Cointime

Download App
iOS & Android

1inch Unveils RabbitHole Feature to Protect MetaMask Users From "Sandwich Attacks"

Validated Project

The 1inch RabbitHole feature will protect MetaMask users from sandwich attacks, one of the most common ways of extracting MEV in DeFi.

The 1inch Network is thrilled to introduce the 1inch RabbitHole, a brand new feature that aims to protect MetaMask users swapping on 1inch from sandwich attacks — the most common type of front-running.

Sandwich attacks explained

When making swaps on decentralized exchanges, users can potentially become victims of a so-called “sandwich attack,” a way of getting maximal extractable value (MEV). Although technically not illegal, sandwich attacks are still a type of manipulating crypto prices by taking advantage of decentralized exchanges’ underlying tech. And a sandwich attack could lead to significant losses for a user.

To run sandwich attacks, specifically created bots are used that scan decentralized exchanges’ memory pools (mempools) where transactions are waiting to be processed. If a bot detects a large pending swap trade, it initiates two transactions: one before the trade and the other one after the trade, basically “sandwiching” the victim’s trade. To get the first transaction directly before the victim’s trade, extra gas fees are paid.

Say, a user wants to buy 1,000 X tokens for 20 Y tokens with a 1% slippage tolerance — meaning that the minimum amount of X tokens they agree to receive is 1,000–1% = 990.

A sandwich bot detects the trade and places a buy transaction for Y directly before the victim’s trade and a sell transaction for Y directly after the victim’s trade. Subsequently, three transactions are executed.

  • Transaction 1: the bot executes the buy transaction, and the high purchase of asset Y pumps its price.
  • Transaction 2: the victim buys Y at a higher price than originally expected, and the large trade pumps Y’s price even higher.
  • Transaction 3: the bot sells Y, pocketing the price difference.

As a result, the user loses their 1% entirely.

The very first sandwich attack is believed to be carried out on Bancor on February 27, 2018:

Since then, users have lost substantial funds due to sandwich attacks, which hit roughly 4% of all swap transactions. In 2022 so far, estimated losses have amounted to the equivalent of at least $800 mln.

The 1inch RabbitHole: a shield from sandwich attacks

The 1inch RabitHole is a feature that solves the problem of sandwich attacks by sending swap transactions on 1inch directly to validators and avoiding putting them to the mempool where sandwich bots can attack them.

To achieve that, the RabbitHole aggregates providers, such as Flashbots, BloXroute, Eden and Manifold, that enable sending swap transactions directly to validators.

The RabbitHole will specifically benefit MetaMask users, as, while some crypto wallets (including the 1inch Wallet, Ledger and Trezor) are capable of creating and signing a transaction, but not broadcasting it immediately, MetaMask is not.

The RabbitHole is designed as a proxy, connecting 1inch users’ MetaMask wallets and Ethereum validators. Its unique algorithm will check swap transactions on 1inch for the threat of a sandwich attack, and, if such a threat is detected, the transaction will be sent directly to validators, using one of the aggregated providers.

For a testing period, the RabbitHole will be free to use. Upon receiving feedback from the community, a decision will be made regarding payment options for the RabbitHole. One possible option could be staking a certain amount of 1INCH tokens.

A step-by-step guide on using the 1inch RabbitHole is available in the Help Center.

Comments

All Comments

Recommended for you

  • ETH Trading Volume on Hyperliquid Exceeds BTC, Reaching Approximately $1.1 Billion in 24 Hours

    On October 11, the trading volume of ETH on the Hyperliquid platform reached approximately $1.1 billion in the last 24 hours, surpassing BTC's $805 million. Market analysts believe that the increase in ETH trading volume is related to suspected exploitation of the PaperTrade mechanism. Earlier today, reports indicated that PaperTrade was allegedly manipulated by two addresses, revealing a significant vulnerability in the protocol: the two wallet addresses executed trades on Hyperliquid with a single transaction size of about $20 million, causing ETH prices to fluctuate by approximately 10 to 20 basis points, and establishing long positions with a notional value of several hundred million dollars on PaperTrade.

  • Ledger Confirms Unauthorized Hardware Implant in Devices, Losses May Exceed $86 Million

    On October 11, Cointelegraph reported that hardware wallet manufacturer Ledger confirmed the presence of unauthorized hardware implants in the devices of an affected user. The incident involves losses related to devices purchased from its Southeast Asian distributor, CryptoBilis. Investigator Specter estimates that the losses may exceed $86 million, involving Bitcoin, Ethereum, and Tron. Ledger stated that it is in contact with the affected users; CryptoBilis has confirmed the suspension of all hardware wallet inventory sales until the investigation is complete. Ledger claims that the incident appears to be limited to this single distributor and its market, and that its own infrastructure, systems, and services have not been compromised. The company has not yet confirmed the number of affected customers or the total amount of losses. Ledger advises users who have not initialized their devices to refrain from doing so, while those who have already initialized their devices may consider transferring their assets to a new signer using a new mnemonic.

  • Anthropic Model Automatically Submits False Leads to Philadelphia Police

    On October 11, according to CCTV International News, the AI model 'Claude Haiku 4.5' from Anthropic automatically accessed the Philadelphia Police Department's webpage for unsolved homicide tips in July this year, filling out a form claiming to have 'potential information related to the case' but did not provide a name or contact information. The form was subsequently marked as spam by the police and did not trigger an investigation. Anthropic released a report on October 9 disclosing the incident and notified the Philadelphia police in advance. The police stated they were previously unaware of the situation, deemed it 'unacceptable,' and requested that technology companies take necessary measures to prevent their AI systems from submitting false information to law enforcement.

  • Industrial Fulian: US International Trade Commission Initiates 337 Investigation Against Company and Subsidiary

    On October 11, Industrial Fulian announced that it was informed the US International Trade Commission officially launched a 337 investigation on October 9 local time, regarding patent infringement claims made by Vicor Corporation. Vicor accuses the company and its subsidiary of infringing on a patent for a 'vertical power supply system.' After an internal review, the company stated that the products involved in this investigation are currently in the internal validation and evaluation stage, and this investigation does not have a substantial impact on the company's current production, operations, or performance.

  • CFTC Issues Two Proposals Clarifying Prediction Markets as Derivatives, Excluding Casino Gambling

    On October 11, Cointelegraph reported that the U.S. Commodity Futures Trading Commission (CFTC) has released two proposals to clarify its regulatory authority over prediction markets. The first proposal defines event contracts related to sports, politics, culture, and weather as 'swaps' products under federal law. CFTC Chairman Michael Selig stated that these products fall under the category of commodity derivatives as defined by the Commodity Exchange Act, and are fully within the exclusive jurisdiction of the CFTC. The second proposal establishes boundaries, explicitly stating that traditional casino-style gambling products—including sports betting and casino games—do not fall within the definition of 'swaps' and are not considered derivatives. This move comes in the context of prediction market operators like Kalshi and Polymarket facing joint lawsuits from multiple states, accused of operating illegal gambling businesses; the CFTC is counter-suing and issuing new regulations in an attempt to clarify the regulatory boundaries between federal and state authorities, paving the way for a potential Supreme Court ruling.

  • Houthi Forces Warn Airlines, Staff, and Passengers Again

    On October 11, the Houthi forces in Yemen issued another warning to airlines, staff, and passengers, advising them not to use airports within Saudi Arabia.

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.