Wiki/Sandwich Attacks Step-by-Step: How MEV Bots Exploit Trades
Sandwich Attacks Step-by-Step: How MEV Bots Exploit Trades - Biturai Wiki Knowledge
ADVANCED | BITURAI KNOWLEDGE

Sandwich Attacks Step-by-Step: How MEV Bots Exploit Trades

A sandwich attack is a predatory strategy in decentralized finance where automated bots manipulate transaction order to profit from a user's trade. These bots execute a buy order before the user's swap and a sell order immediately after,

Biturai Knowledge
Biturai Knowledge
Research library
Updated: 6/27/2026
Technically checked

Structure, readability, internal linking, and SEO metadata were automatically checked. This article is continuously updated and is educational content, not financial advice.

Definition

A sandwich attack is a sophisticated and often predatory form of Maximal Extractable Value (MEV) exploitation within decentralized finance (DeFi). It involves an automated bot strategically placing two transactions around a user's pending trade in a decentralized exchange (DEX). The user's transaction is effectively "sandwiched" between the attacker's buy and sell orders, allowing the attacker to profit from the price impact generated by the victim's trade. This manipulation results in the victim receiving a significantly worse execution price for their swap.

A sandwich attack is an MEV exploit where an attacker places a buy order before a user's pending trade and a sell order after it, profiting from the price movement caused by the user's transaction and leaving the victim with a less favorable trade outcome.

Key Takeaway

The core principle of a sandwich attack is the exploitation of predictable price movements caused by a user's large trade on an Automated Market Maker (AMM). By front-running with a buy and back-running with a sell, MEV bots capitalize on the temporary price shift, effectively extracting value from the victim's transaction. This mechanism highlights a fundamental vulnerability in the transparent and ordered nature of blockchain transaction processing, particularly in DeFi environments where transaction ordering can be influenced.

Mechanics

The process of a sandwich attack unfolds in a precise, multi-step sequence, leveraging the public visibility of pending transactions in a blockchain's mempool. When a user initiates a swap on a DEX, their transaction first enters the mempool, a waiting area for unconfirmed transactions. MEV bots constantly monitor this mempool, scanning for large or impactful trades that could significantly alter asset prices within a liquidity pool.

Upon identifying a suitable target—typically a large swap in a low-liquidity pool, which promises a greater price impact—the bot executes its strategy. First, it places a front-running buy order for the asset the user intends to buy. This buy order is submitted with a higher gas fee to ensure it is processed before the victim's transaction within the same block. This initial buy pushes the price of the asset upwards, creating an artificial price increase before the victim's trade is confirmed. Subsequently, the victim's transaction executes at this artificially inflated price, meaning they receive fewer tokens than they would have under normal market conditions. Immediately after the victim's transaction is confirmed, the bot executes a back-running sell order for the tokens it just acquired. This sell order capitalizes on the higher price established by both the bot's front-run and the victim's subsequent trade, locking in a profit for the attacker. The entire sequence occurs within a single block, making it a rapid and efficient exploit.

Trading Relevance

Sandwich attacks are highly relevant for anyone engaging in decentralized trading, as they directly impact the profitability and fairness of swaps on AMM-based DEXs. Traders, especially those executing large orders, are particularly susceptible. The transparency of the mempool, while a core feature of public blockchains, creates this window of opportunity for MEV bots. The impact is most pronounced in liquidity pools with lower total value locked (TVL) or less trading volume, as these environments are more sensitive to large individual trades, leading to greater price slippage.

For instance, a trader attempting to swap a significant amount of ETH for a less liquid altcoin might find their trade "sandwiched." The bot's front-run buy drives up the altcoin's price, causing the trader to receive less altcoin for their ETH. The bot then sells its newly acquired altcoin at the higher price, profiting from the trader's forced slippage. This dynamic means that even if a trader sets a reasonable slippage tolerance, a sandwich attack can still push the final execution price beyond their expectation, effectively costing them a portion of their capital. Understanding this mechanism is essential for traders to assess the true cost of their transactions and to implement strategies to mitigate such risks.

Risks

The primary risk for users targeted by sandwich attacks is financial loss due to unfavorable execution prices. This loss is a direct result of the attacker's manipulation, which artificially inflates the price at which the victim buys or deflates the price at which they sell. Over time, repeated sandwich attacks can significantly erode a trader's capital, especially for active participants in DeFi. The insidious nature of these attacks means that users often don't immediately recognize they've been exploited, as the transaction appears to complete, albeit at a worse-than-expected rate.

