Strategies II: Volatility, Relative Value, Macro and the Bank Desks · Strategies
29Manipulative Strategies and How They Are Caught
A trader placed large orders he never meant to fill, cancelled them within a fraction of a second, and traded the other side of the price move they caused. In United States v. Coscia the Seventh Circuit upheld his conviction, the first under the Commodity Exchange Act’s anti-spoofing provision. The evidence was in the order log: 24 814 large orders in three months of 2011, of which 0.5% traded, against small orders on the other side of which about 52% were filled. This chapter describes each manipulative practice only as far as the public record does: how it works, why it is illegal or contested, the case that established it, and the detector that finds it. On synthetic account-days, a detector that combines the two features of the Coscia record catches 77% of planted spoofing at a 1% false-positive rate. The order-to-trade ratio, often quoted as a spoofing signal, catches none: market makers cancel more than spoofers do. The build is firm.surveil.
29.1 Spoofing and layering
Definition 29.1 (Spoofing)
Spoofing is bidding or offering with the intent to cancel the bid or offer before execution, so as to create a false impression of supply or demand and trade against the price move it causes.
Definition 29.2 (Layering)
Layering is spoofing with several orders placed at successive price levels on one side of the book, kept away from the best price so that they are seen but unlikely to trade.
How it works. In the Coscia opinion’s account, a program placed a small order on one side and large orders on the other. The large orders suggested supply or demand that did not exist, and moved the price towards the small order, which filled. The large orders were then cancelled, and the process ran in reverse. Each cycle took about two-thirds of a second. It was repeated to more than 450 000 large orders and earned $1.4 million. The CFTC described Sarao’s version in the E-mini S&P 500 future: from 2009 a modified trading platform layered four to six exceptionally large sell orders, one price level apart and at least three or four levels from the best ask, and most were cancelled without trading.
Why it is illegal. The Dodd-Frank Act of 2010 added to the Commodity Exchange Act a prohibition on spoofing, defined as bidding or offering with the intent to cancel before execution. The EU’s Market Abuse Regulation treats orders that give false or misleading signals as manipulation, including orders placed and cancelled by algorithms, and lists as an indicator orders that change the best bid or offer or the book’s representation and are removed before they execute. The offence is the intent, not the cancellation: most orders are cancelled, and Coscia argued that high-frequency traders cancel 98% of theirs.
The enforcement cases. Coscia was convicted on all counts, sentenced to 36 months and lost his appeal in August 2017. The court found intent in the program’s design: it cancelled the large orders after a set time, if the small orders filled, or if a single large order filled. Sarao was charged by the CFTC and the Justice Department in April 2015. The CFTC alleged that he used the layering program on more than 400 trading days, made more than $40 million, and applied close to $200 million of persistent selling pressure for two hours before the Flash Crash of 6 May 2010. In November 2016 he consented to a penalty of $25.7 million and disgorgement of $12.9 million.
As of September 2026 — The law
In the United States, 7 U.S.C. 6c(a)(5)(C) makes it unlawful to engage in trading that is, is of the character of, or is commonly known to the trade as spoofing, defined as bidding or offering with the intent to cancel the bid or offer before execution. In the EU, Article 12 of the Market Abuse Regulation defines market manipulation to include false or misleading signals, trading at the open or close that misleads investors, algorithmic orders that initiate or exacerbate a trend, and the manipulation of benchmarks. Its Annex I lists indicators, among them transactions with no change of beneficial ownership and orders removed before execution after changing the book’s appearance.
29.2 Momentum ignition and marking the close
Definition 29.3 (Momentum ignition)
Momentum ignition is entering orders or trades intended to start or exaggerate a price trend so that other traders’ responses move the price further, and trading against the move they cause.
Definition 29.4 (Marking the close)
Marking the close (banging the close) is trading heavily just before and during the closing period to move the closing or settlement price, to benefit a position whose value depends on that price.
