Breaking Regulatory Compliance
Gotbit SEC Settlement: The Crypto Wash-Trading Controls That Matter Now
The Gotbit SEC settlement shows crypto market-manipulation risk is still live. Here are the wash-trading controls compliance teams should test.
Table of Contents
TL;DR
- The SEC filed a proposed settlement with Gotbit Consulting LLC on July 28, 2026, over allegations that the crypto market maker created artificial volume through wash trading and other transactions with no economic purpose.
- The proposal includes permanent anti-fraud and anti-manipulation injunctions plus a broad bar on participating in securities transactions. It does not state an SEC civil penalty or disgorgement amount.
- This is the clean line compliance teams keep missing: a softer regulatory posture on crypto registration does not make fake volume, matched trading, or deceptive liquidity lawful.
- Exchanges, token issuers, broker-dealers, and market makers should test beneficial ownership, trade-population completeness, market-maker concentration, and escalation evidence—not just rerun a generic AML review.
The Gotbit SEC settlement is a reminder that “crypto-friendly” and “market-manipulation-friendly” are not the same policy.
On August 3, 2026, the SEC announced that it had filed a proposed final judgment against Gotbit Consulting LLC, also known as Gotbit Hedge Fund. The settlement, filed July 28 and still subject to court approval, would resolve allegations that Gotbit manipulated trading in a crypto asset by generating artificial volume through self-trading—commonly called wash trading—and other transactions with no economic purpose.
The proposed judgment does not contain a headline fine. That is important because the scanner’s first-pass data treated an unrelated number as a possible penalty. The actual filed document seeks permanent injunctions and a securities-activity bar, not a stated civil penalty or disgorgement award.
The useful story is the control failure. If your venue’s surveillance can count trades but cannot determine whether the same beneficial owner sits on both sides, “volume” can be manufactured while every dashboard stays green.
What the Gotbit SEC settlement actually does
The SEC sued Gotbit and Fedor Kedrov in October 2024. Its complaint alleged that Gotbit created the appearance of active trading for a crypto asset through wash trades and other economically purposeless transactions.
The litigation then split into two outcomes:
| Party | Current SEC outcome | What the filed document says |
|---|---|---|
| Gotbit Consulting LLC | Proposed settlement filed July 28, 2026; court approval pending | Permanent injunctions under Securities Act Section 17(a), Exchange Act Section 10(b) and Rules 10b-5(a) and (c), and Exchange Act Section 9(a)(2); permanent bar from participating in any securities issuance, purchase, offer, or sale |
| Fedor Kedrov | Claims dismissed with prejudice on March 31, 2026 | The SEC’s notice of voluntary dismissal says Kedrov had not been served and had not filed an answer or summary-judgment motion |
Gotbit’s consent filed with the proposed judgment also acknowledges its separate criminal guilty plea to conspiracy to commit market manipulation and wire fraud and to two wire-fraud counts. The SEC’s release says the company received five years’ probation in June 2025.
That procedural precision matters. This is a proposed SEC judgment, not an entered final judgment. The SEC dismissed its civil claims against Kedrov; the filing does not say a court exonerated him on the merits. And the corporate criminal resolution is separate from the civil settlement now awaiting approval.
The proposed final judgment itself is unusually direct about the prohibited outcome: creating a false appearance or deceiving people about the price or trading market for a security.
Why fake volume is a control problem, not a crypto vocabulary problem
Wash trading is often described too narrowly as one account buying from itself. That pattern is easy to explain and sometimes easy to detect. Real surveillance gets harder when the common controller is hidden across accounts, wallets, legal entities, API keys, or trading venues.
A venue can therefore have complete-looking trade records and still miss the conduct. The failure usually sits in one of four places:
- Identity resolution fails. The surveillance engine sees Account A and Account B, but KYC, wallet attribution, device data, funding sources, and control relationships are not joined well enough to show that one actor controls both.
- The rule watches exact matches only. Manipulative activity can use staggered timestamps, slightly different quantities, related wallets, or a chain of accounts instead of a perfect same-second cross.
- Market-maker activity receives blanket exceptions. High-frequency, two-sided trading is expected from a market maker. That does not make every offsetting trade legitimate. A broad whitelist can become a surveillance blind spot.
