Market Manipulation. Search

Spoofing

Spoofing is placing orders a trader intends to cancel before execution, to create a false impression of supply or demand and move the price toward a smaller genuine order on the other side.

Also called non-bona-fide orders, phantom liquidity, flashing. Observed in futures, equities, options, Treasuries, crypto derivatives. One of the order-book manipulation techniques. 114 enforcement actions in the library.
Updated 2026-09-07

How does spoofing work?

Spoofing works by exploiting the fact that other participants read the order book as information. In an electronic market, the visible depth on each side of the book is one of the few public signals about where the price is likely to go next. A trader who can put a convincing but insincere signal into that book can move the price a tick, and a tick is enough.

The mechanic runs in five steps.

  1. Take the position you actually want. The trader places a modest genuine order — say, 200 contracts to sell at the current offer. This order is real. It is intended to trade, and the trader wants it filled at the best possible price.

  2. Post a large order on the opposite side. The trader then places a much larger order to buy, several price levels deep or just behind the touch. It might be six thousand contracts against the genuine two hundred. This order is not intended to trade. It is intended to be seen.

  3. Let the market read the imbalance. Other participants — human traders, market-making algorithms, and momentum strategies keyed to book imbalance — observe apparent demand far exceeding apparent supply. Market makers shade their quotes up to avoid being adversely selected. Momentum algorithms buy. The price drifts toward the large order.

  4. Execute the genuine order into the demand you manufactured. The small sell order fills at a price a tick or two better than it would otherwise have achieved. That improvement is the entire profit.

  5. Cancel the large order. Often within milliseconds of the fill, sometimes before. The apparent demand vanishes. The book returns to where it was, and the trader keeps the improvement.

The profit on any single cycle is trivial — a tick on two hundred contracts. The strategy only works because it can be repeated hundreds or thousands of times a day at machine speed. That repetition is also its weakness, because it turns a judgement call about one order into a statistical pattern across a hundred thousand.

A spoofed order bookAn order book with three ask levels above the mid and four bid levels below. One bid level, 6,000 shares at 50.00, is drawn in the alert colour and dashed: it dwarfs every genuine level and is placed to be cancelled before it can trade, creating the appearance of demand that pulls the price toward the spoofer’s smaller genuine sell order.Order book Size Price Note 300 50.06 400 50.05 250 50.04genuine sell interest 200 50.02the order the spoofer wants filled 350 50.01 6,000 50.00large order, never meant to trade 300 49.99 asks bidsThe oversized bid is the signal; the small order on the other side is the trade.
The oversized bid at 50.00 is the signal. The 200-lot at 50.02 is the trade.

A worked example with real numbers

Assume a futures contract trading around 50.00, with a tick size of 0.01 and a contract multiplier of $100 per point — so one tick is worth $1 per contract.

The book before the spoof shows roughly balanced depth: about 850 contracts bid across the top three levels, about 950 offered. The spoofer wants to sell 200 contracts.

StepActionPriceSizeIntent
1Place genuine sell50.04200To trade
2Place large bid50.006,000To be cancelled
3Book imbalance shifts to roughly 7.4 : 1 bid
4Genuine sell fills as buyers lift the offer50.04200Filled
5Cancel the large bid50.006,000Cancelled unexecuted

Without the spoof, the realistic fill was 50.03 — the trader would have had to cross the spread or wait. With it, the fill came at 50.04. One tick of improvement on 200 contracts at $100 per point:

200 contracts × 0.01 points × $100 per point = $200

Two hundred dollars. Run the cycle 60 times in a session and it is $12,000 a day. Run it across three products for two years and it is several million dollars, which is roughly the scale of alleged gain that appears in the larger spoofing complaints.

Now note what the arithmetic implies for detection. To make real money, the trader must place the large order and cancel it thousands of times, and must do so in a way that is systematically related to fills on the other side. No single cancellation proves anything. Ten thousand of them, with a median lifetime of 340 milliseconds and a cancellation rate on the large side of 99.7%, prove a great deal.

