MEV bots steal 3% from every swap. $60M/year. Here's how to stop them.

Your DEX Trade Just Cost You 3% More Than You Saw on Screen. Here's the $60 Million Machine Doing It - And Why Nobody Warned You.

By Crypto Strategist | Dr Kamran Jalali | 3 hours ago


You saw the price. You clicked swap. You paid the gas. And somewhere between your finger lifting off the mouse and the transaction confirming on-chain, a machine took a cut you never agreed to.

Not a protocol fee. Not slippage you accepted. A hidden tax extracted by a bot that watched your trade in the public mempool, jumped in front of it, pushed the price against you, and pocketed the difference before your transaction even finished.

This is MEV. And if you've traded on a decentralized exchange in the last year, you've paid it. Probably dozens of times. The only question is whether you knew it was happening.

Here's the part that should make you angry. The biggest predator in this ecosystem, a bot responsible for roughly 70% of all sandwich attacks on Ethereum, just became prey itself. In June 2026, someone drained jaredfromsubway.eth for more than $7.5 million by turning its own automated logic against it. The machine that spent years stealing from traders got outsmarted by a better machine.

If that isn't a wake-up call, nothing is.

What MEV Actually Is (Without the Computer Science Degree)

MEV stands for Maximal Extractable Value. The name sounds technical, but the concept is simple. Blockchains are public. Before your transaction gets confirmed, it sits in a waiting area called the mempool where anyone can see it. Bots scan this waiting area, look for profitable opportunities, and pay validators to reorder transactions so the bot's trade executes before yours, changing the price in its favor.

Think of it like this. You're at an auction. You raise your paddle to bid $1,000 on a painting. Before the auctioneer can acknowledge your bid, someone in the front row shouts "$1,050," the auctioneer accepts it, and then that same person immediately sells the painting to someone else for $1,000. You never got the painting. But your attempted bid moved the market just enough for the front-row bidder to profit.

That's a sandwich attack. And it happens thousands of times per day.

Not all MEV is harmful. Arbitrage bots that equalize prices across exchanges provide a genuine service. Liquidation bots that close underwater loans keep lending protocols solvent. But sandwich attacks are pure extraction. They add no value to the network, improve no market efficiency, and exist solely to transfer money from your wallet to a bot operator's wallet.

There are three types worth knowing:

Arbitrage MEV — beneficial. A bot notices ETH is $1,800 on Uniswap and $1,805 on SushiSwap. It buys low, sells high, and prices converge. You lose nothing. The market works better.

Liquidation MEV — neutral. A bot closes someone's underwater loan on Aave before the borrower can add collateral. The borrower gets liquidated. The protocol stays healthy. You lose nothing unless you're the one being liquidated.

Sandwich MEV — harmful. This is the one that costs you money directly. The bot sees your trade, buys the asset before you, lets your trade push the price up, then sells immediately after. You receive fewer tokens than you should have. The bot captures the difference.

On Ethereum alone, sandwich attacks cost traders approximately $60 million between November 2024 and October 2025. On Solana, the figure is even more staggering. Bots extracted between $370 million and $500 million over a 16-month period ending in May 2025.

This is not a rounding error. This is a systematic wealth transfer from retail traders to automated predators. And until recently, almost nobody talked about it.

The $60 Million Sandwich Machine

Here's exactly how it works. No metaphors. No hand-waving. Just the mechanics.

You open your wallet. You want to swap 1,000 USDC for ETH. The DEX quotes you 0.55 ETH at the current price. You set your slippage tolerance to 1% because you've been told that's reasonable. You submit the transaction.

Your transaction enters the mempool. It sits there, visible to everyone, while it waits for a validator to include it in the next block.

A bot sees it. The bot calculates that your $1,000 swap will move the price of ETH in the pool by roughly 0.3%. The bot also sees your 1% slippage tolerance, which means your trade will still execute even if the price moves against you by 1%.

Here's what the bot does.

Step one: Front-run. The bot submits its own transaction with a higher gas fee, ensuring it gets included before yours. It buys ETH from the same pool. This pushes the price up.

Step two: Your trade executes. Because of the bot's purchase, the pool now has less ETH and more USDC. The price has moved. Your 1,000 USDC now buys 0.542 ETH instead of 0.55 ETH. You still get ETH. You just get less than you were quoted. Because the price moved less than your 1% slippage tolerance, your trade goes through. You never see a failure message. You never know you were robbed.

Step three: Back-run. The bot immediately sells its ETH back into the pool. The price returns to roughly where it started. The bot pockets the difference between what it paid for the ETH and what it sold it for.

The entire attack fits inside a single block. It takes seconds. You receive your tokens, check the amount, and assume the difference between what you expected and what you got is just "how DEXs work."

It isn't. It's a hidden tax. And you just paid it.

