Liquidity, the Order Book and the Tape
In this chapter: We go one layer beneath candles and footprints, into the machinery that produces every print: the order book of waiting orders, the queue that decides who is filled first, and the tape that records every trade. You will learn the three levels of market data (L1, L2, L3), how to read a DOM and a liquidity heatmap, what walls, pulling and stacking are, why visible liquidity can mislead in both directions, how one large order becomes many small prints, what sweeps, stop runs and icebergs really are, why spoofing is a crime and not a strategy, and what the research on order flow imbalance does and does not show. The running theme: displayed liquidity is a promise, not a commitment, and much of this is harder to detect than social media suggests.
The Order Book: L1 vs L2 vs L3 Explained
Every trade you have seen in this book so far, every candle, every delta box, every footprint cell, was born at the same place: the moment an aggressive order met a waiting order. This chapter is about those waiting orders and about the record of their meetings.
What the order book is
The order book is the exchange's list of all limit orders that have been submitted but not yet executed. A limit order, as you saw in earlier chapters, is an instruction to buy or sell at a specific price or better, and it waits until someone agrees to trade with it. Buy limit orders sit on the bid side of the book. Sell limit orders sit on the ask side (also called the offer). Orders that wait are called passive.
A market order does not wait. It is an instruction to trade now at the best price available, and it does so by hitting the passive orders already in the book. The trader who sends it is the aggressor. A trade happens only when an aggressor meets a passive order. If nobody is aggressive, nothing trades, no matter how many orders are waiting.
Market data about the order book is usually described at three levels of detail.
Level 1: the top of the book
Level 1 (L1), also called top of book, shows only four things: the best (highest) bid, the best (lowest) ask, the quantity resting at each of those two prices, and the last trade. A typical retail quote screen, and the raw material for an ordinary candle chart, is L1 plus the stream of trades.
On gold futures, an L1 snapshot might read: best bid 4,240.0 for 14 contracts, best ask 4,240.1 for 9 contracts, last trade 4,240.1. (On an XAUUSD chart the same moment would sit roughly $27–30 lower, around 4,210–4,213; the gap varies and is always approximate.)
Level 2: market by price
Level 2 (L2), also called market by price (MBP) or depth, shows the total quantity waiting at several prices above and below the market. This is the data behind the DOM ladder of the next section.
The crucial word is total. If L2 shows 60 contracts on the bid at 4,239.5, you do not know whether that is one order for 60 contracts, sixty orders for one contract each, or anything in between. CME's classic market-by-price feed publishes up to ten price levels on each side, together with the number of orders at each level, but not the size of each individual order.
Level 3: market by order
Level 3 (L3), known on CME as market by order (MBO), shows every individual order: its anonymous identifier, its size, its price and its place in the queue. CME's MBO feed covers the full depth of the book, not just ten levels, and lets you follow each order as it is added, changed, cancelled or filled.
Why does the distinction matter? Because many ideas in this chapter, such as your position in the queue, native icebergs, and telling a cancellation apart from a fill, can only be examined properly with L3. With L2 you are inferring; with L3 you are reading the event log.
| Level | What it shows | Question it answers |
|---|---|---|
| L1 (top of book) | Best bid, best ask, their sizes, last trade | "What is the price right now?" |
| L2 (market by price) | Total size at each of several prices | "How much is waiting near the market?" |
| L3 (market by order) | Every order: anonymous ID, size, price, queue order | "How many orders, how big, in what sequence, and what happened to each?" |
What no level shows you
Even full MBO data has blind spots, and beginners often assume otherwise.
- Stop orders are invisible until they trigger. A stop is an instruction held by the exchange (or your broker) that becomes an active order only when price reaches a trigger. Until then it is not in the book at all.
- The hidden part of an iceberg order is not displayed (more on this later in the chapter).
- Implied orders, which the exchange synthesises from spread markets between contract months, appear in the price-level data but not in the order-by-order feed.
- Intent changes instantly. The book is a snapshot of what people are willing to do this millisecond. It can be completely different a millisecond later.
Key idea: The order book is intention. A trade is fact. L1 tells you the price, L2 tells you how much is waiting, L3 tells you how many orders, how big, and in what sequence, but always anonymously.
Common mistake: "With Level 2 I can see where the institutions are sitting." L2 gives totals at each price, not identities, and not even the size of individual orders. Even L3 IDs are anonymous: you never learn who placed an order.
Common mistake: "I can see the stops on the DOM." You cannot. Stops do not exist in the visible book until they are triggered.
L3 data is also larger and more expensive, and not every trader needs it. What matters is knowing which level of data a claim actually requires.
How to Read a DOM Ladder
The ladder
DOM stands for depth of market. It is L2 data drawn as a vertical price ladder. Each row is one price. On gold futures (GC) and micro gold (MGC), each row is one tick, the minimum price increment of $0.10. Recall the money value of a tick: $10 per contract on GC (100 troy ounces) and $1 per contract on MGC (10 troy ounces). Always re-check the current specifications on CME's website, because exchanges do change them.
The ladder has a bid column on one side and an ask column on the other. A number in the bid column is the total quantity of buy limit orders resting at that price. A number in the ask column is the total of resting sell orders.
| Bid size | Price | Ask size |
|---|---|---|
| 4,240.4 | 21 | |
| 4,240.3 | 18 | |
| 4,240.2 | 25 | |
| 4,240.1 | 37 | |
| 12 | 4,240.0 | |
| 19 | 4,239.9 | |
| 24 | 4,239.8 | |
| 31 | 4,239.7 |
Approximate XAUUSD equivalent of this ladder: about 4,210–4,213; the gap between futures and spot CFD prices moves through the day.
