# Order-Book Spoofing: What It Looks Like in Live Data

Spoofing is defined by intent, which no market-data feed can observe. Here are the order-book patterns that stand in for it, and where they fail.

Canonical URL: https://vultax.com/research/order-book-spoofing-what-it-looks-like
Author: [Vultax Research](https://vultax.com/editorial-policy)
Published: 2026-09-02
Last public revision: 2026-09-07

Published research snapshots and calculations; these exports do not contain current quotes or live account data. Observation windows and populations are stated in the source captions and methodology. Missing metadata is unknown, not zero. Order-book screens describe observable behaviour and produce probabilistic risk readings. They cannot establish intent, and nothing in this article is an allegation that any exchange, venue, firm or account holder has engaged in spoofing or manipulation. Enforcement outcomes cited are matters of public record. Nothing here is financial advice.

## Key figures

- Largest spoofing penalty: $920.2M — CFTC order against JPMorgan Chase covering spoofing and manipulation in precious metals and Treasury futures
- Largest single-firm spoofing relief: $67.4M — CFTC order against Tower Research Capital for orders placed with intent to cancel before execution
- Defining element: Intent — Under U.S. law the offence is bidding or offering with intent to cancel before execution — a state of mind, not a pattern
- What a feed can observe: Behaviour only — Placement, size, distance from touch, cancellation timing, and price reaction

<a id="section-the-legal-definition-is-about-intent-not-pattern"></a>
## The legal definition is about intent, not pattern

Spoofing, as regulators define it, is bidding or offering with the intent to cancel the order before execution. The offence lives in the trader's intent. That is a critical point for anyone building or buying a detection tool, because intent is precisely the thing that market data cannot contain.

Enforcement history makes the standard concrete. The [CFTC's order against JPMorgan Chase](https://www.cftc.gov/PressRoom/PressReleases/8260-20) covered conduct spanning at least eight years and hundreds of thousands of orders, and carried $920.2 million in monetary relief — the largest the agency has imposed. Its [order against Tower Research Capital](https://www.cftc.gov/PressRoom/PressReleases/8074-19) found orders placed with intent to cancel before execution and required $67.4 million in restitution, disgorgement and penalties. In both cases the finding of intent rested on internal records, communications and trader testimony, not on the order book alone.

Every screen that runs on public market data is therefore a proxy. It identifies order-book behaviour that is consistent with spoofing. Whether it was spoofing is a question that requires evidence a market-data feed does not carry.

<a id="section-the-four-observable-components"></a>
## The four observable components

What a feed can see is the shape of the behaviour. Practitioner and academic accounts converge on roughly the same four components, and a pattern is only interesting when several appear together.

- Disproportionate size — a resting order far larger than the venue's normal depth at that level, which by itself would move the price if it filled
- Distance from the touch — placed close enough to be visible and to influence perception, far enough that it is unlikely to be hit
- Cancellation before execution — pulled as price approaches, rather than filled; a high place-to-cancel ratio with near-zero fill rate is the core statistical signature
- Price reaction and reversal — the book reacts to the order while it rests, and reverts once it is pulled

<a id="section-why-single-large-orders-are-weak-evidence"></a>
## Why single large orders are weak evidence

A large resting order that gets cancelled is, on its own, almost meaningless. Market makers cancel and re-place constantly; that is the job. Cancellation rates above 90% are normal for automated liquidity provision on most venues, and an inventory-managing market maker will pull size the instant its hedge moves.

There are also entirely legitimate reasons a large order appears and disappears. A desk working a parent order will place and pull child orders as its schedule and the prevailing spread change. A risk system will flatten quotes when volatility crosses a threshold. An iceberg's visible tip refreshes and vanishes by design.

This is why the useful unit of analysis is not the order but the episode: a cluster of placements on one side, with a measurable price response, followed by cancellation and reversion, repeated. One event is noise. A repeated pattern on the same pair, on the same side, at similar distances from the touch, is a signal worth attention — and still not a finding.

<a id="section-layering-and-why-it-is-harder-to-see"></a>
## Layering, and why it is harder to see

Layering is the multi-level variant: rather than one conspicuous wall, several orders are placed across adjacent price levels on one side of the book. The aggregate effect on perceived imbalance is the same, but no individual order looks unusual.

