Glossary
Oct 2, 2026

What Is a Sandwich Attack in DeFi? How to Avoid One

A sandwich attack is a bot trading just before and after your DEX swap to profit from its price move. See a worked example and how to avoid one.

What Is a Sandwich Attack in DeFi? How to Avoid One

A sandwich attack is a trading exploit in which a bot places one trade immediately before and one immediately after a victim's DEX swap, profiting from the price move the victim's trade causes. The victim's swap still goes through, but at a worse price, and the difference ends up with the attacker. It is one of the most common forms of MEV on decentralized exchanges.

Sandwich attack definition

The name describes the shape of the attack: the victim's transaction is the filling between two attacker transactions. The first trade (the front-run) buys the same asset the victim is buying, pushing its price up. The victim then buys at that inflated price. The second trade (the back-run) sells into the price the victim pushed even higher.

Sandwich attacks are a specific kind of front-running. Front-running in crypto means acting on knowledge of a pending transaction before it executes; a sandwich adds the second leg so the attacker exits with a profit in the same block.

The attack only works because swaps carry a slippage tolerance. The bot calculates exactly how far it can push the price while keeping the victim's trade just inside its minimum-received limit.

How a sandwich attack works

  1. Spot the target. A bot sees a pending swap that is large relative to the pool and has a generous slippage tolerance.
  2. Front-run. It submits a buy of the same token, arranged to execute first. The pool price rises.
  3. Victim executes. The victim's swap fills at the worse price, still above their minimum, so it does not revert. Their trade pushes the price up further.
  4. Back-run. The bot sells the tokens it bought into the higher price, ending with more of the original token than it started with.

The attacker needs control over ordering, which it buys with high fees or by sending bundles to block builders. That is why sandwich risk depends heavily on how a chain orders transactions and how visible pending trades are.

Sandwich attack example

A hypothetical constant-product pool holds 100 ETH and 300,000 USDC (spot price 3,000). You submit a swap of 30,000 USDC for ETH with a 5% slippage tolerance. Fees and gas are ignored.

  • Without an attack, you would receive 9.0909 ETH. With 5% tolerance, your minimum is 8.6364 ETH.
  • Front-run: the bot buys with 7,000 USDC and receives 2.2801 ETH.
  • Your swap: at the higher price, your 30,000 USDC now buys only 8.6991 ETH. That is above your minimum, so it executes, but you have lost 0.3918 ETH, about 4.3% of your expected output.
  • Back-run: the bot sells its 2.2801 ETH and receives 8,416 USDC.
  • Bot profit: 8,416 − 7,000 = 1,416 USDC, before fees and the cost of winning the ordering.

Had you set a 0.5% tolerance instead, your minimum would have been 9.0455 ETH, and a front-run of this size would have made your trade revert. The attack would not have been worth attempting.

Why sandwich attacks matter

  • The loss is invisible. Your wallet shows a successful swap. Unless you compare the fill to the original quote, you will not notice the gap.
  • Your settings are the main defence. Keep slippage tolerance tight, avoid very large single swaps in shallow pools, and split big orders. Deeper pools make sandwiches less profitable; our Sui DEX comparison shows where depth sits on Sui.
  • Use protected routes where available. Some wallets and aggregators offer private transaction submission or MEV protection that keeps your swap out of public view until it executes.
  • Different from wallet theft. A sandwich never touches your wallet's other funds. Approval-based theft is a separate and more dangerous threat, covered in our guide to wallet drainers and approval phishing.
  • MEV — the wider category of value extracted from transaction ordering.
  • Slippage — the tolerance setting a sandwich bot targets.
  • Price impact — the price move your trade causes, which the attacker rides.
  • AMM (automated market maker) — the pool design that makes prices predictable enough to sandwich.
  • DEX aggregator — routing that can reduce sandwich exposure by splitting orders.

Learn more on the JewelSwap blog

Frequently asked questions

What is front running in crypto?

Front-running in crypto means placing a transaction ahead of a known pending transaction to profit from the price move it will cause. A sandwich attack is front-running plus a second trade after the victim's, so the attacker closes the position immediately.

How do I avoid a sandwich attack?

Set a tight slippage tolerance, trade in deep pools, split large orders, and use wallets or aggregators that offer private or MEV-protected transaction submission where available.

Sandwich attack vs arbitrage: what is the difference?

Arbitrage profits from a price difference between two markets and helps align prices. A sandwich attack profits by forcing a specific user's trade to fill at a worse price, so its profit comes directly out of that user's output.

JewelSwap Crypto Glossary · educational, not financial advice. Updated 2 October 2026. Browse the full glossary.

About the author.

Co-Founder at JewelSwap & CMO at iDenfy. Viktor brings his successful track record of superb development & project management.