Most platforms add more columns: volume at price (how much has traded at each price today or this session), sometimes traded at bid / traded at ask (how much was hit by aggressive sellers or lifted by aggressive buyers at that price), and pulling/stacking columns that show recent changes in resting size (covered two sections from now).
Reading it in three steps
Step 1: find the inside market. The inside market is the highest bid and the lowest ask; here, 4,240.0 bid and 4,240.1 ask. The distance between them is the spread. In the example it is one tick, worth $10 per GC contract or $1 per MGC contract. During active hours gold futures usually trade with a one-tick spread; during thin hours, or in the seconds before a major economic release, the spread often widens to two ticks or more.
Step 2: look at the shape of the depth. Is one side unusually heavy compared with the other? Is there one price with a much larger number than its neighbours? Hold that observation lightly: the next sections explain why.
Step 3: watch how the inside numbers change when trading happens. When the 37 contracts at 4,240.1 shrink to 30, did they shrink because 7 contracts traded there (a fill), or because someone cancelled 7 contracts without any trade (a pull)? This question, filled or pulled?, is one of the most important in this chapter.
What it takes to move one tick
Here is the mechanism that makes the DOM useful. In the ladder above, the price can only print 4,240.2 after the entire 37 contracts on the ask at 4,240.1 are gone, either consumed by aggressive buyers or withdrawn by their owners. The DOM therefore shows you how much work it takes to move price. A thin ask side means little work; a thick one means more.
Key idea: Price moves up one tick only when the whole quantity on the best ask is used up or pulled. Price moves down one tick only when the whole quantity on the best bid is used up or pulled.
Limits of the DOM
The DOM shows only now. It has no memory of what was there a minute ago, which is exactly why the heatmap was invented. Numbers far from the current price are especially unstable, because orders there can be cancelled at no cost long before price arrives. And watching a fast gold DOM by eye for hours is tiring and invites perception errors: you start seeing patterns in noise.
Common mistake: "The side with more size on the DOM will win." This is a popular claim, not proven. Resting size can be cancelled in an instant, and a heavy side may simply attract aggressors who want to trade against it.
Common mistake: Confusing the DOM with the footprint. The DOM shows orders waiting to trade; the footprint shows contracts that did trade. They answer different questions.
Try it: Open a GC or MGC DOM in a simulator around the New York stock market open (09:30 New York time). For two minutes, watch only the inside market. Count how often the spread widens from one tick to two, and try to notice at least once when the best ask shrinks without any print on the tape.
Without a level you chose in advance, the DOM is mostly noise. Its value appears when price arrives at a place you already care about.
Market by Order (MBO): Seeing Individual Orders
Every order has a life story
With market-by-order data, each order has a lifecycle you can follow:
- Add: the order enters the book.
- Modify: its size or price is changed.
- Cancel: it is withdrawn.
- Fill (execution): it trades, fully or partially.
CME gives each order an anonymous OrderID, which stays the same for the order's whole life, and a priority value, which determines its place in the queue at its price and can change when the order is modified in certain ways (the next section explains which ways).
Filled or pulled: the key question
Suppose the L2 bid at 4,239.5 drops from 80 contracts to 20. Two very different stories fit that single fact:
- Aggressive sellers sold 60 contracts at 4,239.5, and the resting buyers absorbed them. Buyers were genuinely present and did trade.
- The resting buyers pulled (cancelled) 60 contracts. Nobody traded; buyers stepped back.
The first is buyers standing their ground; the second is buyers retreating. With L2 you can only guess which, from the timing of trades and book changes. With MBO you see exactly which orders were filled and which were cancelled. Imagine the same moment split by MBO into 35 contracts filled and 25 contracts cancelled: the reality was a mixture, which L2 alone could never reveal.
What else MBO tells you
MBO shows the number and sizes of orders at each price: one 60-lot or forty small orders. It lets you estimate the size of the queue in front of a specific order. And it carries the fingerprints of native iceberg orders, which you will meet later in this chapter. Commercial data vendors distribute CME's market data feed (called MDP 3.0) in MBO form with precise timestamps. Our own order-book indicator, AK FlowBook, is built on this kind of order-by-order data; in this book we use it only to illustrate concepts.
What MBO still cannot show
- It is anonymous. One large order is not necessarily one institution, and several orders may belong to the same trader.
- Parent orders are hidden. Large traders often use algorithms that slice one big intention (the parent order) into many small child orders over minutes or hours. MBO shows the children, never the parent.
- It is heavy. The volume of messages is enormous, and correctly rebuilding the book from them (handling event order, gaps and recoveries) is a technical skill in its own right. A bug in the rebuild produces confident but wrong conclusions.
- Implied liquidity is missing, as noted above.
Common mistake: "MBO lets me see the institutions' hands." This is a popular claim, not proven. The data is anonymous and orders are sliced; better data does not reveal identities.
Common mistake: "Every drop in DOM size means trading happened." It may have been a cancellation.
Key idea: The most practical gift of MBO is simple: it separates executed from cancelled. Better data does not fix bad analysis, but it removes a whole class of guessing.
