Solana Sandwich Attacks Moved From Validators to Apps, a New Report Finds

A three-year study of protected order flow sandwich attacks counts 28.0 million sandwiches on Solana between July 2023 and June 2026, earning 8,631 bots $345.2 million in net profit. Solana has no global public mempool, which was supposed to make this kind of front-running hard. The paper's finding is that every fix the ecosystem shipped closed one leak, and the attacks moved to the next one.

Why was Solana supposed to be safer?

Solana was expected to resist sandwich attacks because transactions never sit in a shared, public waiting room. RPC nodes forward each transaction straight to the next few scheduled block leaders, a design Solana calls Gulf Stream. The Solana Foundation's MEV docs say this "significantly narrows the window for searchers to observe and act on pending transactions."

A sandwich attack is a bot buying just ahead of your swap, letting your trade push the price up, then selling right after. You get a worse fill, and the bot keeps the difference.

The paper uses "protected order flow" as an umbrella term for any transaction whose submission path is meant to reduce front-running compared with a public mempool. On Ethereum that means private RPCs. On Solana it covers essentially every swap, because forwarding to leaders is the default. So every one of those 28 million sandwiches hit a transaction that, by design, bots weren't supposed to see before it landed.

Solana sandwich attacks by era

The first leak was Jito's mempool, and it ran until March 2024. Validators running Jito-Solana connected to a Jito relayer that held each incoming transaction for up to 200 ms, while subscribed searchers watched the stream. Solana never had a public mempool. For a while, it had an opt-in one.

Sandwiching peaked at 125,169 attacks in a single day just before Jito suspended the mempool, citing "negative externalities impacting users on Solana." During that era, the ten most over-represented leaders carried 26.4% of sandwiches while producing 15.7% of blocks, a 1.68x excess.

The ecosystem then went after validators directly. The Solana Foundation removed operators from its delegation program in June 2024. Marinade blocklisted validators from its stake auction under MIP.9 in February 2025. JitoSOL delisted more in October 2025.

Era (start)

Sandwiches

Per day

Tight

Cross-block

Share in over-represented leaders' slots

Jito mempool (Jul 2023)

2.3M

9k

54%

39%

50%

Mempool closed (Mar 2024)

2.6M

28k

87%

13%

7%

Foundation delisting (Jun 2024)

11.1M

46k

84%

15%

16%

Marinade MIP.9 (Feb 2025)

6.7M

26k

18%

79%

9%

JitoSOL delisting (Oct 2025)

5.2M

20k

1%

96%

2%

The leader excess fell from 1.68x to 1.01x by the Marinade era, and per-leader sandwich rates went from two distinct groups to one. Daily volume moved differently. It climbed to about 46,000 a day in the months after the mempool closed and has since settled around 20,000.

Sandwiches moved across blocks

Solana sandwich attacks changed shape as validator exposure faded. Tight sandwiches, where the front-run, victim, and back-run land back to back in one block, made up 54% to 87% of attacks before the delistings. They fell to 18% in the Marinade era and 1% after the JitoSOL delisting. In the final era, 96% of attacks span blocks.

A tight sandwich needs the bot to see your transaction and sit next to it, which leader-level access makes easy. A cross-block sandwich is a bot placing its front leg without that view, hoping your swap lands before its back leg. The paper finds 44.6% of Solana attacks have another swap in the same pool between the legs, the most interference of any chain in the study. Only 88.0% turn a profit before fees, the lowest rate the authors measured.

Bots also adapted to detection. Evasive sandwiches, where the legs are split across several transactions or across two wallets linked by a token transfer, jumped around the mempool closure. Split legs reached about 6% of attacks by mid-2026. Solana is the only chain where the authors see this at scale.

Why are Axiom users sandwiched more?

Once validators stopped explaining the attacks, the victims started clustering by app. Axiom accounted for 41.4% of all sandwich victims in Q2 2025 and stayed above 37% after that. Its excess ratio, meaning its share of victims divided by its share of all swaps, ran from 13.6 to 20.9. Photon peaked at 20.3, GMGN at 14.5, and BullX at 13.9. Every app the authors tracked was over-represented except Jupiter Ultra. Transactions with no identifiable app were under-represented.

Nearly all of Axiom's sandwiched swaps carried a protection flag. Jito's jitodontfront flag is a read-only account key a transaction adds so Jito's Block Engine only accepts bundles that put that transaction first. Axiom set it on 98.5% of its 21.5 million sandwiched victim transactions after the flag launched on April 17, 2025. Padre set it on 99.4%.

The flag's reach is narrow, and the attack structure suggests why. Of the 5.02 million sandwiches hitting flagged Axiom victims, only 16.5% carry a Jito tip. The other 83.5% show no sign of going through a Jito bundle, the only place the flag does anything, which the authors read as consistent with those transactions reaching the leader by another path. Axiom's recommended Secure setting also limits submission to a whitelist of validators, and the authors say their data is "hard to reconcile" with reading any of Axiom's settings as end-to-end protection.

What the paper doesn't claim

The authors do not say Axiom or any other app is leaking transactions. The paper states outright that its data "does not establish whether the applications themselves are the exposure source or whether correlated order flow characteristics contribute to the excess." Telegram bots and trading terminals route far more long-tail token volume through thin pools, where sandwiches pay better. That could account for part of their excess. The same caution applies to unattributed flow, where the data can't separate user sophistication from submission infrastructure.

Multi-victim sandwiches make the app numbers harder to read. On Solana, 36.0% of sandwiches enclose more than one victim, and the paper can't tell which one the bot targeted. Counting only single-victim sandwiches roughly halves Axiom's median excess, from 18.9 to 8.1, though every over-represented app stays well above one. Jupiter Ultra rises to 2.0 in that subset.

The counts also depend on what the detector can see. The dataset covers Raydium, Orca Whirlpools, Meteora, Pump.fun, SolFi v1, and Lifinity v2, and it only counts bots with at least 100 sandwiches, a 60% profit rate, and sandwich legs making up at least 25% of their swaps. Dropping the floor to 50 sandwiches adds 3,361 bots. The authors call their counts a lower bound. The pipeline is open source if you want to check the work.

Takeaways for Solana builders

Solana app and wallet teams should treat jitodontfront as a guarantee about one submission path. If your transactions also reach the leader outside Jito bundles, through a validator whitelist or any other route, the flag covers none of it, and the weakest path sets your users' exposure. The paper's own conclusion is that protection has to cover the whole pipeline, from the app that signs the transaction to the leader that orders it.

Validator and stake pool operators have evidence the delistings worked. Only 2% of attacks now land in over-represented leaders' slots, down from 50% in the Jito mempool era.

Traders should read a terminal's "MEV protection" toggle as a claim about one route to the leader. Axiom's Reduced setting, for example, sends swaps through Jito bundles and inherits only the bundle guarantee.

Solana closed its mempool leak and cleaned up its validator set, and sandwiching continued at about 20,000 a day into mid-2026. The evidence now points upstream of the leader, and the apps with excess ratios above 10 are best placed to show whether the leak is their submission path or their order flow.