Market abuse rules for crypto assets

Crypto trading in the EU now carries the same three prohibitions that have governed share trading for a decade: insider dealing, unlawful disclosure of inside information, and market manipulation. Title VI of Regulation (EU) 2023/1114 wrote them into MiCA in Articles 89 to 92, and they apply to any crypto-asset admitted to trading on a platform in the Union, including the orders and conduct of people who never touch a platform themselves.

For a platform or a broker the practical consequence is an obligation to detect, not merely to abstain: Article 92 requires systems and arrangements that find suspected abuse and a report to the home authority without delay.

Crypto market surveillance display showing anomalous order-book activity alongside linked on-chain wallet flows.

What the three prohibitions cover

Insider dealing under Article 89 means using inside information to acquire or dispose of a crypto-asset, directly or indirectly, for your own account or for someone else's. Canceling or amending an order placed before the information arrived counts as use. Recommending that another person trade, on the basis of the information, counts too, which is the provision that reaches group chats and paid signal services.

Unlawful disclosure under Article 90 means passing inside information to anyone outside the normal course of employment or duties. Market manipulation under Article 91 covers transactions and orders that give false or misleading signals about supply, demand or price, that secure a price at an abnormal or artificial level, that use a fictitious device or deception, and the dissemination of information through any medium that creates a misleading impression where the person knew or ought to have known it was false.

Article 91 also names the case where a person spreads information after taking a position in the asset, without disclosing the conflict. That is the legal basis under which a coordinated promotion followed by a sale becomes an offense and not a trading strategy.

Inside information and the issuer's duty to disclose

Article 88 requires an issuer, an offeror or a person seeking admission to trading to make inside information about itself public, as soon as possible and in a way the public can access and assess. The information goes on the entity's website and stays there for at least five years. A delay is possible where immediate publication would prejudice legitimate interests, the delay does not mislead, and confidentiality is maintained.

Inside information in crypto has a shape of its own. A protocol upgrade that changes supply, a discovered vulnerability, the loss of a banking relationship, a planned de-listing, a reserve shortfall at a stablecoin issuer: each is precise, non-public, and likely to move the price. Article 88 does not accept the argument that a decentralized project has nobody to publish, because it names the offeror and the person seeking admission alongside the issuer.

The surveillance duty on a platform

Article 92(1) binds any person professionally arranging or executing transactions in crypto-assets. That person maintains effective arrangements, systems and procedures to prevent and detect market abuse, and where a reasonable suspicion arises, reports it to the competent authority of its home member state without delay.

What makes crypto surveillance different from equity surveillance is the second data source. A venue sees its own order book, its own accounts and its own trades, as an exchange always has. It also sees deposit and withdrawal addresses, which means an alert can be enriched with on-chain flows: the same beneficial owner behind two accounts, a wallet that funded both sides of a trade, a token distribution that concentrates supply before a promotion. ESMA published guidelines on supervisory practices to prevent and detect market abuse under MiCA, which set out how authorities expect that monitoring to be resourced where manipulation risk is highest. Our page on blockchain forensics covers the analysis side of the chain data.

How the named practices actually work

Wash trading means buying and selling the same asset so that no beneficial ownership changes. The trade prints a volume figure and a price without any economic risk being taken. On a venue where fees are rebated or where listing depends on reported volume, the incentive is direct, and detection relies on linking the two accounts.

Spoofing means entering orders with no intention of executing them, to move the visible depth and pull other participants' orders or quotes, then canceling and trading the other way. Layering stacks several such orders at different price levels. Both are easier in a thin order book, because a smaller notional shifts the picture, which is why they turn up in small-cap tokens more than in the largest pairs.

Pump orchestration means organizing a coordinated buy and a promotion, often in a closed group, so that later buyers provide the exit. The abuse is not the enthusiasm; it is the undisclosed position of the people generating it, which Article 91 covers directly.

Where does a STOR report go in Germany?

