Skip to content

The arithmetic behind order-flow signals: imbalance windows, the microprice, the four ways displayed depth misleads, and how to sample a book honestly.

Автор
EdgeMarket
Опубликовано
Время чтения
9 мин чтения

Most traders look at an order book the way they look at a weather map: bigger cloud on the left, expect rain. Bigger stack of bids, expect the price to go up. That intuition is wrong often enough to be expensive, and understanding exactly why it is wrong is the difference between using book data and being used by it.

This is a working guide to the level-2 book on crypto venues — what the data structure actually contains, the handful of quantities worth computing from it, and the ways each one lies.

What a level-2 book contains

A venue's matching engine holds every resting limit order, sorted by price and, within a price, by arrival time. Three views of that structure are usually published:

  • Level 1 — the best bid and best ask, with the size available at each. The "top of book".
  • Level 2 — the aggregated size resting at each price level, on both sides, usually to some depth limit.
  • Level 3 — every individual order, with its own identifier and place in the queue.

Level 2 is the level most APIs give you, and the aggregation matters more than it looks. A level of 40 BTC might be one institutional order or four hundred retail ones. Those two books behave completely differently when price arrives — the single order either fills or is pulled as a block; the four hundred evaporate at different speeds — and level 2 cannot tell them apart.

What the book contains, then, is a set of conditional statements: if an aggressive order arrives at this price, this much size is currently willing to trade. It is not a set of intentions, not a forecast, and not a promise. Every one of those statements can be withdrawn before it is tested, and most of them are.

The three quantities that come for free

Spread. Best ask minus best bid. Quote it in basis points of the mid, never in dollars — an eight-dollar spread means one thing on BTC and something else entirely on SOL. The spread is the immediate round-trip cost of being wrong about direction, and it widens exactly when you most want to trade.

Mid price. The average of best bid and best ask. It is the most commonly used reference price and the least informative one, because it ignores size completely. A book with 100 units bid and 1 unit offered has the same mid as a book with 1 bid and 100 offered.

Depth. The cumulative size within some distance of the mid. Always define the distance, and always define it in relative terms: "notional resting within 10 basis points" is comparable across assets and across time. "Notional in the top 20 levels" is not comparable to anything, because tick size and level granularity differ per venue and per contract.

Imbalance, and the arithmetic behind it

Order-book imbalance is the simplest asymmetry measure and the one you will see everywhere:

I = (Vbid - Vask) / (Vbid + Vask)

where Vbid and Vask are the resting sizes on each side, within your chosen depth window. It runs from −1 (nothing but offers) to +1 (nothing but bids), and 0 means the two sides are balanced.

The choice of window is not a detail — it is the signal. Imbalance measured on top-of-book only is dominated by market-maker quoting behaviour and flips several times a second. Imbalance measured across a wide window is dominated by resting orders far from the price that nobody expects to trade today. The two series can point in opposite directions at the same instant, and both will be called "book imbalance" by whoever is quoting them at you.

A worked example, so the arithmetic is concrete:

Side · Size within 10 bps · Size within 50 bps
SideSize within 10 bpsSize within 50 bps
Bids120900
Asks801,400
Imbalance+0.20−0.22

The numbers above are an illustration of the arithmetic, not a capture of any real book. Near the touch this market looks bid-heavy; a little further out it looks offered. Neither reading is false. They are answers to different questions, and reporting one without stating the window is how a book signal becomes unfalsifiable.

The microprice: a better anchor than the mid

If size matters, weight by it. The standard fix is the size-weighted mid, usually called the microprice:

Pmicro = (Pask x Vbid + Pbid x Vask) / (Vbid + Vask)

Note the crossing: the ask price is weighted by the bid size. The intuition is queueing. When bids dominate the touch, a marketable order is far more likely to arrive on the buy side and lift the offer, so the expected next trade price sits closer to the ask. The microprice slides toward the side with less resting size, which is the side about to be consumed.

This is a genuinely better fair-value estimate than the mid for very short horizons, and it costs one line of code. It is also where most of the naive "imbalance predicts price" result comes from: imbalance and the microprice are two views of the same instantaneous state. If you build a signal from imbalance and evaluate it against a mid-price return over the next few seconds, you will find a strong relationship, and it will be largely mechanical rather than predictive.

Depth is not commitment

Four properties of real books break the "big stack means support" reading.

Cancellation is free and constant. On any liquid crypto venue, the overwhelming majority of resting orders are cancelled rather than filled. Market makers quote to earn the spread while managing inventory; when the market moves against their inventory they do not defend the level, they withdraw. Depth ahead of a fast move does not absorb it — it disappears before the move arrives. That is why levels "break easily" precisely when they looked strongest.

