Order-Book Spoofing: What It Looks Like in Live Data
Spoofing is defined by intent, which no market-data feed can observe. Here are the order-book patterns that stand in for it, and where they fail.
Key signals
order book spoofingLargest spoofing penalty
$920.2M
CFTC order against JPMorgan Chase covering spoofing and manipulation in precious metals and Treasury futures
Largest single-firm spoofing relief
$67.4M
CFTC order against Tower Research Capital for orders placed with intent to cancel before execution
Defining element
Intent
Under U.S. law the offence is bidding or offering with intent to cancel before execution — a state of mind, not a pattern
What a feed can observe
Behaviour only
Placement, size, distance from touch, cancellation timing, and price reaction
In this article
The legal definition is about intent, not pattern
Spoofing, as regulators define it, is bidding or offering with the intent to cancel the order before execution. The offence lives in the trader's intent. That is a critical point for anyone building or buying a detection tool, because intent is precisely the thing that market data cannot contain.
Enforcement history makes the standard concrete. The CFTC's order against JPMorgan Chase covered conduct spanning at least eight years and hundreds of thousands of orders, and carried $920.2 million in monetary relief — the largest the agency has imposed. Its order against Tower Research Capital found orders placed with intent to cancel before execution and required $67.4 million in restitution, disgorgement and penalties. In both cases the finding of intent rested on internal records, communications and trader testimony, not on the order book alone.
Every screen that runs on public market data is therefore a proxy. It identifies order-book behaviour that is consistent with spoofing. Whether it was spoofing is a question that requires evidence a market-data feed does not carry.
The four observable components
What a feed can see is the shape of the behaviour. Practitioner and academic accounts converge on roughly the same four components, and a pattern is only interesting when several appear together.
- ▶Disproportionate size — a resting order far larger than the venue's normal depth at that level, which by itself would move the price if it filled
- ▶Distance from the touch — placed close enough to be visible and to influence perception, far enough that it is unlikely to be hit
- ▶Cancellation before execution — pulled as price approaches, rather than filled; a high place-to-cancel ratio with near-zero fill rate is the core statistical signature
- ▶Price reaction and reversal — the book reacts to the order while it rests, and reverts once it is pulled
Why single large orders are weak evidence
A large resting order that gets cancelled is, on its own, almost meaningless. Market makers cancel and re-place constantly; that is the job. Cancellation rates above 90% are normal for automated liquidity provision on most venues, and an inventory-managing market maker will pull size the instant its hedge moves.
There are also entirely legitimate reasons a large order appears and disappears. A desk working a parent order will place and pull child orders as its schedule and the prevailing spread change. A risk system will flatten quotes when volatility crosses a threshold. An iceberg's visible tip refreshes and vanishes by design.
This is why the useful unit of analysis is not the order but the episode: a cluster of placements on one side, with a measurable price response, followed by cancellation and reversion, repeated. One event is noise. A repeated pattern on the same pair, on the same side, at similar distances from the touch, is a signal worth attention — and still not a finding.
Layering, and why it is harder to see
Layering is the multi-level variant: rather than one conspicuous wall, several orders are placed across adjacent price levels on one side of the book. The aggregate effect on perceived imbalance is the same, but no individual order looks unusual.
This is where a size-threshold screen fails and a shape-based one is needed. The observable is the ratio of one side's depth to the other across a band of levels, tracked over time, together with how quickly that imbalance decays when it is removed. Layered orders tend to leave together, because they were placed together.
Genuine imbalance builds and decays gradually as independent participants arrive and leave. Imbalance that appears and disappears as a block is behaving like one actor rather than many.
What machine-learning detection adds, and what it does not
Recent academic work has applied sequence models to limit-order-book data to classify spoofing episodes, and to characterise which book states are most spoofable in the first place. The results are meaningful: models trained on order-book sequences outperform fixed-threshold rules, particularly on layering, where no single order crosses a threshold.
What none of this work claims is that the models observe intent. They learn the statistical shape of episodes that were labelled as spoofing, and they inherit the limitations of that labelling. A model trained on regulatory-enforcement cases has learned what caught spoofing looks like, which is not necessarily what spoofing looks like.
The practical consequence is that model output should be treated as a prior, not a verdict — a reason to weight a signal down, not a basis for any claim about a market participant.
How this affects a trading decision
The actionable use of spoofing screens is defensive and almost entirely about position sizing and order placement, not about identifying wrongdoing.
If elevated one-sided book imbalance is present on a pair, the depth you can see is less reliable than it looks. A stop placed just beyond a large visible wall is a stop placed at a level that may not exist when it is tested. A market order sized against displayed depth may fill far worse than the book implied. Both are ordinary execution mistakes made worse by treating displayed liquidity as firm.
The correction is unglamorous: size against depth you have seen persist rather than depth you can see right now; prefer limit orders when book imbalance is elevated; re-check depth after any large visible order disappears, because the level that mattered may have gone with it; and treat a sudden, one-sided depth change as a reason to wait rather than a reason to trade.
What Vultax reports
Vultax surfaces order-book imbalance and cancellation-pressure context inside the market-quality domain of Vi IQ. The reading is elevated or suppressed risk on a market, never an inference of intent, because the underlying data cannot support one. How the domain is computed is documented in the methodology.
The measurement is also bounded by feed fidelity. A screen can only assess order-book behaviour it actually received, and snapshot cadence and feed reliability differ substantially between venues.
See the data behind this article.
Whale flow, arbitrage routes, market-quality signals, and prediction-market context can all feed the same editorial workflow. Use the terminal for live data and subscribe to the newsletter for new briefs.
Sources and evidence
Largest monetary relief imposed by the CFTC; conduct spanning at least eight years and hundreds of thousands of orders
Orders placed with intent to cancel prior to execution, March 2012 to December 2013
GRU-based sequence model for detecting spoofing in limit-order-book data
Interpretable probabilistic models of which order-book states are susceptible to spoofing
Practitioner account of the observable components: rapid placement and cancellation, disproportionate size, avoidance of execution
Crypto-specific overview, including why episodes are typically only identifiable retrospectively
- internalVultax methodology
How order-book imbalance and cancellation-pressure context feed the Vi IQ market-quality domain
Order-book screens describe observable behaviour and produce probabilistic risk readings. They cannot establish intent, and nothing in this article is an allegation that any exchange, venue, firm or account holder has engaged in spoofing or manipulation. Enforcement outcomes cited are matters of public record. Nothing here is financial advice.
Continue reading
Crypto Exchange Feed Latency: 16 Venues Measured
Observed order-book feed latency and uptime across 16 crypto exchanges, measured from live venue feeds over a 24-hour window in September 2026.
Crypto Wash Trading: What the Research Actually Shows
Published estimates of fake crypto volume range from 51% to 95%. Here is why the studies disagree, and what a trader can check without a vendor.
Exchange Liquidity Is Not Volume: How to Judge a Venue
Volume is what an exchange reports. Liquidity is what absorbs your order. The two diverge sharply, and the gap between them is measurable.