Digital Asset Trade Surveillance
How trading platforms, intermediaries and regulators monitor digital asset markets for manipulation, insider dealing and other misconduct, on and off the blockchain.
Overview
Digital asset trade surveillance is the monitoring and investigation of trading activity for signs of market manipulation, insider dealing, misuse of customer information and other forms of misconduct. Its objectives are familiar from traditional financial markets, but its operation is shaped by a distinctive market structure: digital assets may trade continuously across centralized exchanges, decentralized protocols and derivatives venues around the world, across regulatory jurisdictions, while related transfers occur on public blockchains.
Those features can make more activity observable, but not necessarily easier to interpret. A blockchain address does not automatically reveal who controls it, and the public record of a transfer may show little about the purpose of the transaction. At the same time, a centralized platform may hold detailed customer and order information that never appears on-chain. Effective surveillance therefore depends on joining multiple sources of evidence and applying the rules that govern the particular asset, product, venue and entity involved.
For the general principles and institutional framework, see Financial Markets Trade Surveillance on financialmarkets.law.
What Is Digital Asset Trade Surveillance?
In practice, digital asset trade surveillance is used to identify, assess and escalate activity that may violate law, regulation or venue rules. Depending on the business and the market, it may examine:
- orders, cancellations, modifications and executions on centralized trading platforms;
- deposits, withdrawals, blockchain transfers and wallet interactions;
- decentralized exchange transactions and other smart-contract activity;
- activity in related spot, futures, options and perpetual-contract markets;
- funding rates, liquidations, reference prices, indexes and oracle inputs;
- token listings, unlocks, airdrops, governance events and protocol changes; and
- customer, account, wallet-attribution and communications data that provides context for the trading.
Monitoring may occur in real time or near real time, particularly where a platform may need to intervene, and retrospectively, when investigators reconstruct a pattern over a longer period.
Why Is Crypto Trade Surveillance Different?
Many digital asset abuses have recognizable counterparts in traditional markets. Wash trading, spoofing, insider dealing and benchmark manipulation are not new concepts. What changes is the trading environment and the evidence available to identify them.
Markets operate continuously. Crypto spot markets generally trade 24 hours a day, seven days a week. There is no universal close at which positions, alerts and operational issues can be reconciled. A surveillance program may need continuous data collection, dependable handoffs and escalation procedures outside ordinary business hours.
Liquidity is fragmented. The same asset may trade simultaneously on centralized exchanges, decentralized protocols, over-the-counter markets and derivatives venues around the world. Prices and depth can differ, and there is no universal consolidated tape. A platform may therefore see only one part of an economically connected strategy.
Relevant activity can be both on-chain and off-chain. A centralized exchange may match orders and maintain customer balances on its internal systems, recording only deposits and withdrawals on a blockchain. Decentralized transactions, bridge movements and smart-contract calls may be public. Reconstructing a strategy can require both records.
Public addresses are pseudonymous. A blockchain can make transactions permanently visible without identifying the person behind them. One person may control many wallets, while an exchange or custodian may pool assets belonging to many customers. Wallet-clustering and attribution can be useful, but conclusions may be probabilistic and should be treated accordingly.
Business models and conflicts vary. A corporate group may combine exchange operation, brokerage, custody, market making, proprietary trading and token issuance. Those functions can create conflicts or information advantages that a surveillance program must understand.
Tokens have distinctive events and ownership structures. Listings, delistings, unlocks, airdrops, governance votes, protocol upgrades, treasury transactions and security incidents can move prices. Thin liquidity and concentrated holdings may also make some markets easier to influence.
Digital asset surveillance is therefore not a wholly separate theory of market integrity. It is an expanded market-structure and evidence problem that requires familiar principles to be applied across new forms of trading and settlement.
What Does Crypto Trade Surveillance Look For?
The precise legal elements and terminology differ among jurisdictions, but surveillance commonly looks for the following patterns.
