What venue surveillance looks for
Displayed depth appeared on one side, the price moved toward it, and the depth vanished before anything traded against it. Or a stream of trades printed at a price with no apparent change in anyone’s position.
Both are patterns a venue’s surveillance function exists to detect, because both create a picture of supply and demand that does not correspond to willingness to trade. This post describes what those patterns look like from the outside, so that a reader can recognise having read a book that was misleading them. It is deliberately not a description of how to produce any of them: the operational detail is omitted, the conduct is prohibited by venue rules, and the reason it is worth naming at all is defensive.
Why a venue watches its own book
A venue’s product is a price that means something. Every mechanism on it — stop triggers, index composition, mark prices and liquidations — references prints and quotes, so a false quote or a meaningless print propagates into consequences for participants who did nothing.
That makes surveillance a self-interested function rather than a courtesy. A venue whose displayed depth cannot be relied on is a venue whose participants price wider, quote less, and eventually leave. Venues therefore publish rules prohibiting certain order behaviour and run monitoring to find it, and both the rules and the monitoring are venue matters rather than anything this site can characterise for any jurisdiction.
Orders that were never intended to trade
The first family. The common element is quantity displayed in order to be seen rather than to be executed, and withdrawn before it can be.
Spoofing is the general term: resting orders entered with the intention of cancelling before execution, so that the displayed imbalance influences how others price. Layering is the same idea distributed across several price levels rather than one.
What makes these detectable is that intention leaves a statistical signature over time. An order genuinely seeking a fill is sometimes filled. A body of orders that is systematically withdrawn as the price approaches, and systematically replaced when it recedes, has a fill rate and a cancel-to-order ratio unlike anything a participant seeking execution produces. Surveillance works on that distribution, not on any single order — which is why no individual cancellation is evidence of anything, and cancelling orders is entirely ordinary.
What it does to you, if you were reading the book: you priced against depth that was never available. Displayed quantity is an offer, not a commitment, and this is the case where the gap between the two was the point.
Trades that transfer nothing
The second family. Here the deception is in the tape rather than the book.
A wash trade is a trade in which the same beneficial owner is on both sides, so no position and no risk changes hands. Matched orders achieve the same thing between coordinating parties. In both cases a print appears, volume is recorded, and nothing economically happened.
The effect on anyone reading that record is direct. Volume figures include the print. A last-price display shows it. Anything computing an average from prints incorporates it. So a market can appear active at a price where no willingness to transact existed, and every caveat about volume figures becomes sharper: the tape records matches, and a match is not proof that anyone took on anything.
Venues counter the mechanical half of this with self-trade prevention, which stops two orders from the same account matching each other at all — a rule with ordinary consequences for ordinary orders as well.
Patterns that overload rather than deceive
A third family, distinct because the mechanism is capacity rather than misdirection.
Quote stuffing is a volume of order and cancel messages large enough to burden the systems that publish and consume market data. It does not need to convey a false picture; it is enough that the reconstruction on someone’s screen falls behind while the engine does not.
Venues address this structurally more than by detection — message rate limits, order-to-trade ratio requirements, and charges for excessive messaging. Those controls are visible to every participant as plumbing, and their existence is a reasonable clue that the underlying problem is real.
Momentum ignition and ramping describe orders sent to provoke a price move rather than to transact at the current price. Mechanically they overlap with ordinary aggressive execution, which is why this category is the hardest to distinguish and the one where a single episode proves least.
The mechanism
THE MECHANISM — patterns and what they do to you
· Depth appears, price approaches, depth
is withdrawn
→ you priced against quantity that
was never available to trade.
· Systematic cancellation before
execution
→ leaves a fill-rate and cancel-
ratio signature. Surveillance
works on the distribution.
· A single cancelled order
→ EVIDENCE OF NOTHING. Cancelling
is ordinary and constant.
· Same owner on both sides of a print
→ volume recorded, no position
transferred. The tape cannot tell
you which prints these were.
· Very high message rates
→ your reconstruction falls behind
while the engine does not.
· Reading depth or volume as intent
→ NO GUARANTEE either reflects
willingness to trade. Both are
displays, not commitments.
· Which rules exist, message limits,
order-to-trade requirements and
self-trade handling
→ VENUE-SPECIFIC. Published as
venue rules, and they differ.
Worked example
Illustrative figures, synthetic throughout, and written from the position of someone reading the book rather than acting on it.
Suppose the ask side shows 40,004 for 1.2 units and the bid side shows 40,000 for 30.0 units, with the next bid levels also unusually thick. Read naively, that is a heavily one-sided book: a great deal of buying interest close to the current price.
Someone pricing a sell order against that picture might rest at 40,004 rather than crossing, on the basis that the price is well supported. The mechanically honest description of what they have done is: they have accepted execution uncertainty on the strength of displayed quantity.
Now suppose the 30.0 at 40,000 is withdrawn in the moment before any of it trades, and the best bid becomes 39,950 for 0.5. Nothing traded, nothing printed, and the entire basis of the earlier reading has disappeared without leaving a record anywhere except in the sequence of book updates.
That outcome is identical whether the quantity was withdrawn because a participant changed their assessment — which is ordinary, permitted and constant — or because it was never meant to trade. From the outside the two are indistinguishable in the moment, and only a distribution over many episodes separates them. Which is precisely why the defensive conclusion cannot be “identify the manipulation” and has to be “do not treat displayed depth as capacity in the first place”.
The failure mode
Nothing above supports diagnosis. A reader cannot determine from a book or a tape whether a particular pattern was prohibited conduct, and asserting that any specific participant or venue is doing something wrong is not something this site does or could support. What the material supports is calibration.
The characteristic trap is the one the patterns are designed to exploit: treating the book as a statement about what other participants will do. It is a record of what they have currently published, which they may retract for reasons ranging from ordinary risk management to conduct their venue prohibits, and the display is identical across that whole range.
The second trap is on the other side of it. Reading every disappearance of depth as manipulation is a different error with the same root — inferring intention from a display that does not carry any. Cancellation rates in continuously quoted markets are high for entirely mechanical reasons, and most withdrawn quantity is a participant declining to bear a risk they have just repriced.
The durable statement is narrow and it holds in both directions: displayed depth is not capacity, printed volume is not transferred risk, and any cost estimate that depends on either being trustworthy has an unquantified error term.