To BaFin, as the competent authority for the German market. The suspicious transaction and order report follows the template and the content the technical standards under Article 92 prescribe: the person reporting, the asset, the orders and transactions concerned, the reason for the suspicion, and the identity of the persons behind the activity. The report is confidential, and the reporting firm does not tell the customer.

BaFin also runs a route for anyone to report suspected manipulation, which is where a market participant without a reporting duty can send an observation. A platform's own report, with its order-book data attached, is the one that carries evidential weight, which is an argument for keeping the surveillance records in a form an authority can read.

Does MiCA cover tokenized shares and bonds?

No. A token that qualifies as a financial instrument under MiFID II stays under Regulation (EU) 596/2014, the Market Abuse Regulation, and MiCA explicitly leaves it out. A tokenized bond is a bond; the form of the register does not change the regime.

The boundary matters operationally because the two regimes differ in detail: MAR carries the insider list duty, the managers' transactions regime and the closed period, none of which MiCA replicates. A platform that admits both kinds of asset runs two surveillance configurations and two reporting routes. Our pages on tokenized securities and trade surveillance in Germany cover the MAR side.

Who enforces the rules across borders?

The authority of the member state where the conduct occurred or where the asset is admitted, working through the cooperation arrangements MiCA sets out. Because a crypto-asset is usually admitted on several platforms in several member states at once, one manipulation produces alerts in several jurisdictions, and the authorities coordinate instead of each running a separate case.

ESMA's role is convergence: it issues the guidelines and standards, maintains the registers and can intervene in specified circumstances, while the national authority investigates and sanctions. For a German platform that means BaFin as the counterpart, with ESMA setting what BaFin expects to see.

Is MEV market manipulation?

Not by itself, and the answer turns on which form of it you mean. Maximal extractable value describes the profit a block producer or searcher can take by choosing the order of transactions in a block. Reordering to capture an arbitrage between two venues is trading on public information, and MiCA prohibits neither. Placing an order in front of a pending transaction you can see but the market cannot, in order to profit from its price effect, has the shape Article 91 describes: an order that exploits an informational advantage the counterparty cannot have.

The ESMA guidelines on supervisory practices under MiCA name front-running and MEV among the behaviors authorities are expected to understand and look for, which puts the question on a platform's agenda whether or not it has settled on an answer. A venue that routes orders through a public mempool, or that operates its own block space, has a conflict to document.

Social media as a surveillance source

Equity surveillance built its alerts on order books and trade reports, because that is where the conduct showed. In crypto a large share of manipulation starts in public: a post, a coordinated campaign, a paid promotion on a channel with a six-figure following. The ESMA guidelines ask authorities to monitor social media in their market abuse work, and a platform that wants its own alerts to make sense needs the same input, because the order flow alone shows the effect without the cause.

The practical form is a watchlist that correlates a promotion spike with trading in the promoted asset on the venue's own book. That correlation is what turns an unexplained volume move into a reportable suspicion with a named trigger, and it is also what distinguishes a token that moved on genuine interest from one that moved on a campaign by holders who then sold.

What the twelve ESMA guidelines ask of authorities

ESMA published guidelines on supervisory practices to prevent and detect market abuse in crypto-assets, and they matter to firms even though they address authorities. They ask a national authority to work proportionately against the risks in its own market, to build data-driven surveillance, to combine on-chain and off-chain analysis, to train staff on the crypto-specific conduct, to engage with market participants, and to use ESMA to coordinate a case that crosses borders.

For a German platform that list is a preview of the questions BaFin will ask about its own arrangements. An authority told to run data-driven surveillance asks a venue what data its surveillance consumes, and an authority told to combine chain and book data asks whether the venue's alerts do the same.

Market abuse in crypto assets and Finance Loop

Finance Loop is the meeting place for the surveillance, compliance and data teams working on this in Germany, from trading venues and brokers to the forensics firms that read the chain side of an alert. Market abuse in crypto is where classic exchange supervision meets a data source that equity markets never had.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.