Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› How should market integrity teams identify possible pump…
Cyber Security

How should market integrity teams identify possible pump and dump activity from on-chain data without overclaiming criminality?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Cyber Security

Teams should treat on-chain signals as triage, not proof. The practical approach is to look for repeated purchase activity, a sharp liquidity pull by a dominant holder, and a token that quickly becomes illiquid. Those signals help prioritize deeper investigation, especially when paired with off-chain context such as social promotion, wallet attribution, and project governance details.

market integrity teams should treat blockchain activity as one layer of evidence, not a standalone verdict. On-chain data can show concentration, rapid distribution, and liquidity changes, but it rarely proves intent by itself. The useful question is whether the pattern is unusual enough to justify deeper review, not whether the chain data alone can establish manipulation.

A sound read starts with the observable market structure: repeated buys from a small set of wallets, a sudden exit by a dominant holder, thin liquidity, and a sharp price move that is not supported by visible fundamentals. Those signals become more meaningful when they occur together, because each one can have benign explanations in isolation.

For a practitioner, the main discipline is evidentiary restraint. If the data suggests a coordinated sequence, describe it as a suspicious pattern or potential manipulation indicator, then separate what is directly observable from what is inferred. That distinction protects the analysis from overstatement and keeps the case usable for escalation, surveillance, or referral.

What On-Chain Patterns Usually Matter Most

The strongest indicators are structural rather than purely price-based. Repeated acquisition by a cluster of wallets can suggest coordinated accumulation, especially when the wallets are newly funded, closely timed, or otherwise tightly synchronized. A dominant holder rapidly reducing position while liquidity thins can point to a classic distribution phase, particularly when the token becomes difficult to trade afterward.

Teams should also look for signs that the market is being made artificially fragile. Low depth, concentrated ownership, and minimal organic activity can make even modest selling produce outsized moves. In that setting, a token may appear active for a short window and then become effectively illiquid once the largest participant exits.

These observations are more persuasive when compared across time. One spike in activity may be noise; repeated bursts of wallet clustering, followed by liquidity withdrawal and a collapse in trading quality, is a more defensible pattern. That is why analysts should describe the sequence, not just the endpoint.

How to Pair Blockchain Evidence With Off-Chain Context

On-chain activity becomes more actionable when it is tied to off-chain context. Social promotion, influencer campaigns, sudden community hype, project governance changes, and wallet attribution can help explain why a token moved and who may have benefited. Without that context, the same wallet pattern might be a routine treasury move, a market-making adjustment, or a short-lived speculative cycle.

Analysts should therefore avoid drawing criminal conclusions from transaction graphs alone. The better approach is to use blockchain data to narrow the suspect window, then test whether the surrounding conduct fits a manipulation narrative. Governance details matter here because token control, admin privileges, or opaque decision-making can clarify whether the market activity was merely volatile or potentially orchestrated.

For teams building surveillance workflows, this means the on-chain layer should feed case triage, while attribution and communications review supply the human context needed for escalation. The output should be a prioritized investigation queue, not a final accusation.

Risk and Threat Considerations

The main risk is false certainty. On-chain patterns can resemble pump and dump behavior even when the underlying cause is legitimate rebalancing, migration, or fast-changing speculation. Overclaiming criminality can damage credibility, misdirect investigations, and create unnecessary legal or reputational exposure.

Failure mechanism: Analysts over-weight a few visible wallet actions, ignore market structure and off-chain context, and convert suspicious activity into a conclusion of fraud before the evidentiary threshold has been met.

Impact: The team may escalate the wrong cases, miss the real coordination pattern, or produce findings that cannot survive review because they blend observation with inference.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1595 — Active ScanningCovers investigative pattern-finding across observable infrastructure and activity.
Recommendation — Map observed wallet and liquidity patterns to adversary tradecraft indicators before escalating the case.
NIST CSF 2.0DE.AE-02 — Anomalous conditions are analyzed to determine if events are cybersecurity incidentsSupports triage of anomalous transaction patterns into reviewed cases.
GV.RM-03 — Risk management strategy addresses cybersecurity risksFits the need to frame suspicious activity as risk-based investigation, not overclaiming.
ID.RA-01 — Assets are inventoried and prioritized by importance to the missionRelevant because wallet clusters, liquidity pools, and token control points must be prioritized for review.
Recommendation — Analyze anomalous on-chain patterns before treating them as confirmed misconduct. Frame on-chain signals as investigation inputs within a documented risk decision process. Prioritize wallets, pools, and governance accounts that most affect market integrity exposure.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingApplies to reviewing transaction evidence and documenting suspicious patterns.
IR-4 — Incident HandlingSupports escalation from suspicious pattern to structured investigation and response.
Recommendation — Review and document on-chain evidence consistently before escalating a suspected manipulation case. Escalate only cases with sufficient indicators for structured incident handling.

Practitioner Guidance

What to verify: Confirm that the pattern includes both accumulation and exit behavior, and check whether liquidity actually deteriorated after the dominant holder sold. If the token stayed liquid and the activity is explainable by normal market events, downgrade the case.

Decision rule: Use language such as “consistent with potential manipulation” only when multiple signals align and off-chain context supports the theory. If you only have one suspicious signal, keep the case open but non-accusatory.

Practitioner takeaway: The strongest analysis is specific about what the chain shows, careful about what it does not show, and disciplined enough to separate suspicious structure from proof of wrongdoing.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org