Cointime

Download App
iOS & Android

Sandwich Attacks: Are You on the Menu?

Repost from Modern Consensus, Alice Kohn: “Sandwich Attacks: Are You on the Menu?” The full report and all related findings are available on the official website of Modern Consensus.

raditional “front running” is trading of stocks or other financial assets using privileged information about an upcoming transaction that is anticipated to significantly impact its price. For example, brokers could front run trades by using insider knowledge regarding their firm’s imminent issuance of a buy or sell recommendation to clients, a move expected to influence the asset’s price. Trading on this kind of non-public information is illegal in most jurisdictions, not only because it’s unfair to other market participants but also because it degrades the integrity of financial markets and erodes investor trust.

In the often “Wild West” of crypto markets, given that all too often lawmakers haven’t caught up with technology, regulators are preoccupied with increasing their own power or regulating by enforcement – and ultimately, the crypto community has largely failed to police itself – market participants are typically left to fend for themselves.

In the context of decentralized finance (DeFi), front running refers to the practice of a trader or bot capitalizing on advance knowledge of upcoming transactions in a blockchain network, typically on Ethereum given its outsized role, to make profitable trades.

Here’s a breakdown of how it typically works:

  • Observation: front runners use bots to monitor the pool of unconfirmed transactions (known as the mempool*) in a blockchain network. They look for large transactions that will significantly impact the price of a cryptocurrency.
  • Prediction: once a potentially profitable transaction is identified, front runners predict how this transaction will affect the market. For example, a large buy order could increase the price of a cryptocurrency.
  • Action: before the original large transaction is confirmed, the front runner quickly submits their own transaction with a higher gas fee. This higher fee incentivizes miners to prioritize and process the front runner’s transaction first.
  • Profit realization: the front runner’s transaction, processed before the large transaction, capitalizes on the anticipated price movement. For instance, they might buy a cryptocurrency before a large buy order is processed, expecting its price to increase. They then sell it at the higher price after the large transaction has influenced the market.

This practice is controversial and considered unethical by many in the crypto community. It exploits the transparent nature of blockchain transactions and can lead to market manipulation. Efforts to mitigate front running in DeFi include the development of more sophisticated transaction ordering mechanisms and privacy-enhancing technologies.

So what is a sandwich attack? This is a specific type of front running that involves placing not just one but two transactions around a large pending transaction, in order to profit from the price movement it causes. Here’s how it works:

  • First attacker transaction: the attacker spots a large trade (e.g., a buy order) in the mempool.* They then place a similar buy order just before the victim’s transaction executes, increasing the price of the asset.
  • Victim’s transaction: the large order by the victim gets executed at the now-inflated price.
  • Second attacker transaction: the attacker immediately sells the asset at this inflated price, profiting from the price difference caused by the victim’s large order.

So the attacker takes advantage of knowing a victim’s trade details in advance and manipulates the market price to their benefit, both before and after the victim’s transaction. This can lead to a worse trade outcome for the victim because of a phenomenon called “slippage” – the variance between the anticipated and executed prices of an order due to crypto’s inherent volatility when there are low trading volumes.

Ways to avoid being front run

There are several strategies and practices that can help users avoid becoming victims of front running and sandwich attacks in the DeFi space:

Slippage tolerance: setting a low slippage tolerance in decentralized exchanges (DEXes) can prevent your transaction from being executed if the price impact is too high, which is often the case in sandwich attacks.

Private transactions: some platforms offer private transaction services, where details of your transaction are not made public until they are executed. This prevents potential attackers from seeing and exploiting your transaction in advance.

Smaller transactions: large transactions are more likely to be targeted by front runners and sandwich attackers. Splitting a large transaction into smaller ones can reduce visibility and attractiveness to attackers.

Limit orders: using limit orders instead of market orders allows you to specify the maximum price you’re willing to pay or the minimum price you’re willing to accept. This can prevent buying at inflated prices due to front running.

Transaction batching: some services offer transaction batching, where multiple transactions are combined and executed together. This can obfuscate individual transaction details, making it harder for attackers to target specific trades.

Time of execution: executing transactions during less active hours can reduce the likelihood of being targeted, as there are fewer transactions in the mempool for attackers to monitor.

Flashbots: with Ethereum, using Flashbots (a system for miners and traders to directly negotiate transaction inclusion and ordering) via the wallet’s RPC settings can mitigate the risk of being front run.