Why is spoofing illegal?

Spoofing is illegal because the order it places is a lie. Securities and commodities law does not require traders to be right, prudent or profitable, but it does require that an order displayed to the market be a genuine offer to trade. An order placed with the intention of cancelling it before execution is not an offer at all; it is a message crafted to deceive everyone who reads the book.

In commodities and futures, the prohibition is explicit. Section 4c(a)(5)(C) of the Commodity Exchange Act, added by the Dodd-Frank Act in 2010 and codified at 7 U.S.C. § 6c(a)(5)(C), makes it unlawful to engage in any trading practice that “is, is of the character of, or is commonly known to the trade as, ‘spoofing’”, defined as bidding or offering with the intent to cancel before execution. That statutory definition matters: it means a spoofing charge does not require proof that the price actually moved, or that anyone actually lost money. Intent at the moment of placement is the offence.

The CFTC also charges spoofing under its general fraud-based manipulation rule, 17 C.F.R. § 180.1, and under the price manipulation provisions of 7 U.S.C. § 9. Rule 180.1 was modelled on SEC Rule 10b-5 and reaches manipulative or deceptive devices in connection with any swap or contract of sale of a commodity.

In securities, there is no dedicated anti-spoofing statute. Cases are brought under Exchange Act § 9(a)(2), which prohibits transactions creating actual or apparent active trading for the purpose of inducing others to buy or sell, and under § 10(b) with Rule 10b-5, the general antifraud provision. Section 17(a) of the Securities Act reaches the same conduct in offers and sales. FINRA additionally enforces Rule 2020 and Rule 5210 against its member firms, which is why an equity spoofing matter often produces a FINRA action alongside or instead of an SEC one.

Criminally, the Department of Justice charges spoofing under 18 U.S.C. § 1348, the securities and commodities fraud statute, which carries a statutory maximum of 25 years. Prosecutors have also charged wire fraud, and in a number of matters have added conspiracy and, more controversially, racketeering counts where a desk’s conduct was sustained and collective.

The crypto position is narrower than people assume. The CFTC treats bitcoin and ether as commodities, so spoofing on a derivatives venue in those assets falls within the anti-spoofing provision. Spot crypto trading on a venue outside the CFTC’s registration perimeter is a harder case — the agency has asserted fraud-based authority under § 180.1 over spot markets, but the statutory anti-spoofing provision is tied to trading “on a registered entity”. Where a token is a security, the SEC’s antifraud provisions apply on their own terms.

Provisions most often charged
ProvisionCitationPrimary text
Commodity Exchange Act — the anti-spoofing provision7 U.S.C. § 6c(a)(5)(C) Read the text
Commodity Exchange Act — general anti-manipulation authority7 U.S.C. § 9(1) Read the text
CFTC Rule 180.1 — fraud-based manipulation17 C.F.R. § 180.1 Read the text
Securities Exchange Act — manipulative transactions15 U.S.C. § 78i(a)(2) Read the text
Securities Exchange Act — general antifraud15 U.S.C. § 78j(b) Read the text
SEC Rule 10b-517 C.F.R. § 240.10b-5 Read the text
Commodities fraud (criminal)18 U.S.C. § 1348 Read the text

Which real enforcement actions have alleged spoofing?

This library holds 114 enforcement actions tagged spoofing. The table shows the largest by civil penalty together with the most recently filed. Every row links to a page carrying the regulator's own release and, where one was published, the complaint.