Wash trading and artificial volume. A person, related accounts or coordinated parties may trade with themselves or one another to inflate volume, create a misleading appearance of demand or liquidity, improve a token’s ranking or obtain transaction-based incentives. Detecting the pattern may require linking accounts or wallets that do not appear related from trading data alone.
Spoofing and layering. A trader may enter orders without a bona fide intention to execute them in order to create a false impression of supply, demand or market depth, then cancel those orders after trading on the other side. Investigators consider the full order lifecycle and the surrounding market response rather than treating cancellations alone as misconduct.
Pump-and-dump activity. Coordinated accumulation, promotional statements and rapid selling can be used to raise and then exploit a token’s price. Relevant evidence may include concentrated account or wallet activity, common funding sources, social-media timing and transfers to or from trading venues.
Insider dealing or misuse of confidential information. Trading may occur before a listing or delisting, token issuance, treasury action, protocol announcement, exploit disclosure or other market-moving event. The inquiry may focus on access to information, account and wallet relationships, the timing of trades and subsequent transfers.
Front-running and misuse of customer orders. A centralized intermediary or its personnel may trade ahead of customer activity or misuse nonpublic order information. In decentralized markets, participants can sometimes observe pending transactions in a public mempool and influence their ordering. Whether practices such as sandwiching or other forms of maximal extractable value, commonly called MEV, raise legal or regulatory concerns depends on the conduct, disclosures, platform design and applicable rules.
Cross-venue and cross-product manipulation. Trading in a spot market can affect a derivatives price, an index, liquidations, a funding rate or a settlement value, and derivatives positions can create incentives to influence the underlying spot market. Surveillance may need to connect instruments and venues rather than assess each alert in isolation.
Oracle or benchmark manipulation. A person may seek to distort a price input used for settlement, collateral valuation, lending or automated liquidation. The risk is greater where the reference relies on a small number of markets, thin liquidity or inputs that can be moved at relatively low cost.
An alert in any of these categories is a reason to investigate, not a conclusion that misconduct occurred. Legitimate market making, arbitrage, hedging and liquidation can sometimes generate similar patterns.
Who Uses Digital Asset Trade Surveillance?
Centralized crypto exchanges and other licensed crypto-asset or virtual-asset service providers use surveillance to meet regulatory and venue-rule obligations, manage market-integrity risk and investigate conduct on their platforms. Securities and derivatives intermediaries may also have surveillance and supervisory duties when they handle digital asset securities or crypto-related derivatives.
Banks, asset managers, market makers, proprietary trading firms and other institutional participants may monitor their own activity for compliance with law, trading-venue rules and internal policies. In some decentralized settings, protocol developers, operators or governance bodies may also establish monitoring, though their obligations depend on the applicable legal framework.
Regulators and law-enforcement authorities use platform records, regulatory reports, blockchain data and information obtained through domestic or international cooperation. No single participant necessarily has the complete picture: a venue may know the customer but not control an external wallet, while an investigator may see the blockchain path but need platform records to identify the actor.
How Does Digital Asset Trade Surveillance Work?
A digital asset surveillance program generally follows the same broad cycle as surveillance in other financial markets, adapted to the assets, technology and data environment within scope.
1. Define the Surveillance Perimeter
The firm first identifies the legal entities, jurisdictions, products, tokens, venues, customer types and trading methods it must supervise. The analysis should also consider related markets, affiliated businesses and wallet flows that could affect the risks visible on the platform. Asset classification matters because the applicable regulator and rulebook may change depending on whether a product is treated as a security, commodity, derivative, crypto-asset or another regulated instrument.
2. Capture Complete Trading and Account Data
For a centralized venue, the essential record normally includes the full order lifecycle—not just completed trades—together with market data, account information, deposits, withdrawals and platform events. Accurate timestamps, consistent identifiers and reliable reference data are critical. Missing order states or mismatched clocks can make a legitimate strategy appear suspicious or conceal an abusive one.