- Volume is treated as a growth metric before it is treated as evidence. Product and commercial teams want liquidity. Compliance needs to ask how much is organic, how much is concentrated in contracted makers, and whether the activity survives a beneficial-owner test.
This is why the Gotbit case adds something different from the SEC’s Bitcoin Latinum offering-fraud action. The Bitcoin Latinum case involved allegedly false claims about insurance and asset backing. Gotbit is about the integrity of the trading market after an asset exists. The control owners, evidence, and detection logic are different.
The six controls to test after the Gotbit SEC settlement
A generic “market surveillance enabled” control will not survive a serious challenge. The test needs to show what population entered the system, how ownership was resolved, what scenarios ran, what was excluded, and what happened to alerts.
| Control | Named owner | Evidence that should exist | Common failure mode |
|---|---|---|---|
| Trade-population reconciliation | Market Surveillance + Data Engineering | Daily source-to-surveillance counts and notional totals by venue, product, account type, and API channel; documented breaks and repair tickets | A feed is live, but a product code or API channel silently drops from surveillance |
| Beneficial-owner and wallet clustering | KYC/CDD + Blockchain Analytics | Linkage rules using beneficial owner, signer, device, IP, funding wallet, withdrawal wallet, and shared control data; reviewed cluster overrides | Separate accounts are treated as unrelated because legal names differ |
| Matched and round-trip trade detection | Market Surveillance | Alerts for same-price/same-size matches, rapid offsetting trades, repeated counterparty pairs, and trades with limited fee-adjusted economic purpose | Rules detect exact self-matches but miss coordinated accounts or small timing changes |
| Market-maker concentration testing | Head of Market Operations + Compliance | Volume and price-impact reporting by market maker, issuer, pair, and venue; contract inventory; exception rationale | Contracted liquidity is trusted automatically and excluded from challenge |
| Manipulation escalation | CCO or Head of Compliance | Case notes, reconstructed order book, wallet/account relationship analysis, disposition approval, SAR or referral analysis where applicable | Alerts are closed as “expected market-making” without testing ownership or purpose |
| Independent tuning and model review | Internal Audit or independent second line | Scenario inventory, data-lineage test, back-testing, false-negative sampling, change approvals, and issue log | Tuning optimizes alert volume without checking whether known manipulation patterns remain detectable |
Use starter thresholds carefully
There is no universal percentage that proves wash trading. Thresholds should start an investigation, not declare a violation.
A workable starter calibration is to flag activity for review when one or more of these conditions appears:
- one market maker accounts for an unusually high share of a token’s daily volume compared with the prior 90 days;
- the same beneficial-owner cluster repeatedly appears on both sides of trades within a short interval;
- round trips generate little or no economic exposure after fees;
- reported volume increases sharply without a corresponding change in unique funded accounts, external wallet flows, order-book depth, or independent-venue activity; or
- a market maker’s trades disproportionately occur with a small set of related counterparties.
Do not turn those examples into policy limits without calibration. Use your own prior 90 days, test known clean and suspicious cases, and document why each threshold fits the asset’s liquidity and trading design. Then run an anti-gaming test: shift timestamps, quantities, and linked accounts in a controlled test set and confirm the rule still catches the relationship.
The evidence artifact is a tuning memo with the test population, expected results, observed misses, approved changes, and residual risk. A screenshot of a dashboard is not validation.
The market-maker contract belongs in the surveillance perimeter
The awkward ownership issue usually starts before any trade occurs. Business development negotiates liquidity targets. Market Operations manages the relationship. Compliance reviews the counterparty. Surveillance watches the trades. Legal owns the contract. Nobody owns the complete control chain.
Fix that by putting a compliance schedule into every market-maker agreement. At minimum, require:
- a prohibition on wash trading, matched trading, deceptive orders, and undisclosed coordinated accounts;
- disclosure of controlled wallets, subaccounts, trading bots, subcontractors, and affiliated counterparties used for the mandate;
- records sufficient to reconstruct orders, executions, cancellations, transfers, and control changes;
- prompt notice of regulatory inquiries, surveillance alerts from other venues, and changes in beneficial ownership;
- audit and data-access rights that survive termination; and
- suspension and termination rights that do not require a final regulatory finding.
