arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.28115cs.CR

无处可藏:受保护订单流三明治攻击分析

No Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks

Lioba Heimbach, Ozan Solmaz, Burak Öz, Christof Ferreira Torres

首次发表
浏览论文内容

中文总结 AI 辅助

本研究首次对六个区块链上受保护订单流的三明治攻击进行三年纵向测量,揭示现有抢先交易保护机制存在多层漏洞,保障远弱于预期,需加强端到端防御。

中文摘要 AI 辅助

抢先交易长期以来一直困扰着以太坊的公共内存池,使其获得了“黑暗森林”的绰号,在这片森林中,掠食者潜伏着寻找有利可图的交易。作为回应,以太坊和其他区块链生态系统越来越依赖私有RPC和原生保护机制来保护交易免受对手攻击,我们将这些机制称为受保护订单流。然而,这些机制在防止抢先交易方面的有效性以及它们所隐含的信任假设,仍然鲜为人知。在这项工作中,我们进行了首次为期三年的纵向测量研究,针对六个区块链(以太坊、Solana、Tron、Base、Arbitrum和Monad)上针对受保护订单流的三明治攻击。我们引入了检测启发式方法,能够捕获区块内和跨区块的广泛攻击,并基于机器人行为进行过滤,以区分三明治攻击与合法交易活动。我们识别出Solana上有2800万次三明治攻击,Tron上有38,567次,以太坊上有30,607次,Base上有1,889次,这些攻击针对的是旨在免受抢先攻击的交易。重组区块进一步暴露了2,875个以太坊受害者。与传统的公共内存池三明治攻击不同,这些攻击很少紧密围绕其受害者发生,并且在Solana之外,它们由少数实体实施。我们的分析揭示了每一层的暴露风险:Solana上的验证器级和应用级暴露、以太坊上的订单流拍卖和重组区块、Tron上无法防止基于延迟的抢先交易先到先得排序,以及Base上暴露待处理交易的RPC漏洞和可预测的受害者行为。这些发现表明,现有的抢先交易保护机制可能提供的保障远弱于用户的预期,凸显了针对三明治攻击建立更强端到端防御的必要性。

英文摘要

Front-running has long plagued Ethereum's public mempool, earning it the nickname of a "dark forest", where predators lurk for profitable transactions. In response, Ethereum and other blockchain ecosystems increasingly rely on private RPCs and native protections to shield transactions from adversaries, which we refer to as protected order flow. Yet the effectiveness of these mechanisms in preventing front-running, and what trust assumptions they entail, remain poorly understood. In this work, we conduct the first longitudinal, three-year measurement study of sandwich attacks against protected order flow across six blockchains: Ethereum, Solana, Tron, Base, Arbitrum, and Monad. We introduce detection heuristics that capture wide attacks, both within and across blocks, and filter on bot behavior to distinguish sandwiches from legitimate trading activity. We identify 28.0 million sandwich attacks on Solana, 38,567 on Tron, 30,607 on Ethereum, and 1,889 on Base against transactions intended to be protected from front-running. Reorged blocks expose a further 2,875 Ethereum victims. Unlike conventional public-mempool sandwiches, these attacks rarely occur tightly around their victims and, outside Solana, are carried out by a small number of entities. Our analysis uncovers exposures at every layer: validator- and application-level exposure on Solana, order-flow auctions and reorged blocks on Ethereum, first-come-first-served ordering that fails to prevent latency-based front-running on Tron, and both an RPC bug that exposes pending transactions and predictable victim behavior on Base. These findings show that existing front-running protections can provide substantially weaker guarantees than users expect, highlighting the need for stronger end-to-end defenses against sandwich attacks.

发表机构

  • Category Labs
  • ETH Zurich(苏黎世联邦理工学院)
  • Flashbots
  • INESC-ID & Instituto Superior Técnico (IST), University of Lisbon(里斯本大学高等技术学院与电子、信息和系统工程中心)

机构由 AI 辅助整理,请以论文原文为准。

↑