3. Add On-Chain and Cross-Market Context
Where relevant and lawfully available, the firm may add blockchain transactions, wallet clusters, smart-contract events, bridge activity, oracle inputs, external venue prices and related derivatives information. The aim is not to collect every possible data point. It is to capture the information needed to assess the material risks created by the business and its markets.
4. Resolve Relationships Cautiously
Accounts, wallets, funding sources and beneficial owners may need to be linked before coordinated activity becomes visible. Verified customer data can support attribution within a platform. External wallet labels and clustering methods can extend the view, but their confidence levels and limitations should be preserved. A probable relationship should not be presented as a confirmed identity.
5. Apply Risk-Based Detection Procedures
Surveillance may use scenarios, thresholds, statistical analysis, network analysis, anomaly detection and cross-market comparisons. Procedures should reflect the liquidity, volatility, ownership concentration and trading mechanics of the relevant token or product. A threshold suitable for a liquid major asset may be ineffective in a newly listed or thinly traded token.
6. Investigate the Economic Sequence
Reviewers assess the alert in context and reconstruct a common timeline of orders, executions, transfers, wallet movements, market events and related instruments. They consider plausible legitimate explanations and look for evidence of control, coordination, information access, benefit and intent. Communications and case notes may be important, particularly where the trading pattern alone is ambiguous.
7. Escalate and Respond
Material concerns are escalated under documented procedures. Depending on the facts, the response may include enhanced review, preservation of evidence, restrictions on an account or product, changes to platform controls or a report to a regulator or law-enforcement authority. The decision and the supporting evidence should be reproducible.
8. Test and Maintain the Program
Surveillance is not a set-and-forget control. Firms should test data completeness, validate detection logic, review alert outcomes and update coverage as markets, protocols and products change. Automation can help prioritize large volumes of activity, but material decisions should remain explainable and subject to appropriate human review.
The Global Regulatory Landscape
Digital asset surveillance requirements are developing through a mix of general market-abuse laws, product-specific regulation, platform licensing rules and international standards.
United States
The United States has historically regulated digital asset trading through a classification-based division of authority rather than a single comprehensive spot-market regime.
In March 2026, the Securities and Exchange Commission issued an interpretation clarifying how federal securities laws apply to certain crypto assets and transactions, including a token taxonomy and guidance on when non-security crypto assets may be offered as part of an investment contract. Where federal securities laws apply, intermediaries and trading platforms may have registration, supervision and recordkeeping obligations depending on their activities.
The Commodity Futures Trading Commission comprehensively regulates futures, options and swaps on digital asset commodities offered on registered derivatives markets. Registered designated contract markets must monitor trading, enforce their rules and address manipulation risks in listed products, including risks arising from the underlying spot market or settlement process. The CFTC also has enforcement authority over fraud and manipulation in interstate spot commodity transactions, although that authority has not historically amounted to comprehensive day-to-day regulation of all digital asset commodity spot markets.
Other regimes address different risks. The Financial Crimes Enforcement Network and state authorities regulate aspects of money transmission and anti-money-laundering compliance. Those controls can produce customer and transaction information useful to a market-conduct investigation, but AML monitoring is not a substitute for trade surveillance. The federal payment-stablecoin framework established by the GENIUS Act in 2025 likewise addresses important issuer and payment-stablecoin matters, but it is not a general code for surveillance of spot digital asset trading.
Congress has continued to consider broader market-structure legislation. The Digital Asset Market Clarity Act of 2025, commonly called the CLARITY Act, passed the House of Representatives in July 2025 and was reported out of the Senate Banking Committee in June 2026, but the Senate has not passed it and it has not become law. A September 2026 procedural vote to bring the bill to the Senate floor fell short of the 60 votes required. Unless and until such legislation is enacted, the existing division of authority remains in effect. A broader introduction to the classification and agency framework appears in Digital Asset Regulation.