Beyond direct financial losses, sandwich attacks contribute to a less efficient and less trustworthy market environment. They introduce an element of unfairness, where sophisticated bots can consistently extract value from ordinary users. This can deter new users from entering DeFi or lead existing users to lose confidence in the integrity of decentralized exchanges. Furthermore, the competition among MEV bots for these opportunities can lead to "gas wars," where bots bid up transaction fees to ensure their orders are included first, driving up costs for all network participants, including the victims of sandwich attacks themselves.

History and Examples

The concept of MEV, including sandwich attacks, gained prominence with the rise of Ethereum and its robust DeFi ecosystem. As AMM-based DEXs like Uniswap became popular, the transparent nature of the mempool and the ability for validators (or miners, historically) to order transactions created fertile ground for these exploits. Early instances of front-running quickly evolved into more complex sandwich strategies as bots became more sophisticated.

A notable example of sandwich attacks involves stablecoin swaps. While stablecoins are designed to maintain a peg to fiat currencies (e.g., 1 USD), even minor deviations can be exploited. Data from EigenPhi indicated that 38% of all sandwich attacks on Ethereum in 2025 targeted stablecoin pools. An attacker might observe a large swap between USDC and USDT, place a buy order for the slightly undervalued stablecoin, let the victim's trade push its price closer to parity (or even slightly above), and then sell for a profit. This demonstrates that even in markets with minimal volatility, the principle of price impact can be exploited. The continuous evolution of MEV strategies means that while the core mechanism remains, the specific targets and methods of execution adapt to market conditions and protocol changes.

Common Misunderstandings

One common misunderstanding is that sandwich attacks are solely a problem for "whales" or extremely large traders. While larger trades in low-liquidity pools are indeed more attractive targets due to their greater price impact, even moderately sized trades can be susceptible, especially in less liquid markets. The profitability for the attacker scales with the price impact, but the fundamental mechanism applies broadly. Another misconception is that setting a low slippage tolerance completely protects a user. While a low slippage tolerance can prevent a trade from executing if the price moves too much, it doesn't prevent the front-running buy from occurring. Instead, it might cause the victim's transaction to fail after the attacker has already profited from their front-run, resulting in a wasted gas fee for the victim.

Furthermore, some users might confuse sandwich attacks with general market volatility or legitimate price discovery. Unlike natural market fluctuations, a sandwich attack is a deliberate, predatory manipulation of transaction order designed to extract value from a specific user's trade. It's not about predicting market trends but about creating a temporary, localized price shift for personal gain. The distinction lies in the intentional insertion of transactions to manipulate the immediate execution environment of another trade, rather than simply reacting to broader market forces.

Summary

Sandwich attacks represent a significant challenge within the DeFi landscape, embodying a sophisticated form of MEV exploitation. By strategically placing buy and sell orders around a user's pending transaction, MEV bots manipulate asset prices to their advantage, leaving the victim with a less favorable trade outcome. This mechanism thrives on the transparency of blockchain mempools and the deterministic ordering of transactions within a block. While particularly prevalent in large trades and low-liquidity pools, including stablecoin swaps, the underlying principle affects all participants in AMM-based DEXs. Understanding these mechanics is essential for traders to navigate DeFi markets effectively, recognize the risks, and consider strategies to mitigate potential losses from such predatory practices. The ongoing evolution of MEV and counter-MEV measures underscores the dynamic nature of blockchain security and market fairness.

OKX · Official Biturai Partner

OKX

Explore the current OKX offering through the official Biturai partner link. Products and availability may vary by country.

Explore OKX

Partner link · Biturai may receive compensation when it is used · not investment advice

OKX

Disclaimer

This article is for informational purposes only. The content does not constitute financial advice, investment recommendation, or solicitation to buy or sell securities or cryptocurrencies. Biturai assumes no liability for the accuracy, completeness, or timeliness of the information. Investment decisions should always be made based on your own research and considering your personal financial situation.

Transparency

Biturai may use AI-assisted tools to research, structure, or update Wiki articles. Editorially reviewed articles are marked separately; all content remains educational and does not replace your own review.