Selected spoofing actions
Action Agency Filed Penalty Status
CFTC v. HSBC Bank USA (cash vs derivatives schemes, 2023) CFTC 2023-11-07 $1.7bn filed
CFTC v. The Bank of Nova Scotia (spoofing, 2020) CFTC 2020-08-19 $50m judgment
CFTC v. HSBC Bank USA (spoofing, 2023) CFTC 2023-05-12 $45m judgment
CFTC v. unnamed respondents (cash vs derivatives schemes, 2022) CFTC 2022-10-20 $41m judgment
CFTC v. Navinder Singh Sarao (layering, 2016) CFTC 2016-11-18 $38m judgment
SEC v. Frank M. Cerisano Jr. (spoofing, 2026) SEC 2026-08-10 judgment
SEC v. Mingran Wang (spoofing, 2026) SEC 2026-06-25 settled
CFTC v. New York Trader (spoofing, 2026) CFTC 2026-05-06 $200k judgment

All 114spoofingactions →

How does spoofing get detected?

Spoofing is detected statistically, not by watching a screen. Exchanges hold the complete order audit trail — every message, timestamped to the microsecond, attributed to an account — and surveillance systems run pattern queries across it continuously.

The core analytics are these.

Order-to-trade ratio. The number of order messages a participant sends per executed contract. Every venue publishes norms and most set thresholds. A ratio well above the norm is not itself an offence, and legitimate market makers routinely run high ratios, so the metric is a filter rather than a finding.

Order lifetime distribution. Genuine orders have a long-tailed lifetime distribution: some fill immediately, some rest for minutes. A spoofing strategy produces a distribution with a sharp spike in the first few hundred milliseconds and almost nothing after it, because the order’s purpose is served the moment it is seen.

Size asymmetry keyed to fills. The strongest signal, and the one that appears in almost every complaint: repeated episodes in which a large resting order on one side is cancelled within milliseconds of an execution on the other side, where the executed size is a small fraction of the cancelled size. Surveillance systems count these episodes and compute the conditional probability of cancellation given a contra-side fill.

Cross-market correlation. Manipulation of a futures contract to profit in the related cash market, or of one venue’s book to profit on another, only shows up if the data are joined. The CFTC’s and SEC’s cross-market surveillance and FINRA’s consolidated audit trail exist substantially for this purpose.

Message-level reconstruction. Once a pattern is flagged, investigators rebuild the book state at the microsecond of each decision and ask whether the trader’s own orders explain the price movement they then benefited from.

Alongside the data sits ordinary investigative work: chat transcripts, algorithm parameters, source code comments, and the internal compliance alerts a firm generated and then closed.

What penalties does spoofing actually attract?

The numbers below are computed from this site's own case records at build time, not quoted from a secondary source. They change whenever a new action is added to the library.

Actions recorded
114
Median penalty
$600k
Largest penalty
$1.7bn
Criminal parallel
30%
Median sentence
13y 5m

Computed from 114enforcement actions in our own case library tagged spoofing , filed between 2013 and 2026. Median penalty covers the 63actions where a civil monetary penalty was disclosed; median sentence covers the 2 defendants who received a custodial term. Penalties exclude disgorgement and prejudgment interest, which are reported separately on each case page.

Largest single penalty: CFTC v. HSBC Bank USA (cash vs derivatives schemes, 2023) .

What are the red flags?

Spoofing is hard for an outsider to see directly, because the order book updates faster than a human can read it and cancelled orders leave no trace on the tape. These are the signals that are actually observable.

For a compliance function inside a trading firm, the practical controls are narrower and better: monitor cancel rates per trader per product against that trader’s own history, alert on contra-side fills within a fixed window of a large cancellation, and require a written explanation for any strategy whose displayed size routinely exceeds its executed size by more than an order of magnitude.

What spoofing is not

Three distinctions are worth drawing precisely, because they are frequently blurred.

Spoofing is not high-frequency trading. Speed is a capability, not an offence. The great majority of high-frequency activity is market making, arbitrage and execution — lawful, and in most studies associated with narrower spreads. Spoofing happens to be practical at high frequency, which is a different claim.

Spoofing is not the same as quote stuffing. Quote stuffing floods a venue with messages to degrade competitors’ ability to process data. Its target is the infrastructure. Spoofing’s target is the inference other participants draw from the book. They can occur together, and are sometimes charged together, but the theory of harm differs.

