what is a sandwich attack?

Overview of Sandwich Attacks

A sandwich attack is a type of exploit in cryptocurrency transactions where a malicious trader, often called a "searcher" or "MEV bot," traps a victim's transaction between two of their own transactions—one executed immediately before (front-running) and one immediately after (back-running) 12. This manipulation forces the victim's trade to execute at a significantly worse price, resulting in a profit for the attacker and a loss for the victim 23.
Sandwich attacks are a form of Miner Extractable Value (MEV) 4. They are considered the predominant category of MEV extraction, surpassing arbitrage and liquidation strategies in cumulative value extracted from the Ethereum blockchain by mid-2021 4.

How a Sandwich Attack Works

The attack exploits the transparency of the mempool (the waiting area for unconfirmed transactions) and the mechanics of Automated Market Makers (AMMs), such as Uniswap 12.
The process typically involves the following steps 15:
  1. Scanning the Mempool: The attacker's bot constantly scans the mempool for a victim's pending transaction, usually a large swap, that could be profitable to exploit 15.
  2. Front-Running (The Buy): The attacker submits a buy transaction for the same asset the victim is trying to purchase 15. To ensure their transaction is processed first, the attacker pays a higher gas fee than the victim 15. This buy order causes the price of the asset to rise due to price impact 12.
  3. Victim's Transaction: The victim's transaction is executed next, but because the price has already been inflated by the attacker's front-run, the victim buys the asset at a much higher price than they initially expected, suffering from high slippage 15.
  4. Back-Running (The Sell): Immediately after the victim's transaction is confirmed, the attacker submits a sell transaction for the asset they just bought 15. This sell order drives the price back down, and the attacker profits from the difference between their initial buy price and the final sell price, which was inflated by the victim's trade 15.
This sequence of transactions—Attacker Buy (Txn₁), Victim Trade (Txn₀), Attacker Sell (Txn₂)—is executed sequentially within the same block or across consecutive blocks, effectively "sandwiching" the victim's trade 1.

Impact and Prevalence

Sandwich attacks intensify during periods of high market volatility and uncertainty 6. Data from a six-month period in 2022 showed that attack counts spiked significantly during major market events, including the Terra Fallout, the Three Arrows Capital (3AC) crisis, and the FTX Collapse 6.
Key observations regarding the impact of these attacks include:
  • Dominant MEV Strategy: Sandwich attacks were the predominant category of cumulative MEV extracted from Ethereum between 2019 and 2021, surpassing $250 million by mid-2021 4.
  • Victim Losses: Users have lost substantial funds due to sandwich attacks, with estimated losses amounting to at least $800 million in 2022 alone 7.
  • Target Platforms: Platforms with higher liquidity and volume, such as Uniswap V3, appear to be more susceptible to these attacks than others like SushiSwap 6.
  • Transaction Volume: The majority of transaction volumes prone to being sandwiched fall within the $10,000 to $1 million range 8.

Mitigation Strategies

One method developed to protect users from sandwich attacks is to prevent their transactions from entering the public mempool, where they can be observed by bots 7. Features like the 1inch RabbitHole aggregate providers (such as Flashbots and BloXroute) to send swap transactions directly to validators, bypassing the mempool and shielding the trade from sandwich bots 7.
You're viewing a shared conversation. Your questions will start a new chat.