How they work. The Market Abuse Regulation names orders that initiate or exacerbate a trend as manipulation; the chapter found no enforcement case that uses the term momentum ignition, and the CFTC’s Sarao complaint describes spoofing designed to cause price swings that could be exploited. Marking the close is better documented. In the CFTC’s Optiver case, traders accumulated large Trading at Settlement positions, priced at the day’s settlement, in NYMEX crude oil, heating oil and gasoline futures. They then traded futures in the opposite direction shortly before and during the close, to push the settlement in their favour.
Why it is illegal. Trading at the close that misleads investors relying on closing prices is manipulation under the Market Abuse Regulation, and trading timed to move settlement and reference prices is one of its indicators. In the United States it is manipulation or attempted manipulation under the Commodity Exchange Act.
The enforcement case. The complaint alleged 19 attempts in March 2007, at least 5 of them successful, and false statements to NYMEX. NYMEX’s own surveillance detected the trading. In April 2012 a consent order imposed a $13 million civil penalty and $1 million in disgorgement, trading limits on Optiver, and trading bans of two to eight years on three former officers.
29.3 Wash trades and benchmark manipulation
Definition 29.5 (Benchmark manipulation)
Benchmark manipulation is submitting false inputs to a benchmark, or trading or coordinating to move the data it is calculated from, to benefit positions valued at the benchmark.
How they work. A wash trade (Book 3, chapter 16) has the same beneficial owner on both sides, so it creates volume and prices without a change of ownership. In October 2024 the SEC charged three firms that described themselves as market makers, and nine individuals, with selling market manipulation as a service to crypto-asset promoters. They were alleged to have self-traded and used bots that at times generated billions of dollars of artificial volume a day. Cong and co-authors estimated wash trading at over 70% of reported volume on unregulated crypto exchanges. Benchmark manipulation is best known from the foreign exchange fixes. In May 2015 four banks agreed to plead guilty to conspiring to manipulate the euro-dollar rate: their traders, in a chat room called “The Cartel”, coordinated around the 1:15 p.m. ECB and 4:00 p.m. WM/Reuters fixes (Book 2, chapter 17).
Why they are illegal. Transactions with no change of beneficial ownership are an indicator of manipulation under the Market Abuse Regulation, and manipulating a benchmark’s calculation is manipulation under its Article 12. In the United States, wash trades in futures are prohibited by the Commodity Exchange Act, and securities manipulation by the securities laws.
The enforcement cases. The foreign exchange guilty pleas carried fines of more than $2.5 billion. The SEC’s 2024 case was part of an investigation in which the FBI created a token of its own and the firms were alleged to have manipulated its market.
29.4 Sandwiching and its legal status
A sandwich attack (Book 3, chapter 22) buys ahead of a victim’s pending swap on a decentralised exchange and sells right after it, in the same block, so the victim trades at a worse price. It uses information that the blockchain makes public by design: pending transactions in a public mempool. Users can avoid it by sending transactions through private channels, and services such as Flashbots Protect hide transactions from sandwich bots. Whether sandwiching is front-running in the legal sense, manipulation or neither is unsettled: the chapter found no court ruling on it in the record it searched, and it names no case.
29.5 Surveillance: detectors and their errors
firm.surveil builds account-days, one row per account per day, from legitimate types chosen to trip naive detectors, and plants 100 episodes of each manipulation with the patterns described in the enforcement records. Among 11 500 legitimate account-days there are 5 000 market makers who cancel almost everything, 3 000 who refresh all their quotes after every fill, 1 500 deep-book providers whose large orders far from the touch rarely fill, and 2 000 directional traders. Each detector gets a threshold set so that 1% of legitimate account-days are flagged (Listing 29.1):
| practice | detector | caught | most flagged legitimate type |
|---|---|---|---|
| spoofing | order-to-trade ratio | 0% | market makers (1.8%) |
| fill-rate gap, small and large | 37% | deep providers (7.7%) | |
| cancels after fills | 51% | quote refreshers (3.8%) | |
| gap cancels | 77% | deep providers (7.7%) | |
| marking the close | share of volume at the close | 1% | index funds (3.7%) |
| share next-day reversal | 21% | index funds (3.7%) | |
| settlement position | 61% | index funds (3.3%) | |
| wash trades | self-matched trades | 74% | multi-algorithm firms (4.0%) |
| share of trades self-matched | 97% | multi-algorithm firms (5.0%) |
The order-to-trade ratio fails because the spoofer’s defining behaviour is not cancelling a lot: market makers cancel more. It is cancelling one kind of order and trading another, which is the Coscia testimony: two order sizes in use, with very different cancellation rates. Each half of that pattern has innocent explanations. Deep-book providers’ large orders rarely fill; quote refreshers cancel right after fills. Only together do the two features separate the spoofers (Figure 29.1). Closing-window volume alone flags index funds, which must trade at the close; reversal and a position priced at the settlement are what the Optiver record adds. Self-matches flag firms whose independent algorithms occasionally cross, so the share of an account’s trades that self-match works better than the count.
