DeFi 102: MEV, Slippage, and More

DeFi 102: MEV, Slippage, and More

By Michael @ CryptoEQ | CryptoEQ | 23 Nov 2023


You are reading an excerpt from our free but shortened abridged report! While still packed with incredible research and data, for just $20/month you can upgrade to our FULL library of 50+ reports (including this one) and complete industry-leading analysis on the top crypto assets. 

67cbbf4723857b85c151585aa280e6d940346c501cef75bafd7dea02b44b24c9.png

Becoming a Premium member means enjoying all the perks of a Basic membership PLUS:

  • Full-length CORE Reports: More technical, in-depth research, actionable insights, and potential market alpha for serious crypto users
  • Early access to future CORE ratings: Being early is sometimes just as important as being right!
  • Premium Member CORE+ Reports: Coverage on the top issues pertaining to crypto users like bridge security, layer two solutions, DeFi plays, and more
  • CORE report Audio playback: Don’t want to read? No problem! Listen on the go.

 

What Is Maximum Extractable Value (MEV)?

Unlike a lot of things in the crypto world, MEV is pretty well named. It is exactly what it sounds like. Given how blockchains are constructed and all the entities involved with aggregating/including/executing/broadcasting transactions, MEV is the maximum amount of economic value these privileged entities (some would even use the crypto slur “middlemen”) can squeeze out (extract) of each on-chain transaction. Sounds sh*tty at first glance, right? And you’re not entirely wrong. But just like with anything, as you learn more, it’s not so black-and-white. However, one thing is for certain, MEV is here, happening, and it isn’t going away any time soon (if ever). Therefore, an entirely new industry within the crypto economy has been created in the last 2-3 years and it’s big business.

So, again, but this time a more formal definition: Maximal Extractable Value (MEV) represents the total economic benefits block producers can obtain by arbitrarily including, excluding, and reordering transactions. Initially referred to as "miner extractable value," the term evolved to encompass a broader meaning as Ethereum (where most everything happens in crypto land, including MEV opportunities) moved to Proof of Stake, eliminating miners, and, thus, making it a less applicable term. Miners were replaced with validators and “Maximum Extractable Value” made more sense.

MEC diagram Source: BlockNative

“Soooo… I thought cryptocurrencies were peer-to-peer (p2p), meaning no middlemen. Isn’t that kind of one of its core principles? And now, you’re telling me there’s an entire industry of middlemen looking to profit off me?”

To understand MEV, it is essential to grasp the process of block production in blockchains. Contrary to popular belief, transactions in blockchains are not recorded on a first-come, first-served basis. Instead, blockchains operate more like auction houses, selling block space to the highest bidder.

Blockchain networks consist of computer nodes called block producers, including miners (PoW), validators (PoS), and sequencers (L2). These block producers collect user-submitted transactions and generate blocks. Since each block can accommodate only a limited number of transactions, block producers prioritize transactions with the highest gas fees when demand is high to maximize their profitability. This extra profit obtained by block producers from users by selectively including, excluding, and reordering transactions is what we call MEV.

transaction ordering diagram Source: Xangle

MEV exists primarily because (i) block space is limited (e.g., 30M gas maximum for Ethereum), (ii) all blockchain activities are publicly visible, (iii) there is a fee market, and (iv) block producers have control over transaction ordering.

MEV “Attacks” and How Users Suffer

MEV attacks come in various forms. The primary types of MEV attacks include:

  1. Front-Running: This occurs when an attacker takes advantage of a highly profitable transaction (e.g., arbitrage) identified in the mempool by duplicating the transaction but with a higher gas fee. This allows them to "steal" the opportunity from the original user.
  2. Back-Running: In contrast to front-running, back-running involves generating a profit by placing an order immediately after a target transaction has been executed. A common example of back-running is an MEV bot placing an opposing order right after a temporary high slippage occurs due to a large-scale transaction, allowing it to profit from arbitrage trading.
  3. Sandwich Attack: This type of MEV attack combines both front-running and back-running, generating profit before and after the target transaction when successful. Such attacks often occur on AMM DEXs like Uniswap. An illustration of this is when a user submits a large buy order for a particular cryptocurrency, which is projected to raise the price from one value to another. The MEV bot anticipates this, purchases the memecoin ahead of the transaction, and then supplies liquidity to the DEX at a slightly higher price. The targeted order proceeds to buy all the memecoin from the bot at the inflated price, making a risk-free profit for the bot. Following the temporary inflation, the bot sells off its inventory at a higher price (known as back running) and then repurchases it after the market correction, exploiting passive liquidity providers.
  4. Liquidation: MEV bots can also monitor lending protocols like MakerDAO and Aave in real-time for opportunities to liquidate a user's position and profit from the liquidation fee. These bots exploit vulnerable positions by liquidating them when the opportunity arises, earning a profit through fees associated with the liquidation process.

