A sandwich attack wraps your swap with a bot’s buy, then a sell, skimming value from slippage. Here’s what it is, why retail traders get caught, and how to cut your risk starting today.
Problem: What a sandwich attack is and why it hits retail
A sandwich attack is a form of Miner/Maximal Extractable Value (MEV) that targets your decentralized exchange (DEX) swap. A bot spots your pending trade in the mempool, buys the token first to push the price up, lets your swap execute at the worst price you allow, then sells right after. You get worse execution. The bot takes the spread.
This isn’t private-key theft or a rug pull. It’s predatory trade placement around your order. You tend to see it when you trade tokens with thin liquidity, set wide slippage, broadcast on public RPC endpoints, or send large orders relative to the pool.
Evidence: On-chain patterns and current risk climate
On-chain, a sandwich shows up as two quick transactions from the same bot or cluster bracketing your swap. A small buy nudges the price up, your higher-slippage swap lands, then a sell pulls the price back toward where it started. Price impact, gas bidding, and identical router paths are common markers. Even if the bot uses private relay infrastructure, its transfers in and out of the pool are visible on-chain after inclusion.
Step back and look at TrustSniffer’s data. It shows how often retail wallets cross paths with risk. As of 2026-07-24, TrustSniffer has assessed 1,367,639 wallets, and 753,716 carry a risk signal (about 55%). That’s a high background rate of exposure to problematic flows, which compounds execution risks like sandwiching when users chase illiquid tokens or click unvetted approvals.
Sanctioned and issuer-frozen exposure isn’t trivial either. Out of 1,367,639 assessed wallets, 15,867 are sanctioned or issuer-frozen, about 1.16% by count. For users asking “is wallet safe,” that matters: counterparties and routers you interact with can inherit or propagate exposure even when you never touched a known scam. TrustSniffer has also assessed 2,019 websites tied to crypto activity, a reminder that phishing pages and fake routers remain part of the attack surface alongside MEV bots.
A sandwich attack worsens your execution price. It doesn’t, by itself, drain your wallet or seize approvals. Those losses come from other threats (phishing, malicious approvals, or compromised keys).
Action: Cut your sandwich risk and answer “is wallet safe” for your setup
You can’t turn MEV off. You can make your trades unattractive to sandwich bots and lock down your setup. Use these steps as your defaults:
- Use MEV-protected order flow. Route swaps through providers that support private or shielded relays (e.g., wallets or RPCs that advertise MEV protection) so mempool bots can’t see your intent before inclusion.
- Prefer batch auctions or intents-based routers. Aggregators that batch orders or match peer-to-peer (e.g., intents/auction models) reduce exploitable slippage windows compared with naive AMM swaps.
- Tighten slippage and use limit orders when available. A 0.3–0.5% slippage band on liquid pairs cuts surface area. For illiquid tokens, use limits or skip the trade.
- Avoid thin-liquidity pools. Check pool depth and expected price impact before submitting. If price impact exceeds a few percent on your size, reconsider or split the order.
- Split large orders and randomize timing. Smaller clips leave less spread to capture and make gas sniping less profitable.
- Simulate before you send. Use reputable simulators to preview execution price and gas. If the expected price impact is large, revise the plan.
- Audit approvals. Grant token allowances per trade or use “exact-in” approvals. Revoke stale allowances after use to contain damage if a dApp is compromised.
- Check counterparties and URLs. Run addresses and sites through TrustSniffer’s wallet-risk checker and confirm entities against the sanctions directory. For a macro view of risk trends, watch the live Risk Index.
If you suspect a sandwich, review the block that holds your swap. Look for a prior small buy and a quick sell from the same cluster, elevated gas fees, and your swap landing between them at the top of your slippage band. If you see that pattern repeatedly on a pair, change venues or routing.
- Sandwich attack
- A DEX trade-manipulation tactic in which a bot places a buy before a pending swap and a sell after it, extracting value through price movement.
What this means for retail risk management
Sandwiching is a tax on haste and opacity. Fire a large, high-slippage market order into a thin pool over a public RPC and you invite it. Route privately. Keep slippage tight. Choose deeper liquidity or batch-auction venues, and most bots move on to richer targets. Pair that with steady hygiene: verify URLs, keep approvals minimal, and use a hardware wallet for key isolation. Then answer “is wallet safe” with evidence, not hope, by scanning exposure and testing a small trade before size.
Related reading: Analysis of Cross-Runtime Attack Chains in Malicious Python Packages.
How TrustSniffer knows this
These findings come from TrustSniffer's own analysis engines — an on-chain AML tracer (USDT/USDC issuer freezes and taint on Ethereum and TRON) and a website-risk analyzer — cross-checked against sanctions and issuer data. Aggregate figures reflect everything the engines have assessed.
For address-level context, use TrustSniffer’s wallet-risk checker and treat the result as a screening signal rather than proof of ownership, intent, or wrongdoing.
Known public risk labels can also be reviewed in the TrustSniffer sanctions directory, with the original authority checked before a decision is made.
Sources
Reviewed by TrustSniffer Intelligence on 2026-07-24. This is automated, attribution-based analysis of public on-chain and web data for informational purposes only — not financial, legal, or investment advice. Third-party labels reflect their sources. Verify independently before acting.