Spoofing is not aggressive order placement. A trader who genuinely wants to buy 6,000 contracts and posts them, then cancels because the market moved, has done nothing wrong. The entire question is what the trader intended at the moment of placement — which is why these cases are, in the end, evidentiary rather than technical.

Frequently asked questions about spoofing

Is spoofing illegal in the United States?
Yes. Spoofing in commodities and futures is expressly prohibited by 7 U.S.C. § 6c(a)(5)(C), added by the Dodd-Frank Act in 2010. In securities it is charged under the Exchange Act's antifraud and anti-manipulation provisions. Both the CFTC and the SEC bring civil actions, and the Department of Justice prosecutes it criminally.
What is the difference between spoofing and layering?
Layering is spoofing spread across several price levels at once. A spoofer may post one outsized order; a layerer posts a stack of orders at successive prices to build an apparent wall of depth. The legal analysis is identical, and regulators frequently charge both terms in the same complaint.
Is cancelling an order illegal?
No. Cancellation is ordinary, lawful and constant — most orders in modern electronic markets never trade. What makes spoofing unlawful is intent: the order was placed with the intention to cancel it before execution, so it was never a genuine offer to trade at all.
How do regulators prove intent to cancel?
Rarely from a confession. They rely on patterns across thousands of orders — cancellation timing, size asymmetry, the relationship between the large side and fills on the small side — plus chat messages, code comments, and the algorithm's own parameters where an automated strategy was used.
Can a trading algorithm spoof without a human intending it?
An algorithm can produce the pattern, but liability follows the people who designed, configured and deployed it. Several enforcement actions have turned on source code and configuration files showing that cancellation before execution was the design, not an emergent accident.
What penalties do spoofers face?
Civil penalties, disgorgement of trading profits, trading bans and registration bars. Criminal exposure is real: sentences of several years have been imposed under the commodities fraud statute, and some prosecutions have added wire fraud counts carrying substantially longer maximums.
Does spoofing happen in crypto markets?
Yes, and it is prosecutable. The CFTC treats bitcoin and ether as commodities, so spoofing on derivatives venues falls squarely under the anti-spoofing provision. Offshore venues with weaker surveillance and no order-audit trail make detection harder, not lawful.
How much money does spoofing actually make?
Per event, very little — often a fraction of a cent per share or tick, on a small genuine order. The economics depend on repetition at scale. That is also what makes it detectable: a profitable spoofing strategy has to run thousands of times, and each run leaves a record.
Is a large order that gets cancelled always a spoof?
No. Genuine traders cancel constantly as prices move, hedges fill, or risk limits bind. Market makers cancel and repost by design. The distinguishing feature is not cancellation but the absence of any intention to trade at the moment of placement.
Who investigates spoofing first?
Usually the exchange. CME Group, ICE, Nasdaq and NYSE run their own surveillance and refer patterns to regulators. FINRA surveils across US equity venues. A CFTC or SEC action is often the second stage of a process that started with an exchange's own alert.

Terms defined on this page

Order Book · Bona Fide Order · Order To Trade Ratio · Bid Ask Spread · Resting Order · Scienter · Market Microstructure

Sources

  1. Commodity Exchange Act § 4c(a)(5)(C) — the anti-spoofing provision — Cornell Legal Information Institute
  2. CFTC Interpretive Guidance and Policy Statement on Disruptive Practices — Federal Register
  3. 17 C.F.R. § 180.1 — prohibition on manipulative and deceptive devices — Electronic Code of Federal Regulations
  4. SEC Rule 10b-5 — Electronic Code of Federal Regulations
  5. CFTC enforcement actions index — Commodity Futures Trading Commission

Reviewed September 7, 2026. Every statute link points at the primary text. If something here is wrong, tell us — corrections are logged in public.