Cointime

Download App
iOS & Android

The Most Common Types of MEV and Protection From Toxic Strategies

Validated Project

MEV can be an effective mechanism for making profits in DeFi, but often, profits come at the expense of other users.

MEV refers to the maximal extractable value generated from reordering transactions within a block. While MEV originally stood for “miner extractable value,” after last year’s Ethereum Merge, which replaced miners with validators, the term was changed to “maximal extractable value.”

MEV opportunities

Block builders benefit from “priority” fees users are willing to pay to speed up their transactions. Meanwhile, so-called searchers can detect potentially lucrative transactions that could impact a crypto asset’s value, bringing them a profit. Then, they pay extra in order to slip in their transactions early in a block. Potentially vulnerable transactions could be detected in the mempool, the node’s holding area for submitted and unconfirmed transactions before they are added to a block. Those pending transactions, especially large ones that can potentially move market prices and create arbitrage opportunities, can become a target for malicious searchers.

On the one hand, MEV is an integral part of DeFi’s market environment and could be used for healthy profit strategies, as long as other users are not harmed. At the same time, when searchers take advantage of MEV opportunities in a toxic way, it can lead to other users’ losses, as well as increased transaction costs and other negative consequences.

Overall, MEV scenarios could be divided into those based on the source of extraction (DEX arbitrage, liquidation) and on the type of implementation (generalized front-running, front-running, back-running and sandwich attacks).

MEV sources

DEX arbitrage

The price of the same crypto asset can vary across different DEXes, and an arbitrageur, while simultaneously buying and selling on various markets, profits from the price difference. Basically, arbitrageurs are simply relying on natural price fluctuations. Meanwhile, front-running also happens in arbitrage. For instance, a searcher bot can find a pending transaction and insert its own transaction in front of it to extract the value offered by that arbitrage opportunity. A searcher can also create an artificial arbitrage opportunity by reordering transactions on a liquidity pair before a back-run (described below).

Liquidation

When a user takes out a collateralized loan, and, due to crypto volatility, the collateral’s value later falls below a specified figure, the liquidation of the loan takes place: the smart contract sells the collateral to cover the debt and allows any user to buy it. A MEV opportunity occurs when such a transaction is identified. A searcher’s liquidation transaction is inserted in the block before all other transactions, enabling the searcher to buy the liquidated collateral at the most advantageous price.

Also, when a trader tries to re-collateralize their loan, the transaction can be censored in the process of adding funds. At the same time, the liquidation might still continue allowing searchers to buy the original collateral at a discount.

MEV types

Generalized front-running

Searchers use mempool-tracking bots to identify profitable transactions. An attacker then replaces the address of a potentially profitable transaction with their address and checks whether it is lucrative by running the transaction locally. If the result is favorable, the transaction with the replaced address will front-run the original transaction by setting a higher gas price.

Front-running

Front-running occurs when a transaction similar to that made by a user is placed directly before it in a queue to be filled. By doing that, the front-runner impacts the prices of the swapped assets, making a profit at the expense of the victim, who ends up receiving a lower amount of the target token than expected.

Back-running

Conversely, back-running occurs when a transaction is inserted immediately after the target transaction to make a profit from the market fluctuations generated by a large transaction. Although, technically, back-running does not affect other traders, an active use of this tactic can substantially increase transaction fees.

Sandwich attacks

One common form of front-running/back-running is a sandwich attack in which orders are placed before and after a target price-changing transaction, thus taking advantage of price pressure on both sides. The front-run transaction causes the movement of value. The victim’s transaction is executed at a new, less favorable price, and the final transaction captures the price difference, leaving the victim’s transaction front-run and back-run as if in a sandwich.

MEV protection with 1inch

While arbitrage and liquidations are generally neutral MEVs, traders can lose the entire amount of slippage tolerance as a result of front-running and sandwich attacks since users’ trades settle at a higher price than expected. 1inch makes sure that traders avoid the risk of being front-run or sandwiched.

In Fusion mode: Fusion swaps are performed by resolvers, with whom transactions are directly matched and then placed in a bundle with other orders to be included in the block. Bots cannot attack Fusion swaps since they are combined with other transactions.

In Legacy mode: Legacy mode does not involve resolvers and the transaction execution process follows a regular scenario. But the 1inch Wallet has long been featuring an opportunity for users to create and sign a transaction without broadcasting it to the mempool, where it could be visible to bots. In late 2022, 1inch’s frontrunning protection was stepped up by the introduction of the RabbitHole feature. With the 1inch RabbitHole, all swap transactions are sent directly to validators, bypassing mempools where sandwich bots could attack them.

