Decentralised exchanges are a classic example of financial infrastructure with competing risk characteristics. They allow users to exchange cryptoassets directly through blockchain-based smart contracts, without transferring custody to a conventional exchange or relying on a central operator to match every order.
That architecture can improve accessibility, transparency and resilience. Trades are generally recorded on a public ledger, allowing investigators to reconstruct transactions with a level of technical detail that is rarely available in traditional markets.
The same design can make misconduct easier to execute. A trader can create several pseudonymous wallets, acquire a token before a price-sensitive announcement and sell shortly afterwards without opening a conventional exchange account in their own name. The transaction may be publicly visible while the person controlling the wallet remains unknown.
Solidus Labs’ introduction of DEX-Based Insider Trading Detection to its HALO platform in 2023 was significant because it addressed this gap directly. The system was designed to correlate on-chain token swaps with off-chain listing announcements and identify wallet addresses whose timing and trading behaviour suggested possible use of confidential information.
For financial crime and market-surveillance teams, the wider lesson extends beyond one product. Effective crypto-market oversight requires institutions to connect blockchain activity with listing decisions, employee access, exchange accounts, funding flows, communications and the legal definition of market abuse.
Key Takeaways
- Insider Trading Risks Extend Into Decentralized Exchanges
- DEX Activity Requires Crypto-Native Market Surveillance
- On-Chain Transparency Can Support Market Abuse Detection
- Off-Chain Context Remains Essential for Effective Investigations
- Token Listings Can Create Significant Insider Trading Risk
- Suspicious Token Swaps May Reveal Pre-Announcement Trading
- DeFi Market Abuse Can Be Harder to Detect Than Centralized Exchange Activity
- Traditional Surveillance Models May Not Fully Capture DEX Behaviour
- Crypto Market Integrity Requires Real-Time Monitoring
- Regulators Are Increasingly Focused on Decentralized Market Abuse
- Market Surveillance and Transaction Monitoring Are Converging
- Data Integration Is Critical to Identifying Manipulative Behaviour
- Advanced Analytics Can Strengthen Investor Protection in DeFi
- Greater Transparency Can Help De-Risk Decentralized Finance
Listen the podcast
Watch the video
Why DEX-based insider trading matters now
Token-listing announcements can be highly price-sensitive. Admission to a major centralised exchange may give a cryptoasset access to new customers, deeper liquidity and greater market visibility. Traders who know about the decision before it becomes public may be able to buy the token on a DEX and sell after the announcement causes demand and price to rise.
Solidus Labs’ analysis of 234 ERC-20 listing announcements found indicators it associated with insider trading around 131 events, representing 56% of the listings reviewed. The platform identified 411 suspected trading events involving 105 individual wallets or connected wallet groups.
The figures should be interpreted carefully. They are surveillance findings produced through a proprietary methodology, not judicial determinations that every flagged trade constituted unlawful insider dealing. A suspicious pattern can support an investigation, but it does not establish who controlled the wallet, how they obtained the information or whether a legal duty was breached.
The analysis nevertheless illustrates the potential scale of the market-integrity problem. More than half of the suspected entities identified by Solidus appeared around at least two listing events, while some wallet clusters traded before more than ten announcements. Repetition can be particularly significant because it is more difficult to explain as coincidence, ordinary speculation or a one-off analytical success.
The threat is not confined to exchange employees. Inside information can be accessible to token issuers, advisers, market makers, technology providers, communications agencies, listing committees and other parties involved in preparing the announcement.
How listing-event insider trading works
The operating model begins with access to non-public information. A centralised exchange may decide to list a token several days before announcing that decision publicly. Employees and external partners involved in technical integration, liquidity preparation, legal review or communications may learn the token’s identity and expected announcement time.
The trader then needs a venue where the asset is already available. Many tokens trade on decentralised liquidity pools before they are admitted to a major centralised platform. A person with advance knowledge can exchange Ether or a stablecoin for the token through an automated market maker.
The trader may divide the purchases across several wallets to reduce the apparent size of the position. Funds can be routed through intermediary addresses, bridges or other services before reaching the trading wallets.
