Order-book risk: reading walls that may not be there when you arrive

A large resting order looks like support until it is cancelled. This page publishes the measured depth on either side of the mid and the service status of each venue that reported it, so quoted liquidity can be read as what it is — an offer that can be withdrawn — rather than as a floor under the price.

Reported BTC market depth

Measured BTC depth by venue, and the service status each venue reported on the same pass.

Observed · Observed

Reported cost to move the market by 2%, alongside the corresponding BTC pair and reported turnover.
ExchangePair+2% depth−2% depthReported 24h volumePair status
BinanceBTC/USDT23,158,39221,061,4881,075,102,719No flag reported
CoinbaseBTC/USD18,247,12817,980,026470,288,737No flag reported
KrakenXBT/USD22,174,84519,648,670168,670,804No flag reported
OKXBTC/USDT10,484,61714,337,004444,676,493No flag reported
GateBTC/USDT18,184,46730,468,098467,735,937No flag reported

What you can do with it

Treat a wall as a claim

Visible size is an intention to trade at a price, not a commitment. On some venues large walls are routinely pulled as price approaches. The useful question is not how big the wall is but how long walls of that size have tended to survive there.

Read depth on both sides

Asymmetry is more informative than absolute size. A book with heavy depth below and thin depth above will behave differently under the same news than a balanced one, whatever the last trade says.

Separate a venue problem from a market signal

Depth that vanishes across every venue at once is a market event. Depth that vanishes at one is often that venue's problem, which is why the service status is collected on the same pass and shown beside it.

Work the book in the app

The crypto workspace keeps the order-book views next to the chart for a selected pair, so a change in depth can be read against what the price was doing at the time.

How it works

What can be observed, and what cannot

What is observable from public data: how much size is quoted, how it is distributed, and how it changes. What is not observable: who placed it, what they meant by it, and whether they intended to trade. Spoofing is defined by intent, and intent does not appear in a public feed.

This public page therefore provides depth and service context rather than cancellation histories. It does not establish that any order was spoofed, and it names no participant.

Rapid change is normal as well as suspicious

Market makers adjust quotes constantly, and a book that repaints many times a second is a healthy book, not a manipulated one. That is precisely why a single snapshot of a large wall proves nothing in either direction, and why the honest framing is a question about persistence rather than a flag on an order.

Why this sits next to the depth tables

The same measured depth that makes a venue look resilient is the input to any judgement about resting liquidity, so the two belong on one page. The published research linked below the tables goes into the observable shapes in more detail, with the windows it measured over.

Reading persistence instead of size

The question worth asking about a wall is not how big it is but how long walls like it have survived on that venue. Size is a single observation; persistence is a pattern, and only a pattern can support any inference at all.

That is also the honest limit of a public page. Following a specific order through its life needs a level of feed access this site does not publish, so what is here is depth and venue status, and the research beside it describes the shapes that have been observed elsewhere.

In the app, order-book views sit next to the chart so a change in quoted size can be read against what the price did next. That pairing is usually more informative than any single snapshot of the book.

What each plan gives you here

What a plan changes on this surface.

Spoofing Risk availability by plan
What you getFreeEssentialPremiumPro
Crypto prices, order books and depthIncludedIncludedIncludedIncluded
Six-domain Vi IQ detail on every pairNot includedIncludedIncludedIncluded
The tables on this site, as JSON and CSVIncludedIncludedIncludedIncluded

Full plan comparison and prices · Refer & earn 30%

Compared with the manipulation-alert products

Some products issue per-order spoofing alerts. The gap between what a public feed can show and what such an alert asserts is large, and Vultax does not close it by asserting more than the data supports. What is published here is the depth, the venue status and the research, and the conclusion is left to the reader.

Competitor details last checked . They describe other products as their operators published them, not as an assessment of them.

The table in full

Each table carries its own source, observation time, coverage and limits, and can be taken away as JSON or CSV. A missing value means the source did not report it; it is never rendered as a zero.

01 Market snapshot

Exchange service status

The service-status responses already collected by Vultax.

ObservedObserved 5 rowsWithin this table’s source-time freshness window; prices can change between observations.

Exchange service status. Configured exchange status endpoints; operational status does not establish feed completeness or execution access.
ExchangeIndicatorSource message
CoinbasenoneAll Systems Operational
KrakenminorPartially Degraded Service
Binancenonenormal
OKXnoneAll systems operational
Kalshinoneexchange active

CoverageConfigured exchange status endpoints; operational status does not establish feed completeness or execution access.

The upstream status messages retain the provider’s meaning; different providers use different status vocabularies.

SourcesVultax crypto pack · exchange status endpoints

Questions

Can Vultax tell me an order is spoofed?

No, and neither can anyone else from public data alone. Spoofing turns on intent. This page provides depth and status context and links research on the observable patterns.

What is layering?

Placing multiple orders at successive price levels to give an impression of depth, with the intention of cancelling them. The pattern can be described from public data; the intention cannot.

Does a disappearing wall mean manipulation?

Usually not. Quotes are cancelled all the time for ordinary reasons. Frequency and context matter far more than any single instance.

Does this cover every venue?

Only the venues that responded on the observation pass, named in the table. Coverage depends on the feeds available.

Which plan do I need?

This page is free. The order-book risk views inside the crypto workspace sit on Essential and above.

Is this an accusation against an exchange?

No. Nothing here alleges wrongdoing by any exchange or participant, and no figure on this page should be read as such.

Coverage and methodology

  • Public tables mirror existing Vultax source packs. They do not include account data, private watchlists or the complete app dataset.
  • Source time, coverage and limitations apply to each table. Missing values are unavailable, not zero.
  • This public mirror provides depth and service context. It does not expose cancellation histories or establish spoofing intent.

Methodology

Published research behind this page

Dated write-ups of the same sources. A figure in a study describes the window it was written about, not the snapshot above.

  1. Spoofing is defined by intent, which no market-data feed can observe. Here are the order-book patterns that stand in for it, and where they fail.

  2. Published estimates put fake or non-economic bitcoin volume at 51% to 95%, and above 70% on unregulated venues. Why the studies disagree, why depth and slippage judge a venue better than volume (Binance: 64.3% of volume, 30.7% of depth, per Kaiko), and what to check yourself.

Take this into the workspace

The depth and status tables are public. Essential adds the order-book risk views inside the app.

A free account needs no payment card and starts no subscription. Figures on this page were observed . JSON · Markdown · Schema