l0grisk intelligence · english

// analysis

The market beyond the screen: billions of order messages outside JPMorgan surveillance

From 2014 to 2021, JPMorgan failed to feed more than 99% of the order messages on one US venue into its surveillance systems. Part one connects the manipulation admitted in 2020, the gap discovered in 2021 and the 2024 sanctions without treating a control failure as proof of new abuse.

dated revision: July 31, 2026French originalprimary sourcesno tracker

In June 2021, onboarding a new trading venue exposed an anomaly at JPMorgan. Order and trade feeds were not properly reaching its surveillance tools. The internal review then expanded across the world: at least 30 venues were affected, several products were involved and some gaps dated back to 2014. On one US venue identified only as “DCM-1”, more than 99% of order messages escaped surveillance from 2014 to 2021. The volume ran into billions. The Commodity Futures Trading Commission did not find billions of fraudulent trades. It established a surveillance failure on an exceptional scale.

The distinction defines this investigation. Missing data do not prove manipulation. They prevent the very control designed to detect it. The problem becomes more serious in light of the past: in September 2020, JPMorgan had admitted manipulation in precious metals and US Treasuries, promised remediation and described a strengthened system to the CFTC. Part of the market nevertheless remained invisible to it.

This two-part investigation reconstructs the record from orders issued by the CFTC, Federal Reserve and Office of the Comptroller of the Currency, the Department of Justice criminal case, Securities and Exchange Commission action and JPMorgan’s own SEC filings. This part establishes chronology and risk. Part two examines sponsored access, the surveillance pipeline and the material missing from the public record.

An established scandal

The starting point is neither rumour nor extrapolation. In September 2020, JPMorgan entered a deferred prosecution agreement with the Department of Justice. The bank admitted two separate wire-fraud schemes involving market manipulation.

The DOJ case record first covers gold, silver, platinum and palladium futures. From March 2008 to August 2016, traders and salespeople on trading teams in New York, London and Hong Kong placed orders intended for cancellation before execution on tens of thousands of occasions. The second scheme involved Treasury futures and the cash market for Treasury notes and bonds. From April 2008 to January 2016, the DOJ records thousands of deceptive sequences.

Liability did not remain solely corporate. In August 2023, Gregg Smith and Michael Nowak received prison sentences. Smith was sentenced to two years, Nowak to one year and one day. The DOJ put losses to market participants in the scheme tried before the jury at more than $10 million. Those convictions concerned precious metals and individual conduct proven at trial. They establish nothing about the messages missing from surveillance between 2014 and 2021.

Spoofing, a false order in the book

A limit order book displays intentions to buy and sell. Price, quantity and visible depth help participants and algorithms estimate supply and demand. The Commodity Exchange Act defines spoofing as bidding or offering with the intent to cancel before execution.

The mechanism used by JPMorgan traders combined two sides:

  1. a genuine order intended for execution;
  2. one or more deceptive orders on the opposite side, intended for cancellation.

The false orders created the appearance of stronger buying or selling pressure. Once the genuine order traded at a more favourable price, the deceptive orders disappeared. A rapid cancellation alone does not prove spoofing. Intent to cancel before execution is the decisive element. Criminal cases established it from trading sequences, communications and other evidence.

SPOOFING: TWO SIDES, TWO INTENTIONS Teaching diagram based on facts admitted and tried in the 2020 case. GENUINE ORDER intent to execute desired purchase or sale DECEPTIVE ORDERS intent to cancel displayed opposing pressure SKEWED ORDER BOOK GENUINE ORDER EXECUTES deceptive orders are then cancelled Cancellation is not inherently fraudulent. Prior intent separates spoofing from a legitimate order. Sources: DOJ case 20-CR-175; CFTC Order 20-69, 29 September 2020.
The diagram isolates the general logic. Actual sequences varied by product and trader. The legal proof did not rest on cancellation rates alone.

Eight years, two teams, three markets

The 2020 CFTC order goes further than the criminal summary. It describes hundreds of thousands of deceptive orders in precious metals and Treasury futures from 2008 to 2016. JPMorgan traders created artificial prices in many instances. The order also found a supervision failure at J.P. Morgan Securities.

Warning signs existed. The CFTC cites internal alerts, inquiries from CME and the Commission, and internal allegations from a JPMorgan trader. Before 2014, the surveillance system could not effectively identify spoofing. A newer tool followed, yet the firm still failed to identify, investigate and stop the conduct during the relevant period.

The SEC separately documented manipulation in cash Treasuries from April 2015 to January 2016. J.P. Morgan Securities admitted the findings. Genuine orders were accompanied almost simultaneously by non-bona-fide orders on the opposite side to improve execution prices. The conduct was not confined to metals or futures.

A strengthened system presented in 2020

At settlement, JPMorgan described a significant change in control. The CFTC order records the firm’s representations: hundreds of new compliance officers, larger budgets, specific training, surveillance of more than 80 equity exchanges and more than 40 futures and options exchanges.

JPMorgan also said it used three primary alert types in the SMARTS software for spoofing and layering. Quality testing covered alerts referred to a higher review level and alerts closed without such referral. Monthly reports aggregated alerts by trader, team, supervisor and region. The firm further represented that its communications platforms processed about 100 million electronic messages each month and analysts reviewed every alert generated by that communications surveillance.

The CFTC did not frame those statements as an end-to-end audit of every market feed. It recorded them among JPMorgan’s remediation representations. The order required the firm to maintain and update a programme designed to detect and deter violations.

The $920.2 million commonly attached to the case was one coordinated resolution, not three independent sums. The DOJ breakdown was a $436,431,811 criminal penalty, $311,737,008 in victim compensation and $172,034,790 in disgorgement. Credits for CFTC and SEC payments prevented double counting of the same components.

A new venue exposes the gap in June 2021

Nine months after the settlement, an ordinary event prompted a major discovery. JPMorgan was preparing to onboard a new venue. In June 2021, it identified significant gaps in the order and trade data reaching its surveillance systems.

The review went global. According to the May 2024 CFTC order, gaps affected at least 30 venues, multiple products and periods dating back to at least 2014. JPMorgan disclosed them to the Commission in 2021 and represented that it had not known about them. They therefore had not been discussed during the 2020 settlement.

The CFTC states the consequence directly: at the time of the spoofing resolution, JPMorgan was not surveilling certain order messages. Improvements described in 2020 could have been genuine for data present in the system. They did not cover absent data.

TWO CASES, ONE OVERLAP The periods overlap; the legal findings remain distinct. ESTABLISHED MANIPULATION 2008 2016 precious metals and Treasuries SURVEILLANCE GAPS 2014 June 2021 2023 discovered in 2021, represented as remediated in 2023 SEPT. 2020 spoofing settlement and remediation representations 2024 Fed, OCC, CFTC The overlap does not establish new abuse in the missing feeds. Sources: DOJ 20-CR-175; CFTC 20-69 and 24-07; Fed 24-007-B-HC; OCC AA-EC-2023-50.
Admitted manipulation spans 2008 to 2016. Surveillance gaps began by 2014 and lasted through 2023 on some venues. The overlap identifies a control failure, not new unlawful trading.

DCM-1 and more than 99% missing

The most severe case involved a regulated US futures venue anonymised by the CFTC as “DCM-1”. From 2014 to 2021, JPMorgan failed to feed billions of order messages into surveillance. More than 99% of the venue’s messages went unsurveilled.

Three qualifications prevent a false reading:

  • an order message can create, modify or cancel an order and is not necessarily an executed trade;
  • the message count gives neither a total dollar value nor the size of any position;
  • the CFTC sanctioned a supervision failure, not new manipulation across every missing message.

JPMorgan said most activity came from sponsored access trading for three significant algorithmic firms. The order names neither the venue nor the firms. Part two examines this architecture because it changes the origin of orders without removing the need for complete surveillance data.

A golden source without reconciliation

The technical cause described by the CFTC was a data-governance error. JPMorgan used feeds received directly from exchanges. It had a quarterly process for reconciling the completeness of some data sent to surveillance tools, but direct-from-exchange feeds were excluded.

The assumption sounded reassuring and became the central defect: exchange data were treated as a golden source and therefore not tested by the same reconciliation. The content could be accurate at origin and still fail during configuration, transport or entry into the system. The CFTC identifies configuration problems that kept feeds from entering a third-party surveillance system.

Risk did not live solely in data quality. It appeared between systems. A file could be reliable and an alert engine functional while the end-to-end chain remained blind because nobody compared messages received with messages expected.