The math gets worse as your trade size grows. A $10,000 swap in a thin liquidity pool might lose 2-3% to a sandwich attack. A $50,000 swap could lose 5% or more. And because the attack happens inside your slippage tolerance, you have no automatic protection unless your slippage is set lower than the bot's expected profit margin.

In 2025, approximately 38% of all sandwich attacks on Ethereum targeted stablecoin pools. Think about that. Stablecoins are supposed to be the safest trades. USDC to USDT should move barely at all. Yet a single USDC-to-USDT swap on Uniswap v3 lost a trader over $215,000 to a sandwich attack. The bot didn't care that the assets were stable. It cared that the trade was large and the slippage was loose.

The Bot That Ate Ethereum — And Then Got Eaten

If MEV bots were a movie villain, jaredfromsubway.eth would be the final boss.

This single bot was responsible for roughly 70% of all sandwich attacks on Ethereum. It operated with machine-speed precision, scanning every pending transaction, calculating profitability, and executing attacks across thousands of trades per day. The name was a joke. The operation was not.

For years, jaredfromsubway.eth was the invisible hand picking pockets across the Ethereum ecosystem. It didn't discriminate between small traders and whales. It didn't care if you were swapping $100 or $100,000. If the math worked, the bot attacked.

Then, in June 2026, the predator became prey.

An attacker spent several weeks setting a trap. They deployed dozens of fake token contracts and fake liquidity pools that looked like profitable MEV opportunities. Some mimicked familiar assets like wrapped ETH (WETH), USDC, and USDT. The pools appeared real. The tokens appeared real. The opportunities appeared genuine.

Jaredfromsubway.eth's bot did what it always did. It scanned the mempool, saw what looked like a profitable trade, and generated approvals for helper contracts to spend tokens on its behalf. Those approvals were used normally in earlier tests. But later, the attacker created routes where the approvals stayed open.

Then they struck. The attacker used those open approvals to drain more than $7.5 million from the bot's wallets. Some funds were routed through Tornado Cash, a mixing service that obscures transaction trails.

Security firm Blockaid confirmed the incident was not a normal phishing attack and not a simple contract bug. The attacker targeted the bot's decision-making system itself. The machine that had spent years exploiting human traders was outsmarted by a human who understood how machines think.

The irony is almost poetic. But the lesson is practical. If the most sophisticated MEV bot in Ethereum history can be exploited through its own automation, what chance does your average trader have?

The answer is: not much, unless you actively protect yourself.

It's Not Just Ethereum

Most coverage of MEV focuses on Ethereum because that's where the data is most visible. But Solana might actually be worse for retail traders.

On Solana, MEV bots extracted between $370 million and $500 million over a 16-month period ending in May 2025. The per-attack profits are often larger because Solana's lower fees make it cheaper to run aggressive strategies. A bot can attack smaller trades and still profit because the cost of front-running is minimal.

Ethereum's high gas fees create a natural floor. A sandwich attack needs to extract more than the gas cost to be profitable. On Solana, that floor is almost nonexistent. A bot can profit from a $50 swap. On Ethereum, the same attack might cost more in gas than it could extract.

This means Solana traders face MEV on a volume basis that Ethereum traders don't. Every swap, no matter how small, is potentially a target. The cumulative effect is a death by a thousand cuts.

And here's what makes this particularly relevant now. As Ethereum Layer-2s like Arbitrum and Optimism reduce gas costs, they're importing Solana's MEV problem. Cheaper transactions mean more attacks on smaller trades. The MEV ecosystem is expanding, not contracting.

The Bigger Picture: Perpetual Futures Manipulation

Sandwich attacks on DEX swaps are visible. You can see them on Etherscan. You can calculate exactly what you lost. But there's a parallel manipulation happening in perpetual futures that is even harder to detect.

James Davies, a derivatives veteran who tried to launch perpetual futures in 2013, warned about this exact problem over a decade ago. Institutional investors killed his product because they realized the funding rate mechanism could be gamed.

Here's how it works. Perpetual futures use a funding rate paid every eight hours to keep the contract price aligned with the spot price. If the perpetual trades above spot, longs pay shorts. If it trades below, shorts pay longs.

The manipulation is simple. A large player pushes the spot price above or below the funding rate calculation point for just a moment. The funding rate gets calculated based on that manipulated price. The attacker collects the funding payment. Then they unwind their position.

Davies estimated that for small altcoins, $250,000 could generate thousands of percentage points in annual return through this manipulation. For Bitcoin on Binance, extracting 5-8% annually might require $200 million. For mid-cap stocks, if they ever launched perpetuals, the same trick could yield 5% with minimal capital risk.

"This is happening every single day," Davies said. "I see entities that are running this. Market-makers nod and smile and look the other way."