Queue Position and FIFO: Why Being First Matters
Who fills first?
When many limit orders wait at the same price and an aggressor arrives, the exchange's matching engine must decide which waiting orders get filled first. CME uses several matching algorithms. The most widely used is FIFO (first in, first out): at a given price, the order that arrived first is filled first. Published data indicates FIFO accounts for the largest share of volume on CME Globex. Some other products use pro-rata matching (fills split in proportion to order size) or a hybrid. Check the official CME specification for the algorithm on any contract you trade; in this book we work with FIFO for gold.
Think of a queue at a ticket window: first to join, first served, however large your order.
Rules that keep or lose your place
On CME, priority follows a simple logic:
- Reducing the size of your order keeps your place in the queue.
- Increasing the size loses your place: the order goes to the back.
- Changing the price loses your place: at the new price you join the back of that queue.
Touched is not filled
Here is the consequence that surprises almost every new trader. Suppose your buy limit order is at 4,240.0 (roughly 4,210–4,213 in XAUUSD terms) and there are 300 contracts in the queue ahead of you. Price trades down to 4,240.0, 200 contracts trade there, and then price bounces. You were never filled, because 100 contracts were still ahead of you when the selling stopped.
A worked example: your order sits 140th in a 220-contract queue. Price touches your level once and 90 contracts trade; it touches again later and 30 more trade. In total 120 contracts traded at your price, and you were still 20 contracts from the front. Nobody cheated you. You were simply not first in line.
Easy fills can be bad fills
The opposite case teaches something deeper. When your limit order fills instantly and completely, sometimes it is because the entire queue was consumed and price went straight through your level. You were filled precisely because the market was moving against you. This is called adverse selection: the fills that come easiest are often the worst ones, because they happen when the other side has a stronger reason to trade.
This is also why backtests that assume "price touched my limit, so I was filled" are optimistic. Chapter 12 returns to this in detail.
Key idea: At one price, first come, first served. Price touching your order is not the same as your order being filled.
Common mistake: "Price reached my limit and I wasn't filled, so the broker cheated." Usually the FIFO queue explains it completely.
Common mistake: Repeatedly nudging an order up and down by a tick "to be ready". Every price change sends you to the back of a queue.
Without MBO data, nobody knows your exact queue position. Platforms that display "queue ahead" are estimating, using assumptions such as "cancellations happen at the back of the queue" or "cancellations are spread proportionally". These are models, not measurements.
The Liquidity Heatmap: The Order Book With Memory
The DOM, recorded over time
The DOM shows only the present instant. A liquidity heatmap is the DOM recorded over time and drawn as a picture:
- The horizontal axis is time.
- The vertical axis is price.
- The colour of each point is the quantity of resting limit orders at that price at that moment. Warm or bright colours mean a lot of resting liquidity; cool or dark colours mean little.
On top of this background, most heatmaps draw the price line and trade bubbles: circles whose size shows the traded quantity and whose colour shows which side was the aggressor.
Three basic patterns
Learn to recognise three things a bright band can do:
- Held. A bright horizontal line persists for a long time. Someone, apparently, is willing to trade a lot at that price.
- Eaten. Price reaches the band, trade bubbles appear, and the band fades. The liquidity really traded: it was filled.
- Pulled. Price approaches and the band fades without trade bubbles. The liquidity was withdrawn.
The difference between patterns 2 and 3 is the same filled-or-pulled question from the MBO section, now visible as a picture.
Why the heatmap helps
The heatmap gives the order book a memory. You can see where liquidity keeps returning, where the book is thin (dark areas, where price may travel quickly because little is in the way), and what happened the last time price met a particular band.
Why the heatmap can mislead
- It is usually built from L2, so it inherits L2's ambiguity about fills versus cancels when both happen at the same price.
- Colour settings change the story. Contrast and threshold controls decide what looks "huge". A band that looks enormous on one screen may look ordinary on another simply because of the colour scale. Comparing two screenshots made with different settings is meaningless.
- It is seductive. Heatmaps are beautiful, and beautiful pictures invite stories. The risk of seeing meaning in randomness (storytelling bias) is higher here than on almost any other chart.
Common mistake: "Bright bands act like magnets and pull price toward them." This is a popular claim, not proven.
Common mistake: Treating a bright band as certain support or resistance. Liquidity can be pulled at the last moment.
Try it: Choose one colour setting for your heatmap, write it down, and never change it during a study period. Then, over a full New York session (around 08:20–13:30 New York time), mark one example each of a band that held, one that was eaten and one that was pulled.
Liquidity Walls, Pulling and Stacking
Definitions
A liquidity wall is a price in the book where the resting quantity is unusually large compared with the nearby prices, for example several times the typical size of the surrounding levels. On a heatmap it is a bright band; on the DOM it is one conspicuously large number.
"Unusually large" is always relative. Forty contracts might be a wall at 02:00 New York time during the quiet Asian session and completely ordinary at 10:00 during New York. Defining a wall by a fixed number for every hour of the day is a mistake.
Stacking means limit orders being added at one or more prices: resting size grows without any trade to explain it. Pulling means limit orders being cancelled: resting size shrinks without any trade. Many platforms show a pulling/stacking column next to the DOM that displays the recent net change at each price. With L2 data, that column sees only the net change: if trades and cancellations happen at the same price at the same time, separating them is an estimate.
