High Severity
MEV / Mempool

MEV and Sandwich Attacks

Every transaction you submit to a public mempool is visible before it's confirmed. MEV bots scan pending transactions, identify profitable opportunities, and reorder or insert their own transactions to extract value — often at your users' expense.

How a sandwich attack works

1

Bot spots your swap in the mempool

Your transaction to swap 10 ETH for USDC on Uniswap is broadcast but not yet confirmed. The bot sees it and calculates the expected price impact.

2

Front-run: bot buys before you

The bot submits its own buy transaction with a higher gas price, ensuring it's mined first. This pushes the price up.

3

Your transaction executes at a worse price

Your swap goes through at the now-inflated price. You receive fewer tokens than you would have at the original price.

4

Back-run: bot sells immediately after

The bot sells its position right after your transaction, capturing the price difference as profit. You're the filling in the sandwich.

Types of MEV attacks

Attack TypeWho it affectsScale
Sandwich attacksDEX users making large swapsVery high
ArbitrageProtocols with stale prices (neutral — corrects prices)High
LiquidationsBorrowers near their liquidation thresholdHigh
Time-bandit attacksOn-chain randomness or time-sensitive logicLow but growing
Governance front-runningDAO proposals with predictable effectsMedium

Scan for MEV vulnerabilities

Our scanner checks for zero-slippage swap calls, on-chain randomness, spot price reads used for critical logic, and other patterns that make your protocol or users vulnerable to MEV extraction.