Crypto trade surveillance is the practice of monitoring orders, trades, and on-chain activity to detect market abuse before it becomes an enforcement problem, and a July 2026 working paper showed exactly why it matters: researchers found that 821 suspected manipulators pulled roughly $8.2 million out of Polymarket’s five-minute Bitcoin contracts by pushing spot prices on Binance in the final seconds before settlement (Source: Stanford University). The price moves reverted almost immediately after each contract resolved.
That is the shape of the problem. The manipulation did not happen on the venue that lost money. It happened somewhere else, in another asset class, on a timescale measured in seconds. Any surveillance system watching only its own order book would have seen nothing unusual at all.
Key Takeaways
- Surveillance monitors orders and trades for manipulation, not just money laundering.
- MiCA Article 92 requires EU crypto firms to detect and report market abuse.
- Crypto manipulation crosses venues, chains, and asset classes constantly.
- On-chain data and order book data must be analyzed together.
- The MiCA transitional period closed on 1 July 2026 with no extension.
What Crypto Trade Surveillance Actually Covers
There is a persistent confusion between two different compliance functions, and it costs teams real money when they buy the wrong system.
Transaction monitoring, the AML function, asks where funds came from and where they are going. It scores wallets, screens against sanctions lists, and traces flows through mixers and bridges. Trade surveillance asks a different question: was this trade fair? It looks at order placement, cancellation patterns, timing, counterparty relationships, and price impact to decide whether someone gamed the market rather than participated in it.
Most serious programs run both. They answer to different rules, different regulators, and increasingly different data pipelines. A firm with excellent AML compliance programs can still be wide open to spoofing, and regulators have started noticing the gap.
How the Detection Layer Works
A surveillance platform ingests raw market activity, normalizes it, runs behavioral models against it, and surfaces alerts for human review. Simple in outline. Difficult in practice, because crypto generates four kinds of data that do not naturally sit in the same schema.

Order book and execution data
This is the closest analog to equities surveillance. Every order placed, modified, cancelled, or rejected gets timestamped and stored. Detection models look for patterns across that stream: repeated cancellations at the top of the book, self-matching between related accounts, orders sized to move a thin market.
On-chain activity
Blockchain data adds a layer that traditional finance never had to model. Wallet clustering can link accounts that look independent on a venue. Transaction ordering within a block reveals front-running. Validator behavior and block proposal patterns can indicate manipulation on proof-of-stake networks, which is why serious programs monitor protocol events and not only order book prints.
Cross-venue correlation
The Polymarket case is the textbook example. Manipulation on one venue targeted settlement on another. Detecting it requires normalized feeds from multiple exchanges, spot and derivatives, centralized and decentralized, aligned to a common clock. Very few firms build this themselves.
Behavioral and identity context
KYC records, account age, funding sources, device fingerprints, and social signals turn an anonymous alert into an investigable case. A wash trading pattern between two accounts means little until you know they share a funding wallet.
The Patterns Surveillance Systems Look For
Crypto manipulation typologies borrow heavily from traditional markets, then add a few of their own.
Wash trading creates fake volume by trading an asset between related parties with no change in beneficial ownership. It inflates a token’s apparent liquidity, lifts its ranking on aggregator sites, and helps it clear listing thresholds at larger exchanges. Detection looks for repeat trades between the same addresses, zero net position change, and volume spikes without price movement.
Spoofing and layering involve placing large orders with no intention to execute, pulling them once the market reacts. In thin crypto order books, a modest spoofed order can move price meaningfully.
Insider trading around token listings remains one of the most consistent patterns in the market. A trader buys ahead of a listing announcement, an exploit disclosure, or a large institutional order. The first criminal conviction here came in 2023, when a former Coinbase employee was jailed for tipping associates about upcoming listings.
Pump-and-dump schemes target low-liquidity tokens. Coordinated buying spikes the price, social channels amplify the move, and organizers sell into the retail demand they manufactured.
Settlement and oracle manipulation is the newest category, and the Stanford findings put it on the map. When a contract settles against a single price snapshot, anyone with enough size can push the underlying market for a few seconds and collect. The researchers noted that fifteen-minute contracts showed far less abuse, pointing to settlement window design rather than prediction markets themselves as the vulnerability.
MEV and front-running exploit transaction ordering on-chain. Bots detect a pending swap, insert their own transaction ahead of it, and capture the price difference.
What MiCA Now Requires
The EU moved first, and the requirements are specific.
Title VI of MiCA, Articles 86 through 92, prohibits insider dealing, unlawful disclosure of inside information, and market manipulation in crypto-assets admitted to trading on an EU platform. Article 92(1) puts the detection burden on persons professionally arranging or executing transactions, a category that covers exchanges, brokers, and a range of intermediaries. Those firms must have arrangements, systems, and procedures capable of preventing and detecting abuse.
The technical detail arrived through Commission Delegated Regulation (EU) 2025/885. Firms must analyze every order and transaction, whether placed, modified, cancelled, or rejected, and whether it sits on a trading platform, off it, or on the distributed ledger. Systems need deferred automated reading, replaying, and analysis of order book data. Suspicious Transaction and Order Reports go to the national competent authority on a prescribed template that now carries the Digital Token Identifier.
One point gets missed: the rules also require human analysis. Automated alerts alone do not satisfy Article 92. Someone qualified has to review, and the audit trail has to show it.