s2_surveil.roc.A surveillance alert is where an investigation starts, not the verdict. At a 1% false-positive rate, 115 legitimate account-days are flagged for every 77 true spoofing episodes caught in this sample. Real surveillance ranks alerts, reads the orders behind them and looks for intent, as the courts did (Figure 29.2).
s2_surveil.detectors.29.6 Strategy files
The seven manipulative practices below are described, in the order this series requires, by how they work, why they are illegal or contested, the enforcement case and the surveillance detector. The last file is the surveillance desk’s own.
Strategy file 29.1 — Spoofing
Who is harmed. Traders who respond to displayed orders and trade at prices moved by orders that were never meant to trade.
Instruments and venues. Futures and other markets with visible central limit order books.
How it works. Large orders on one side, cancelled before they can trade, and small orders on the other that fill after the price moves.
Why it is illegal. Bidding or offering with intent to cancel before execution: 7 U.S.C. 6c(a)(5)(C); false or misleading signals under the Market Abuse Regulation.
Enforcement case. United States v. Coscia (7th Cir. 2017): 36 months, conviction affirmed.
Surveillance detector. Small and large orders’ fill rates compared, with large cancellations right after fills on the other side.
How it is caught. Exchange and regulator surveillance of order logs; intent read from program design and trading records.
Evaluating the detector honestly. Legitimate look-alikes in the evaluation (deep-book providers, quote refreshers); false positives at the threshold used.
Sources. Seventh Circuit opinion (2017); this chapter: 77% caught at 1% false positives.
Strategy file 29.2 — Layering
Who is harmed. Traders reading the depth of the book.
Instruments and venues. Deep, visible order books; the E-mini S&P 500 in the Sarao case.
How it works. Several large orders at successive levels, kept away from the best price and cancelled, as in the CFTC’s account.
Why it is illegal. Spoofing under US law; orders that change the book’s representation and are removed before execution under the Market Abuse Regulation.
Enforcement case. CFTC v. Nav Sarao Futures Limited PLC and Sarao (2015): penalty and disgorgement of $38.6 million by consent (2016).
Surveillance detector. Persistent large orders several levels from the touch, re-priced as the market moves, with a near-zero fill rate.
How it is caught. Order-book reconstruction; complaints from other participants.
Evaluating the detector honestly. Market makers who quote size deep in the book look the same until trading on the other side is added.
Sources. CFTC press releases 7156-15 and 7486-16.
Strategy file 29.3 — Momentum ignition
Who is harmed. Traders whose algorithms follow short-term trends.
Instruments and venues. Electronic markets with trend-following participants.
How it works. Orders or trades intended to start or exaggerate a move, traded against as others follow.
Why it is illegal. Market Abuse Regulation Art. 12(2)(c)(iii): orders that initiate or exacerbate a trend.
Enforcement case. No case using the term was found; spoofing cases describe price swings caused to be exploited.
Surveillance detector. Bursts of aggressive orders followed by opposite trading and a reversal (Annex I indicator (e)).
How it is caught. Pattern alerts on concentrated trading with reversals.
Evaluating the detector honestly. Legitimate execution algorithms also trade in bursts; reversals are common.
Sources. Market Abuse Regulation, Art. 12 and Annex I.
