Volver
Execution8 min de lectura

Protected flow still gets sandwiched

Order-flow auctions work, and the residual is measurable. A three-year six-chain measurement counts 30,607 protected-flow sandwiches on Ethereum by 7 bots, and finds that 66.8% of private sandwich victims surface in at least one auction dataset. The exposure is the auction itself.

Aún no está en tu idioma — mostrando inglés.

Order-flow auctions are usually argued rather than measured. Supporters say the mechanism rebates value to users and closes the public mempool. Critics say front-running simply moved one hop along the routing path. Both sides have been making the case from theory for about three years.

That changed last month. A measurement study of protected order flow across six chains, covering 1 July 2023 to 30 June 2026, puts a number on the residual: on Ethereum, 30,607 sandwiches against transactions that were routed specifically to be protected, carried out by 7 persistent bots, for $622,358 gross and $254,566 net after fees.

Those are the authors' figures, and the important part is not that sandwiches exist. It is that the residual is now a measured quantity with a documented mechanism, rather than a hypothesis about what might happen further down the path.

What the auction actually does

An order-flow auction inverts the transaction. The user is not bidding for inclusion. Searchers bid for the right to trade behind the user's transaction, and the winning bid is rebated back.

Flashbots describes it plainly: "By introducing another auction before the bundle auction, order flow auctions redirect profit previously captured by validators to users. This is accomplished by auctioning off the transaction slots right behind the user transaction to searchers that want to best capture the backrun opportunity."

MEV Blocker's own documentation walks the nine steps. The ones that matter for sandwiching:

The RPC "shares the transaction (without signature) with a permissioned or permissionless set of searchers (depending on the endpoint)," mixes in "real and AI-generated fake transactions," and for swaps "removes some sensitive information (such as slippage tolerance) from the transaction, preventing sandwich attacks."

Selection inverts the usual objective. "The searcher that provides the bundle with the highest rebate value for users gets selected as the winner (NOT the searcher that pays the highest fee to the validator)."

The split is fixed at 90/10. "Once the builder has selected a searcher bundle bid, they are obligated to refund 90% of that bid's value to the user and use the remaining 10% to pay the validator/proposer." Flashbots describes the same figure as a cross-auction invariant: retail outcomes "are aligned across auctions by the requirement that transactions sent to builders by order flow auctions can only be included if 90% of the searcher bid is refunded to the specified address."

Underneath, the blockspace auction is a "first-price sealed-bid auction which allows users to privately communicate their bid and granular transaction order preference without paying for failed bids," with "Finality protection: Once propagated to the network, it becomes impractical to modify Flashbots blocks containing Flashbots bundles."

Note what the design gives up. MEV Blocker says it plainly: "In a permissionless environment, searchers can't be prevented from misusing shared data, so fake transactions add uncertainty to the data." Decoys discourage frontrunning. They do not forbid it.

What the measurement found

The study is by Lioba Heimbach (Category Labs), Ozan Solmaz (ETH Zurich), Burak Öz (Flashbots), and Christof Ferreira Torres (INESC-ID and Instituto Superior Técnico, University of Lisbon), submitted 23 September 2026. One co-author is affiliated with Flashbots, which is worth knowing before reading the numbers as neutral.

The Ethereum row of their results table: 30,607 attacks, 7 entities, 91.9% of them profitable, $622,358 gross, $254,566 net, with 99.96% of the profitable share priced in USD. Fees are the most consequential line. Their words: "Fees cut the profit from $622,358 to $254,566, i.e., 59.1% of the gross profit goes to fees."

Seven bots, three years, roughly $255k net. Compare that to the same table's Solana row, where 8,631 bots extracted $383,433,932 gross and $345,185,014 net over the same window.

The structural difference is worth noting: these attacks "rarely occur tightly around their victims and, outside Solana, are carried out by a small number of entities." Tight sandwiches were 0.25% of Ethereum attacks. Attackers span wider positions or separate blocks, which the authors read as operating "under more limited information."

So the OFA residual on Ethereum is a narrow, specialist, low-volume extraction that fees absorb by about 60%. It is not a free-for-all.

Why competition did not close it

The obvious defence is that the auction crowds the backrun. Multiple searchers bid for the same victim, and competition should eat the margin. The authors tested this directly and found the bottleneck is liquidity, not bidder count.

They examined "the number of active X–Y pools (direct count)" for all 39,461 victim transactions. The direct pool count is one for 68.1%, two for 21.1%, and greater than two for 10.7%. So "31.9% have at least one active direct alternative."

An arbitrage back-run can only erase a sandwich, they write, when "sufficient alternative liquidity is available." For roughly two thirds of victims there was no second pool to route through, so no rival back-run existed to take the extracted margin. Competition needs somewhere to compete.

The auction is the exposure

The more important finding is about where the information leak sits. Across "the 34,360 victims of 28,128 successful private sandwich attacks, 66.8% appear in at least one OFA dataset, with 35.5% appearing in multiple ones." Overall, "53.0% of all attributed sandwich victims appear in multiple OFA datasets."

That share is the cost of running the mechanism. Every OFA shares something with searchers, because searchers have to see enough to bid. The paper then documents an attack that uses exactly that:

"Cross-OFA Correlation. Overall, 53.0% of all attributed sandwich victims appear in multiple OFA datasets. This is particularly relevant for MEV-Share and MEVBlocker, whose disclosure mechanisms can be correlated to reveal additional information. MEV-Share selectively discloses transaction information together with a double-hashed transaction hash... A searcher observing both feeds can double-hash transaction hashes exposed by MEVBlocker and compare them against the MEV-Share stream. A match identifies a genuine MEVBlocker transaction and can reveal information unavailable from either feed in isolation."