A simple example: at 4,236.0 the bid shows 30 contracts. Over the next few seconds it rises to 90 while nothing trades there. That is +60 of stacking. A minute later it drops from 90 to 35, again with no trades printed at that price: −55 of pulling.
A reasonable (not certain) interpretation
If price is moving down toward a bid level and bids at and below that level are being stacked, waiting buyers are showing up. That may mean temporary support. If those same bids are being pulled as price approaches, buyers are stepping back, and price may pass through more easily. This is ordinary auction logic: price travels more easily in the direction that offers less resistance.
Why can this be meaningful at all? Market makers, firms that continuously quote both a bid and an ask and earn from the spread, and other short-term traders cancel their orders when they sense risk. Pulling can therefore reflect real information or real fear.
Why most of it means little
These changes happen in milliseconds, and algorithms react far faster than any human eye. Much stacking and pulling is routine quote management that carries no "message" at all.
Common mistake: "A big wall means an institution intends to defend that price." This is a popular claim, not proven.
Common mistake: "When a wall is pulled, price must move in that direction." This is a popular claim, not proven.
Key idea: Stacking and pulling describe intention in the moment, not a forecast. They are worth watching only at levels you chose before the session, such as yesterday's value area edges or the overnight low, and even then as context rather than as a trigger.
Why Visible Liquidity Can Be Fake
A promise, not a contract
A limit order is, until the moment it executes, a cancellable offer. No rule obliges someone who has posted a 200-contract bid to leave it there, provided they did not place it with the intention of cancelling it (that would be spoofing, covered later). So treat displayed liquidity as a promise, not a commitment. There are at least five reasons the displayed book differs from what you could actually trade against.
1. Normal, legitimate cancellations. Market makers adjust orders constantly according to risk. When price rushes toward them, the rational move is to pull. The uncomfortable result: liquidity tends to disappear exactly when it is needed most.
2. Flickering. Some orders appear and disappear within fractions of a second. On your screen they look big; in practice you never had a real chance to trade with them.
3. Hidden liquidity. The error runs the other way too. Iceberg orders display less than their true size, so what you see can be smaller than what is really there, not only larger.
4. Manipulative orders. Spoofing and layering are orders placed with the intent to cancel before execution. They are illegal in US markets, but from the outside proving intent is practically impossible.
5. Feed delay. What reaches your screen is already late, by milliseconds or more, compared with the state of the matching engine. In fast moments, the picture you are looking at is already old.
What the minutes before a release look like
A classic gold example: in the two minutes before a scheduled 08:30 New York time data release, such as the consumer price index (CPI) or the US jobs report, liquidity on a GC heatmap often thins out on both sides and the spread widens. Market makers do not want to be caught holding resting orders when the number comes out. When the release hits, price can jump through the empty space, because there is little resting liquidity in the way.
What to trust
The practical conclusion is simple: take liquidity seriously only when trading confirms it. That means price reached the level, volume actually traded there, and the level held. That is absorption you can see in the footprint (Chapter 9). Liquidity that has never been touched is weak information.
Key idea: Displayed size can be larger than the real tradable size (pulls, flicker, spoofing) or smaller (icebergs). Only trades at a level tell you what was real.
Common mistake: "Every wall that disappeared was a spoof." Most cancellations are legitimate risk management. Calling something spoofing without regulatory-grade data is meaningless.
Common mistake: "Then the DOM is worthless." It is not worthless; it is probabilistic information, not certain information.
Time & Sales: Reading the Tape
What the tape is
Time & Sales (T&S), also called the tape, is the chronological list of every completed trade. Each line is a print and shows:
- the time,
- the price,
- the size (number of contracts),
- and, on CME futures, the aggressor side: whether a buyer lifted the ask with a market order (a buy aggressor, usually shown in green) or a seller hit the bid (a sell aggressor, usually red).
The name comes from the paper ticker tapes that telegraph machines printed in old stock exchanges.
A short slice of gold tape might look like this:
| Time (NY) | Price | Size | Aggressor |
|---|---|---|---|
| 10:14:07.312 | 4,240.1 | 3 | Buy |
| 10:14:07.312 | 4,240.1 | 1 | Buy |
| 10:14:07.890 | 4,240.0 | 2 | Sell |
| 10:14:08.105 | 4,240.0 | 7 | Sell |
| 10:14:08.106 | 4,239.9 | 1 | Sell |
Approximate XAUUSD equivalent: around 4,210–4,213.
Intention versus action
The DOM shows intention: orders waiting. The tape shows action: what actually traded. The delta and footprint charts from earlier chapters are in fact statistical summaries of the tape. The footprint adds up these same prints by price and by aggressor side; delta is the difference between aggressive buying and aggressive selling.
So why look at the raw tape at all? Because it preserves sequence and rhythm, which summaries throw away. Did the large prints arrive back to back? Did price rise on many small prints or a few big ones? Did trading keep hitting one price while price refused to move, a possible sign of absorption?
Limits of the tape
- A print is not necessarily an order. One large market order that matches against several resting orders may appear as several prints, depending on the data feed and platform. The section on big trades below explains this in detail.
- In busy moments the tape runs faster than a human can read. Filters and grouping become necessary.
- Some trades are reported under different rules, for example legs of calendar spreads or privately negotiated block trades. They should not be mixed with ordinary screen trades without care.