Sandwich Attacks

To understand how a sandwich attack works, it is important to understand how the price of an asset is calculated on the blockchain. The price of an asset is typically calculated as the current exchange rate between assets. For example, if a contract is currently trading 10 USDC for 100 CEQcoin, then you could say CEQcoin has a price of 0.10 USDC.

However, prices generally move in response to buying and selling pressure. If a large order is sitting in the mempool, traders have an incentive to copy the order but with a higher gas price. That way, they can purchase the asset before the large order, let the large order move the price up, and then sell the asset right away.

sandwich attack mev diagram Source: Xangle

The sell order is sometimes called “backrunning.” The sell order can be done by placing a sell order with a lower gas price so that the sequence looks like this:

  1. Frontrun buy
  2. Large buy
  3. Sell

The primary defense against this attack is to provide a “slippage” parameter. If the “frontrun buy” itself pushes the price up past a certain threshold, the “large buy” order will revert, making the frontrunner fail on the trade.

It’s called a sandwich because the large buy is sandwiched by the frontrun buy and the backrun sell. 

Malicious MEV activities, such as front-running or sandwich attacks, significantly impair user experiences. As long as MEV bots exist, amateur traders have almost no chance of profiting from arbitrage opportunities they fairly identified. Users' funds are frequently exploited, as demonstrated in the "Ethereum is a Dark Forest" example. MEV-Explore reports that the total extracted MEV since January 2020 amounts to approximately $675 million (with the actual MEV estimated to be much higher) as of October 29, 2022.

The intense competition caused by PGA leads to network overload and gas fee inflation. For instance, the average gas fee skyrocketed to 474 gwei during Yuga Labs' Otherdeed sale on May 1, and miners and bots extracted $44 million in MEV on the day the Chinese government announced a ban on using crypto assets on May 19, 2021.

Malicious MEV activities can severely threaten network security and pose centralization risks. A prime example is time bandit attacks, in which MEV attackers re-execute blockchain history to steal profit, undermining network stability and trust. This type of attack can occur when block rewards are significantly smaller than MEV profits. Attackers are more likely to target smaller blockchains with weaker security.

 

Slippage Attacks

In the fast-paced realm of decentralized finance (DeFi), one significant consideration for market participants is 'slippage'. As in traditional financial markets, slippage refers to the difference between the expected price of a trade and the price at which the trade is executed. In DeFi, slippage specifically denotes the price variance that may occur from the moment a participant submits a swap trade to when the trade actually executes. While typically minimal, slippage can be substantial during volatile periods or for tokens with low liquidity, potentially leaving traders with more or frequently fewer tokens than anticipated.

In order to mitigate such risks, DeFi platforms should offer users the ability to set a 'slippage parameter'—a minimum number of output tokens they aim to receive from the swap. This feature ensures that if a swap fails to meet the specified minimum amount, the transaction will automatically reverse, thus protecting users from unfavorable market conditions. However, there are prevalent implementation errors to watch for in DeFi platforms that both developers and auditors should address.

Firstly, the absence of a slippage parameter can prove dangerous. DeFi platforms should obligate users to specify this parameter—the minimum token return they seek from a swap. It is crucial to guard against swaps that set slippage to zero, a code that signifies the user's willingness to accept a minimum of zero output tokens. This situation makes users vulnerable to massive fund losses through Miner Extractable Value (MEV) bot sandwich attacks. While platforms might provide a default value if users neglect to specify one, the user's slippage parameters should always supersede platform defaults.

Another significant factor is the inclusion of an expiration deadline. Sophisticated protocols such as Automated Market Makers (AMMs) can enable users to set a deadline parameter, which enforces a time limit for the execution of the transaction. Without a deadline, transactions can linger in the mempool, resulting in delayed execution and potentially a less favorable price for the user.

It is worth noting that setting the deadline to 'block.timestamp' provides no protection. Validators could hold the transaction, and the block it eventually falls into will align with the 'block.timestamp', negating any protective function. Consequently, users engaging with AMMs should be able to set expiration deadlines, and the absence of one could create a critical vulnerability for fund losses, especially in the absence of a slippage parameter.

In conclusion, as an investor or user in the crypto space, understanding these key features and their proper implementation is crucial to navigate the complexities of the DeFi landscape, protecting your investments from potentially significant losses due to slippage or other vulnerabilities. DeFi platforms, developers, and auditors must all work cohesively to implement and monitor these parameters effectively. As the saying goes, 'knowledge is power'—and in the world of DeFi, this wisdom holds doubly true.

How do you rate this article?

64


Michael @ CryptoEQ
Michael @ CryptoEQ

I am a Co-Founder and Lead Analyst at CryptoEQ. Gain the market insights you need to grow your cryptocurrency portfolio. Our team's supportive and interactive approach helps you refine your crypto investing and trading strategies.


CryptoEQ
CryptoEQ

Gain the market insights you need to grow your cryptocurrency portfolio. Our team's supportive and interactive approach helps you refine your crypto investing and trading strategies.

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.

Page not displaying correctly?