Sandwich Attack
Pronunciation: SAN-dwihch uh-TAK
Definition
Sandwich Attack is an attack or weakness pattern that surrounds a victim’s pending trade with attacker transactions to profit from the victim’s predictable price impact. Sandwich Attack must be evaluated through its prerequisites, entry point, affected asset or trust boundary, attacker capability, observable indicators, and possible financial or operational impact. Defenses against Sandwich Attack combine secure design, least privilege, validation, monitoring, rate or value limits, and tested containment and recovery procedures.
Overview
In a sandwich attack, the attacker observes a trade before confirmation, buys or sells ahead of it, lets the victim move the market, and then reverses the position. Transaction ordering and automated execution make the sequence possible.
Profit depends on liquidity, victim slippage tolerance, fees, competition, and block-building rules. The victim receives a worse execution price, while failed attack legs, volatile markets, or protective routing can expose the attacker to loss.
Users can set tight but realistic slippage, use protected transaction channels, split or time orders carefully, and choose deeper markets. Protocols and wallets should improve price-impact warnings, private order handling, batch execution, and monitoring of harmful ordering behavior.
Sandwich Attack is an attack or weakness pattern that surrounds a victim’s pending trade with attacker transactions to profit from the victim’s predictable price impact. Sandwich attacks monetize predictable price impact and transaction ordering, making slippage control, execution privacy, liquidity, and routing design important defenses.
Assessment of Sandwich Attack should trace an attack or weakness pattern that surrounds a victim’s pending trade with attacker transactions to profit from the victim’s predictable price impact from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving attack should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the Sandwich attack path should be tested against the architecture associated with attack.
Retesting for Sandwich Attack should reproduce the Sandwich attack path involving attack, examine adjacent paths, and verify the conditions for safely returning the affected service to normal operation.
Key Takeaway
Sandwich attacks monetize predictable price impact and transaction ordering, making slippage control, execution privacy, liquidity, and routing design important defenses.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)