The prevalence: "Among attributed victims, 28.3% appear in both MEV-Share and MEVBlocker, of which 75.3% are in no other OFA." And the authors pre-empt the obvious objection about incidental overlap: "88.6% of victims in this MEV-Share–MEVBlocker-only category occur in single-victim sandwiches, making incidental inclusion unlikely."

The full-disclosure route is larger still. "Blink appears in 62.2% of attributed victims, and 33.4% of attributed victims are observed only in Blink... a large class of victim transactions was available in full to Blink's approved searchers before inclusion."

Read plainly: a whitelisted searcher does not need to guess. The protection there is the onboarding process, not cryptography.

The paper also reports what it could not explain: "1,727 MEV-Share-only victims (7% of attributed) and 1,553 MEVBlocker-only victims (6.3%; cf. Table 21)." Their conclusion is worth quoting because it is the honest form of the finding: "An additional exposure source may therefore be missing from our data."

And the structural fix they name is composition. "If a transaction originator submits the same signed transaction through multiple RPCs or OFAs, information revealed along one path can weaken the protections of another. Such multi-path submission should therefore be treated as a composition risk."

Reorgs are the other leak

Private means private until inclusion. A block that is proposed and then loses votes undoes that. "Any private transaction in such a block loses its privacy since the block carrying it has been broadcast."

Across "the 9,297 reorged blocks in our data, covering January 2024 to June 2026, we find 140,854 swap transactions, of which 56,730 were private when the stale block was proposed." Upon canonical re-inclusion, "2,875 are sandwiched." Ninety-three bots do it, and the concentration is extreme: "the extraction on victims never seen individually is highly concentrated, with one bot attacking 55% of the victims and the top five 82%."

One operator, monitoring stale blocks, accounted for more than half of the victims that never appeared in a public mempool at any point.

A different shape: CoW

CoW Protocol is not an order-flow auction in this sense, and conflating the two misleads. Its docs describe a batch mechanism: "CoW Protocol collects and aggregates intents off-chain and auctions them off to solvers. The auction is combinatorial because each solver can submit multiple bids." The protocol "filters out 'unfair' batched bids... It then selects the combination of winning bids that maximizes the surplus received by the orders."

The protection comes from clearing, not from secrecy: "Fair combinatorial auctions allow for Uniform Directed Clearing Prices (UDP), where a directed asset pair that appears multiple times across orders in the same auction settles for a consistent price. This makes transaction order irrelevant within the block, undermining the ability for MEV bots to extract value."

Making order irrelevant is a stronger guarantee than hiding order. The 2026 measurement is about routes where the user's order stayed visible to someone and the mechanism relied on deterrence, privacy settings, and competition.

Relay, September 2026

One real incident, described by the party that had to pay for it.

Relay co-founder Jason Maier, in a public statement on 28 September 2026: "This weekend, we identified an issue in Relay's API that exposed pending trade information before execution. MEV searchers used it to sandwich trades, worsening prices for people trading through Relay."

The figures, as stated: the activity ran "from Sep 12 to Sep 26, with most of it concentrated from Sep 23 to 26." Searchers "used pending route statuses to infer onchain routes and trade ahead of orders before execution, extracting roughly $136k in profit." "About 5,600 users were affected, with a median impact of $11.88." Remediation included "a $50k bounty" to the reporter and compensation of "approximately $312k."

A median of $11.88 against roughly $136k extracted is a small-per-user, high-volume leak. The total is not large. The shape is systemic.

The part worth keeping is the author's own conclusion: "MEV takes many forms. Attackers can exploit transactions in public mempools, infer trades from order details, maliciously participate in auctions, or find gaps in how data moves between providers. Protecting one part of the path is not enough if sensitive information is exposed elsewhere. Attack methods evolve, and protections need to evolve with them."

"Protecting one part of the path is not enough" is the paper's finding stated by someone who had to compensate 5,600 users for finding it.

One sourcing note: Relay's own website was unreachable throughout this reporting. Every request to relay.link and its blog path returned HTTP 429 behind a bot checkpoint. All Relay facts above come from the co-founder's public statement, which is the affected party's own account. Secondary outlets report the same numbers, so the figures are not in dispute, but the infrastructure disclosure is absent.

What the numbers do and do not license

They do not say order-flow auctions fail. 90% rebated, backrun-only, signature stripped, decoy traffic injected, uniform clearing where available: those are real mechanisms and they work against the public-mempool sandwich. Ethereum's protected-flow number, seven bots and $254,566 net across three years, is a small residual by design.

They do say the routing layer is an attack surface of its own, and one that grows when more routers compose. 66.8% of private sandwich victims appearing in at least one auction dataset is not a side effect of a bad week. It is the price of the mechanism, and the paper measures it.

What a user can actually take from this: check whether a route hides your order or merely promises to. A refund percentage is a payout rule, not a privacy property. Avoid submitting the same signed transaction through two providers. Prefer designs that make order irrelevant, over designs that make order secret.

Sources

No routing path removes execution-quality risk on its own. Private order flow, backrun-only auctions and refund rules reduce public-mempool extraction; they do not eliminate it, and the figures above are measurements of what remains. Market conditions, pool liquidity and third-party routing can all move realised outcomes away from documented rules. Verify the route actually used, and treat any stated refund as a rule rather than an observed payout.

Risk note: cryptocurrency trading, leveraged perpetual futures, and automated algorithmic strategies carry significant risk of rapid and total financial loss. Never risk funds you cannot afford to lose completely. Data recovered from a public chain or indexer describes what happened, not whether the decision was sound, and order-flow protections reduce extraction without removing it. Nothing in this article is investment advice, a recommendation, or an offer to sell any product.