- Enforcement
- Markets & Trading
- Governance & Accountability
Four cents to $4,580 in three minutes
A single erroneous warrant order slipped past a firm's controls, not because a check was missing, but because one had switched itself off.

Nasdaq · AWC · Market Access Rule
Case: Nasdaq v. UBS Securities LLC Outcome: Censure + $32,500
Four cents to more than $4,580 in about three minutes
Source: Nasdaq v. UBS Securities LLC, Letter of Acceptance, Waiver and Consent, accepted 9 September 2026.
~114,000× price move
- ADV control paused the order
- Trader reviewed and released it
- No downstream backstop applied
- Trades were later broken
The warrant moved from approximately $0.04 to more than $4,580 in about three minutes, roughly 114,000-fold. The ADV control paused the order; after trader review, no downstream backstop applied because warrants are outside LULD. This comparison shows the stated endpoints and control sequence; the settlement does not specify the intraday price path.
Case at a glance
Source: Nasdaq v. UBS Securities LLC, Letter of Acceptance, Waiver and Consent, accepted 9 September 2026.
A 100,000-warrant order was about seven times the instrument's average daily volume. The resulting trades in the three-minute window were broken, including 38,056 shares on Nasdaq; UBS accepted a censure and $32,500 fine without admitting or denying the findings.
An order that should have been stopped twice
On 7 March 2025, UBS Securities LLC routed an erroneous customer market order to buy 100,000 warrants of a single low-priced security. The order was roughly seven times the entire average daily volume of that instrument. Within about three minutes, the price of the warrant climbed from approximately four cents to more than $4,580, a move of more than one hundred thousandfold, before the exchanges intervened. UBS submitted a Clearly Erroneous petition, and after discussion between Nasdaq and other venues, every trade at or above four cents inside the three-minute window was broken, including 38,056 shares executed on Nasdaq.
What makes the episode worth studying is not that a fat-finger order reached the market. Those happen. What makes it instructive is that UBS actually had a control positioned to catch it. The order tripped the firm's average-daily-volume control, which paused it for human review on the Retail Market Making desk. A trader looked at it. And then the order was released, without the one discretionary tool that would have capped its price impact, into a routing path where no further automated control was waiting. The security was a warrant, and warrants sit outside the Limit Up-Limit Down bands that would have caught almost any other instrument.
On 9 September 2026, Nasdaq accepted a Letter of Acceptance, Waiver and Consent under which UBS agreed to a censure and a $32,500 fine, without admitting or denying the findings. The dollar figure is small. The design lesson is not. This was a firm whose control architecture assumed that once a human had reviewed an order, the machine no longer needed to, and an asset class for which the market's own circuit breaker did not apply. The two assumptions met on the same order.
What the settlement found
The AWC frames the conduct under the Market Access Rule. Section 15(c)(3) of the Securities Exchange Act of 1934, and Rule 15c3-5(b) beneath it, require a broker-dealer with market access to establish, document, and maintain a system of risk management controls and supervisory procedures reasonably designed to manage the risks of that business. Rule 15c3-5(c)(1)(ii) requires controls reasonably designed to prevent the entry of erroneous orders, including by rejecting orders that exceed appropriate price or size parameters or that indicate duplicative orders. Nasdaq Rule General 9, Sections 1(a) and 20(a) layer on the exchange's own conduct and supervision obligations.
The specific defect, as the settlement describes it, lived in a piece of design logic. During the review period, running from 29 August 2023 to 16 July 2025, UBS operated what the AWC calls an anti-redundancy logic. Under it, an order that had been paused and reviewed by firm personnel at the parent-order level for one or more price or size controls would not then trigger additional automated downstream controls at the child-order level. For securities covered by the Limit Up-Limit Down plan, an additional LULD-based control still applied further down the chain. Warrants are not covered by the LULD plan. So once a paused warrant order was released after review, there was no comparable automated backstop left to catch it.
On the March 7 order, that is exactly the sequence that played out. The order's size triggered the ADV control at the order-routing level and paused for review by a Retail Market Making trader. The trader conducted a review and released the order without using the discretionary manual price completion tool, a feature that lets the trader set a completion price beyond which further child orders stop routing. Because the order was for warrants and had been released following review, it met no further automated downstream control. The firm's SmartEx algorithmic logic converted the parent order into child orders priced within the prevailing national best bid and offer, and the Smart Order Router sent them out to Nasdaq and other market centers, where the price ran away.
When a human review turns off the machine
Anti-redundancy logic is not, on its face, a bad idea. Firms build it precisely because layered controls can fire repeatedly on the same order, flooding traders with duplicate alerts and slowing legitimate flow to a crawl. The intuition is reasonable: if a control has already paused an order and a qualified person has looked at it, re-running the same family of checks downstream feels wasteful. The problem is what that intuition quietly assumes. It assumes the human review is an adequate substitute for the automated control it suppresses. On the March 7 order, it was not, because the substitute step, the price completion tool, was discretionary, and the trader did not use it.
