BestChange News
Best Change news

What is a sandwich attack and how does it work

Advanced Hype Crypto for newbies Crypto security
With the development of DeFi (decentralized finance), new methods of market manipulation have emerged in the crypto industry. One of the most common is the so-called sandwich attack — a scheme in which attackers profit from other users’ trades even before they are confirmed on the blockchain.
A sandwich attack is a type of MEV* (Maximal Extractable Value) strategy in which network participants profit by changing the order of transactions. Users of decentralized exchanges (DEXs) executing large trades are most often the victims of sandwich attacks.
* MEV (Maximal Extractable Value) — additional profit that validators, miners, or specialized bots can earn by changing the order of transactions on a blockchain. For example, a bot may detect a large order to buy a token (a digital asset on the blockchain), execute its own trade before the user, and profit from the resulting price change.
Sandwich attacks became especially widespread after the DeFi boom* in 2020, when platforms such as Uniswap gained popularity. However, Ethereum co-founder Vitalik Buterin had warned about the risks of such manipulation several years earlier.
* The DeFi (decentralized finance) boom was a period of rapid growth in decentralized financial services, during which users began moving from traditional crypto exchanges and financial platforms to blockchain protocols that operate without intermediaries. The key feature of this period was that users gained the ability to:
  • exchange cryptocurrencies without centralized exchanges;
  • borrow and lend crypto assets;
  • earn interest on stored assets;
  • profit from providing liquidity;
  • participate in governing crypto projects through tokens (digital assets on the blockchain).
It was in 2020 that DeFi evolved from an experimental niche into a полноценный sector of the crypto market. The total value locked (TVL — Total Value Locked) in DeFi protocols increased from approximately $1 billion to more than $15 billion during 2020.

Why decentralized exchanges are vulnerable to sandwich attacks

The main reason sandwich attacks exist is the AMM (Automated Market Maker)* model used by most decentralized exchanges.
* AMM (Automated Market Maker) — a mechanism used by decentralized exchanges in which cryptocurrency prices are determined automatically within a liquidity pool. Instead of an order book, as on traditional exchanges, AMMs rely on algorithms and token reserves (digital assets on the blockchain). The more actively users buy a cryptocurrency, the higher its price becomes within the pool.
Unlike traditional platforms with order books, AMM-based exchanges use liquidity pools and automatically adjust the prices of digital assets (tokens) based on supply and demand. If a user buys a large amount of an asset, its price within the pool rises even before the trade is completed.
Attackers exploit exactly this effect during sandwich attacks.

How a sandwich attack works

A sandwich attack consists of three main stages:

1. Detecting a large transaction

First, MEV bots (automated programs designed to extract maximal extractable value) monitor the mempool (the queue of unconfirmed transactions) on Ethereum and other blockchains. The bots search for large orders that could significantly affect a token’s price (a digital asset on the blockchain).

2. Front-running the trade

After detecting a suitable transaction, the attacker submits their own transaction to buy the same asset while offering a higher network fee. As a result, the attacker’s operation is included in the block before the victim’s trade. By the time the user’s order is executed, the token’s price (digital asset on the blockchain) has already increased.

3. Selling at an inflated price

Immediately after the victim’s transaction is completed, the attacker sells the purchased asset at a higher price and locks in the profit. As a result, the legitimate user’s transaction becomes “sandwiched” between two operations performed by the attacker — hence the term “sandwich attack.”

Why sandwich attacks are possible

One of the reasons sandwich attacks have become widespread is Ethereum’s public mempool (the queue of unconfirmed transactions), where pending transactions are visible to all network participants.
Another factor is the transaction prioritization mechanism. After Ethereum transitioned to the Proof-of-Stake consensus mechanism (“proof of stake”), validators* gained the ability to determine the order of operations within a block. Usually, transactions offering higher fees are confirmed first.
* Validators are participants in a blockchain network who verify transactions, confirm their authenticity, and add new blocks to the blockchain. In simple terms, they ensure that network operations follow the rules and receive cryptocurrency rewards for this work.
MEV bots (automated programs for extracting maximal extractable value) exploit this system by increasing transaction fees and “overtaking” regular users’ trades.

Why sandwich attacks are dangerous

Experts believe sandwich attacks harm not only individual traders but also the entire DeFi (decentralized finance) ecosystem.
Main risks include:
  • artificially increased volatility*;
  • poorer trade execution quality;
  • growing financial losses for traders;
  • declining trust in decentralized exchanges.
* Volatility is a measure of how strongly an asset’s price changes over a certain period of time. High volatility means sharp price swings in both directions.
Low-liquidity cryptocurrencies* and small-cap altcoins (alternative cryptocurrencies) are considered the most vulnerable because even relatively small trades can drastically affect their price.
* A low-liquidity cryptocurrency is a cryptocurrency with low trading volume and a limited number of buyers and sellers. Due to low liquidity, even relatively small trades can sharply change the price of such an asset, making it especially vulnerable to sandwich attacks and other forms of market manipulation.

How to protect yourself from sandwich attacks

Completely eliminating the risk of sandwich attacks is difficult, but several methods can reduce potential losses.

Limiting slippage

One of the most effective methods is setting a slippage* limit.
* Slippage is the difference between the expected price of an asset at the moment a trade is submitted and the actual execution price. It usually occurs because of high volatility or insufficient market liquidity.
If the asset price changes beyond the specified threshold, the trade will automatically fail. This helps users avoid purchasing cryptocurrency at an artificially inflated price.

Using private relays

Professional traders use Flashbots (tools designed to reduce risks associated with maximal extractable value exploitation) and other solutions that allow transactions to be sent directly to validators without passing through the public mempool (the queue of unconfirmed transactions).
In this case, attackers simply cannot see the transaction before it is confirmed.

Notable cases of sandwich attacks

Attacks on Four.Meme

In February and March 2025, the platform Four.Meme suffered two sandwich attacks. According to analysts, the total damage exceeded $300,000. The incidents once again demonstrated that even modern projects remain vulnerable to sandwich attacks.

$4 Million profit in one day

A trader using the address “jaredfromsubway.eth” became widely known after earning around $4 million in a single day through a series of successful sandwich attacks on the Ethereum network. His activity became so massive that fee revenues temporarily surpassed those of some major crypto services.

Uniswap user losses

One of the most high-profile cases occurred in March 2025, when a Uniswap user exchanged stablecoins (stable cryptocurrencies) Tether and USDC worth approximately $220,000 but received assets worth only about $5,200 after execution. The loss exceeded $200,000 and became one of the largest examples of the consequences of sandwich attacks for ordinary DeFi (decentralized finance) users.
Exchanger Rate Min. Max. Reviews
Open this exchange direction on the monitoring website