Sandwich attacks: what they are and how to avoid getting eaten
Show how sandwich attacks work step-by-step and teach the practical defenses every on-chain trader should use.
Lesson path
Crypto and DeFi
On-Chain Basics
Pass the check before saving this lesson.
Pass the check to unlock nextOpen track mapChange starting pointToday's tiny win: make one idea click.
Show how sandwich attacks work step-by-step and teach the practical defenses every on-chain trader should use.
You're the meat in the middle
A sandwich attack is the MEV form most retail traders quietly fund without ever realizing it. It works in three steps. Step one: you submit a swap on a DEX. Your transaction lands in the public mempool, visible to every bot in the world. Step two: a bot sees your pending swap, calculates how much it will move the price in the pool, and submits its own buy transaction with a higher gas tip so it confirms first. Step three: your transaction now executes at a worse price because the bot pushed the pool. Right after yours confirms, the bot sells what it just bought, capturing the price difference. You're the bread on both sides. They're the filling.
How much does this cost? Depends on the size of your trade and the depth of the pool. On a small liquid pair like a major stablecoin pair, the loss might be cents. On a low-liquidity token or a larger trade, the loss can be 1 to 5 percent or more. Over a year of active swapping, this compounds into real money. And because most wallets default to generous slippage tolerances (sometimes 1 to 3 percent), the bots have room to operate inside what looks like normal slippage.
Three defenses that actually work. One — tighten your slippage. If a sandwich would require more than your slippage allows, your transaction reverts and you don't get sandwiched. You'll pay gas on the failed transaction but not the sandwich tax. Two — use a private RPC for large swaps. These submit your transaction to validators directly, bypassing the public mempool. Bots can't sandwich what they can't see. Most major wallets let you set a custom RPC. Three — for big trades, prefer batch-auction or aggregator routes that bundle multiple users into one settlement at a uniform price. They're harder to sandwich by design.
One last point. Not every bad fill is a sandwich. Sometimes the price genuinely moved while your transaction was pending. Sometimes liquidity shifted. Check the block your swap landed in on Etherscan — if you see a buy from an unknown wallet right before yours and a sell from the same wallet right after, that's the textbook sandwich pattern. If you only see your trade in the block, the slippage came from normal volatility.
Recap: sandwich = bot buys, you trade at worse price, bot sells. Defenses: tighten slippage, use a private RPC for large swaps, prefer batch-auction routes for big trades. Check Etherscan after suspicious fills.
Knowledge check
Answer before moving on.
1. What's the single most effective free thing you can do to avoid sandwich attacks on small trades?
2. You suspect your last swap got sandwiched. How do you check?
3. When does a private RPC help you most?
Pass the check before saving.
Use the knowledge check first. After you pass it, this card turns into the save-and-continue handoff.