DEX aggregators: using DEX aggregators such as CoW Swap can help, as they split your transaction across multiple DEXes, reducing the impact of your trade on any single liquidity pool and making it harder for attackers to profit from sandwich attacks.

Upgraded protocols: some DeFi protocols are implementing solutions to mitigate these risks, such as using different transaction processing mechanisms that are less susceptible to front running.

Constant vigilance: ultimately, staying informed about the latest security practices and being aware of the risks inherent in DeFi trading is crucial.

It’s important to remember that while these strategies can reduce the risk of being front run or sandwich attacked, they can’t eliminate it entirely. Always exercise caution and stay updated on best practices in the rapidly evolving DeFi landscape.

* A blockchain’s mempool (short for “memory pool”) functions as a temporary storage area for pending transactions, facilitating transaction validation, preventing double-spending, and enabling nodes to choose transactions for inclusion in mined blocks based on fees, which contributes to blockchain integrity and efficiency.

Comments

All Comments

Recommended for you

  • Ledger Confirms Unauthorized Hardware Implant in Devices, Losses May Exceed $86 Million

    On October 11, Cointelegraph reported that hardware wallet manufacturer Ledger confirmed the presence of unauthorized hardware implants in the devices of an affected user. The incident involves losses related to devices purchased from its Southeast Asian distributor, CryptoBilis. Investigator Specter estimates that the losses may exceed $86 million, involving Bitcoin, Ethereum, and Tron. Ledger stated that it is in contact with the affected users; CryptoBilis has confirmed the suspension of all hardware wallet inventory sales until the investigation is complete. Ledger claims that the incident appears to be limited to this single distributor and its market, and that its own infrastructure, systems, and services have not been compromised. The company has not yet confirmed the number of affected customers or the total amount of losses. Ledger advises users who have not initialized their devices to refrain from doing so, while those who have already initialized their devices may consider transferring their assets to a new signer using a new mnemonic.

  • Anthropic Model Automatically Submits False Leads to Philadelphia Police

    On October 11, according to CCTV International News, the AI model 'Claude Haiku 4.5' from Anthropic automatically accessed the Philadelphia Police Department's webpage for unsolved homicide tips in July this year, filling out a form claiming to have 'potential information related to the case' but did not provide a name or contact information. The form was subsequently marked as spam by the police and did not trigger an investigation. Anthropic released a report on October 9 disclosing the incident and notified the Philadelphia police in advance. The police stated they were previously unaware of the situation, deemed it 'unacceptable,' and requested that technology companies take necessary measures to prevent their AI systems from submitting false information to law enforcement.

  • Industrial Fulian: US International Trade Commission Initiates 337 Investigation Against Company and Subsidiary

    On October 11, Industrial Fulian announced that it was informed the US International Trade Commission officially launched a 337 investigation on October 9 local time, regarding patent infringement claims made by Vicor Corporation. Vicor accuses the company and its subsidiary of infringing on a patent for a 'vertical power supply system.' After an internal review, the company stated that the products involved in this investigation are currently in the internal validation and evaluation stage, and this investigation does not have a substantial impact on the company's current production, operations, or performance.

  • CFTC Issues Two Proposals Clarifying Prediction Markets as Derivatives, Excluding Casino Gambling

    On October 11, Cointelegraph reported that the U.S. Commodity Futures Trading Commission (CFTC) has released two proposals to clarify its regulatory authority over prediction markets. The first proposal defines event contracts related to sports, politics, culture, and weather as 'swaps' products under federal law. CFTC Chairman Michael Selig stated that these products fall under the category of commodity derivatives as defined by the Commodity Exchange Act, and are fully within the exclusive jurisdiction of the CFTC. The second proposal establishes boundaries, explicitly stating that traditional casino-style gambling products—including sports betting and casino games—do not fall within the definition of 'swaps' and are not considered derivatives. This move comes in the context of prediction market operators like Kalshi and Polymarket facing joint lawsuits from multiple states, accused of operating illegal gambling businesses; the CFTC is counter-suing and issuing new regulations in an attempt to clarify the regulatory boundaries between federal and state authorities, paving the way for a potential Supreme Court ruling.

  • Houthi Forces Warn Airlines, Staff, and Passengers Again

    On October 11, the Houthi forces in Yemen issued another warning to airlines, staff, and passengers, advising them not to use airports within Saudi Arabia.

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.

  • BTC Surpasses $83,000

    Market data shows that BTC has surpassed $83,000, currently priced at $83,020.19, with a 24-hour decline of 0.2%. The market is experiencing significant fluctuations, so please ensure proper risk management.