Strategy file 29.4 — Wash trades
Who is harmed. Investors who read volume and prices as genuine interest.
Instruments and venues. Crypto assets on unregulated venues; futures; thinly traded securities.
How it works. Trading with oneself or a related account, with no change of beneficial ownership.
Why it is illegal. Prohibited in US futures and securities markets; an indicator of manipulation under the Market Abuse Regulation.
Enforcement case. SEC charges against three purported market makers and nine individuals (October 2024).
Surveillance detector. The share of an account’s trades matched against the same beneficial owner.
How it is caught. Beneficial-ownership data across accounts; exchange self-match prevention records.
Evaluating the detector honestly. Firms with independent algorithms cross each other by accident; counts penalise large honest traders.
Sources. SEC press release 2024-166; Cong and co-authors (2022); this chapter: 97% caught at 1% false positives.
Strategy file 29.5 — Marking the close
Who is harmed. Holders of positions and contracts priced at the close or settlement.
Instruments and venues. Futures settlements; closing auctions; Trading at Settlement contracts.
How it works. A position priced at the settlement, then heavy trading against it in the closing minutes, as in the CFTC’s Optiver account.
Why it is illegal. Manipulation under the Commodity Exchange Act; trading at the close that misleads investors under the Market Abuse Regulation.
Enforcement case. CFTC v. Optiver (consent order 2012): $14 million; trading bans for former officers.
Surveillance detector. Closing-window share of volume, with a reversal the next day and a position priced at the settlement.
How it is caught. Exchange surveillance of settlement windows; NYMEX detected Optiver’s trading.
Evaluating the detector honestly. Index funds must trade at the close; volume alone flags them.
Sources. CFTC press release 6239-12; this chapter: 61% caught at 1% false positives.
Strategy file 29.6 — Benchmark manipulation
Who is harmed. Everyone whose contracts reference the benchmark.
Instruments and venues. Foreign exchange fixes; interest-rate benchmarks; commodity assessments.
How it works. False submissions, or coordinated trading around the calculation window.
Why it is illegal. Market Abuse Regulation Art. 12(1)(d); price fixing and manipulation under US law.
Enforcement case. Four banks’ guilty pleas for foreign exchange fix manipulation (May 2015), fines over $2.5 billion.
Surveillance detector. Trading concentrated around calculation times, with communications review.
How it is caught. Communications surveillance; benchmark administrators’ data checks.
Evaluating the detector honestly. Clients’ fix orders are legitimately executed around the fix.
Sources. US Department of Justice (2015); Book 2, chapter 17.
Strategy file 29.7 — Sandwiching
Who is harmed. Users whose pending swaps are visible in a public mempool.
Instruments and venues. Decentralised exchanges on public blockchains.
How it works. A purchase before a pending swap and a sale after it, in the same block (Book 3, chapter 22).
Why it is contested. It exploits information public by design; no court ruling on it was found in the record searched.
Enforcement case. None named.
Surveillance detector. Pairs of transactions by one address bracketing another’s swap in the same pool and block.
How it is caught. It is avoided rather than caught: private transaction channels hide swaps.
Evaluating the detector honestly. Arbitrage that happens to bracket a swap looks alike.
Sources. Flashbots documentation.
Strategy file 29.8 — Detector: cancellation-pattern surveillance
Who pays you, and why. The venue, the broker or the firm itself, obliged to detect and report suspicious orders.
Instruments and venues. Every order log the firm or venue keeps.
Signal. Per account-day: the gap between small and large orders’ fill rates, times the share of large cancellations right after a fill on the other side.
Sizing and execution. A threshold set to the number of alerts investigators can read.
Costs. Investigators’ time; false positives.
How it dies. Manipulators who mix sizes and timings; legitimate strategies that drift into the pattern.
Horizon, capacity, infrastructure. Daily; complete, time-stamped order logs.
Backtest honestly. Evaluate on legitimate look-alikes, at the operating threshold, with the episodes labelled from real cases where possible.