This is where a size-threshold screen fails and a shape-based one is needed. The observable is the ratio of one side's depth to the other across a band of levels, tracked over time, together with how quickly that imbalance decays when it is removed. Layered orders tend to leave together, because they were placed together.

Genuine imbalance builds and decays gradually as independent participants arrive and leave. Imbalance that appears and disappears as a block is behaving like one actor rather than many.

<a id="section-what-machine-learning-detection-adds-and-what-it-does-not"></a>
## What machine-learning detection adds, and what it does not

Recent academic work has applied [sequence models to limit-order-book data](https://arxiv.org/pdf/2110.03687) to classify spoofing episodes, and to characterise [which book states are most spoofable](https://arxiv.org/pdf/2504.15908) in the first place. The results are meaningful: models trained on order-book sequences outperform fixed-threshold rules, particularly on layering, where no single order crosses a threshold.

What none of this work claims is that the models observe intent. They learn the statistical shape of episodes that were labelled as spoofing, and they inherit the limitations of that labelling. A model trained on regulatory-enforcement cases has learned what caught spoofing looks like, which is not necessarily what spoofing looks like.

The practical consequence is that model output should be treated as a prior, not a verdict — a reason to weight a signal down, not a basis for any claim about a market participant.

<a id="section-how-this-affects-a-trading-decision"></a>
## How this affects a trading decision

The actionable use of spoofing screens is defensive and almost entirely about position sizing and order placement, not about identifying wrongdoing.

If elevated one-sided book imbalance is present on a pair, the depth you can see is less reliable than it looks. A stop placed just beyond a large visible wall is a stop placed at a level that may not exist when it is tested. A market order sized against displayed depth may fill far worse than the book implied. Both are ordinary execution mistakes made worse by [treating displayed liquidity as firm](https://vultax.com/research/crypto-wash-trading-what-the-research-shows).

The correction is unglamorous: size against depth you have seen persist rather than depth you can see right now; prefer limit orders when book imbalance is elevated; re-check depth after any large visible order disappears, because the level that mattered may have gone with it; and treat a sudden, one-sided depth change as a reason to wait rather than a reason to trade.

<a id="section-what-vultax-reports"></a>
## What Vultax reports

Vultax surfaces order-book imbalance and cancellation-pressure context inside the market-quality domain of Vi IQ. The reading is elevated or suppressed risk on a market, never an inference of intent, because the underlying data cannot support one. How the domain is computed is documented in the [methodology](https://vultax.com/methodology).

The measurement is also bounded by feed fidelity. A screen can only assess order-book behaviour it actually received, and [snapshot cadence and feed reliability differ substantially between venues](https://vultax.com/research/crypto-exchange-feed-latency-september-2026).

<a id="section-how-to-read-the-live-figures"></a>
## How to read the live figures

The strip at the top of this page is not a screenshot of the day this was written. Every ten minutes Vultax re-reads the trade tapes of five venues for prints of $100,000 or more in the last thirty minutes, the buy share of those prints, CoinGecko's depth within 2% of mid, and Deribit's implied-volatility index and rewrites the figures; the Vi IQ beneath them scores the same six domains the terminal scores for a pair, computed for BTC on the major spot venues, with any domain that cannot be computed shown as unavailable rather than filled in. Read the numbers as a live check on the argument above, and the revision notes at the end for what has changed since publication.

Prints are the opposite of spoofs: they are orders that traded. A burst of large prints with the buy share far from 50% is genuine one-sided flow; a wall in the book that never prints while the tape stays quiet is the pattern this article describes. Depth is the denominator both are measured against, and DVOL says whether the market is in a state where a wall would matter.

<a id="section-context-from-elsewhere"></a>
## Context from elsewhere

The enforcement record keeps confirming the definition above: intent to cancel, not size. The Department of Justice's September 2025 resolution with two traders at a large institution covered more than a thousand spoof orders in Treasuries and related futures placed between 2014 and 2020, years after the CFTC's record $920 million order against JPMorgan for the same conduct in metals and Treasuries. The CFTC first applied the statute to bitcoin futures in 2021, and its February 2026 prediction-markets advisory lists disruptive trading among the conduct it polices on any designated contract market.

