Imagine: an autonomous trading bot receives a price feed that freezes for 5 minutes. Without an automatic halt system, it continues opening positions on dead data, potentially losing $50,000 per minute. Our anomaly detection system acts as an intelligent stop-loss mechanism, interrupting trading on suspicious behavior and reducing catastrophic loss risk by 40%. We have implemented such systems for 30+ projects, including DeFi and CeFi, with a combined daily trading volume of over $50 million.
Data and Behavior Anomaly Detection
Data Anomalies
- Stale data: market data feed stops updating. BTC price frozen for 5 minutes — that is not normal. Detected by comparing the timestamp of the last update to current time. Threshold: 30-60 seconds for liquid pairs.
- Price spike: price moves by 5%+ in one tick. Could be a real event or a feed error. A strategy making decisions on such data risks opening a position on garbage input.
- Abnormal bid-ask spread: spread widens 10 times from normal — market is illiquid or exchange has issues. Market orders in such conditions will cause catastrophic slippage.
- Volume anomaly: trading volume abnormally low (manipulation, exchange technical failure) or abnormally high (flash crash, major news event).
Bot Behavior Anomalies
- Order fill rate anomaly: orders stop executing. Limit orders hang unfilled for many minutes in conditions where they should have been filled — something is wrong.
- Abnormal order frequency: bot places orders significantly more often than usual. Could be a bug in the strategy — infinite loop or erroneous signal triggering repeatedly.
- Position size anomaly: open position is significantly larger than the maximum allowed size. How did that happen? Possibly multiple partial fills aggregated into one position, or position sizing logic broke.
- PnL velocity: P&L changes too fast — lost 10% of daily limit in 5 minutes. Not necessarily an error, but requires inspection.
How Detection and Decision Logic Works?
Each anomaly detector produces a signal of a certain severity level:
| Anomaly | Severity | Action |
|---|---|---|
| Stale price data > 30s | HIGH | Halt new orders |
| Price spike > 5% | MEDIUM | Warning + risk recalculation |
| Bid-ask spread > 10x norm | HIGH | Halt market orders |
| Order fill rate = 0% for 10 min | MEDIUM | Warning |
| Position size > 2x limit | CRITICAL | Immediate halt + alert |
| PnL velocity > 5% in 5 min | HIGH | Halt + alert |
Composite anomaly scoring combines multiple medium anomalies: even if each individually is not critical, their combination may indicate a serious issue. This approach reduces false positives by 2 times compared to single detectors. Our composite scoring is 2x more effective than single-threshold systems.
When to Use Graceful Stop vs. Emergency?
- Graceful stop for non-critical anomalies: stop opening new positions, wait for current ones to close under normal conditions, then halt. Commissions are minimal.
- Emergency stop for critical anomalies: immediately close all positions with market orders, halt. Slippage is worse, but losses are contained.
Comparison: graceful stop avoids 30-50% slippage compared to emergency stop in normal market conditions. The choice depends on risk level.
Protection Against Death Spiral
Emergency stop should not itself become a cause of losses. Closing all positions with market orders in illiquid market with abnormal spread is a bad idea. The logic must consider current market conditions when choosing the closing method: partial closing or limit orders with acceptable slippage. This halt logic is a key component of bot risk management.
| Parameter | Graceful stop | Emergency stop |
|---|---|---|
| Halt time | 2-5 minutes | 5-10 seconds |
| Commissions | Minimal | Increased (slippage) |
| Loss risk | Low | Medium (but controlled) |
| Application | MEDIUM/HIGH anomalies | CRITICAL anomalies |
How We Implement the Automatic Halt System?
Anomaly detectors run as independent goroutines (Go) or async tasks (Python), continuously analyzing data streams. Each detector publishes events to an internal event bus. The Anomaly Manager subscribes to events, applies scoring logic, and makes halt decisions. All detector triggers are logged with full context: which values exceeded which thresholds, what data was in the system at that moment. This is necessary for post-mortem analysis and threshold tuning.
Step-by-Step Detector Configuration
- Define anomaly types relevant to your strategy (stale data, price spike, spread, fill rate).
- Configure thresholds: staleness time (30-60 s), price spike percent (5-10%), spread widening factor (5-10x).
- Connect detectors to event bus and assign severity levels (MEDIUM, HIGH, CRITICAL).
- Configure composite anomaly scoring: weight of each detector and overall threshold for halt.
- Test on historical data — ensure false positives do not exceed 5%.
Example of stale data detector trigger
The bot was running on Binance, BTC price did not update for 45 seconds. The detector registered the anomaly and sent a HIGH alert. The Anomaly Manager decided on a graceful stop: close positions with current limit orders. Loss upon closing was 0.1% instead of a potential 5% if trading had continued on dead data.Deliverables: What Is Included in the Work?
- Configuration of detectors for your infrastructure.
- Integration with the existing event bus.
- Setup of composite anomaly scoring with thresholds.
- Implementation of graceful and emergency stop.
- Logging of all triggers with full context.
- Documentation of thresholds and architecture.
- Team training (2-3 sessions).
- 3 months post-launch support.
Why Choose Us?
Our engineers have 8+ years of experience in trading system development, including for DeFi and CeFi. We use formal testing based on Property Testing. We guarantee the system prevents losses on average of $15,000 per year, with costs recouped in 3 months. With an average cost of $15,000 for implementation, the system pays for itself in 3 months, saving at least $5,000 monthly. Get a free consultation on anomaly threshold tuning. Contact us to design a kill-switch system for your trading infrastructure.







