MEV sandwich attacks explained: how bots front-run your swap
An MEV sandwich attack is a type of front-running where a bot places a buy order just before your swap and a sell order just after it, profiting from the price movement your trade causes. The bot "sandwiches" your transaction between its own two trades, forcing you to buy at a worse price.
How the Attack Works in Practice
MEV stands for "Maximal Extractable Value." In a sandwich attack, a bot monitors the public mempool - the waiting room for unconfirmed transactions - for large pending swaps. When it spots yours, it executes a three-step sequence:
- Front-run buy: The bot sends its own buy transaction with a higher gas fee, ensuring it gets processed before yours. This pushes the pool price slightly higher.
- Your swap executes: Your transaction goes through at the elevated price, buying fewer tokens than expected.
- Back-run sell: The bot immediately sells the tokens it just bought, profiting from the price difference. This pushes the price back down.
The bot's profit comes directly from the slippage you experience. The larger your swap relative to the pool's liquidity, the more price impact you cause, and the more profit a sandwich bot can extract.
Why dexs are vulnerable
Unlike centralized exchanges, decentralized exchanges like MilkshakeSwap display all pending transactions publicly in the mempool. Anyone running a node can see exactly what swaps are about to happen. Bots are simply automated programs that scan these transactions and react faster than any human could.
The constant product formula (x*y=k) that governs pools makes this possible. A bot can calculate exactly how much your swap will move the price and place its own orders accordingly. The attack works on any AMM-based DEX, not just MilkshakeSwap.
How much can you lose?
The loss depends on three factors: - Swap size relative to pool liquidity: Larger swaps cause more price impact, creating more profit for bots. - Slippage tolerance you set: A higher tolerance lets the bot push the price further. - Competition among bots: Multiple bots may race to sandwich your trade, sometimes driving the price against you further.
In extreme cases, users have lost 10-20% of a swap's value to sandwich attacks. For small swaps in liquid pools, the loss may be fractions of a percent and barely noticeable.
How to protect yourself
You cannot fully prevent sandwich attacks, but you can reduce your risk significantly.
Use lower slippage tolerance
Set your slippage tolerance as low as your trade can realistically succeed. For most swaps on MilkshakeSwap, 0.5% to 1% is reasonable. If you set 5% or higher, you invite bots to take that entire buffer.
Consider MEV protection rpcs
Some wallet providers and RPC endpoints offer private transaction submission. Instead of broadcasting your swap to the public mempool, the transaction goes directly to a validator who includes it in a block without exposing it to bots. Services like Flashbots, Bloxroute, or Eden Network provide this.
Split Large Swaps
A single large swap is a prime target. Splitting it into several smaller transactions over time makes each one less attractive to bots. The price impact per trade is lower, and bots may not bother with small moves.
Use DEX Aggregators
Aggregators like 1inch or Paraswap split your swap across multiple pools and often include MEV protection features. They can route your trade through private order flows or use techniques like "virtual balance" to hide your true swap size.
Trade during lower activity
Sandwich bots are less active during periods of low network congestion or on less popular token pairs. Trading during off-peak hours can reduce your exposure.
When sandwich attacks fail
Not every attempt succeeds. Bots compete with each other, and if two bots try to sandwich the same trade, they can end up sandwiching each other - a situation called "salad." The bot may also misjudge the pool's liquidity or fail to get its transactions confirmed in time, losing money on gas fees.
Additionally, some pools use mechanisms like fees on transfers or dynamic fees that reduce bot profitability. However, standard Uniswap V2-style pools (which MilkshakeSwap uses) offer no built-in protection.
The Bottom Line
Sandwich attacks are a structural feature of public mempool-based DEXs. They are not hacks - they exploit the transparent, permissionless nature of blockchain transactions. By understanding how they work and adjusting your trading behavior, you can reduce your exposure without giving up the benefits of decentralized swapping.
Not financial advice. milkshakeswap.finance publishes market data and general information about MilkshakeSwap Token. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.