The Solana sandwich attack is making a comeback: priority fees become "protection fees," and the on-chain "dark cycle" escalates again.

CN
PANews
Follow
1 year ago

Author: Frank, PANews

As the Solana ecosystem faces a decline in trading volume due to the retreat of MEME, a more insidious crisis is spreading. Recently, many users in the community have complained that on-chain users frequently encounter sandwich attacks even when they pay priority fees (Tips). Some validator nodes have even been accused of participating in these attacks. This phenomenon exposes the deep-seated contradictions within the Solana ecosystem—MEV (Maximum Extractable Value) has evolved from a technical vulnerability into a systematic harvesting tool.

Data shows that the profits of a certain sandwich attacker have skyrocketed from $30 million in two months to $287 million in six months, forcing users to struggle between being "sandwiched" and "paying higher protection fees." Behind this crisis is a triple strangulation of validator interests, the alienation of the priority fee mechanism, and the collapse of user trust.

Industrialization of Sandwich Attacks—From Guerrilla Warfare to Assembly Line Harvesting

Previously, PANews conducted an in-depth investigation into the MEV situation on the Solana chain and exposed the most notorious sandwich attack bot starting with "arsc," which made over $30 million in profit within two months (Related reading: In two months, “seizing” $30 million, Solana's largest sandwich attacker earns $570,000 daily, inciting public anger).

Months have passed; what is the current state of sandwich attacks on the Solana chain?

First, it is regrettable that sandwich attacks on the Solana chain have not subsided due to community outcry and media exposure. Instead, they have adopted new methods, employing a larger-scale attack matrix.

Taking the previously investigated address Ai4zqY7gjyAPhtUsGnCfabM5oHcZLt3htjpSoUKvxkkt as an example, this address ultimately used its capabilities until November 15, 2024. According to PANews statistics, this address profited approximately $287 million over a six-month period from May to November.

Solana Sandwich Attacks Resurge: Priority Fees Become "Protection Fees," On-Chain "Dark Cycle" Upgraded

Moreover, there have been new changes in attack methods. To avoid being tracked, sandwich attack bots on the Solana chain have switched to using a larger batch of new addresses and established programs to execute attacks in bulk.

For example, this attack program has 77 addresses and, as of March 12, has conducted a total of 429,000 transactions (since these are specifically for sandwich attacks, all transactions can be considered as attacks). Assuming each attack requires two transactions, this program has conducted a total of 215,000 attacks.

Another address, 4vJfp62jEzcYFnQ11oBJDgj6ZFrdEwcBBpoadNTpEWys, has conducted 210,000 attacks in the past month, transferring approximately $1.6 million to exchanges, with an average profit of $7.6 per transaction.

In fact, there are now far more programs conducting large-scale sandwich attacks daily than there were six months ago. However, due to the inability to conduct data statistics, we cannot obtain precise numbers.

Solana Sandwich Attacks Resurge: Priority Fees Become "Protection Fees," On-Chain "Dark Cycle" Upgraded

The Embarrassment of Priority Fees: From "Accelerated Fees" to "Protection Fees"

In the face of increasingly frequent attacks, users have attempted to mitigate risks by using trading bots or increasing priority fees, but the priority fee mechanism has completely alienated—transforming from a tool for enhancing transaction efficiency into a disguised "on-chain tax," further burdening users.

The beneficiaries are those validator nodes profiting from MEV income.

The recently discussed SIMD-0228 proposal aims to reduce the staking rewards for nodes, but the premise is that the proposal's authors believe the current MEV income is sufficient to cover these nodes' costs.

Returning to the topic of MEV, one can observe a strange Möbius loop. Sandwich attacks drive users to pay priority fees, which in turn increase node income, and some nodes participate in sandwich attacks. When several links are connected, the harvesting strategy of sandwich attackers becomes the most lucrative profit model on the Solana chain.

Users are left to choose between "losing principal due to being sandwiched" and "paying higher priority fees."

Of course, this dark gameplay went unnoticed during the bull market, as users were more focused on wealth effects and major hacking incidents. In most cases, those affected by sandwich attacks or small rug pulls could only consider themselves unlucky, while attackers waited to collect their money.