Sources. United States v. Coscia (2017); this chapter: 77% at 1% false positives, against 0% for the order-to-trade ratio.
29.7 Tutorial: in the order log
Goal. Build account-days of legitimate types and planted episodes, score them with detectors drawn from the enforcement records, and measure each detector’s catch rate at a fixed false-positive rate. End state: the table and two figures.
The spoofing detectors.
def spoof_scores(d: dict) -> dict: """Order-to-trade ratio; the gap between small and large orders' fill rates (log ratio); the share of large cancellations that follow a fill on the other side; and the product of the last two (both must be high).""" orders = d["n_small"] + d["n_large"] fills = d["f_small"] + d["f_large"] otr = orders / np.maximum(fills, 1) gap = np.log((d["f_small"] + 1) / (d["n_small"] + 2)) - np.log((d["f_large"] + 1) / (d["n_large"] + 2)) linked = d["linked"] / np.maximum(d["c_large"], 1) return {"order-to-trade": otr, "fill-rate gap": gap, "cancel after fill": linked, "gap x cancel": np.maximum(gap, 0) * linked}Listing 29.1. Order-to-trade, fill-rate gap, cancels after fills, and both. code/firm/surveil/firm_surveil.py Evaluation.
def tpr_at_fpr(score, label, fpr: float = 0.01) -> dict: score, label = np.asarray(score, float), np.asarray(label) thr = np.quantile(score[label == 0], 1 - fpr) return {"threshold": float(thr), "tpr": float((score[label == 1] > thr).mean()), "fpr": float((score[label == 0] > thr).mean())} def flagged_by_type(score, d: dict, fpr: float = 0.01) -> np.ndarray: thr = tpr_at_fpr(score, d["label"], fpr)["threshold"] return np.array([(np.asarray(score)[d["kind"] == k] > thr).mean() for k in range(d["kind"].max() + 1)])Listing 29.2. The catch rate at the threshold that flags a fixed share of legitimate accounts. code/firm/surveil/firm_surveil.py - Run
detectors(),roc()andfig_surveil.py.
What to change next. Add a legitimate type that hedges options with small orders against large quotes; measure how many alerts per day an investigator would read; add the closing detector’s position data from a second source.
29.8 Build: surveillance
Purpose. Labelled account-days and detectors for spoofing, marking the close and wash trades, evaluated at fixed false-positive rates.
Interface. SurveilConfig(…), spoofing_days, close_days, wash_days, spoof_scores, close_scores, wash_scores, tpr_at_fpr(score, label, fpr), flagged_by_type.
Rules. Legitimate types chosen to trip each detector; episodes only as described in enforcement records; no manipulation’s profit modelled.
Acceptance tests. code/firm/surveil/tests/: the catch rate by hand; scores on two account-days; the combined detector beats its parts and the order-to-trade ratio fails; the self-match share by hand.
Stretch. Order-level logs; ranking alerts; detectors learned from labelled cases.
Sources and further reading
- United States v. Coscia, No. 16-3017 (7th Cir. 2017), 866 F.3d 782.
- Commodity Futures Trading Commission, press releases 7156-15 (21 April 2015), 7486-16 (17 November 2016) and 6239-12 (19 April 2012).
- Regulation (EU) No 596/2014 on market abuse, Article 12 and Annex I.
- US Department of Justice, press release on foreign exchange guilty pleas, 20 May 2015.
- Securities and Exchange Commission, press release 2024-166, 9 October 2024.
- L. W. Cong, X. Li, K. Tang and Y. Yang, “Crypto wash trading”, NBER Working Paper 30783, 2022.
29.9 Exercises
Exercise 29.1 ★
A trader placed 24 814 large orders, of which 0.5% traded. How many traded?
Solution
Solution of Exercise 29.1.
orders traded; the other 24 690 were cancelled.
Exercise 29.2 ★
At a 1% false-positive rate on 11 500 legitimate account-days, how many are flagged, and how many true episodes of 100 does a detector with a 77% catch rate find?
Solution
Solution of Exercise 29.2.
legitimate account-days flagged, against 77 true episodes: fewer than half the alerts are true.
Exercise 29.3 ★
Sarao’s consent order required a penalty of $25.7 million and disgorgement of $12.9 million. What was the total?
Solution
Solution of Exercise 29.3.
About $38.6 million.
Exercise 29.4 ★★
Why does the order-to-trade ratio fail to catch spoofers?
Solution
Solution of Exercise 29.4.
Cancelling a lot is what market makers do: they quote continuously and replace their quotes as prices move, and cancel more than the spoofers in the sample. What distinguishes a spoofer is cancelling one kind of order while trading another, which the ratio averages away.
Exercise 29.5 ★★
Why is closing-window volume alone a poor detector of marking the close?
Solution
Solution of Exercise 29.5.
Index funds and other investors must trade at the close, because their benchmarks are closing prices; heavy closing volume is their normal behaviour. The Optiver record adds what matters: a position priced at the settlement opposite to the closing trades, and a move that reverses.
Exercise 29.6 ★★
Why must intent, not cancellation, define spoofing?
Solution
Solution of Exercise 29.6.
Almost every order in modern markets is cancelled, and legitimate traders cancel when prices move or after fills; a rule based on cancellation alone would prohibit market making. The statute and the Market Abuse Regulation target orders placed to be cancelled, or to mislead, which courts infer from design and patterns, as in Coscia.
Exercise 29.7 ★★★
Coding. Run roc(). How many spoofing episodes does the combined detector catch at false-positive rates of 0.1% and 10%, and what does that mean for an investigator’s workload?
Solution
Solution of Exercise 29.7.
63% at a 0.1% false-positive rate (about 11 legitimate alerts) and 100% at 10% (about 1 150). Catching the last third of episodes costs a hundred times more alerts: the threshold is set by how many alerts investigators can read.
Exercise 29.8 ★★★
Find the flaw. “Our surveillance flagged no one with an order-to-trade ratio above our limit this year, so we have no spoofing.”
Solution
Solution of Exercise 29.8.
The order-to-trade ratio caught none of the planted spoofers and flagged market makers instead. Having no alerts from a detector that cannot see the pattern says nothing about whether the pattern is there.
29.10 Problem: In the Order Log
Problem 29.1
Weekend problem — manipulative strategies and surveillance
The public enforcement record and the chapter’s synthetic account-days.
Part I — Spoofing.
- Define spoofing and layering.
- What did the Coscia record show about his orders?
- What did the CFTC allege about Sarao?
- What does US law prohibit, and what does the Market Abuse Regulation list?
Part II — Other practices.
- Define momentum ignition and marking the close.
- What happened in the Optiver case?
- Define benchmark manipulation; what happened at the FX fixes?
- What did the SEC allege in 2024?
Part III — Surveillance.
- Describe the synthetic account types and why each is there.
- Give the detector table.
- Why does combining two features work?
- What is the legal status of sandwiching?
Part IV — The verdict.
- State the named result: each detector’s true-positive rate at a fixed false-positive rate, and how legitimate market making triggers them.
- What happens to an alert after the detector fires?
- How would you evaluate a detector honestly?
- What would a manipulator change to avoid the combined detector, and what would that cost the manipulation?
- Why do the enforcement cases matter to detector design?
- Which strategy file is legitimate?
- How does this chapter relate to chapter 24’s mark-outs?
- In one sentence: what separates a market maker from a spoofer?
Solution
Solution of Problem 29.1.
- Spoofing is bidding or offering with the intent to cancel before execution; layering is spoofing with several orders at successive levels kept away from the best price.
- Small and large orders on opposite sides; large orders cancelled after time, a small fill or a single large fill; 24 814 large orders of which 0.5% traded, small orders about 52% filled; over 450 000 large orders and $1.4 million.
- A modified platform layering four to six large sell orders three or four levels from the best ask, on over 400 days, profits over $40 million, and close to $200 million of pressure before the Flash Crash; $38.6 million by consent in 2016.
- Spoofing as defined in 7 U.S.C. 6c(a)(5)(C); the regulation lists false signals, trading at the close, orders that initiate trends, benchmark manipulation, and indicators such as orders removed before execution.
- Momentum ignition: orders intended to start or exaggerate a trend; marking the close: heavy trading at the close to move a closing price.
- Traders offset large Trading at Settlement positions by trading against them in the closing minutes; 19 attempts, 5 successful; $14 million.
- False inputs or coordinated trading to move a benchmark; four banks pleaded guilty in 2015 to manipulating fixes, with fines over $2.5 billion.
- Three purported market makers and nine individuals wash-traded crypto assets for promoters, with bots generating billions of dollars of volume a day.
- Market makers, quote refreshers, deep-book providers and directional traders, each tripping one detector; planted spoofers following the Coscia pattern.
- Spoofing: 0%, 37%, 51% and 77% caught; close: 1%, 21%, 61%; wash: 74% and 97%, each at 1% false positives.
- Each feature has innocent causes that rarely occur together; the spoofer’s pattern needs both.
- Unsettled: no court ruling was found; it is avoided by private transaction channels.
- At a 1% false-positive rate the combined spoofing detector catches 77% and the order-to-trade ratio 0%, flagging market makers; the close detector catches 61% and flags 3.3% of index funds; the self-match share catches 97% and flags 5.0% of multi-algorithm firms.
- It is ranked and investigated: the orders behind it are read, and intent is looked for in design, communications and records.
- On legitimate look-alikes, at the operating threshold, counting alerts per investigator, with episodes from real cases where possible.
- Mix order sizes and timings; the more the large orders look like genuine orders, the more often they trade, which is exactly the risk the manipulation was designed to avoid.
- They describe the observable patterns that define the offence and that courts accepted as evidence of intent.
- The cancellation-pattern surveillance detector.
- Mark-outs price a client’s information; surveillance asks whether an account’s orders were meant to trade at all.
- The market maker’s orders are meant to trade; the spoofer’s are meant not to.
29.11 Interview questions
Interview question 29.1 ★ trader
You cancel 95% of your orders. How do you show you are not spoofing?
Solution
Solution of Interview question 29.1.
By showing that orders are genuine: they trade at similar rates across sizes and sides given their distance from the touch, cancellations follow price moves and risk limits rather than fills on the other side, and the code’s cancellation rules have legitimate purposes, documented before trading.
Interview question 29.2 ★★ researcher
Design a spoofing detector from an order log, and say how you would test it.
Solution
Solution of Interview question 29.2.
Per account and day, compare fill rates of large and small orders and the timing of large cancellations relative to fills on the other side; score their combination; test on labelled cases and on legitimate strategies chosen to look similar; report the catch rate at the operating false-positive rate.
Interview question 29.3 ★★ trader
You hold a large position priced at today’s settlement. What may you do in the closing minutes?
Solution
Solution of Interview question 29.3.
Trade for genuine reasons (hedging, client orders) in ways that do not aim to move the settlement; avoid concentrating trading against the position in the closing window; document the reasons; check the firm’s rules and the venue’s.
Interview question 29.4 ★★ risk
What controls should a trading firm have against its own algorithms manipulating markets?
Solution
Solution of Interview question 29.4.
Pre-trade review of algorithms’ cancellation and order-size logic; self-match prevention; surveillance of the firm’s own order logs with the detectors above; limits on closing-window trading against settlement-priced positions; communications surveillance; training and escalation.
Interview question 29.5 ★★ developer
What must an order log record for surveillance to work?
Solution
Solution of Interview question 29.5.
Every order event (new, modify, cancel, fill) with exchange and local timestamps, account and beneficial owner, algorithm and version, price, size, side and venue, and the reason for cancellations where the system knows it; kept complete and unaltered.
Interview question 29.6 ★★★ researcher
A detector flags 1% of 11 500 legitimate account-days and 77 of 100 episodes. What share of alerts are true, and what happens to it if episodes are ten times rarer?
Solution
Solution of Interview question 29.6.
of alerts are true. With ten episodes instead of 100 and the same threshold, : rarer offences make every detector’s alerts mostly false.