So the failure was not one gap but the alignment of three. First, a design gap: the downstream automated control was switched off by the act of parent-level review, converting a layered defense into a single point of dependence. Second, a coverage gap: warrants fall outside LULD, so the market-wide safety net that catches most runaway prices simply did not exist for this instrument. Third, a discretion gap: the one remaining tool that could have contained the damage was optional, and optional controls fail exactly when a busy person under time pressure decides, in good faith, that they are not needed. Remove any one of the three and the order is likely stopped. All three were present at once.
There is a fourth element that a supervisor should not miss, and it is the timeline. This was not UBS's first market access finding. On 3 May 2022, the firm consented to Nasdaq findings that it had failed to establish, document, and maintain adequate market access risk controls, and paid $90,000 as part of a larger fine. The review period for the warrant matter began the following year and ran into 2025. A repeat finding in the same rule family is the kind of pattern that examiners weight heavily, because it suggests remediation that closed a specific hole without asking whether the same class of hole existed elsewhere in the architecture.
The instructive move UBS made afterward is a tell about the real root cause. The firm did not simply retrain the desk. It revised its written supervisory procedures so that a paused warrant order must be either rejected or resumed using the price completion tool, removing the discretion. Then it implemented a new automated price impact control that applies regardless of whether the instrument is part of the LULD plan. In other words, the firm stopped relying on the market's circuit breaker to cover a gap in its own, and it stopped treating a human review as a reason to disarm the machine. That is the correct lesson, arrived at after the fact.
Seven steps, one missing gate
Reconstructed from the settlement, the order's journey shows where each control sat, and where the one that mattered was absent.
The seven-step warrant order path
Source: Nasdaq v. UBS Securities LLC, Letter of Acceptance, Waiver and Consent, accepted 9 September 2026.
The ADV control paused the order, but the trader released it without a price ceiling. Parent-level review suppressed child-order controls; warrants had no LULD backstop. SmartEx then routed child orders, and the exchanges broke the resulting trades.
The pitfalls this case sets out plainly
Strip the episode down and it becomes a checklist of the ways market access controls fail in practice, none of which requires a missing control to occur. The first is the substitution assumption: treating a human review as interchangeable with an automated check, and building logic that turns the machine off once a person is involved. Reviews are valuable, but they are slower, discretionary, and fallible under load. A control architecture should let a review add a layer, not remove one.
The second is asset-class blind spots. LULD is such a reliable backstop for listed equities that firms can drift into leaning on it without noticing. Warrants, rights, certain ADRs, when-issued lines, and other instruments outside the plan are exactly where that lean becomes a fall. A control inventory that is complete for common stock can be quietly empty for the long tail, and the long tail is where erroneous orders do the most spectacular damage, because thin liquidity turns a mis-sized order into a vertical line.
The third is the optional-control trap. A tool that a trader may use is a tool that, on the wrong morning, a trader will not use. Where the downside is a runaway price and broken trades, discretion is a liability. The firm's own remediation recognized this by making the price completion tool mandatory for paused warrant orders. The general principle: for high-consequence, low-frequency events, defaults should be safe and overrides should require an affirmative, logged decision, not the reverse.
The fourth is repeat-finding drift. Closing the specific hole from a prior enforcement matter is necessary but not sufficient. The more useful question after any market access finding is structural: where else does this same class of assumption live in our controls? UBS's 2022 matter and its 2025 review period sit in the same rule family. A firm that had asked the broader question in 2022 might have found the warrant gap before an order did.
- Where does anti-redundancy or de-duplication logic suppress a downstream control after a parent-level review, and is the suppressed control ever the last line of defense?
- Which traded instruments fall outside LULD, and does each have an equivalent firm-side price-impact control that does not depend on the market-wide band?
- Which market access controls are discretionary rather than mandatory, and what is the loss exposure if the discretion is exercised the wrong way on a thin name?
- Do order-size checks reference the specific instrument's ADV, so that 700% of a warrant's volume is caught as sharply as 700% of a liquid stock's?
- For any prior market access finding, has the same class of assumption been swept for across every asset class and routing path, not just the one that was cited?
These are not hypotheticals bolted onto the case. Each maps directly to a step in the order path above, and each is the kind of structural question that surfaces a gap while it is still a design choice rather than a broken trade.
The same rule, a very wide range of outcomes
The Market Access Rule has generated a long line of enforcement since it took effect, and the striking thing about that line is its range. The same core failure, controls not reasonably designed to prevent erroneous or duplicative orders, has produced everything from a small exchange censure to one of the most famous near-collapses in market history. What separates them is rarely the sophistication of the firm. It is whether a single point of dependence happened to sit in the path of a bad order.