Read more: https://medium.com/1inch-network/the-most-common-types-of-mev-and-protection-from-toxic-strategies-53ec43202e12

Comments

All Comments

Recommended for you

  • ETH Trading Volume on Hyperliquid Exceeds BTC, Reaching Approximately $1.1 Billion in 24 Hours

    On October 11, the trading volume of ETH on the Hyperliquid platform reached approximately $1.1 billion in the last 24 hours, surpassing BTC's $805 million. Market analysts believe that the increase in ETH trading volume is related to suspected exploitation of the PaperTrade mechanism. Earlier today, reports indicated that PaperTrade was allegedly manipulated by two addresses, revealing a significant vulnerability in the protocol: the two wallet addresses executed trades on Hyperliquid with a single transaction size of about $20 million, causing ETH prices to fluctuate by approximately 10 to 20 basis points, and establishing long positions with a notional value of several hundred million dollars on PaperTrade.

  • Ledger Confirms Unauthorized Hardware Implant in Devices, Losses May Exceed $86 Million

    On October 11, Cointelegraph reported that hardware wallet manufacturer Ledger confirmed the presence of unauthorized hardware implants in the devices of an affected user. The incident involves losses related to devices purchased from its Southeast Asian distributor, CryptoBilis. Investigator Specter estimates that the losses may exceed $86 million, involving Bitcoin, Ethereum, and Tron. Ledger stated that it is in contact with the affected users; CryptoBilis has confirmed the suspension of all hardware wallet inventory sales until the investigation is complete. Ledger claims that the incident appears to be limited to this single distributor and its market, and that its own infrastructure, systems, and services have not been compromised. The company has not yet confirmed the number of affected customers or the total amount of losses. Ledger advises users who have not initialized their devices to refrain from doing so, while those who have already initialized their devices may consider transferring their assets to a new signer using a new mnemonic.

  • Anthropic Model Automatically Submits False Leads to Philadelphia Police

    On October 11, according to CCTV International News, the AI model 'Claude Haiku 4.5' from Anthropic automatically accessed the Philadelphia Police Department's webpage for unsolved homicide tips in July this year, filling out a form claiming to have 'potential information related to the case' but did not provide a name or contact information. The form was subsequently marked as spam by the police and did not trigger an investigation. Anthropic released a report on October 9 disclosing the incident and notified the Philadelphia police in advance. The police stated they were previously unaware of the situation, deemed it 'unacceptable,' and requested that technology companies take necessary measures to prevent their AI systems from submitting false information to law enforcement.

  • Industrial Fulian: US International Trade Commission Initiates 337 Investigation Against Company and Subsidiary

    On October 11, Industrial Fulian announced that it was informed the US International Trade Commission officially launched a 337 investigation on October 9 local time, regarding patent infringement claims made by Vicor Corporation. Vicor accuses the company and its subsidiary of infringing on a patent for a 'vertical power supply system.' After an internal review, the company stated that the products involved in this investigation are currently in the internal validation and evaluation stage, and this investigation does not have a substantial impact on the company's current production, operations, or performance.

  • CFTC Issues Two Proposals Clarifying Prediction Markets as Derivatives, Excluding Casino Gambling

    On October 11, Cointelegraph reported that the U.S. Commodity Futures Trading Commission (CFTC) has released two proposals to clarify its regulatory authority over prediction markets. The first proposal defines event contracts related to sports, politics, culture, and weather as 'swaps' products under federal law. CFTC Chairman Michael Selig stated that these products fall under the category of commodity derivatives as defined by the Commodity Exchange Act, and are fully within the exclusive jurisdiction of the CFTC. The second proposal establishes boundaries, explicitly stating that traditional casino-style gambling products—including sports betting and casino games—do not fall within the definition of 'swaps' and are not considered derivatives. This move comes in the context of prediction market operators like Kalshi and Polymarket facing joint lawsuits from multiple states, accused of operating illegal gambling businesses; the CFTC is counter-suing and issuing new regulations in an attempt to clarify the regulatory boundaries between federal and state authorities, paving the way for a potential Supreme Court ruling.

  • Houthi Forces Warn Airlines, Staff, and Passengers Again

    On October 11, the Houthi forces in Yemen issued another warning to airlines, staff, and passengers, advising them not to use airports within Saudi Arabia.

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.