European Union / MiCA
The European Union’s Markets in Crypto-Assets Regulation, or MiCA, contains an express crypto-specific market-abuse regime. Title VI of Regulation (EU) 2023/1114 prohibits insider dealing, unlawful disclosure of inside information and market manipulation involving crypto-assets within its scope.
Article 92 requires persons who professionally arrange or execute transactions in crypto-assets to maintain effective arrangements, systems and procedures to prevent and detect market abuse and to report reasonable suspicions to the relevant competent authority. Commission Delegated Regulation (EU) 2025/885 provides further detail on those systems, procedures and reports. Among other things, it addresses monitoring methods such as order-book replay and makes clear that outsourcing or delegation does not remove the regulated person’s responsibility.
MiCA does not displace the EU rules that already apply to financial instruments. A tokenized financial instrument may instead fall within the Market Abuse Regulation and the MiFID framework. The first question is therefore whether the crypto-asset and activity fall within MiCA or another body of EU financial-services law. The European Securities and Markets Authority has also issued supervisory guidelines (April 2025) intended to promote consistent, risk-based oversight by national competent authorities.
Hong Kong
Hong Kong’s Securities and Futures Commission places direct market-surveillance expectations on licensed virtual asset trading platform operators. Under the licensing framework and applicable guidelines, operators are expected to maintain internal policies, controls and effective systems for identifying manipulative or abusive activity, notify the SFC of actual or potential misconduct and take appropriate remedial measures.
The SFC’s November 2025 shared-liquidity guidance emphasizes surveillance across connected arrangements and the reliable identification of originating clients and ultimate beneficiaries. Its February 2026 framework for virtual asset perpetual contracts, a high-level policy statement rather than a binding rule, calls for real-time cross-market surveillance across spot and perpetual products, together with controls addressing mark prices, funding rates and forced liquidations. Operators that wish to offer perpetual contracts, which may be made available only to professional investors, must submit their proposed product structures to the SFC for review before any offering begins. These expectations reflect the risk that manipulation or disruption in one market can affect pricing and positions in another.
Dubai and Other Emerging Regimes
Dubai’s Virtual Assets Regulatory Authority regulates virtual-asset activities in mainland Dubai and its free zones, other than the Dubai International Financial Centre. VARA’s Market Conduct Rulebook and Exchange Services Rules address market offences, surveillance, information sharing and notification of suspected abuse. Exchange-service providers must maintain surveillance arrangements and provide VARA with relevant information, including information concerning significant exposures in correlated markets.
VARA’s jurisdiction does not extend to the entire United Arab Emirates. The Dubai International Financial Centre and Abu Dhabi Global Market operate separate financial-services regimes, and federal authorities also have relevant roles.
More broadly, jurisdictions are drawing on common international principles even when their licensing structures differ. The International Organization of Securities Commissions’ Policy Recommendations for Crypto and Digital Asset Markets (November 2023) address conflicts, market manipulation, surveillance, custody, operational risks and cross-border cooperation. The recommendations are not a single global law, but they provide a benchmark against which national regimes and platform controls can be assessed.
How the Framework Fits Together
The global framework is best understood as a sequence of linked questions rather than a single hierarchy of rules.
First, what asset, transaction and product are involved? Classification can determine whether securities, commodities, derivatives, crypto-asset-specific or payments rules apply. Second, where and how did the activity occur—on a centralized platform, derivatives venue, decentralized protocol, blockchain or across several connected markets? Third, which entity has both the legal responsibility and access to the relevant evidence?
One strategy can cross several regulatory and technical boundaries. An actor might acquire a token on an offshore spot exchange, build a position in a regulated derivatives product and transfer assets through self-hosted wallets or decentralized protocols. The spot platform, derivatives venue, blockchain analytics provider and regulator may each see a different part of the pattern.