The archetype. A flawed software deployment sent millions of unintended orders into the market in roughly 45 minutes, generating a loss that crippled the firm. The SEC's action turned on the absence of adequate market access controls and a system to catch the runaway before it ran. Different trigger, identical lesson: when one layer fails, something automated has to be waiting underneath.
The SEC found that Merrill's market access controls were set with internal limits so permissive, and in some cases bypassable, that they did not reasonably prevent erroneous orders from reaching the market. A reminder that a control which exists on paper but is calibrated or overridable into irrelevance is, for enforcement purposes, not a control.
A configuration error in August 2013 caused Goldman to send thousands of mispriced options orders into the market within minutes. As with UBS, the damage flowed from an automated path that lacked a reasonably designed check on obviously erroneous prices, and many of the resulting trades had to be broken.
The closest structural cousin, and the same regulator. Nasdaq found J.P. Morgan's financial risk-management controls and supervisory procedures were not reasonably designed to prevent certain erroneous and duplicative orders. A recent, granular reminder that the exchange SROs are actively examining the plumbing of market access, not just the headline blowups.
Set the fines side by side and the point is not the amounts. It is that the $32,500 UBS matter and the Knight near-collapse sit on the same fault line. The dollar outcome is mostly luck, a function of how far a bad order ran before something stopped it. The control lesson is constant.
Where Market Access enforcement concentrates
Source: RegLabs cases tagged Market Access Controls & Trading Risk Management, by regulator (U.S. venues shown).
FINRA leads the U.S. venues shown with 117 cases, followed by NYSE Arca (87), NYSE (64), NASDAQ (60), Cboe BZX (58), and SEC (30). Across all regulators, RegLabs holds 1,411 market access cases carrying roughly $5.29 billion in penalties. The volume sits with the SROs, whose examinations reach the order-handling detail this case turns on.
What the pattern says to the rest of the market
Read across the record, market access enforcement is overwhelmingly an exchange-SRO story. FINRA and the venue regulators account for the great majority of the 1,411 cases in the RegLabs set, and their actions tend to turn on the granular mechanics of order handling: how a control is calibrated, whether it is mandatory, what happens to a child order after a parent is reviewed. The SEC brings the headline cases, but the day-to-day pressure comes from the SROs, and their examinations increasingly reach into exactly the kind of design logic that failed here.
For Nasdaq specifically, the UBS matter fits a consistent posture. The exchange has repeatedly pursued firms whose controls were not reasonably designed to prevent erroneous and duplicative orders, from J.P. Morgan to Jefferies to Morgan Stanley, and it does so with modest fines but pointed factual findings. The message a compliance officer should take is that the size of the penalty understates the significance of the citation. A $32,500 fine attached to a repeat finding in the same rule family is a signal about scrutiny, not a measure of tolerance.
Globally, the theme generalizes as markets speed up and asset coverage widens. The instruments most likely to produce a spectacular erroneous-order event are precisely those outside the standard safety nets: warrants and structured products outside LULD, thinly traded lines where a mis-sized order has no depth to absorb it, and newer venues and hours where market-wide protections are inconsistent. As trading extends toward longer sessions and more automated order entry, the firm-side backstop matters more, not less, because the market-wide one cannot be assumed to be there. The through-line from Knight in 2013 to UBS in 2026 is that layered, mandatory, asset-complete controls are the defense, and any architecture that lets a single review or a single coverage gap stand alone is one bad order away from a headline.
Find the disarmed control before an order does
The gap that cost UBS a censure was not visible as a broken control. It was visible as a design assumption: a downstream check suppressed by an upstream review, on an asset class the market's own backstop never covered. Those assumptions are exactly what regulatory analytics are built to surface. RegLabs regulatory models let a firm map its own control architecture against the full enforcement record, so the questions an examiner would ask show up as review items first.
UBS Securities LLC settled this matter without admitting or denying the findings. The prior 2022 Nasdaq matter is noted as context on repeat findings, not as an adjudication of the current facts. Penalty amounts and the price move are stated as recorded in the settlement and the RegLabs record. The hero visual is an illustrative reconstruction, not a tick-by-tick chart. This post is informational and is not legal advice.
Sources
- Nasdaq v. UBS Securities LLC, Letter of Acceptance, Waiver and Consent, accepted 9 September 2026. Primary document: Nasdaq Disciplinary Actions (NQ), 9 Sep 2026.
- Case record and analytics: RegLabs Studio.
- Parallels: SEC v. Knight Capital Americas LLC (2013); SEC v. Merrill Lynch, Pierce, Fenner & Smith (2016); SEC v. Goldman, Sachs & Co. (2015); Nasdaq v. J.P. Morgan Securities LLC (2023). Thematic figures: RegLabs enforcement database, cases tagged Market Access Controls & Trading Risk Management (n = 1,411).
- Rules referenced: Securities Exchange Act § 15(c)(3); Rules 15c3-5(b) and 15c3-5(c)(1)(ii); Nasdaq Rule General 9, Sections 1(a) and 20(a).
