Market surveillance for blockchain finance · early-stage

Suspicious DeFi trades.A clearer picture.

Aurora is building tools that help regulators and institutional compliance teams spot potential manipulation in blockchain markets, investigate what happened and prepare the evidence for review.

Regulators and supervisorsInstitutional compliance teams

Illustrative example

How Aurora helps

The analyst asks the questions. Aurora is built to gather the answers.

A suspicious pattern is rarely visible in a single transaction. Aurora is designed to connect the surrounding trades, wallets and price effects so an analyst can judge what happened.

Monitor

Follow activity on supported exchanges and lending markets as new blocks arrive.

What is happening, and where?

Flag

Raise sequences that resemble known manipulation patterns, with the reason stated plainly.

What deserves a closer look?

Investigate

Reconstruct the order of events, the wallets involved and the effect on price and liquidity.

Who was involved, and what did it do to the market?

Document

Arrange the evidence into a report draft that a person reviews, edits and decides on.

How should the findings be recorded?

The analyst decides. Flags and drafts are meant to help an analyst choose what to look at and what to write. They do not establish intent, and Aurora does not file anything with a regulator.

Behind the workflow: PULSE-MEV13. The analytical engine Aurora is developing to link three tasks usually done separately: spotting patterns, estimating market impact and structuring the report. The name records thirteen development iterations.

How a sandwich attack works

Illustrative example · suspected sandwich attack
Step 1 of 4

A trader places an order

Someone decides to buy on a blockchain-based exchange. Their order waits briefly before it is processed.

Trades on these markets are recorded on a public ledger, but the people behind wallets usually are not.

Step 2 of 4

Another trader surrounds it

A second wallet buys just before the order and sells just after it, pushing the price up and then back down.

The original trader pays more than they were quoted. The other wallet keeps the difference.

Step 3 of 4

Aurora flags the pattern

The two surrounding trades are linked to the same wallet and raised for investigation, with the reason stated plainly.

A flag is a starting point for an analyst, not a finding.

Step 4 of 4

An analyst reviews the evidence

The sequence becomes a short case summary: what happened, the related transactions, the observed effect and a report draft.

A person checks it, edits it and decides what happens next.

This example shows the intended workflow with invented data. It is not a live feed or a validated detection, and not every step shown is fully built today.

Explore the details

How the same example would appear as raw records. Block, positions, wallets and sizes are invented.

Block · positionWalletActionMarketSize
4,813 · 110xc2…55Add liquidityETH/USDC+38 ETH
4,813 · 120x3f…a1Buy ETHETH/USDC40 ETH
4,813 · 130x9b…7eBuy ETH (the trader)ETH/USDC10 ETH
4,813 · 140x3f…a1Sell ETHETH/USDC40 ETH
4,813 · 150x77…d0Repay loanwETH market12.5 ETH

Highlighted rows are the two trades from wallet 0x3f…a1 either side of the trader's order. Reconstructing the order of events, the wallets involved and the price effect is the work Aurora is designed to organise for the analyst.

Why we are building it

It began as a legal research question.

“If financial markets are becoming programmable and decentralized, shouldn't regulatory surveillance become programmable and decentralized as well?”

Alimul Ghani Rudra, from the research that led to Aurora
AURORA: Institutional DeFi Market Abuse Surveillance and Systemic Risk Intelligence Framework
Alimul Ghani Rudra · SSRN working paper · February 2026

Aurora started in Alimul Ghani Rudra's LLM thesis, which asked whether market-abuse rules written for markets with identifiable intermediaries could work in decentralised markets built on smart contracts, automated market makers and pseudonymous actors. The research proposed a surveillance framework. Aurora is that framework being built into software.

More about the research framework

The framework connects five kinds of analysis that are usually handled separately:

  1. 01Market-state reconstruction. Rebuild what a market looked like around an event.
  2. 02Behavioural analysis. Look at how wallets act over time and in relation to each other.
  3. 03Causal simulation. Ask what the market would have done without the suspect activity.
  4. 04Systemic-risk analysis. Consider whether an event could spread across protocols.
  5. 05Regulatory mapping. Relate observed behaviour to existing market-abuse frameworks.

The paper's evaluation was carried out in simulation. It shapes the design but is not evidence of how the software performs in production.

Long-term ambition: a digital regulatory layer for DeFi, so that market-abuse rules and supervision can work directly with programmable markets. That is a direction of travel, not something that exists today. Aurora itself is ordinary software run by a team; it monitors decentralised markets but is not decentralised.

Team

Two founders, one from the research and one from the product.

Alimul Ghani Rudra

Founder
Research & regulatory framework

Alimul originated Aurora through his LLM research into market abuse in decentralised finance and authored its surveillance framework. He brings the legal and regulatory research perspective behind the product.

LLB (Hons) · LLM in Global Business & Finance · Bristol, UK

Ishmam Ahmed

Co-founder
Product engineering, design & growth

Ishmam works across Aurora's backend development, product design and user experience, helping turn its research vision into a usable platform. He also shapes Aurora's positioning, marketing and fundraising preparation.

Backend development · interface and user journeys · YC and pre-seed preparation

Where Aurora is today. Aurora has implemented software and documented live-data integration. Detection quality and parts of the investigation workflow still need validation, which is the next stage of work.

Built so far
  • A surveillance dashboard with documented connections to live blockchain and market data.
  • A first set of detectors for DeFi abuse patterns and an alert feed.
  • Report drafts generated from alerts, and workspaces that keep each organisation's cases separate.
Validating next
  • Measure detection against documented incidents: detection rate, false positives and latency.
  • Test the workflow with prospective users in regulatory and compliance teams.
  • Complete the investigation layer, including market-impact and coordination analysis.

Next step

Working on supervision or compliance for blockchain markets?

We would like to show you the workflow and hear how your team handles these cases today. Investors in early-stage infrastructure are welcome to reach out as well.

Contact

Contact details coming soon.

Product

auroramev.app

Talk to the founders

Contact details coming soon.

An email address and booking link will be added here shortly.