After the listing becomes public and the token’s value increases, the trader sells into the new demand. Proceeds may be returned to the original funding source, transferred to a centralised exchange, bridged to another blockchain or distributed through additional wallets.
This creates an identifiable sequence: accumulation before a price-sensitive event, disposal after publication and movement of the proceeds away from the trading address.
The individual transactions are visible on-chain, but intent and attribution remain off-chain questions. The blockchain does not state that the trader was an employee, adviser or tippee. It records what the address did, not why the person controlling it acted.
How DEX-based surveillance works
The Solidus Labs tool was designed to combine two forms of information that conventional surveillance systems often analyse separately.
The first is an event database containing listing announcements and their publication times. The second is on-chain trading data from decentralised liquidity pools.
The platform can identify wallets that purchased a relevant token during a defined pre-announcement period and sold after the information became public. It can then assess factors such as trading size, timing, profit, repeat behaviour, common funding sources and links between addresses.
A single purchase before a listing is not enough to establish suspicion. Crypto traders regularly speculate on potential listings, follow public rumours and monitor blockchain-development activity. The control value comes from combining several indicators.
A wallet may acquire the token shortly before the announcement despite having no previous history of trading it. It may sell almost immediately afterwards, realise a material profit and repeat the same behaviour around several unrelated listings. Several wallets may also receive funds from one source or return proceeds to a common destination.
This is where blockchain analytics becomes more than transaction search. Entity-resolution techniques attempt to identify addresses that are likely to be controlled by the same person or coordinated group.
The resulting alert should be treated as an investigative lead. It indicates that the timing and network behaviour require explanation; it does not replace the legal and evidential assessment.
Why legacy surveillance can miss the activity
Traditional trade-surveillance systems were built around identifiable accounts, centralised order books and activity occurring within one regulated venue. The institution typically knows the customer, records every order and can compare employee accounts with confidential-information lists.
DEXs change that architecture.
Trading is executed through smart contracts rather than an exchange-maintained order book. The wallet address may have no verified identity attached to it. Activity can move across several DEXs, routers and blockchains, while the same trader also uses accounts at centralised venues.
A centralised exchange monitoring only its own platform may see the post-announcement sale but not the earlier DEX purchase. A blockchain-monitoring system may see both trades but lack access to the confidential listing calendar and employee records required to understand their significance.
Surveillance must therefore cross the boundary between on-chain and off-chain data.
The system also needs to distinguish insider dealing from legitimate activity. Arbitrageurs may buy a token on one venue after detecting public signs that another venue is preparing to list it. Market makers may accumulate inventory to support expected liquidity. Other traders may act on social-media rumours, changes in token deposits or publicly observable blockchain activity.
Alert quality depends on context, not timing alone.
Insider dealing is not the same as every unfair on-chain trade
DEX markets contain several behaviours that can disadvantage other users without necessarily constituting insider dealing.
Maximal extractable value involves validators or specialised searchers influencing transaction ordering to capture economic value. A sandwich strategy may place one transaction before and another after a user’s swap, profiting from the resulting price movement.
Front-running can also involve observing a pending transaction in the public mempool and submitting another transaction with a higher fee so that it is processed first.
Wash trading creates artificial activity through transactions between accounts under common control. Pump-and-dump schemes use coordinated promotion and trading to inflate a token before insiders sell. Liquidity manipulation may involve adding or withdrawing assets from a pool to influence price or market confidence.
These practices raise serious market-integrity questions, but their evidential foundations differ. Insider dealing concerns the use of material non-public information. Market manipulation concerns conduct that creates false signals, distorts price or deceives other participants.
A resilient surveillance programme needs separate typologies, thresholds and investigative playbooks rather than categorising every suspicious DEX transaction as insider trading.
Regulatory expectations are becoming clearer
The regulatory treatment of crypto-market abuse has historically been fragmented because the legal status of the asset and trading venue can vary between jurisdictions.
The United States’ first criminal prosecution described as a cryptocurrency insider-trading case involved confidential Coinbase listing information. A former employee admitted tipping his brother and a friend about assets scheduled for listing. Prosecutors used wire-fraud offences, while the Securities and Exchange Commission separately alleged insider dealing involving cryptoasset securities.