The Collapse of Trading Volume Leads to a Shift in the Sandwich Model: From "Bundling" to "Queue Jumping"

However, this logic is changing as the market declines. According to discussions on social media and investigations by PANews, the cost of an efficient sandwich attack is not low.

The largest cost comes from attackers needing to deploy multiple validator nodes globally to insert transactions at the earliest opportunity. It is important to note that this logic does not mean that the attacker's nodes must lead the block to execute the attack; the key is that when the attacker listens for the latest attackable transaction, they must send the transaction from the node physically closest to the leading block. Generally, deploying a complete set of attack node clusters can cost millions of dollars.

Such costs, while ensuring a steady income from attacks, also place certain profit and loss pressures on sandwich attackers. As the trading volume on-chain gradually declines, the attackers' income will also decrease. Moreover, stronger competition will form among attackers, where whoever can offer higher priority fees may capture a larger market share.

Under this competition, transactions without priority fees gradually fail to meet the attackers' targets. Hence, we see the cases mentioned earlier where multiple transactions that paid priority fees were still attacked.

For example, in this transaction, the victim paid a priority fee of 0.000075 SOL, which previously would not have been attacked. However, now sandwich attackers are paying higher fees, increasing to 0.0044 SOL. In this transaction, the user attempted to conduct a transaction worth approximately 5 SOL but was robbed of 0.08 SOL by the attacker.

Solana Sandwich Attacks Resurge: Priority Fees Become "Protection Fees," On-Chain "Dark Cycle" Upgraded

In fact, based on investigations of multiple attack transactions, we found that these attacked users generally adopted a priority fee standard of less than 0.001 SOL, making them vulnerable to attacks.

In this process, it is also necessary to explain that the attackers' methods have changed. In the past, sandwich attackers generally used a bundling approach, packaging transactions that did not pay priority fees into a single transaction bundle, allowing the submitting attacker to arrange the order at will. However, now that most users pay a certain priority fee, they are not bundled with other transactions, so it can be observed on-chain that current sandwich attacks mostly adopt a non-bundled approach, initiating two independent transactions before and after the target transaction. Therefore, the amount of priority fee becomes a critical standard.

In summary, the evolution of sandwich attacks on the Solana chain has shifted from the past, where paying a priority fee could avoid being bundled into a sandwich attack, to a situation where insufficient priority fees may still lead to transactions being inserted before and after.

For users, the next choice is no longer whether to pay priority fees, but whether the fees paid are sufficient. It seems that this has once again entered a cycle as previously described.

Only by continuously increasing priority fees can nodes maintain their original income levels amid declining trading volumes. On the other hand, if users are unwilling to compromise, they can only suffer greater losses of principal.

Increased Risk of Node Data Leakage Exacerbates Ecological Dilemma

However, there is a prerequisite in this process: the leading block nodes must cooperate with sandwich attackers for data leakage, allowing attackers to know in advance about transactions that have already paid priority fees. Since February 27, the founder of Pepe boost has called on the Solana official on the X platform to pay attention to this matter. Additionally, GMGN co-founder and PinkPunkBot have publicly raised similar issues on social media. However, as of March 13, the Solana official has not responded to this.

As of March 10, data shows that the daily priority fees on the Solana chain have dropped to around 14,000 SOL, a decrease of over 92% from the January peak of 183,000 SOL.

Solana Sandwich Attacks Resurge: Priority Fees Become "Protection Fees," On-Chain "Dark Cycle" Upgraded

The number of active addresses on the Solana chain has also fallen to 2.14 million, a 75% decrease from the peak of 8.78 million. In an already severely shrunk market environment, continuing to allow sandwich attacks is clearly akin to draining the swamp, further driving users away from the Solana ecosystem.

The competition among public chains has never been limited to an arms race of TPS numbers; it is more about whether ecological participants can establish a sustainable value consensus. In the face of plummeting trading volumes and shrinking priority fee income, Solana is facing a difficult situation: if the MEV interest groups are allowed to continue devouring user assets, the network activity built on MEME over the past year may be hard to replicate. Draining the swamp will ultimately leave no fish.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink