Sandwich attacks, explained: how bots eat your swap and how floors stop them

BlazePhoenix Engineering · updated 2026-07-19 · 4 min · written from the deployed bytecode

By Mitra (@Sigmacrit) — anonymous developer of the BlazePhoenix protocol. The code is the résumé.

Abstract in 15 languages · resumo · resumen · 摘要 · 要旨 · ملخص

EnglishA sandwich bot buys right before your swap and sells right after, pocketing your slippage tolerance — the defense is a tight minOut plus floors the CONTRACT enforces per leg, not the frontend.

PortuguêsUm bot sanduíche compra mesmo antes do teu swap e vende logo depois, embolsando a tua tolerância de slippage — a defesa é um minOut apertado mais floors que o CONTRATO impõe por leg, não o frontend.

EspañolUn bot sándwich compra justo antes de tu swap y vende justo después, embolsándose tu tolerancia de slippage — la defensa es un minOut ajustado más floors que el CONTRATO impone por leg, no el frontend.

FrançaisUn bot sandwich achète juste avant votre swap et vend juste après, empochant votre tolérance de slippage — la défense : un minOut serré plus des planchers imposés par le CONTRAT à chaque leg, pas par le frontend.

DeutschEin Sandwich-Bot kauft direkt vor deinem Swap und verkauft direkt danach — er kassiert deine Slippage-Toleranz; die Verteidigung ist ein enges minOut plus Floors, die der VERTRAG pro Leg erzwingt, nicht das Frontend.

РусскийСэндвич-бот покупает прямо перед вашим свопом и продаёт сразу после, забирая ваш допуск проскальзывания — защита: жёсткий minOut плюс полы, которые КОНТРАКТ навязывает на каждом плече, а не фронтенд.

TürkçeSandviç botu takasından hemen önce alır, hemen sonra satar ve kayma toleransını cebine atar — savunma, sıkı bir minOut artı frontend'in değil SÖZLEŞMENİN her bacakta dayattığı tabanlardır.

العربيةيشتري بوت الساندويتش قبل تبديلك مباشرة ويبيع بعده مباشرة جانياً هامش انزلاقك — الدفاع هو minOut ضيق مع أرضيات يفرضها العقد على كل ساق، لا الواجهة.

हिन्दीसैंडविच बॉट आपके स्वैप से ठीक पहले खरीदता और ठीक बाद बेचता है, आपकी स्लिपेज सहनशीलता हड़प लेता है — बचाव है सख्त minOut और वे फ्लोर जो कॉन्ट्रैक्ट हर लेग पर लागू करता है, फ्रंटएंड नहीं।

日本語サンドイッチボットはあなたのスワップ直前に買い、直後に売って、許容スリッページを懐に入れます。防御は厳しめのminOutと、フロントエンドでなくコントラクトが各レッグに強制するフロアです。

中文三明治机器人在你交易前一刻买入、后一刻卖出,把你的滑点容忍度装进口袋——防御是收紧 minOut,加上由合约而非前端在每条腿上强制的下限。

한국어샌드위치 봇은 당신의 스왑 직전에 사고 직후에 팔아 슬리피지 허용치를 챙깁니다 — 방어는 타이트한 minOut과 프런트엔드가 아닌 컨트랙트가 레그마다 강제하는 플로어입니다.

Bahasa IndonesiaBot sandwich membeli tepat sebelum swap Anda dan menjual tepat sesudahnya, mengantongi toleransi slippage Anda — pertahanannya adalah minOut ketat plus floor yang dipaksakan KONTRAK per leg, bukan frontend.

বাংলাস্যান্ডউইচ বট আপনার সোয়াপের ঠিক আগে কেনে আর ঠিক পরে বেচে, আপনার স্লিপেজ সহনশীলতা পকেটে ভরে — প্রতিরক্ষা হলো টাইট minOut এবং প্রতি লেগে কন্ট্রাক্টের বলবৎ করা ফ্লোর, ফ্রন্টএন্ডের নয়।

FilipinoAng sandwich bot ay bumibili bago pa ang swap mo at nagbebenta pagkatapos agad, kinukuha ang slippage tolerance mo — ang depensa ay masikip na minOut at mga floor na ipinapatupad ng KONTRATA kada leg, hindi ng frontend.

Your pending swap is public the moment it enters the mempool. A sandwich bot sees it, pays to be ordered right BEFORE you (buying the token you want, pushing its price up), lets your swap execute at the worse price, then sells right AFTER you — pocketing, almost mechanically, whatever slippage you tolerated. It is the dominant form of MEV (maximal extractable value) against retail, and it is constant.

The bot's profit is bounded by your slippage setting: tolerate 5% and you have posted a 5% bounty. That is why "auto" or double-digit slippage on a liquid pair is an invitation, and why the single best user habit is a TIGHT minOut you actually mean.

What real protection looks like

Frontend-computed protection has a hole: if the site is compromised, your "minimum" can be set to dust. The structural fix is a floor the CONTRACT derives for itself at execution: BlazePhoenix's Router recomputes the minimum on-chain (the Iron Law Φ — hard-clamped so it can never fall below 75% of plan) and honours your minOut only when it is TIGHTER. And because a route-level floor can be gamed by sacrificing one leg, every individual leg must also deliver ≥75% of plan or the whole transaction reverts — a sandwich must now beat every leg at once.

Your part stays simple: half-a-percent slippage on deep pairs, private RPCs if you trade size, and venues where the floor lives in bytecode, not in a web page.

Do not trust this page — reproduce it

Every claim above is checkable against the chain. Start here:

cast call 0x2a779f9Be49aac57495A8B6467Cc325a8a47Eb9f "LEG_FLOOR_BPS()(uint256)" --rpc-url https://mainnet.base.org → 7500: the per-leg floor is a public constant

Contracts are verified on every chain we deploy to — addresses in the protocol manifest. Deeper formal treatment: the whitepaper (PDF).

Share this article · join the discussion

Related engineering