The State of Sandwich Attacks on Solana: Insights from Three Years of Data

A collaborative academic study has provided a comprehensive analysis of sandwich attacks across six major blockchain networks over a three-year period. The data reveals that the Solana network recorded approximately 28 million such attack incidents, a figure that underscores the prevalence and severity of this exploit on high-throughput chains.

Comparing the Effectiveness of Different Protection Schemes

The research specifically compared the efficacy of various transaction protection mechanisms. It found that transactions shielded by a privacy-enhanced aggregator design experienced a significantly lower probability of sandwich attacks compared to the industry average. Its excess attack ratio was only 0.7, with a single-victim scenario ratio of 2.0. This performance was far superior to other comparable solutions, which exhibited ratios as high as 18.9 and 11.1.

Application Layer, Not Base Layer, is Key to Defense

The paper's central conclusion challenges a common assumption: that resisting sandwich attacks depends more on application-layer routing strategies and privacy design than on the underlying blockchain's consensus or performance. Intelligent routing algorithms can split and obfuscate transaction intent, while effective privacy features (like transaction mixing) significantly increase the difficulty for attackers to identify and insert malicious transactions.

  • Routing Optimization: Splitting large trades across multiple paths or leveraging liquidity pool complexity to disrupt attacker tracking.
  • Privacy Enhancement: Delaying the public revelation of transaction details or hiding final recipient addresses to reduce pre-analysis risk.

The Persistent Risk: The Validator Factor

Despite the strong potential shown by application-layer solutions, the study also issues a warning: sandwich attacks have not been eliminated on chains like Solana. A persistent risk vector lies with validator nodes. In theory, validators with transaction ordering power could still collude to execute attacks if they act maliciously. This necessitates ongoing improvements in protocol governance and validator incentive design within the ecosystem.

This research offers a clear guide for DeFi users and developers: when selecting trading tools, priority should be given to examining their application-layer privacy and routing protections, not just the underlying chain's TPS. For projects, shifting some security focus from "chain choice" to "application design" may be a more effective strategy for safeguarding user assets.