Common mistake: "A green print means someone bought and nobody sold." Every trade has one buyer and one seller. The colour only tells you who was the aggressor. A green print of 5 at the ask means a buyer used a market order and a resting seller was filled for 5 contracts.
Common mistake: "Old-school tape reading still gives a reliable edge." This is a popular claim, not proven. Competing by eye against algorithms has become very hard.
Tape Speed: Bursts, Quiet, and What Pace Tells You
Measuring pace
Tape speed, or pace, is how many trades or how many contracts execute per unit of time, for example per second or per ten seconds. Old floor traders felt it as the sound of the ticker; modern platforms show it as a number or a bar.
Speed only means something relative to the hour
Absolute speed means nothing on its own. Gold at 03:00 New York time (London), at 10:00 (New York) and at 08:30 on a release day runs at completely different rhythms. Fifty trades in ten seconds could be a frenzy at 03:00 and an ordinary moment at 10:00. Always measure speed relative to what is normal for that same time of day on previous days. A simple way is to compare the current pace with the typical pace for the same clock time over the last few weeks, as a z-score (how many standard deviations above or below normal) or as a percentile.
A burst has three possible meanings
A burst is a sudden spike in the number of trades in a short time. It can mean:
- The start of a move. New information or a break of a level activates aggressors.
- The end of a move (a climax). The last buyers or sellers, often stop orders, rush in, and the other side absorbs them.
- A mechanical event. Stops being triggered behind a level, or a scheduled news release.
The burst itself does not say which. Two things decide: location (are we at a level that matters?) and outcome (did price continue after the burst, or stall?).
Quiet is information too
When price arrives at an important level and the tape is calm, nobody is in a hurry to push through. Many traders believe that slow breakouts are less trustworthy than fast ones. That is a popular claim, not proven, and it is exactly the kind of idea you should test on your own data before relying on it.
Key idea: Pace measures activity, not direction. Combine it with delta or the footprint, and always judge it against the same hour of the day.
Common mistake: "Fast tape means get in." A burst at a climax can be the worst possible moment to act.
Common mistake: "High speed means institutions have arrived." This is a popular claim, not proven. It may just be a cluster of small traders' stops being triggered.
Gold note: On a typical gold day you can expect at least three bursts that have nothing to do with each other: the London open, any 08:30 New York data release, and often one at the high or low of the day. Same spike on the speed panel, very different meaning.
Big Trades: Why One Order Prints as Many Small Fills
How matching splits an order
Imagine someone sends a market order to buy 50 GC contracts. At the best ask there are 12 small limit orders from different traders, queued in FIFO order. The matching engine fills the 50-lot against each of them in turn, and if they are not enough, it moves on to the next price. The result, depending on the feed and the platform, may be dozens of small prints on the tape (3, 1, 5, 2, 4…) all with almost the same timestamp, instead of one print of 50.
CME's market data feed reports the trades caused by one aggressive order as a single match event, summarised by price level and optionally with order-level detail. Many platforms and data vendors, however, display trades per resting order or per price, which breaks the event into pieces. That is why tools exist that group near-simultaneous prints in the same direction back together, to estimate the true size of the aggressive order.
A real example: 278 contracts in one go
On 2 October 2026, the day of the US jobs report, gold futures reacted at 08:30 New York time as the number was released. In the first moments, one aggressive buy order for 278 GC contracts hit the book. It was too large to be filled at the best ask, so it consumed the whole ask queue at one price, then the next, then the next, sweeping several consecutive price levels in a fraction of a second. On a raw tape this single decision appeared as a long column of small prints at rising prices. Only by grouping the fills of the same aggressive event does the true picture emerge: one participant, one order, 278 contracts. That is 27,800 troy ounces (278 × 100), which at a gold price above $4,200 is well over $100 million of notional value, and every $1 move in gold changes its value by $27,800.
Note what this one order tells you and what it does not. It tells you that one participant was impatient enough to pay through several prices at the moment of the release. It does not tell you who they were, whether this was their whole position or one slice of it, or what price would do next.
Two problems that remain
- Grouping is an estimate. Grouping prints by time and direction can merge two independent orders that happened to arrive almost together, and can split a single order if the timestamps are imperfect.
- Truly large traders often do not send one huge order. Execution algorithms such as TWAP (time-weighted average price) and VWAP algorithms, or icebergs, slice a parent order into dozens of child orders spread over minutes or hours, specifically to avoid looking big. So a "big trade" on the tape is better described as an impatient aggressor than as "smart money".
What our own testing showed
In our own testing, simple "big trade" detection from raw prints was unreliable: most of the prints it flagged were not genuinely large orders at all, precisely because real orders print as many small fills and unrelated small fills can look like one. Grouping prints improved the picture. But even correctly identified big trades were not, on their own, a signal that predicted direction after costs.
Key idea: A raw print is not an order size. One large market order matches against many smaller resting orders and can print as many small fills.
Common mistake: "Big bubble = institution = follow it." This is a popular claim, not proven.
Common mistake: Filtering the tape for prints above a fixed size without grouping. You get both false alarms and missed events. And comparing big-trade statistics between two platforms that group prints differently compares apples with oranges.
Liquidity Sweeps and Stop Runs
Sweeps
A sweep happens when one or more aggressive orders consume several price levels in rapid succession: the entire ask at the first price is taken, then the second, then the third. On a heatmap it looks like a steep staircase with trade bubbles one after another. The 278-lot order from the previous section is a textbook sweep.