Hidden and iceberg orders. Many venues let a trader display a small slice of a larger order, replenishing the display after each fill. Displayed size is then a lower bound on real size, and it is a biased lower bound: the participants most likely to hide are the ones with the largest orders. A book can be far deeper than it looks, in exactly the situations where depth matters most.

Queue position is invisible at level 2. Two orders at the same price are not equivalent. The one that arrived first fills first, and the last order in a long queue at a level may never fill at all. Aggregated size tells you the queue is long; it never tells you where in it you are, which is the only thing that determines whether your passive order is a fill or an unfilled hope.

Some of it is not real. Placing orders with the intent to cancel before execution — spoofing — is prohibited on regulated venues and is a live enforcement risk there. Crypto venues vary in how aggressively they police it. Any book signal that responds to displayed size is, by construction, a signal that can be manufactured by whoever is willing to display size they never intend to trade.

Resting depth versus aggressive flow

The two data series people conflate are the book and the tape.

The book is passive intent: liquidity waiting to be taken, revocable at zero cost.

The tape is realised aggression: trades that actually happened, each one tagged with the side that crossed the spread. Trade imbalance — signed volume over a window — is a record of what did happen, and unlike book imbalance it cannot be cancelled retroactively.

They answer different questions. The tape tells you where pressure came from; the book tells you what it will cost the next participant to apply more. The informative combinations are the ones where the two disagree — sustained buying pressure that fails to move price means the offer is being replenished by size you cannot see, and that is a far more interesting observation than either series alone.

Resilience: what happens after the print

The most useful and least-watched book property is how fast depth comes back after it is consumed. A venue where a large market order removes three levels and the book refills within a second is a venue with real market-making capacity. A venue where the same order leaves a hole that persists is one where the next order of the same size will move price much further.

Resilience is measurable and it is not a price prediction — it is a cost prediction, which is the thing execution actually depends on. It also degrades in a predictable pattern: it collapses around scheduled events, funding settlements and liquidation cascades, which is exactly when position sizes tend to be largest.

Four books, not one

BTC does not have "an order book". It has one book per venue, per contract type. The books on Binance, Bybit, OKX and Hyperliquid are separate structures with separate participants, fee schedules and tick sizes — and Hyperliquid's is an on-chain central limit order book, with a different latency profile from the others.

Two consequences follow. First, depth is fragmented: the total liquidity available at a price is spread across venues, and no single book shows it. Second, an imbalance visible on one venue and absent on the others is usually flow, not information — one participant working an order in one place. Cross-venue agreement is the cheapest filter available for book signals, and almost nobody applies it.

We sample the book across those four venues every minute for exactly this reason: a depth reading is only interpretable next to its own history and next to the other venues. That is also the design principle behind our published measurements — every number we show comes with what it does not cover. The public register is where those live, including the bands where the measurement does not flatter us.

Sampling a book without lying to yourself

Three implementation details ruin more order-flow research than any modelling error.

  1. Snapshots at a fixed interval are not the book. If you poll depth once a second, you are sampling a structure that changes hundreds of times a second, and you will systematically miss the transient states that precede fast moves. Consume the delta stream, apply the updates in sequence, and keep the sequence numbers — a gap means your local book is wrong and must be rebuilt from a fresh snapshot, not patched.
  2. Timestamp everything at the venue, not at your machine. Network latency varies with load, which varies with volatility. Local timestamps will quietly correlate your measurement error with the thing you are trying to measure.
  3. Reconstruct the book as it was, not as it ended. Any research on "the book before a move" needs point-in-time state. Rebuilding it from a later snapshot leaks the future into the feature, and the resulting backtest will look spectacular and be worth nothing.

A short checklist

Before trusting any conclusion drawn from a book, answer these:

  • Over what depth window is the imbalance computed, and does the conclusion survive changing it?
  • Is the comparison mid-to-mid, or microprice-to-microprice? The first will overstate the result.
  • Does the signal hold on more than one venue at the same moment?
  • What fraction of the displayed size actually traded, historically, at that level?
  • Would the same signal have appeared if someone simply wanted it to appear?

The book is a genuinely rich data source — the richest available on crypto venues, and the only one that describes the cost of the trade you have not made yet. It is just not a prediction. Treat it as a measurement of cost and capacity, cross-check it against the tape, and it will pay for the plumbing. Treat it as a signal of direction and it will pay for someone else's.

Related reading: what funding rates say about positioning, which covers the other half of crypto market structure — the state of leverage rather than the state of the book.