SandwichCheck
MEV fundamentals

What is a sandwich attack?

A sandwich attack is a form of maximal extractable value (MEV) in which an attacker places one trade before a victim’s decentralized-exchange swap and another trade after it.

How the sandwich works

The attacker’s first transaction moves the pool price against the victim. The victim then executes at a worse price, within the slippage tolerance they approved. The attacker’s second transaction reverses the position and may capture the price difference.

  1. Frontrun: the attacker buys before the victim, moving the price.
  2. Victim swap: the victim receives less favorable execution.
  3. Backrun: the attacker sells after the victim and closes the position.
Being adjacent is not enough. Three nearby swaps only become persuasive evidence when their pool, directions, ordering, senders, token flows, and economics form a coherent pattern.

Why swaps become targets

A public pending transaction can reveal the pool, direction, amount, and permitted slippage before it is confirmed. A sufficiently large swap with loose slippage may create room for an attacker to pay transaction fees and still profit.

Possible effects on the victim

How to reduce exposure

Use conservative slippage, avoid unnecessarily large single swaps, compare routes, and consider protected or private transaction submission where available. These measures reduce risk but do not guarantee immunity from every form of MEV.

Check a swapHow detection worksRead the methodology