Market manipulation in crypto is no longer treated in the European Union as a largely undefined problem left to individual exchanges or national rules. The Markets in Crypto-Assets Regulation, better known as MiCA, has applied generally since 30 December 2024, and its market-abuse provisions now provide a common legal framework for conduct involving crypto-assets admitted to trading or submitted for admission. By 2026, those rules are supported by detailed reporting, record-keeping and surveillance requirements introduced during 2025, as well as supervisory guidance from the European Securities and Markets Authority (ESMA). This matters for wash trading, spoofing and insider dealing because regulators can assess not only completed trades but also orders, cancellations, changes to orders, communications and certain activity connected with distributed ledger technology. The result is a much clearer distinction between ordinary speculative trading and behaviour intended to create a false impression of demand, supply, liquidity or price.
MiCA deals with crypto market abuse mainly through Articles 86 to 92. The scope is wider than activity that takes place directly on a regulated crypto exchange. When a crypto-asset has been admitted to trading in the EU, or a request for admission has been made, the market-abuse rules can cover related transactions, orders and behaviour even when the activity occurs elsewhere. Article 86 also extends the rules to relevant actions and omissions carried out in the Union and in third countries. This is particularly important for crypto because the same asset can trade around the clock through several exchanges and jurisdictions. A manipulative strategy therefore does not escape scrutiny simply because one part of the activity took place outside the particular exchange on which the asset was admitted to trading.
Article 91 sets out a broad definition of market manipulation. It covers transactions, trading orders and other behaviour that give, or are likely to give, false or misleading signals about the supply, demand or price of a crypto-asset. Conduct that holds a price at an abnormal or artificial level can also fall within the prohibition, as can transactions or other activity using deception or fictitious devices. The rule is deliberately broad enough to address different manipulation techniques rather than relying on a closed list of named schemes. It can also cover false or misleading information circulated through the internet or other media when the person responsible knew, or should have known, that the information was misleading. This makes the rules relevant not only to exchange activity but also to coordinated promotional campaigns designed to influence a token’s price.
Insider dealing is treated separately but is part of the same market-integrity framework. Under Article 87, inside information generally means precise, non-public information relating to a crypto-asset, issuer, offeror or person seeking admission to trading that would probably have a significant price effect if it became public. For people executing client orders, confidential information about a significant pending client order can also qualify. Article 89 prohibits using such information to buy or sell the relevant crypto-assets and can also cover cancelling or changing an existing order after obtaining inside information. Passing a recommendation to another person on the basis of that information can create a problem too. Article 90 separately prohibits unlawful disclosure, so merely passing confidential price-sensitive information to another person can breach MiCA even if the insider does not personally make a trade.
Wash trading usually involves transactions in which the same economic interest is effectively present on both sides of a trade, or several coordinated accounts trade among themselves, with the aim of manufacturing activity rather than genuinely transferring market risk. The apparent volume can make an asset look more liquid or more actively demanded than it really is. MiCA does not need a separate rule carrying the label “wash trading” for this conduct to be caught. A deliberately arranged series of trades that creates a false impression of supply, demand, volume or price can meet the Article 91 definition of market manipulation. ESMA has also referred to wash trades in its MiCA work when discussing the type of behaviour that transaction records should help supervisors identify. A single self-match, however, is not by itself proof of manipulation: the pattern, purpose, economic effect and surrounding circumstances remain relevant.
Spoofing works differently. A trader may enter large or repeated orders that appear to show strong buying or selling interest but are not intended to remain available for genuine execution. Those orders can influence other market participants or automated trading systems. The trader then cancels or changes them, sometimes after trading on the opposite side of the market. MiCA specifically covers the placing, cancellation and modification of orders when such behaviour creates false or misleading signals or makes genuine orders harder for others to identify. It also prohibits attempted market manipulation, meaning an unsuccessful effort to distort the market does not automatically fall outside the rules. Regulators can therefore examine the full order sequence rather than focusing only on trades that were ultimately executed.