For offshore spot venues, which are where most of the walls in this article appear, no comparable enforcement exists, so the observable components below are the only test available. Whether a venue's own surveillance catches layering depends on the venue, and none of the large spot venues publishes its cancellation statistics.

## Questions

### What is order-book spoofing?

Placing orders with the intent to cancel them before they trade, to make supply or demand look larger than it is and move other traders. The legal test is intent; the observable signs are size, placement, cancellation timing and what the tape did while the order sat there.

### Is a large order wall proof of spoofing?

No. Large resting orders are also how market makers and funds work; the same wall can be real or a spoof. The article lists the four components that distinguish them, and the live figures give the depth and print context to judge one against.

### Is spoofing illegal in crypto?

On U.S.-regulated derivatives venues, yes, and the CFTC has charged spoofing in bitcoin futures since 2021. On offshore spot venues it depends on the venue's rules; the CFTC's February 2026 advisory extends the disruptive-trading prohibition explicitly to prediction markets.

### How should a trader react to a wall?

Treat it as information about what might happen, not a promise. Size the position for the wall being pulled, and prefer prints on the tape over resting size in the book as evidence of where the market is going.

## Revision notes

- 2026-09-07: Live figures and a Vi IQ for this subject now refresh every ten minutes on this page from outside sources and Vultax's own tables; a context section, the questions below and these revision notes were added.
- 2026-09-07: Added the September 2025 DOJ Treasuries resolution, the CFTC's JPMorgan order and its February 2026 prediction-markets advisory to the enforcement record.

## Sources and methodology

- [CFTC — JPMorgan ordered to pay $920.2 million for spoofing and manipulation](https://www.cftc.gov/PressRoom/PressReleases/8260-20) — Largest monetary relief imposed by the CFTC; conduct spanning at least eight years and hundreds of thousands of orders
- [CFTC — Tower Research Capital ordered to pay $67.4 million](https://www.cftc.gov/PressRoom/PressReleases/8074-19) — Orders placed with intent to cancel prior to execution, March 2012 to December 2013
- [Protecting Retail Investors from Order Book Spoofing (arXiv 2110.03687)](https://arxiv.org/pdf/2110.03687) — GRU-based sequence model for detecting spoofing in limit-order-book data
- [Learning the Spoofability of Limit Order Books (arXiv 2504.15908)](https://arxiv.org/pdf/2504.15908) — Interpretable probabilistic models of which order-book states are susceptible to spoofing
- [Bookmap — detecting deceptive trading practices](https://bookmap.com/blog/unmasking-spoofing-detecting-and-navigating-deceptive-trading-practices) — Practitioner account of the observable components: rapid placement and cancellation, disproportionate size, avoidance of execution
- [Cointelegraph Research — Spoofing Order Books in the Crypto Market](https://web.archive.org/web/20240423174942/https://research.cointelegraph.com/articles/spoofing-order-books-in-the-crypto-market) — Crypto-specific overview, including why episodes are typically only identifiable retrospectively. Archived copy: the research.cointelegraph.com host was retired in 2026
- [Vultax methodology](https://vultax.com/methodology) — How order-book imbalance and cancellation-pressure context feed the Vi IQ market-quality domain
- [Moore & Van Allen — Latest DOJ spoofing settlement (Treasuries, Sep 2025)](https://www.mvalaw.com/investigations-and-regulatory-advice/latest-doj-spoofing-settlement) — Two traders at a large institution placed more than 1,000 spoof orders in Treasuries and related futures between 2014 and 2020; the resolution turned on intent to cancel, not on order size.
- [CFTC — Enforcement Division issues Prediction Markets Advisory (25 Feb 2026)](https://www.cftc.gov/PressRoom/PressReleases/9185-26) — Names insider trading, fraud and manipulation, wash sales and pre-arranged trading, and disruptive trading as conduct the Commission polices on any designated contract market, and reminds venues of their duty to keep audit trails and surveil.

Changing market context is available on the [article page](https://vultax.com/research/order-book-spoofing-what-it-looks-like). It is separate from the published study exported here.
