-run others, whether they lean on price oracles that could be manipulated against it, and whether its execution patterns could be exploited. The board’s question isn’t only whether we can detect manipulation in the market. It is whether our own activity could be the manipulation, or the thing being manipulated, and whether we would know. In a market this new, most firms haven’t yet looked, and looking is part of the preparation the incoming regime demands.
Where each technique surfaces, whether it has a traditional analogue, and the data you need to see it.
| Technique | Traditional parallel? | Primary detection data | Key signal |
|---|---|---|---|
| Wash trading | Yes, amplified by anonymity | On-chain plus order book | Balanced buy/sell, volume that doesn’t move price |
| Spoofing / layering | Yes, now cross-venue | Cross-venue order book | Large visible orders cancelled, execution elsewhere |
| Pump-and-dump | Yes, socially industrialised | Social signals plus price/volume | Coordinated social spike before a price ramp |
| MEV / transaction ordering | No | Mempool / on-chain | Front-run, sandwich and back-run patterns in blocks |
| Flash loan attack | No | Smart contract plus oracle data | Large atomic borrow, price/oracle distortion, repay |
Take a thinly traded token that spikes 40 percent in an hour and gives most of it back by the end of the day. A legacy surveillance system flags the price move and the volume, raises an alert, and an analyst opens the exchange data, sees heavy two-way trading, finds nothing conclusive, and closes it. On the venue data alone, it reads as volatility.
A firm with integrated surveillance sees something else. The on-chain data shows that much of the volume came from a cluster of wallets that analysis links to a single controlling entity, wash trading dressed as interest. The social data shows a coordinated burst of promotion across two Telegram channels in the 30 minutes before the ramp, with a tiered structure in which some accounts bought before the promotion even started. The cross-venue data shows the real selling happened on a second, smaller exchange while the visible buying pressure sat on the first. Put together, the three streams describe a textbook pump-and-dump with a wash-trading overlay, run across venues and coordinated on social media. No single data stream proved it; the combination did.
A system that produces alerts and dashboards but misses crypto-native abuse is worse than none, because it looks like coverage. That is worse than having no system, because no system at least tells you where you stand. A firm running an equity-grade tool against a crypto book gets a steady stream of alerts on the patterns the tool understands, closes them diligently, and concludes its surveillance is working. Meanwhile the wash trading hidden behind wallet clusters, the cross-venue spoofing, the MEV extraction and the flash loan exploits all pass underneath, because the tool has no feed and no model that could catch them.
So moving into digital assets can’t be a matter of pointing existing tools at a new asset class. Every crypto surveillance build I’ve worked on has had to start by accepting that the data foundations are different, on-chain rather than exchange-only, that the manipulation typologies are partly new, and that the firm needs people who understand blockchain mechanics working alongside those who understand market abuse. A repurposed equity system is unlikely to satisfy SYSC systems-and-controls expectations for crypto. The choice is to build or buy genuine crypto surveillance now, before the regime arrives, rather than assume an equity stack stretches to cover a market it was never designed for.
This insight is provided for general informational purposes only and doesn’t constitute legal, investment, or regulatory advice.