Market Manipulation. Search

Anatomy of a spoofing case: what the enforcement record actually contains

Spoofing cases are built from order audit trails rather than from confessions. The evidence is statistical — cancellation timing, size asymmetry, and the relationship between cancelled orders on one side and fills on the other — and the enforcement record shows penalties ranging from nothing to tens of millions for conduct that is mechanically identical.

Published 2026-08-12 · 11 min read

There is a version of the spoofing story that gets told in general coverage: a trader in a bedroom, an algorithm, a market crash, a dramatic arrest. It is a good story and it is mostly beside the point.

The enforcement record contains something less cinematic and more useful. Spoofing prosecutions are built from message-level data, they turn on statistical patterns rather than on any individual order, and the penalties they produce vary by orders of magnitude for conduct that is mechanically identical. This post works through what the records in this library actually show.

The conduct is trivially simple

Spoofing has no technical sophistication in it. Place an order you do not intend to trade. Let other participants read the imbalance. Execute a smaller genuine order on the other side at a slightly better price. Cancel.

The profit per cycle is one tick. In a futures contract at $100 per point with a 0.01 tick, a 200-lot genuine order improved by one tick earns $200. That is the whole gain from an episode involving thousands of contracts of displayed size.

Which means the strategy is only economic at volume, and volume is what makes it detectable. A single cancelled order proves nothing — the great majority of orders in every electronic market are cancelled, and market makers cancel constantly by design. Ten thousand cancellations with a median lifetime of a few hundred milliseconds, systematically preceding fills on the opposite side, is a different kind of fact.

That asymmetry between the triviality of the act and the volume required to profit from it explains almost everything about how these cases are made.

What the evidence actually is

Read enough of these records and a pattern emerges in what regulators rely on.

The order audit trail is the case. Every message sent to a venue, timestamped to the microsecond and attributed to an account. From it, investigators compute order-to-trade ratios, order lifetime distributions, and — the measure that does most of the work — the conditional probability that a large resting order is cancelled given a fill on the contra side.

Nobody confesses to placing an order they intended to cancel. They explain that they changed their mind, that the market moved, that risk limits bound. Each explanation is plausible for one order and unavailable for ten thousand.

Communications and code supply the intent. Several matters have turned on algorithm configuration files and source code comments describing what a strategy was designed to do. A parameter named for the cancellation delay is more probative than any amount of testimony.

The Sarao matter in this library is tagged layering rather than single-order spoofing, which is the more common shape: the orders are spread across several price levels so that the imbalance looks like ordinary depth rather than one anomalous order. The earlier action and the later one appear as separate records, which is itself instructive about how these matters progress.

The institutional cases look different

Individual traders and institutions produce different-looking records, and the difference is not mainly about the conduct.

The HSBC spoofing action in this library carries a $45 million penalty. The Deutsche Bank matter carries $30 million and is tagged settlement price manipulation alongside the order-book conduct. The RBC wash trading action sits at $35 million.

Compare the individual matters. Milrud records no penalty figure in our data at all. Several layering actions against individuals resolve with figures in the hundreds of thousands.

Two things drive the gap, and neither is the seriousness of the conduct.

Institutional cases bundle supervision failures. A firm is charged not only for what its traders did but for the controls that did not catch them. Those charges are frequently the larger component, and they do not require proving any individual’s intent.

Ability to pay is a real factor. Penalties are calibrated partly to the respondent, which is defensible as policy and makes the aggregate figures a poor guide to how seriously any particular conduct is treated.

The consequence for anyone reading enforcement data: penalty size measures the defendant more than the offence. The penalty distribution chart shows this directly — the spread within spoofing is enormous, and the median is far below the mean.

Multiple actions, one course of conduct

A feature of this library that surprises people looking at it for the first time: the same conduct frequently generates several records.

The Lek Securities matters appear more than once, because litigation releases are published at filing and again at resolution. Sarao appears twice for the same reason. A single course of conduct can produce a CFTC action, an SEC action, a FINRA action, an exchange disciplinary proceeding, and a criminal prosecution.

This matters for anyone counting. Our case index records actions, not schemes, and the year facet pages count filings rather than conduct. Aggregating them as though each represented distinct misconduct overstates the picture, which is why the data pages carry that caveat explicitly.

What the charging decisions reveal

The statutory choices in these records are worth reading closely.

In futures, the express anti-spoofing provision at 7 U.S.C. § 6c(a)(5)(C) makes the analysis clean: bidding or offering with intent to cancel before execution is prohibited outright, and the regulator need not prove that the price moved or that anyone lost money. The offence is complete at placement.

In securities there is no equivalent provision, and cases run through Exchange Act § 9(a)(2) and Rule 10b-5. That is a harder path, because it requires characterising the order as a deceptive device rather than pointing at a statute that names the conduct.

The practical result is visible in this library’s composition. Order-book manipulation charged by the CFTC substantially outnumbers the equivalent charged by the SEC, and the SEC matters more often involve a registered firm where FINRA rules supply an additional hook.