A useful objective definition: a sweep is the consumption of at least a few consecutive price levels within a very short time (fractions of a second to a few seconds), by aggressors in one direction.
Stop runs
A stop run is a particular kind of sweep. Above an obvious swing high (a recent peak that everyone can see), and below an obvious swing low, the previous day's high or low, or the overnight high or low, stop orders tend to accumulate. Above a high, these are the protective buy stops of traders who are short, plus breakout buy orders from traders who want to join a move up. When price reaches that zone, the stops become market orders and create new aggressors in one burst. The result is a jump in tape speed and a short, sharp price spike.
CME's feed also marks trades that came from triggered stop orders, and some platforms use MBO data to highlight stop executions on the chart, with limitations.
The famous pattern: break and close back inside
The pattern most traders talk about goes like this: price breaks the high, stops are triggered, but there is no follow-through, and price closes back inside the previous range. This is often called a failed breakout. In the language of auction market theory (Chapter 7), the auction above the level was not accepted. The logic: if no new buyers arrived and only stops were executed, the fuel for the move ran out.
What to check, after the fact:
- Did the sweep happen at a level you had marked in advance?
- What did delta do above the high? Heavy buying with no further progress in price suggests absorption.
- In the next few minutes or bars, was price accepted back inside the range, or did it build value above the high?
The limitation that matters
Many sweeps continue. A genuine breakout starts with exactly the same sweep. You can only see "it closed back inside" afterwards, never at the moment of the sweep itself.
Common mistake: "Market makers deliberately hunt my stops." This is a popular claim, not proven. Price goes where liquidity is, and stops are liquidity. No conspiracy is needed to explain why price visits them.
Common mistake: "After every sweep, price reverses." This is a popular claim, not proven.
Common mistake: Acting in the middle of a sweep, before any evidence of acceptance or rejection exists.
Iceberg Orders: Native vs Synthetic
What an iceberg is
An iceberg order is a large limit order of which only a small part, the display quantity, is visible in the book. When the visible part is filled, the next part is released from a hidden reserve. This is called a refill. The name is the obvious image: only the tip of an iceberg is above the water.
Why anyone uses one
Showing a 500-contract order tells the whole market about it. Others may queue in front of it, step away from it, or move price away from it. An iceberg lets a large order be worked with less market impact.
Two kinds on CME
1. Native icebergs. The exchange itself holds the hidden reserve. On CME the order is sent with a display quantity, and when the visible tip is filled, Globex releases the next tip automatically. Two technical clues follow from this. In MBO data, the refreshed tip keeps the same OrderID as before. And the exchange's trade reporting can show a traded quantity at that order that is larger than the quantity that was ever displayed. Together these make native icebergs reasonably detectable with MBO data. Whether native icebergs are permitted depends on the product; check CME's documentation for the contract you trade.
2. Synthetic icebergs. The trader's platform or algorithm builds the iceberg itself. Each time the small visible order is filled, the software sends a brand-new order with a new OrderID. To the market these are just ordinary limit orders, indistinguishable from anyone else's. One more consequence: every synthetic refill is a new order, so under FIFO it joins the back of the queue behind everything already waiting at that price.
| Native iceberg | Synthetic iceberg | |
|---|---|---|
| Who holds the hidden size | The exchange | The trader's platform or algorithm |
| OrderID on refill | Same | New each time |
| Queue position on refill | Managed by the exchange | Back of the queue each time |
| Detectable with MBO | Reasonably, from the clues above | Only as a statistical pattern, often not at all |
A real example: shows 2, trades 176
Back to 2 October 2026. A few minutes after the 08:30 jobs-report burst, with gold trading around 4,241.5 on the GC contract (roughly 4,212–4,215 in XAUUSD terms, using an approximate $27–30 gap), a hidden buyer appeared on the bid at 4,241.5. Its visible part was only 2 contracts. Yet 176 contracts traded into that order as aggressive sellers kept hitting it, and the visible 2 kept reappearing. Price held at that level for about 25 minutes.
Then the level broke, and gold fell about $40 (on GC that is $4,000 per contract; on MGC, $400 per contract).
This example is valuable precisely because it does not end the way the folklore says it should. A buying iceberg was detected, it really absorbed a lot of selling, it really held price for a while, and price then fell sharply anyway. An iceberg tells you that someone had hidden size at a price. It does not tell you their overall direction (the buying could have been closing a short position, or one leg of a hedge or spread), how long they intend to stay, or where price will go next. The order can also be cancelled at any moment.
Key idea: An iceberg reveals hidden size at a price, not a prediction of direction.
Common mistake: "A buy iceberg means price will go up." This is a popular claim, not proven, and the 2 October example shows the opposite can happen.
Common mistake: "Icebergs always mean banks or institutions." This is a popular claim, not proven. Anyone with a suitable platform can place one.
Detecting Icebergs: Why It's Harder Than It Looks
How detection generally works
Commercial tools and academic research on CME data (for example a well-known 2019 study by Dmitry Zotikov on iceberg detection in CME futures) use roughly the same logic.
For native icebergs:
- Compare the quantity traded against an order with the quantity it displayed. If more traded than was ever shown, a hidden reserve existed.
- Watch for size reappearing under the same OrderID immediately after a fill.