The distinction between aggressive trading and manipulation depends heavily on evidence. A large order that is cancelled because market conditions change is not the same as a sequence designed from the outset to mislead other traders. For that reason, supervisors need detailed information about the time an order was entered, its price and size, subsequent amendments, cancellations, executions and links to other activity. EU rules introduced in 2025 require standardised order-book records and broader records of crypto services, orders and transactions. These records make it easier to reconstruct what happened before and after a suspicious price movement. They can also help identify relationships between accounts that would be difficult to spot from headline trading volume alone, particularly when repeated patterns occur over several sessions.
MiCA supervision is shared between EU-level coordination and national enforcement. ESMA develops common standards and supervisory guidance, while the competent authority in each Member State performs much of the direct supervision, investigation and enforcement work. ESMA’s guidelines on preventing and detecting market abuse were published in 2025 and address features that make crypto supervision different from traditional securities monitoring, including cross-border trading and the heavy use of social networks. They call for a proportionate, risk-based approach and greater consistency between national authorities. By August 2026, ESMA had also published an updated compliance table for these market-abuse guidelines, providing a public view of how national authorities report their implementation of the common supervisory approach.
Article 92 places important responsibilities on businesses that professionally arrange or execute crypto transactions. They must maintain effective arrangements, systems and procedures for preventing and detecting market abuse. When they have reasonable grounds to suspect abuse, they are required to report it without delay to the competent authority in the relevant Member State. The duty is not limited to a completed purchase or sale. A suspicious order, cancellation, alteration or behaviour connected with the functioning of distributed ledger technology can also require attention. This is crucial for spoofing because the most significant evidence may consist of orders that disappear before execution. It also matters for attempted manipulation, where the scheme may fail to achieve its intended price effect but the underlying behaviour can still be investigated.
Commission Delegated Regulation (EU) 2025/885 made those responsibilities considerably more specific. Firms covered by the reporting duty must maintain an appropriate level of human analysis rather than relying entirely on automated alerts. Depending on their size and activity, they must also use suitable ICT systems, including systems capable of reading, replaying and analysing order-book data after the event. Records documenting the examination of potentially abusive activity must generally be retained for five years, including the reasoning behind decisions to submit or not submit a suspicious transaction and order report, commonly known as a STOR. Surveillance work can be delegated or outsourced under specified conditions, but the firm that holds the regulatory obligation remains responsible for compliance. This prevents a business from treating an external monitoring provider as a way to transfer its legal accountability.
A typical investigation starts by reconstructing activity rather than looking at one isolated price chart. Supervisors and compliance teams can examine when orders appeared, how long they remained open, whether they were repeatedly changed or cancelled, which transactions followed them and whether the same accounts or related accounts benefited. Trading-venue operators must retain structured order information, while MiCA also imposes transparency requirements for bid and ask prices, market depth and completed transactions. This creates several layers of evidence. For suspected spoofing, investigators may compare large visible orders with the trader’s executions on the opposite side. For suspected wash trading, they may look for repeated trades between connected accounts, unusually circular flows or turnover that produces little genuine change in economic exposure.
Crypto surveillance also requires a wider view because relevant evidence may exist on-chain, across several exchanges and in public communications. A token can move rapidly between wallets, centralised services and decentralised protocols, while discussion on social networks can influence prices within minutes. ESMA has explicitly recognised both the cross-border nature of crypto trading and the importance of social media when developing its supervisory approach. EU rules also establish mechanisms for national authorities to exchange information when a suspicious case involves more than one Member State. The competent authority examining an incident can therefore combine transaction records, order information, STORs and other available evidence rather than treating each national market in isolation. On-chain transparency can sometimes help this work, although linking a wallet address to the person controlling it may still require additional evidence.
Red flags vary according to the suspected behaviour. For wash trading, unusually repetitive trades between the same or apparently connected accounts, rapid back-and-forth transfers and volume that rises sharply without a comparable change in genuine market interest can warrant further review. In a spoofing case, repeated large orders that are cancelled as the market approaches them, particularly when followed by profitable trading in the opposite direction, can be significant. Insider-dealing reviews can focus on accounts that build positions shortly before a major non-public event such as an important listing decision, material token-supply change or other price-sensitive announcement. None of these patterns automatically establishes a breach. Surveillance generates evidence and questions; human analysis is still needed to determine whether there is a reasonable explanation or a credible indication of manipulation.