The case demonstrated that pseudonymous trading does not prevent attribution where authorities can connect wallets with exchange accounts, communications, devices and personal relationships. It also highlighted the importance of the asset’s legal classification and the duty owed by the person who disclosed the information.
The European Union has established a more explicit crypto-market-abuse framework through MiCA. The regime prohibits insider dealing, unlawful disclosure of inside information and market manipulation involving covered cryptoassets.
Persons professionally arranging or executing cryptoasset transactions must maintain systems capable of preventing and detecting market abuse and report reasonable suspicions to competent authorities. The reporting obligation can extend beyond orders and completed trades to features of the distributed-ledger environment that indicate abusive behaviour.
European supervisory guidance expects authorities to reconcile on-chain, off-chain and cross-market data where possible. It also recognises the relevance of social media, validators, miners, order-book manipulation, token-supply abuse and extractable-value strategies.
The United Kingdom has also finalised a dedicated Market Abuse Regime for Cryptoassets. Its framework places gatekeeper and surveillance responsibilities on UK cryptoasset trading platforms and includes expectations concerning on-chain monitoring and cross-platform information sharing.
The direction of travel is clear: crypto-market surveillance is becoming a defined regulatory capability rather than a voluntary risk-management enhancement.
What an evidence-led investigation looks like
The investigation should begin with the event itself. Analysts need to identify when the listing decision was made, when it became sufficiently certain to be price-sensitive, who had access to the information and when it was disclosed publicly.
The trading chronology should then be reconstructed. Relevant evidence includes the time of each swap, token quantity, acquisition cost, disposal value, realised profit and relationship to the announcement.
Wallet funding and withdrawal activity can reveal the wider network. Investigators should trace where the capital originated, whether several addresses shared a funding source and where the proceeds moved after the trade.
Centralised-exchange records may provide identity information where an address deposited or withdrew through an identifiable account. Other evidence can include IP addresses, devices, know-your-customer files, bank payments and Travel Rule information.
The review should also examine legitimate explanations. Was there public speculation about the listing? Did the wallet regularly trade similar tokens? Was the position part of a market-making or arbitrage strategy? Did the trader assume substantial risk over a longer period rather than purchasing immediately before publication?
Internal evidence is equally important. Access logs, listing-committee records, confidentiality controls and employee communications can establish who knew the information and whether it was shared improperly.
The strongest case is built through convergence: suspicious trading, repeat timing, wallet attribution, access to confidential information and evidence connecting the person’s knowledge with the transaction.
What a resilient control stack looks like
The first layer is information governance. Exchanges, issuers and advisers should define when a listing decision becomes confidential, restrict access and maintain records showing who viewed or received the information.
The second layer is employee and connected-person surveillance. Personal-dealing policies should cover self-hosted wallets and decentralised trading rather than only accounts held at traditional brokers or centralised exchanges.
The third layer is event-based analytics. Surveillance systems should correlate listing decisions, token launches, partnership announcements, protocol upgrades and other price-sensitive events with pre- and post-event trading.
The fourth layer is cross-market coverage. Firms should connect centralised orders, DEX swaps, bridges, wallet transfers and social-media activity. Monitoring only one venue creates blind spots that sophisticated traders can exploit.
The fifth layer is wallet clustering and attribution. Shared funding, common withdrawal destinations, recurring transaction patterns and links to known exchange accounts can reveal coordinated activity hidden behind several addresses.
The sixth layer is typology-specific detection. Insider dealing, wash trading, spoofing, pump-and-dump activity, abusive extractable-value strategies and liquidity manipulation should not be compressed into a single generic market-abuse alert.
Finally, firms need documented escalation and reporting processes. Analysts must know when a pattern requires internal investigation, restriction of an employee, preservation of evidence or submission of a suspicious transaction and order report.
How blockchain transparency becomes a defensive advantage
DEXs are sometimes described as opaque because users trade through pseudonymous addresses. In another sense, they are radically transparent. Every swap, transfer and smart-contract interaction is preserved on a ledger that investigators can analyse retrospectively.
A traditional venue may retain detailed records, but external investigators usually cannot examine them without formal access. Public blockchains allow surveillance teams to observe the transaction path directly and test relationships across long periods.
