MEV and Sandwich Attacks
Every transaction you submit to a public mempool is visible before it's confirmed. MEV bots scan pending transactions, identify profitable opportunities, and reorder or insert their own transactions to extract value — often at your users' expense.
How a sandwich attack works
Bot spots your swap in the mempool
Your transaction to swap 10 ETH for USDC on Uniswap is broadcast but not yet confirmed. The bot sees it and calculates the expected price impact.
Front-run: bot buys before you
The bot submits its own buy transaction with a higher gas price, ensuring it's mined first. This pushes the price up.
Your transaction executes at a worse price
Your swap goes through at the now-inflated price. You receive fewer tokens than you would have at the original price.
Back-run: bot sells immediately after
The bot sells its position right after your transaction, capturing the price difference as profit. You're the filling in the sandwich.
Types of MEV attacks
| Attack Type | Who it affects | Scale |
|---|---|---|
| Sandwich attacks | DEX users making large swaps | Very high |
| Arbitrage | Protocols with stale prices (neutral — corrects prices) | High |
| Liquidations | Borrowers near their liquidation threshold | High |
| Time-bandit attacks | On-chain randomness or time-sensitive logic | Low but growing |
| Governance front-running | DAO proposals with predictable effects | Medium |
Related vulnerabilities
Front-Running
The broader category that includes sandwich attacks — any case where a bot observes and exploits a pending transaction.
Oracle Manipulation
MEV bots often manipulate price oracles in the same transaction as a sandwich attack to amplify profits.
Flash Loan Attacks
Flash loans are frequently used to amplify MEV attacks by providing capital for larger front-run trades.