This is why market surveillance, on-chain analytics, AML controls and regulator-level oversight are complementary but distinct. Effective supervision connects legal classification with venue records, blockchain evidence, account identity, cross-product activity and cross-border cooperation. No individual data source or authority should be assumed to supply the complete answer.
What Are the Limits of Digital Asset Trade Surveillance?
Digital asset markets can produce unusually rich transaction data, but surveillance remains subject to important limits.
Attribution is incomplete. A wallet address does not necessarily identify its controller. Labels and clusters may be outdated, contested or probabilistic, and a service address may aggregate many customers.
Blockchain visibility is partial. Centralized exchange orders, internal transfers and beneficial ownership may not appear on-chain. Privacy technologies, bridges, mixers and activity across multiple chains can complicate tracing. Conversely, a public transfer may reveal little about the parties’ purpose.
Market data is fragmented. A venue may not see trading on another platform, over the counter or through a decentralized protocol. External data can expand coverage, but its quality, timestamps, identifiers and availability may vary.
Intent is an evidentiary question. A suspicious order or transfer sequence may justify an inquiry without proving knowledge, coordination or manipulative purpose. Communications, control relationships and economic benefit may be necessary to distinguish abuse from coincidence or legitimate strategy.
Legitimate conduct can resemble misconduct. Arbitrage, market making, hedging, rebalancing, liquidation, airdrop claims and some transaction-ordering strategies can produce unusual patterns. Poorly calibrated surveillance can miss meaningful conduct or overwhelm reviewers with alerts.
The market changes quickly. New tokens, protocols, bridges, derivatives and incentive structures can make existing scenarios obsolete. Procedures and data coverage need periodic reassessment.
Regulatory reach is uneven. Offshore entities, decentralized governance, conflicting asset classifications and restrictions on cross-border information sharing may limit access to evidence or enforcement options.
Surveillance can make connected risk more visible and investigations more consistent and reproducible. It cannot, by itself, resolve every question of identity, intent, jurisdiction or legal classification.
Key Authorities
United States. Commodity Exchange Act, Section 6(c)(1), 7 U.S.C. § 9 and CFTC Rule 180.1, 17 C.F.R. § 180.1; Commodity Exchange Act, Section 5(d), 7 U.S.C. § 7(d) and 17 C.F.R. Part 38; Securities Exchange Act of 1934, 15 U.S.C. § 78a et seq.; SEC Interpretation, Release No. 33-11412 (March 2026); GENIUS Act, Pub. L. 119-27; Digital Asset Market Clarity Act of 2025, H.R. 3633.
European Union. Regulation (EU) 2023/1114 (MiCA), Title VI and Article 92; Commission Delegated Regulation (EU) 2025/885; Regulation (EU) No 596/2014 (MAR); Directive 2014/65/EU (MiFID II); ESMA supervisory guidelines on market abuse under MiCA (April 2025).
Hong Kong and Dubai. SFC circular on shared liquidity arrangements (November 2025); SFC high-level framework for virtual asset perpetual contracts (February 2026); VARA Market Conduct Rulebook; VARA Exchange Services Rules.
International. IOSCO, Policy Recommendations for Crypto and Digital Asset Markets (November 2023).
Frequently Asked Questions
What is digital asset trade surveillance?
Digital asset trade surveillance is the monitoring and investigation of orders, trades, transfers and related information for potential market manipulation, insider dealing, misuse of customer information and other market-conduct violations. It may combine centralized exchange data, blockchain activity, related derivatives information and customer or account records.
How is crypto trade surveillance different from traditional trade surveillance?
The underlying market-integrity concerns are often similar, but crypto markets are continuous, globally fragmented and split between centralized and decentralized infrastructure. Relevant evidence can include pseudonymous wallets, smart contracts, bridges, token events and activity across spot and derivatives markets. There is also no universal consolidated view of trading.
Is blockchain analytics the same as trade surveillance?