The compliance clock has already run out. MiCA’s transitional period closed on 1 July 2026, and ESMA confirmed in April that there would be no extension. Several member states closed earlier, including Germany and Ireland at the end of 2025. Firms serving EU clients without full CASP authorization now have no transitional cover anywhere in the union.
Where the United States Stands
The US picture is less settled. The CLARITY Act, which would assign spot digital commodity markets to the CFTC and write the SEC boundary into statute, passed the House in July 2025 and cleared the Senate Banking Committee on a 15 to 9 vote in May 2026. As of late July 2026 it had no floor vote scheduled.
Agencies have moved without it. The SEC and CFTC issued a joint classification in March 2026 naming sixteen assets as digital commodities outside securities laws, and the CFTC ran a twelve-month crypto initiative that produced the first listed spot crypto trading on regulated exchanges. Guidance is not statute, though. Any of it can be rescinded by a future administration, which is why compliance teams treat the MiCA requirements as the practical global baseline and build to those. Anyone tracking how crypto regulation is evolving across jurisdictions will recognize the pattern: the strictest regime sets the engineering spec.
Why Crypto Is Harder Than Equities
Equities surveillance has forty years of accumulated practice behind it. Crypto breaks several assumptions that practice depends on.
Markets never close, so there is no overnight batch window and no settled end-of-day state. Liquidity fragments across hundreds of venues with no consolidated tape. Participants are pseudonymous, so linking accounts requires clustering heuristics rather than a legal entity identifier. Assets settle instantly, which means an alert that fires ten minutes late is an incident report rather than an intervention. And roughly half the market operates through smart contracts where there is no order book at all, only transactions in blocks.
Volatility compounds the problem. A model tuned on equity price behavior will fire constantly on a token that routinely moves fifteen percent in an hour. Tuning out that noise without tuning out real abuse is the hardest part of running the system, and it is where most in-house builds stall.
Building or Buying a Program
Start with scope. List the venues, asset classes, and jurisdictions you touch, then map which regulator claims each one. That document drives everything downstream.
Next, get the data pipeline right before worrying about models. Surveillance quality is capped by feed quality, and normalizing non-standard exchange APIs into one schema is unglamorous work that determines whether anything else functions.
On the build-versus-buy question, most firms buy. The vendor market has consolidated around a handful of specialists including Solidus Labs, Nasdaq, Eventus, Kaiko, and Chainalysis, several of which now sell into prediction markets specifically. Meanwhile, Kalshi brought in Solidus Labs for trade surveillance in February 2026, and Polymarket partnered with Chainalysis a few months later on on-chain monitoring after the settlement findings surfaced.
Whatever you deploy, budget for the alert review function. Vendors increasingly ship agentic tooling to cluster and prioritize alerts, similar to what AI in fraud detection has done for payments. It reduces headcount pressure. It does not remove the regulatory requirement for qualified human judgment on every escalation.
Conclusion
Crypto trade surveillance has moved from a nice-to-have into a licensing condition. If you serve EU clients, you need systems that analyze every order and transaction across venues and chains, plus documented human review and a working STOR process. Whereas, if you operate in the US, the statutory picture is unfinished, but the agencies are active and the practical standard is converging on the European one anyway.
The harder lesson from the past year is architectural. Manipulation now routes around single-venue monitoring by design, exploiting the seams between spot and derivatives, on-chain and off-chain, one venue’s price and another venue’s settlement. Whatever you buy or build, judge it on whether it can see across those seams. A system that only watches your own order book will keep telling you everything looks fine.
Read Next
Keep going on crypto market structure and compliance:
- Navigating Consumer Duty: Implications for Crypto and FX Exchanges
- How Regulated Crypto ETFs Are Shaping Mainstream Adoption of Digital Assets
- Evaluating How Cross Chain Technology Is Changing Crypto Asset Swaps
Frequently Asked Questions
Crypto trade surveillance is the monitoring of orders, trades, and on-chain activity to detect market abuse such as wash trading, spoofing, insider dealing, and price manipulation. It analyzes how trades were placed and executed rather than where the money came from. Exchanges, brokers, and market makers use it to meet regulatory obligations and to protect market integrity on their venues.
Crypto trade surveillance differs from transaction monitoring in the question it answers. Surveillance examines trading behavior to find manipulation, while transaction monitoring traces the source and destination of funds to find money laundering. Both are usually required, they report to different rules, and buying one when you need both is a common and expensive mistake.
Yes. MiCA Article 92 requires persons professionally arranging or executing crypto-asset transactions to maintain effective arrangements, systems, and procedures for preventing and detecting market abuse. Commission Delegated Regulation (EU) 2025/885 specifies that firms must analyze every order and transaction, including cancellations and rejections, and file Suspicious Transaction and Order Reports with their national competent authority.
Crypto trade surveillance detects wash trading, spoofing and layering, insider trading around listings and disclosures, pump-and-dump schemes, cross-venue and settlement manipulation, and on-chain front-running. Detection models combine order book patterns, wallet clustering, and timing analysis.
The cross-venue patterns are hardest to catch because the abusive activity often occurs on a different platform from the one that absorbs the loss.
Most firms buy rather than build, because the hard parts are feed normalization across dozens of non-standard exchange APIs and model tuning that survives crypto volatility. Established vendors include Solidus Labs, Nasdaq, Eventus, Kaiko, and Chainalysis. Building in-house makes sense mainly for firms with unusual venue coverage or proprietary detection needs that vendors do not serve.