For synthetic icebergs: look for new limit orders at the same price, appearing immediately after the previous one is filled, with similar sizes. This is only a statistical pattern, never a proof.
Why it is hard
1. The synthetic ambiguity. In a busy gold market, dozens of traders may be placing orders at the same price at the same time. One trader's "refill" is indistinguishable from another trader's fresh order. You get many false positives (detections of icebergs that were not there) and many false negatives (real icebergs that went unnoticed). At least one major commercial vendor states in its documentation that its detection targets native icebergs for this reason.
2. Data and timing. Vendor documentation also notes that timestamp differences between systems and data aggregation under heavy load can shift detections or create false ones. A feed interruption means an incomplete history.
3. Detection is not meaning. Even a correct detection says only "hidden size was here". It does not say whether the owner is a net buyer or seller overall. A sell iceberg might be hedging a larger long position elsewhere. It does not say where price goes next.
4. Detection only comes afterwards. An iceberg is detected after it has refilled several times, which means part of the "news" is already in the price by the time you see the label.
A useful way to hold all this in mind is a simple two-by-two table:
| Iceberg really present | Iceberg not present | |
|---|---|---|
| Detector says yes | True positive | False positive |
| Detector says no | False negative | True negative |
And beside it, one more line: even a true positive is not a direction.
What our own testing showed
In our own testing, the side of a detected iceberg did not, on its own, predict where the market went next. Icebergs can be seen, and they show where someone wanted size, but that is information about intent, not a directional signal. The 2 October example is one vivid case of a general result.
Common mistake: "Tool X shows all icebergs." No tool reliably detects synthetic icebergs.
Common mistake: "A sell iceberg at the high means go short." This is a popular claim, not proven.
Common mistake: Judging a detection tool by a handful of hand-picked screenshots. That is selection bias: you only remember the examples that worked. Judge tools on all events, including the boring and the wrong ones.
Spoofing and Layering: What They Are and Why They're Illegal
Definitions
Spoofing means placing a bid or offer with the intent to cancel it before it executes. The usual purpose is to create a false impression of supply or demand so that other participants react, while the spoofer trades on the opposite side at a better price.
The classic sequence has three steps:
- A large (fake) sell order appears above the market, creating the impression of selling pressure.
- Meanwhile, the spoofer's real buy order lower down gets filled by sellers who reacted to that impression.
- The large sell order is cancelled.
Layering is the multi-level version: many orders placed at several prices on one side of the book to build false depth.
The law
In the United States, the Dodd-Frank Act of 2010 added section 4c(a)(5)(C) to the Commodity Exchange Act. It explicitly prohibits conduct that "is, is of the character of, or is commonly known to the trade as, 'spoofing' (bidding or offering with the intent to cancel the bid or offer before execution)". Exchange rules forbid it too, notably CME Rule 575 on disruptive practices. The key element is intent; carelessness alone is not enough. And the law does not depend on size: a small trader placing orders to scare others and then cancelling them is breaking the same rule.
Real cases exist, including in gold. In 2020 the US Commodity Futures Trading Commission (CFTC) resolved a case against JPMorgan that included spoofing in precious metals futures, gold among them, on COMEX between 2008 and 2016. Total payments across the related US cases came to roughly $920 million. Another well-known case is Navinder Sarao, who used a layering algorithm in E-mini S&P 500 futures and whose activity was linked by authorities to the events of the May 2010 "flash crash".
What it might look like on a heatmap
Possibly: large bands that keep retreating as price approaches, or vanish just before being touched, while trading happens on the other side of the book. But legitimate market-maker cancellations produce exactly the same shape. Only a regulator, with identity data, full order records and communications, can establish intent. A screenshot cannot.
Key idea: We teach spoofing so that you are not fooled by it, never as something to do or to "ride". Any course or video that presents spoofing as a strategy is inviting you to break the law.
Common mistake: "Every wall that got pulled was a spoof." No. Most cancellations are legitimate.
Common mistake: "I'm small, so placing orders to scare others and cancelling them is fine." The law is about intent, not size.
Common mistake: "I can detect spoofs and trade against them." This is a popular claim, not proven.
Order Flow Imbalance (OFI): What the Research Actually Says
The question
In a widely cited paper, Rama Cont, Arseniy Kukanov and Sasha Stoikov ("The Price Impact of Order Book Events", Journal of Financial Econometrics, 2014) asked a simple question: over short intervals, what explains price changes? Their answer was order flow imbalance (OFI): the imbalance between supply pressure and demand pressure at the best bid and best ask.
How OFI is built
Every event at the inside market adds either buying pressure or selling pressure:
| Event at the inside | Contribution to OFI |
|---|---|
| Size on the best bid grows, or the best bid moves up | + (more demand) |
| Size on the best bid shrinks (trade or cancel), or the best bid moves down | − (less demand) |
| Size on the best ask grows, or the best ask moves down | − (more supply) |
| Size on the best ask shrinks (trade or cancel), or the best ask moves up | + (less supply) |
OFI over an interval is the sum of these contributions. The main finding is an approximately linear relationship:
price change ≈ β × OFI
where β (beta) is a sensitivity coefficient. And β is inversely related to market depth: in a thin book, the same imbalance moves price more; in a deep book, it moves price less. This is the same intuition as the DOM section, now stated as an equation: the less resting size there is to get through, the further a given push travels.