For the closely related techniques the same logic applies. Quote stuffing is barely charged at all in securities, because characterising message volume as deception is harder still. Momentum ignition is described constantly in guidance and charged rarely, because every order in it is genuine and the case rests entirely on purpose.

What is missing from the record

Three absences are worth naming, because they shape what this data can support.

Conduct that was never detected. This library records enforcement. The relationship between enforcement and underlying conduct depends on a detection rate that is unknown and, from this data, unknowable. A rise in spoofing actions in a given year tells you about regulators.

Conduct detected and not charged. Exchanges resolve a great deal through their own disciplinary processes, and those outcomes are not consistently published in a form that can be compiled.

The counterfactual. Nearly every settled matter is resolved without admission. What the respondent would have argued at trial, and whether it would have succeeded, is not in the record.

What to take from this

Three things, if you read one enforcement record after this post.

Look at the technique tags, not the headline. Our tags are editorial — regulators charge statutory provisions, not technique names — but they make comparable conduct comparable across agencies and years in a way the charging language does not.

Read the penalty against the respondent. A $45 million institutional settlement and a $200,000 individual judgment can describe the same trading.

Check the status. A matter recorded as filed is an allegation and nothing more. The editorial policy sets out how this site handles that distinction, and it is the distinction that most coverage of enforcement gets wrong.

What a complaint actually contains

For anyone who has not read one, the structure of these documents is worth describing, because it explains what regulators think they need to prove.

The account and the venue. Which accounts, at which firms, trading which products on which venues, over what period. Precise, because everything downstream is computed from it.

The pattern description. A narrative account of one representative episode — orders placed, sizes, prices, timing, cancellation. This is the part that gets quoted in coverage, and it is illustrative rather than probative.

The statistics. The part that carries the case. Numbers of episodes, cancellation rates conditioned on contra-side fills, order lifetime distributions, comparisons against the trader’s own baseline. Regulators are usually explicit that no single order is alleged to be unlawful in isolation.

The intent evidence. Communications, algorithm parameters, code comments, or — where none of these exist — an argument that the pattern admits no innocent explanation.

The relief sought. Penalties, disgorgement, trading bans, registration bars.

Read a few and the emphasis becomes clear: the narrative is scaffolding and the statistics are the building. Coverage reverses that, which is why the public understanding of these cases is so different from what the documents actually assert.

Why so many records carry no penalty figure

Forty-three of the 103 spoofing and layering records in this library disclose no civil penalty. That is not forty-three actions where nobody paid anything.

Three explanations account for most of it.

Filing-stage releases. An action announced at filing describes allegations; relief comes later, in a separate release that appears as a separate record. The 2015 Sarao record and the 2016 one are the same conduct at two stages.

Non-monetary relief. Trading bans, registration bars and injunctions are frequently the substantive outcome, particularly against individuals for whom a bar ends a career more decisively than a fine.

Extraction limits. Our figures come from parsing the regulator’s own text. Where a release states an amount in a form our rules do not recognise, the field is left null rather than guessed at, and the case carries a marker saying it has not been reviewed by a person.

All three mean the monetary totals on this site are lower bounds, and the penalties chart says so on the page.

Reading one of these records yourself

If you want to examine a case rather than take our summary for it, the sequence that works is:

Start with the primary document. Every case page links the regulator’s release and, where one exists, the complaint. Where our summary and the primary document disagree, the primary document is correct — we say so on every page.

Check the status. filed means alleged and unproven. settled means an outcome was agreed, almost always without admission, which establishes a resolution rather than a fact.

Check the review flag. Records marked unreviewed were extracted automatically. The link is reliable; the parsed figures may not be.

Look at the technique tags critically. They are our editorial judgement, not the charges brought. Where a tag seems wrong, it may well be, and the corrections process is the fastest way to fix it.

The spoofing technique page carries the mechanics, the statutes and the penalty statistics computed from these records. The full spoofing case list is the underlying data, and cases.json is all of it in a form you can query yourself.

Techniques referenced

Cases referenced

Action Agency Filed Technique Penalty Status
CFTC v. Navinder Singh Sarao (layering, 2016) CFTC 2016-11-18 Layering , Price Manipulation +1 $38m judgment
CFTC v. HSBC Bank USA (spoofing, 2023) CFTC 2023-05-12 Spoofing $45m judgment
SEC v. Lek Securities Corp., et al. (layering, 2019) SEC 2019-10-10 Layering $1m judgment
SEC v. Aleksandr Milrud (layering, 2015) SEC 2015-01-13 Layering judgment
CFTC v. Deutsche Bank (price manipulation, 2018) CFTC 2018-01-29 Price Manipulation , Spoofing $30m judgment
CFTC v. Royal Bank (wash trading, 2014) CFTC 2014-12-19 Wash Trading $35m judgment

Reviewed August 12, 2026. Spotted an error? Tell us.