MiCA gives market-abuse rules substantial enforcement weight. Member States-abuse rules substantial enforcement weight. Member States must ensure that their competent authorities have powers to deal with infringements of Articles 89 to 92, which cover insider dealing, unlawful disclosure, market manipulation and failures in prevention or reporting. For these breaches, MiCA provides for maximum administrative fines of at least €5 million for a natural person. For a legal person, the maximum must reach at least €15 million or, under the relevant turnover-based measure, 15% of total annual turnover. Authorities must also be able to impose a fine of at least three times the profit gained or loss avoided when that amount can be determined. Other available measures can include orders to stop the conduct, restrictions on dealing, suspension or withdrawal of authorisation in appropriate cases and lengthy management bans for repeated infringements. The exact sanction in an individual case depends on national law, the facts and the seriousness of the breach.
For regulated crypto businesses, compliance therefore involves more than installing software that generates alerts. Trading rules, internal escalation procedures, staff training, conflicts-of-interest controls and access to confidential information all matter. A firm needs to know who reviews a suspicious alert, what additional evidence must be collected, when the issue should be escalated and how the decision is recorded. Operators of crypto trading venues also have specific responsibilities to maintain systems able to prevent or detect market abuse and to inform the competent authority when they identify actual or attempted abuse through their trading systems. Standardised records introduced under MiCA make weak internal procedures easier for supervisors to identify because authorities can request detailed information about orders, transactions and the reasoning behind previous surveillance decisions.
Issuers, offerors and people seeking admission of a crypto-asset to trading also need clear controls around confidential information. Article 88 generally requires inside information that directly concerns them to be disclosed to the public as soon as possible in a way that allows fast access and a complete, correct and timely assessment. A delay is possible only when specified conditions are satisfied, including protection of a legitimate interest, no likelihood of misleading the public and an ability to keep the information confidential. Employees, advisers and others who receive such information cannot treat it as an informal advantage for personal trading. Traders and promoters face similar risks when coordinating transactions to create artificial liquidity, entering misleading orders or publicly promoting a crypto-asset after taking a position without properly disclosing the resulting conflict of interest.
MiCA has made the EU rulebook clearer, but it does not bring every crypto-asset and every type of activity under the same regime. Title VI applies to crypto-assets admitted to trading or for which admission has been requested, while crypto-assets that qualify as financial instruments are outside MiCA and can instead fall under existing EU securities legislation. Fully decentralised arrangements can also create difficult questions where there is no identifiable issuer or service provider carrying out a regulated function. The Commission has already been required by MiCA to assess developments in decentralised finance and whether further regulation is needed. For users, this means the presence of EU market-abuse rules should not be interpreted as proof that every token, exchange, decentralised service or overseas activity is subject to identical supervision.
Cross-border enforcement remains another practical challenge. MiCA can apply to relevant conduct occurring in third countries when it concerns crypto-assets within the scope of its market-abuse title, but legal jurisdiction and practical access to evidence are different matters. Important liquidity may sit with companies outside the EU, trading can be divided among multiple services, and individuals can control several addresses without publicly revealing their identity. Automated strategies can also generate thousands of orders in short periods, making simple manual review unrealistic. This is why the EU approach combines standardised records, automated surveillance, human analysis and cooperation between authorities. These tools significantly improve supervisors’ ability to reconstruct behaviour, but they cannot guarantee that every manipulative scheme will be identified immediately or that evidence located outside the Union will always be easy to obtain.
By 2026, the biggest change brought by MiCA is therefore not the disappearance of wash trading, spoofing or insider dealing, but the existence of a common legal and supervisory structure for identifying and pursuing them. The market-abuse provisions have applied since 30 December 2024, detailed surveillance and STOR requirements were added during 2025, and ESMA’s supervisory guidelines now shape the way national authorities approach crypto market integrity. Order cancellations can be examined alongside completed trades, suspicious patterns can be reviewed across borders, and confidential information about a crypto-asset or significant client order can fall within a defined insider-dealing regime. Investors should still treat unexplained volume, sudden liquidity, aggressive social promotion and abrupt price moves critically. MiCA provides stronger tools for detection and enforcement, but market integrity ultimately depends on those tools being used effectively against the evidence in each case.