A small worked example. In a ten-second window on gold, 25 contracts are added to the best bid (+25), 10 contracts on the best ask are lifted by buyers (+10), and 15 contracts are added to the best ask (−15). OFI = +25 + 10 − 15 = +20. If, in that market at that time, β were about one tick per 20 contracts of imbalance, the model would associate this window with a price change of about +1 tick ($10 on GC, $1 on MGC). The numbers are illustrative; β has to be estimated from data and changes with depth and time of day.
How OFI differs from delta
Delta counts only aggressive trades. OFI also counts the adding and cancelling of limit orders at the inside. So a mass cancellation of bids (pulling) produces negative OFI even if not a single contract trades. OFI is, in that sense, closer to a measure of the whole contest at the inside, not just the part that ended in trades.
The honesty point that matters most
The paper's core finding is about contemporaneous explanation: in the same interval in which OFI was positive, price went up. That is very different from "OFI is positive now, so price will go up later". The power to predict future price changes is much weaker, concentrated at very short horizons (seconds), and fought over by the fastest participants, high-frequency trading firms with infrastructure no retail trader can match. The study was also carried out on US stocks; any application to gold futures has to be tested separately.
Key idea: Explains is not predicts. OFI describes the mechanism of price change in the moment; it is not, on its own, a forecasting tool for a human trader.
Common mistake: "Academic research has proved that OFI predicts price." The main relationship is contemporaneous.
Common mistake: "OFI is just delta." It is not: it includes additions and cancellations of resting orders.
Common mistake: Applying results from US equities to gold futures without testing them on gold data.
For our purposes, OFI is valuable as a way to understand why price moves when it does, and as a piece of context at levels chosen in advance. It is not an independent signal.
Chapter summary
- The order book (resting limit orders) is intention; a trade (aggressor meets passive order) is fact.
- L1 = best bid, best ask, last trade; L2 = total size at several prices; L3/MBO = every order, anonymously, with its lifecycle. None shows untriggered stops or hidden iceberg size.
- The DOM is L2 as a ladder with no memory. Price moves one tick only when the whole inside quantity is consumed or pulled. MBO separates filled from pulled.
- Gold matches FIFO: reducing size keeps priority, increasing size or changing price loses it. Touched is not filled; easy fills can be bad fills.
- The heatmap is the book with memory: bands hold, get eaten, or get pulled. Walls are relative; stacking and pulling are momentary intention, mostly routine risk management.
- Displayed liquidity can be larger than real (pulls, flicker, spoofing, feed delay) or smaller (icebergs). Trust liquidity that trades and holds.
- The tape records actual trades with aggressor side and keeps sequence and rhythm. Tape speed is judged against the same hour; a burst's meaning depends on location and outcome.
- One large order prints as many small fills. The 278-contract buy on 2 October 2026 swept several prices in a single event. Big trades are impatient aggressors, not necessarily smart money.
- Sweeps consume several levels fast; stop runs are sweeps into clusters of stops. Failed and genuine breakouts start the same way.
- Icebergs hide size. Native ones are reasonably detectable with MBO; synthetic ones look like ordinary orders. Detection is hard, comes late, and is not direction: on 2 October a hidden buyer absorbed 176 contracts while showing 2, and price later fell about $40.
- Spoofing and layering are illegal in the US (CEA 4c(a)(5)(C), CME Rule 575). Intent is the key element, and a heatmap cannot prove it.
- OFI explains price changes in the same interval, with impact inversely related to depth. Explaining is not predicting.
Checklist
- I can say which data level (L1, L2 or L3) a claim actually requires before I believe it.
- I can find the inside market and the spread in dollars for GC and MGC, and when resting size drops I ask "filled or pulled?".
- I remember that touched is not filled, and I do not assume fills at the first touch in any test.
- My heatmap colour settings are fixed and written down.
- I judge walls relative to the session and hour, not by a fixed number.
- I only take liquidity seriously when trades confirm it at a level I chose in advance.
- I judge tape speed against the same time of day on previous days.
- I know my platform's rule for grouping or splitting prints before I use big-trade statistics.
- I treat a sweep as unresolved until price shows acceptance or rejection.
- I treat icebergs as information about hidden size, not as direction.
- I never place orders I intend to cancel in order to influence others.
- I remember that OFI explains, it does not predict, and that research on stocks must be retested on gold.
Quiz
- Level 2 shows 60 contracts on the bid at 4,239.5. What do you know for certain?
- On CME's FIFO matching, which change to a resting order keeps its place in the queue: increasing the size, moving the price by one tick, or decreasing the size?
- On a heatmap, a bright band fades as price approaches, with no trade bubbles at that price. What most likely happened?
- Why can a single 50-lot market buy order appear on the tape as many small prints?
- Under US law, what makes an order "spoofing"?
Quiz answers
- Only that 60 contracts are resting at that price right now, coming from orders you cannot see individually. You do not know whether it is one order or many, who placed them, or whether they will hold price. They may be cancelled at any moment.
- Decreasing the size. Increasing the size or changing the price sends the order to the back of the queue.
- The liquidity was most likely pulled (cancelled). Fading with trade bubbles would indicate it was filled.
- Because it matches against many smaller resting orders, one after another in FIFO order and possibly across several prices, and many feeds and platforms display each of those fills as a separate print.
- It was placed with the intent to cancel it before execution. Size alone, or the mere fact that an order was cancelled, does not make it spoofing; intent is the key element.