This transparency can expose serial misconduct. A wallet that trades before one announcement may appear lucky. A connected cluster that repeatedly accumulates tokens before confidential listings and sells immediately after publication creates a materially stronger pattern.
The defensive opportunity depends on data integration. Blockchain records need to be combined with verified identities, event calendars, employee access, exchange deposits and external intelligence.
Technology can identify the pattern. Human investigators still need to establish materiality, knowledge, legal duty, intent and the appropriate regulatory response.

What this means for financial crime leaders
DEX-based insider trading should not be governed solely as a blockchain-analytics issue. It is a market-integrity risk connecting information security, employee conduct, trade surveillance, financial crime, legal analysis and regulatory reporting.
The Solidus Labs tool was important because it demonstrated that public blockchain data could be aligned with confidential-event timelines to identify trading that legacy systems might miss. Its deeper significance is the surveillance model it represents: on-chain and off-chain evidence must be analysed together.
Leaders should ask whether their organisations know who has access to listing information, whether employee trading policies cover self-hosted wallets and whether surveillance follows an asset across both centralised and decentralised venues.
They should also resist treating every algorithmic alert as proof of wrongdoing. Pseudonymous trading, market speculation and automated execution create legitimate activity that can resemble abuse. Defensible decisions require calibrated models, source-level evidence and experienced review.
Decentralisation does not eliminate insiders, confidential information or conflicts of interest. It changes where the trading occurs and how the evidence must be assembled.
The institutions best prepared for this risk will be those that use blockchain transparency as an investigative advantage, connect wallet behaviour with human access and build market-surveillance controls capable of following misconduct wherever liquidity moves.
What Financial Institutions Should Consider
- Extend Market Surveillance to Decentralized Exchanges
- Integrate On-Chain and Off-Chain Intelligence
- Monitor Trading Around Token Listings and Announcements
- Detect Suspicious Pre-Listing Token Activity
- Strengthen Wallet Attribution and Entity Resolution
- Apply Behavioural Analytics to DEX Trading Patterns
- Identify Connected Wallets and Coordinated Trading
- Use Blockchain Analytics for Market Abuse Investigations
- Develop Crypto-Specific Insider Trading Scenarios
- Connect Trade Surveillance With AML Monitoring
- Strengthen Governance Around Employee Crypto Trading
- Monitor Conflicts of Interest and Privileged Information
- Preserve On-Chain Evidence for Investigations
- Improve Coordination Between Compliance, Surveillance and AML Teams
- Conduct Retrospective Reviews After Material Token Events
- Assess Third-Party Crypto Surveillance Capabilities
- Monitor Emerging DeFi Market Manipulation Typologies
- Build a Unified Crypto Market Integrity Framework
Download the briefing
Insider Trading on Decentralised Exchanges: Detecting Market Abuse On-Chain




Insider trading on decentralised exchanges demonstrates that transparency and accountability are not the same thing. Blockchain transactions may be publicly visible, but the identities, relationships and information advantages behind those transactions can remain hidden across pseudonymous wallets, external platforms and private communications.
Effective detection therefore requires more than monitoring token prices or individual swaps. Institutions must connect on-chain trading with off-chain events, including listing decisions, employee access, issuer communications and the timing of public announcements. Repeated pre-event accumulation, rapid post-announcement disposal and common funding or withdrawal patterns can create strong investigative leads, particularly when the same wallet clusters appear across several confidential events.
However, surveillance alerts are not proof of misconduct. Legitimate speculation, arbitrage, market making and public rumours can produce similar patterns. Defensible investigations must establish who controlled the relevant wallets, what information they possessed, whether that information was material and non-public, and whether a legal or professional duty was breached.
The strongest control frameworks will therefore combine event-based analytics, wallet attribution, cross-market surveillance, employee-dealing controls and source-level evidence. They will also distinguish insider dealing from other forms of crypto-market abuse, including wash trading, pump-and-dump activity, front-running and liquidity manipulation.
Ultimately, decentralisation does not remove conflicts of interest or the misuse of confidential information. It changes the venues, identities and evidence involved. Organisations that connect blockchain transparency with human access and accountable investigation will be better positioned to protect market integrity wherever cryptoasset liquidity moves.