Three penalties and one data failure

On 14 March 2024, the Federal Reserve and OCC acted simultaneously. The Fed found gaps from 2014 to 2023 on at least 30 global venues and inadequate controls over data and reconciliation. It classified the practices as unsafe or unsound and imposed $98,167,980.

The OCC reached the same unsafe-or-unsound finding. Its order concerned billions of trading instances, at least 30 venues, data governance and venue coverage. It imposed $250 million, paid to the Treasury according to the agency.

On 23 May 2024, the CFTC added a nominal $200 million obligation. Its order granted two $50 million credits for payments under the OCC and Fed actions. The CFTC-specific payment therefore became $100 million if both credits applied, producing a coordinated total of $448,167,980. In its 30 June 2024 Form 10-Q, JPMorgan rounded the figure to $450 million and said it had paid it.

2024: NOMINAL AMOUNTS AND CREDITS The three gross amounts cannot be added without accounting for credits. OCC $250m FEDERAL RESERVE $98.168m CFTC, NOMINAL $200m MINUS $100m OF CFTC CREDITS $50m for the OCC payment, $50m for the Fed payment $448.168m EFFECTIVE Sources: Fed 24-007-CMP-HC; OCC AA-EC-2023-49; CFTC 24-07; JPMorgan Q2 2024 10-Q.
JPMorgan reported the aggregate as $450 million after rounding. The three gross orders totalled $548.168 million, but the CFTC credited $100 million.

A limited finding in the second case

The 2024 actions did not find a repetition of the 2008 to 2016 manipulation. The CFTC sanctioned J.P. Morgan Securities for failure to supervise. JPMorgan admitted the facts concerning the scope and causes of the gaps and acknowledged a violation of CFTC Regulation 166.3. Under the settlement formula, it neither admitted nor denied the other findings.

In its second-quarter 2024 report, JPMorgan said it had reviewed the previously unsurveilled data and identified no employee misconduct, harm to clients or harm to the market. This was the firm’s published conclusion. Regulatory orders also required detailed reports and independent review. Their contents do not appear in the public documents consulted for this investigation.

The DOJ, meanwhile, closed the 2020 criminal case. The three-year DPA term expired on 29 September 2023. On 29 March 2024, the Department moved to dismiss with prejudice on the ground that JPMorgan had fully met its obligations; the court granted the motion the same day. The decision followed the Fed and OCC orders but concerned compliance with the earlier criminal agreement. It did not erase the 2024 findings or certify every surveillance feed.

Part two and the control black box

Part one supports a narrow conclusion. JPMorgan admitted a vast historical manipulation scheme. During part of the remediation period, billions of messages did not reach surveillance. Regulators established a supervision failure, not a new fraud across those messages.

The central risk is therefore one of knowledge. A bank can count alerts, calibrate scenarios and hire control staff while remaining unaware of a massive upstream absence. Without end-to-end reconciliation, the dashboard measures only data received.

The investigation continues in “After the fines: the black box inside JPMorgan market surveillance”: sponsored access, venue inventories, mandated reports, independent review, public unknowns and tests for remediation.

Primary sources

  1. CFTC, Order 20-69 on manipulation and supervision failures, 29 September 2020.
  2. Department of Justice, case 20-CR-175 and deferred prosecution agreement, updated 27 August 2024.
  3. Department of Justice, sentencing of Gregg Smith and Michael Nowak, 22 August 2023.
  4. SEC, cash Treasury manipulation action, 29 September 2020.
  5. Federal Reserve, Orders 24-007-B-HC and 24-007-CMP-HC, 14 March 2024.
  6. OCC, trade-surveillance order and penalty, 14 March 2024.
  7. CFTC, Order 24-07 on surveillance gaps, 23 May 2024.
  8. JPMorgan Chase, Form 10-Q for 30 June 2024, Trading Venues Investigations note.

Method and limit: each penalty was reconciled to its order and applicable credits. “Billions” refers to order messages, not dollar value. This investigation attributes no misconduct to missing feeds beyond conduct already admitted or tried. JPMorgan’s conclusions are labelled as such. No internal report, non-public consultant report or non-public remediation report was used.

This analysis is not investment advice.

// cite this analysis

l0g, “The market beyond the screen: billions of order messages outside JPMorgan surveillance”, l0g.fr, published July 31, 2026, updated July 31, 2026, https://l0g.fr/en/analysis/jpmorgan-market-beyond-screen-order-surveillance/


$ cd ../analysis