No. Blockchain analytics examines on-chain activity and may support AML, sanctions, fraud, asset-recovery or market-conduct work. Trade surveillance asks whether trading and related conduct violated market-abuse or venue rules. On-chain analytics is one potential source of evidence within that broader inquiry.
Who regulates crypto market manipulation in the United States?
The answer depends on the asset, product and intermediary. The SEC applies federal securities law where a digital asset or transaction is within its jurisdiction. The CFTC regulates crypto derivatives on registered markets and can pursue fraud and manipulation in spot digital asset commodity transactions. Other federal and state authorities may address AML, consumer protection, money transmission or criminal conduct. There is no single answer for every digital asset market.
Does MiCA require crypto market surveillance?
Yes, for entities within the relevant provision. Article 92 requires persons professionally arranging or executing transactions in in-scope crypto-assets to maintain effective arrangements, systems and procedures to prevent and detect market abuse and to report reasonable suspicions. The obligation is role-specific and does not apply to every participant in an in-scope crypto-asset market.
Can decentralized trading be monitored?
Often, at least in part. Public blockchains can reveal swaps, transfers, smart-contract interactions and transaction ordering. Monitoring can identify patterns across wallets and protocols, but attribution, off-chain coordination and the identity of a responsible operator may remain uncertain. The legal duty to monitor depends on the applicable regime and the role of the entity involved.
Does suspicious on-chain activity prove market manipulation?
No. An on-chain pattern can be a useful lead, but it must be assessed alongside market conditions, order and account records, wallet attribution, related positions, communications and the legal elements of the suspected violation. A visible transaction does not by itself establish identity, coordination or intent.
Related Resources
- Digital Asset Regulation — the classification and agency framework governing digital assets in the United States.
- Crypto Fraud & Asset Recovery — fraud typologies, tracing and recovery of misappropriated digital assets.
- Oracle Manipulation — how distorted price feeds affect settlement, collateral valuation and automated liquidation.
- Crypto Pump-and-Dump Schemes — coordinated accumulation, promotion and rapid selling in thinly traded tokens.
- Pig Butchering — relationship investment scams and the platform and blockchain signals that expose them.
- Whistleblower Programs — the SEC and CFTC whistleblower programs, a parallel channel through which misconduct reaches regulators.
- Financial Markets Trade Surveillance — the general principles and institutional framework for trade surveillance in traditional financial markets, on financialmarkets.law.
Further Reading
Insightful thought leadership, offered as a resource for readers.
Eventus Systems, Inc. · March 2026
Published by Eventus, a trade surveillance software vendor, without a credited individual author; the piece closes with a description of the vendor’s own products. It argues that extended-hours trading, tokenized equities and prediction markets are eroding the boundary between traditional and digital asset markets, and that surveillance calibrated for one market structure carries over poorly to the other, particularly where reference prices are less stable and trading never pauses.
Martina Rejsjö · Eventus Systems, Inc. · July 2025
Published by Eventus, a trade surveillance software vendor, and written by its Head of Product Strategy. The author argues that surveillance conducted within single asset-class silos misses conduct whose economic purpose spans related products and venues, and makes the case for cross-product analysis that follows the activity rather than the instrument.
Pig-Butchering, Evolving Schemes and Surveillance
Joseph Schifano · Eventus Systems, Inc. · December 2022
Published by Eventus, a trade surveillance software vendor, and written by its Global Head of Regulatory Affairs at the time; the piece closes with a description of the vendor’s own product. It discusses a FINRA regulatory notice on pump-and-dump-like schemes in thinly traded small-cap initial public offerings, in which victims recruited through social media are induced to buy the inflated shares, and summarizes the trading indicators FINRA suggested member firms watch for. The piece addresses securities markets rather than digital assets specifically.
Eventus Systems, Inc., a trade surveillance software vendor, contributed to the drafting of this page. Neither party paid the other for its contribution, and G. Dowd Law LLC retains editorial control.