2 min read

Solana Study Finds Protected Transaction Flows Do Not Stop Sandwich Attacks

Researchers detected 28,042,725 protected-flow sandwich attacks from July 1, 2023, through June 30, 2026, generating an estimated $345.2 million in net profit after fees.

Mentioned assets
Metal tokens pass through branching channels in a clear acrylic model / TokenPost.ai
Metal tokens pass through branching channels in a clear acrylic model / TokenPost.ai

Researchers detected 28,042,725 protected-flow sandwich attacks on Solana over three years, showing that private transaction systems can reduce some front-running exposure without eliminating the attack pattern.

The attacks occurred from July 1, 2023, through June 30, 2026, and involved 8,631 bots retained under the study’s detection criteria. Those criteria required each bot to execute at least 100 sandwich attacks, record profitable results in at least 60% of them and have sandwich activity account for at least 25% of its swaps.

The attackers generated an estimated $383,433,932 in gross profit and $345,185,014 after fees. The figures cover detected attacks that met the study’s methodology and do not represent every possible sandwich attack.

A sandwich attack occurs when a bot trades before and after a user’s swap, moving the pool price against the user before reversing its position. The research examined protected order flow, including private remote procedure calls, local mempools, order-flow auctions and other systems designed to limit public front-running.

The study recorded 30,607 detected protected-flow attacks on Ethereum, 38,567 on Tron and 1,889 on Base. It found no persistent protected-flow sandwich attackers on Arbitrum or Monad.

On Solana, the research identified exposure linked to both validators and applications. Validator-related exposure weakened after 2025, while victims became more concentrated around particular applications. That shift indicates that protection at one point in a transaction’s path may not prevent exposure elsewhere.

Detected Solana attacks were often wider or less tightly positioned than conventional public-mempool sandwiches. Attackers used validators, application-level routing and other transaction-submission infrastructure to reach trades moving through protected systems.

Jupiter Ultra V3 includes Iris, Jupiter Beam, Predictive Execution and Ultra Signaling. Ultra Signaling is an on-chain mechanism that allows proprietary market makers to distinguish Ultra-originated order flow.

The evidence does not show that any single application eliminates sandwich-attack exposure. They show that transaction-routing and application design can materially influence user exposure even when trades are submitted through infrastructure intended to limit front-running.

Loading…