Legal owns the clause. Market Operations owns the complete contract inventory. KYC owns identity refreshes. Surveillance owns the data mapping. The CCO owns exceptions.
If Sales says the maker will not disclose wallet or subaccount information, record the refusal as a risk decision. Do not quietly convert missing data into a monitoring assumption.
What to check Monday morning
First 30 days: prove coverage
Market Surveillance should reconcile every trading source to the surveillance platform and segment results by product, account, API connection, and market-maker status. Data Engineering should investigate every unexplained break. Compliance should inventory all market-maker exceptions and identify who approved them.
Deliverables:
- signed source-to-surveillance population reconciliation;
- current market-maker and related-wallet inventory;
- list of whitelists, suppressions, and scenario exclusions;
- open issues for missing ownership or trade data; and
- preservation notice for relevant order, trade, wallet, and communication records if a credible gap is found.
Days 31–60: challenge the scenarios
Run a controlled test set containing exact self-matches, linked-account crosses, staggered round trips, coordinated wallets, and high-volume trades with minimal economic exposure. Record which scenarios fire and which do not.
The second line should sample closed “expected market-making” alerts and ask a simple question: what evidence established that the counterparties were independent and the trades had a legitimate market-making purpose?
Deliverables:
- scenario-by-scenario test results;
- false-negative and override analysis;
- threshold calibration memo;
- revised escalation criteria; and
- approved remediation plan with accountable owners and dates.
Days 61–90: close the governance gap
Update contracts and onboarding standards. Connect material surveillance findings to KYC refresh, account restrictions, suspicious-activity analysis where applicable, and issuer or venue governance. Internal Audit should verify the remediation evidence rather than accepting management’s status label.
This is where the issue tracker matters. A missing wallet linkage is not “closed” because a rule was edited. Closure requires data lineage, test results, production deployment evidence, and a sample showing the repaired control works.
The broader SEC posture supports the same conclusion. The agency may be stepping back from some registration-driven crypto cases, but its 2026 enforcement focus remains centered on fraud and market manipulation. Teams planning under the evolving crypto framework should also keep the market-integrity workstream separate from their broader 2026 crypto compliance roadmap.
The practical takeaway
The Gotbit filing does not create a new wash-trading rule. It shows how old anti-fraud and anti-manipulation authorities reach a familiar crypto operating model: outsourced liquidity, opaque beneficial ownership, automated trading, and volume that looks legitimate until someone reconstructs who was really trading with whom.
Start with the population. Resolve ownership. Challenge market-maker exceptions. Preserve the evidence behind every alert disposition. If those four pieces are weak, policy language will not save the program.
If a surveillance gap has already become a remediation project, the Issues Management Tracker & Template gives you the owners, milestones, evidence fields, and closure discipline to keep it from becoming the next repeat finding.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the Gotbit SEC settlement?
Did the SEC impose a monetary penalty on Gotbit in the proposed settlement?
What is wash trading in crypto markets?
What controls can detect crypto wash trading?
Why does the Gotbit action matter if the SEC has changed its approach to crypto?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
Stablecoin Issuers Just Got a Customer Identification Mandate. The Comment Deadline Is August 21.
On June 18, 2026, FinCEN and four federal banking agencies proposed the first-ever Customer Identification Program requirements for permitted payment stablecoin issuers under the GENIUS Act. The comment period closes August 21. Here's what the rule requires, where it matters most, and what stablecoin compliance programs need to build.
Aug 2, 2026
Regulatory Compliance
UBS $125 Million AML Penalty: The Data Failures Behind the Repeat Violation
The UBS AML penalty exposes FX wire data gaps, weak CDD, and failed remediation. Here is what compliance teams should test now.
Aug 2, 2026
Regulatory Compliance
Examiners Are Now Asking About Your Non-Work-Authorized Borrower Portfolio: What the July 2026 Interagency Guidance Requires
On July 13, 2026, the OCC, FDIC, and NCUA issued interagency guidance telling financial institutions to apply safe-and-sound credit risk practices when lending to borrowers not legally authorized to work in the US. Here's what examiners will actually look for — and how to build a defensible program.
Aug 1, 2026