
SimpleSwap Blog
Sandwich Attacks: How MEV Bots Target DEX Swaps
Learn how MEV sandwich attacks manipulate DEX swap prices, how related MEV bot scams work, and practical ways to reduce your exposure.
Read the full articleA sandwich attack happens when a searcher places one trade before a DEX swap and another after it, profiting from the price movement caused by the user's trade.
The first trade moves the price before your swap executes. Your transaction then pushes the price further, letting the searcher trade again immediately after and capture the difference. Your swap sits between the two trades – hence “sandwich.”
Sandwiching is not a scam in the same sense as phishing or impersonation: it relies on transaction ordering and market mechanics rather than deceiving you into sending funds.
A related scam is different: fake “MEV bot” tutorials or contracts promise easy trading profits, then ask you to fund a contract designed to send your crypto to the scammer.
Every transaction involved is technically valid. That is exactly what makes it hard to regulate – and easy to underestimate.
$60M
estimated annual trader losses to sandwich attacks on Ethereum
70%
of measured attacks trace back to a single operator
~40%
of attacks target “safe-feeling” stablecoin and low-volatility pools
Ranked roughly by how much they help.
Services like Flashbots Protect route your trade to block builders without it passing through the public mempool, so searchers cannot see it coming.
Your slippage setting is the ceiling on how much a sandwich can take. A wide default on a large trade is an invitation.
Sandwich profit scales with how much your trade moves the pool – smaller orders and deeper liquidity leave less to extract.
MEV-protected or private transaction routing and more deliberate slippage settings can reduce exposure, but they are not an absolute guarantee.
The full guide explains mempools, slippage, private transaction routing, real sandwich attacks and how fake “MEV bot” schemes turn the same concept into a scam.