Sandwich attacks and the limits of private routing: what THORChain does differently
THORChain offers an interesting case study: its swap-ordering mechanism has operated for years, making conventional sandwich attacks at the protocol level economically unviable while protecting more than 1.1 million unique wallets that have swapped on the network.
Ask a DeFi user about sandwich attacks today and most of them probably won’t be too concerned. They have good reason to think so as most wallets now use private routing while the number of sandwich attacks has collapsed.
However, this overlooks one important point. Private routing is ultimately a fixed layered on top of a problem that still exists at the protocol level. And that fix has already shown cracks, from data leaks to attacks executed through private channels, which means that part of the problem has simply moved from the public mempool to private infrastructure.
Even the Ethereum Foundation is now exploring ways to address toxic MEV directly at the protocol level. THORChain offers an interesting case study: its swap-ordering mechanism has operated for years, making conventional sandwich attacks at the protocol level economically unviable while protecting more than 1.1 million unique wallets that have swapped on the network.
Sandwich attacks, a “market” in decline but still extracting.
On Ethereum, the share of blocks containing at least one sandwich trade ran near two thirds through 2024. By mid-2026, it sits closer to one fifth.
EigenPhi tracked monthly sandwich extraction falling from nearly $10 million in late 2024 to around $2.5 million by October 2025, with the average attack clearing just over $3. At that level, the gas and priority fees needed to win a position can exceed what the attack returns, and close to 30% of active bots lost money over the period. What followed was a consolidation into a handful of operators, with jaredfromsubway.eth alone accounting for roughly 70% to 85% of Ethereum sandwich-related priority fee spending by mid-2026 (Greenfield Capital, August 2026).
Despite the decline, the sector remains extremely active: sandwiching still represents 35% to 51% of MEV-related priority fees, while the number of wallets being sandwiched on Ethereum remains above 12,000 per week.
More interestingly, we could assume that sandwich attacks mainly target volatile assets, but the data shows a different picture. In late 2025, EigenPhi reported that roughly a quarter of attacks involved ETH, BTC wrappers and LST pairs, while around 12% involved stablecoins. This has changed further in 2026, with stablecoins now representing more than 50% of activity and major assets and their wrappers accounting for around 15%.
The pattern observed on Ethereum is also visible on other chains. BNB Chain experienced a net decline in the number of sandwich attacks following the introduction of stronger MEV protection at the wallet level. But as activity resumes across the broader market, the share of attacks also starts to increase again. On Solana, sandwich activity fell from more than 15,000 attacks per day to roughly 1,000 between February and June 2025, before climbing back toward 5,000 per day during summer 2026.
The fix moved the attack
There are several reasons that can explain this decline, including the end of the memecoin mania, lower trading activity across the board, and the Fusaka upgrade, which significantly reduced transaction fees. However, there is one trend that cannot be ignored: order flow leaving the public mempool.
Indeed, private order flow reached roughly 92% of Ethereum DEX volume by August 2026, while private transactions represented closer to 30% of broader Ethereum activity only two years earlier. Part of this migration came from users themselves, moving toward solutions such as CoW Swap or manually adding a defensive layer on top of their transactions. But a large part also came directly from the trading infrastructure, with MetaMask, OKX Wallet, Uniswap Wallet and several major BNB Chain wallets taking decisive steps to protect users from sandwich attacks by default.
However, what can be seen as a solution is ultimately a fix that introduces another layer of trust and risk. In April 2023, Flashbots disclosed a flaw in its Protect infrastructure that inadvertently exposed metadata from pending private transactions for a week. A study led by Mancino and Rezzoli later identified 2,932 sandwiches involving transactions that were not observed in the public mempool across two months in late 2024, with roughly 65% traced to a single operator. On October 22, 2025, Jito banned 15 validators linked to sandwich activity after researchers documented multi-slot attacks affecting roughly 222,000 victims and extracting 529,000 SOL over a year.
More recently, in March 2026, CoW Protocol investigated evidence that a transaction submitted through a private RPC may have leaked into the public mempool before inclusion, potentially enabling significant MEV extraction around a $50 million swap.
This leads to an obvious conclusion: the fix is ultimately a stack of intermediaries sitting on top of a base protocol that still permits the attack. In June 2026, the Ethereum Foundation’s chief strategy advisor described toxic MEV as a structural threat to network neutrality and pointed to reducing the ecosystem’s reliance on private order flow as part of the solution. In other words, the longer-term objective is to remove, or at least significantly reduce, the ability to sandwich directly at the protocol level rather than simply hiding transactions from public view.
And that is exactly where THORChain becomes a useful case study. THORChain settles native cross-chain swaps between assets such as BTC, ETH, USDT, USDC, TRX and, soon, XMR without relying on wrapped tokens or external bridges. And all of these trades can happen without sandwich risk, because the way swaps are ordered at the protocol level prevents an attacker from profitably placing one transaction before a victim and another immediately after.
Ordering that can't be bought
THORChain's original design: ordering by slip-fee
A sandwich needs three things in sequence: the attacker's buy, the victim's trade, and the attacker's sell. On Ethereum, that sequence can be purchased because priority fees determine transaction position.
THORChain has never relied on a priority fee auction. Swaps are collected into a queue, scored and sorted before execution, so their position is determined by the economics of the trade itself.
What decides that position is the liquidity fee. THORChain charges a slip-based fee calculated from the size of the trade relative to the pool depth it consumes. It scales with the square of the trade, so a swap twice as large pays roughly four times as much, and the fee accrues to the pool rather than to a block producer.
At the end of each block, queued swaps are scored on that fee and sorted from highest to lowest. An attacker front-running a targeted swap therefore needs a first leg large enough to rank ahead of it and a second leg small enough to rank below it. Selling back less than they bought means sitting on inventory, and both legs pay the slip fee, sized according to the targeted trade rather than the expected profit.
The combination of fee-based ordering and the slip-based fee is what made sandwich attacks unprofitable, but it came with a trade-off: the quadratic curve can quickly become expensive, which pushed the protocol to rework how swaps execute while keeping the protection intact.
Note: Anyone willing to dig further into the math can check this example and the relevant documentation.
Fee logic has changed but protection still holds
Streaming swaps were the answer. A large order gets split into smaller sub-swaps, executed a few blocks apart with arbitrageurs rebalancing the pool in between. By doing so, the slip-fee drops by roughly (n-1)/n, where n is the number of sub-swaps. That left pools earning less, which is why a minimum fee was introduced a few months after. It currently sits at 10 basis points, charged on every sub-swap.
None of these changes touched the underlying logic. The sub-swaps are still scored based on the liquidity fee and executed from highest to lowest. Streaming swaps only makes things harder for an attacker, because sandwiching a full order now means front-running and back-running every sub-swap in turn.
Streaming swaps also shrinks the potential value to extract. Sub-swaps exist to limit pool impact, and the protocol enforces a floor on how thin they get. With the current setting, a fully streamed order moves the pool by roughly 5 bps per slice.
The maths then become relatively straightforward. To sandwich a trade, the attacker has to successfully position trades before and after each sub-swap, pay 10 bps per leg and keep a part in inventory to extract around 5 bps of price movement. The profitability simply doesn’t hold.
Swappers should remain cautious, no matter the protection
Private routing has clearly reduced the visible sandwich attack surface but it remains a fix layered on top of a base protocol where the attack is still possible. And as the Flashbots, Jito and CoW cases show, the protections are not absolute.
This is also why the Ethereum Foundation is now looking at toxic MEV at the protocol level rather than relying entirely on private routing. And considering that the assets being targeted are mainly the ones users actually move at scale, including stablecoins, ETH and BTC-related assets, it is worth looking at alternatives in the meantime.
THORChain addressed this problem years ago at the protocol level and offers a robust anti-sandwich mechanism where protection comes from the way swaps are ordered. For users looking to reduce the risk of receiving less value than expected during a swap, THORChain is worth considering.