The connection to MEV is clear. Both exploit the same structural weakness: a public, transparent system where the moment of price discovery can be manipulated by those with enough capital and speed. Your DEX swap gets sandwiched. Your perpetual position gets funding-gamed. The machine wins both ways.

How to Check If You've Already Been a Victim

Most traders don't know they've been sandwiched because the attack leaves no obvious trace. Your trade succeeds. You receive tokens. The only difference is you received slightly fewer than you should have.

Here's how to check.

Step 1: Find your transaction hash. Open your wallet history, locate the swap, and copy the transaction hash.

Step 2: Paste it into Etherscan. Look at the transaction details. Check the "Value" or "Token Transfer" section. Compare the amount you expected to receive with the amount you actually received.

Step 3: Look at surrounding transactions. In the same block, do you see two transactions from the same address — one buying the token before yours, and one selling it after? If yes, you were almost certainly sandwiched.

Step 4: Use a free MEV tracker. Tools like EigenPhi, MEV-Explore, or Flashbots' MEV-Share dashboard can show you historical MEV extraction. Some wallets now include MEV loss tracking in their transaction history.

If you trade regularly, the cumulative amount you've lost to MEV probably exceeds your total gas fees for the year. For active traders, it might exceed your gas fees for several years.

The Protection Guide (Do This Now)

You can't eliminate MEV exposure entirely without stopping trading. But you can reduce it dramatically. Here's exactly how.

Use Flashbots Protect. This is the single most effective tool. Flashbots Protect sends your transaction through a private relay, bypassing the public mempool where MEV bots hunt. Your transaction only becomes visible after it's already included in a block. No mempool, no sandwich attack.

Setting it up takes two minutes. In MetaMask, go to Settings > Networks > Add Network, and add the Flashbots Protect RPC endpoint. For other wallets, visit protect.flashbots.net and follow the instructions. Some wallets like Rabby and Rainbow have Flashbots Protect built in as a default or toggle option.

Set slippage correctly. Most DEXs default to 0.5% or 1% slippage. For stablecoin swaps, set it to 0.1% or lower. For volatile assets, 0.5% is usually enough. The higher your slippage, the more room you give bots to work. A 5% slippage setting is an open invitation.

Break large trades into smaller chunks. A $10,000 swap is a juicy target. Ten $1,000 swaps are less attractive because the profit per attack drops while the gas cost stays roughly the same. Yes, you pay more in total gas. But you lose far less to MEV.

Use MEV-resistant DEXs. CowSwap uses batch auction pricing, which makes sandwich attacks structurally impossible. All trades in a batch execute at the same price, so there's no way to front-run or back-run individual transactions. Other options include MEV Blocker and certain aggregator routes that use private relays by default.

Avoid low-liquidity pools. Thin liquidity means your trade moves the price more, which means more profit for a sandwich bot. Stick to deep pools for major pairs. If you need to trade an exotic token, consider doing it on a centralized exchange where MEV doesn't exist in the same form.

Check your token approvals. The jaredfromsubway.eth attacker didn't exploit a code bug. They exploited open token approvals. If you've approved unlimited spending for a DEX or protocol, revoke approvals you no longer use. Tools like Revoke.cash make this easy.

What the Future Looks Like

The Ethereum community has proposed MEV-Burn, a protocol change that would destroy MEV profits instead of giving them to validators. The idea is elegant: if validators can't profit from MEV, the incentive to extract it disappears.

But the reality is messier. MEV-Burn might push extraction underground, onto private mempools, or onto other chains with less protection. It might also reduce validator revenue, potentially threatening network security if staking becomes less attractive.

Solana is experimenting with different approaches, including localized fee markets and priority fee structures that make sandwich attacks more expensive. But none of these solutions are live at scale yet.

The uncomfortable truth is that MEV is a feature of transparent, permissionless blockchains, not a bug. As long as transactions are visible before confirmation and prices move based on trade size, someone will find a way to profit from the ordering. The best you can do is minimize your exposure.

Key Takeaways

  1. MEV bots extracted $60 million from Ethereum traders in one year and $370-500 million from Solana traders in 16 months. This is not a fringe issue. It's a systematic tax on every DEX user.
  2. Sandwich attacks work by front-running and back-running your trade, pushing the price against you while you pay the difference. Your slippage tolerance is the bot's profit margin.
  3. The biggest MEV bot in Ethereum history, jaredfromsubway.eth, was itself drained of $7.5 million in June 2026. If the predator can become prey, no trader is safe without protection.
  4. Perpetual futures face a parallel manipulation problem where funding rates get gamed by large players pushing spot prices at calculation moments.
  5. Protection is straightforward: use Flashbots Protect, set tight slippage, break large trades into chunks, use MEV-resistant DEXs like CowSwap, and revoke unused token approvals.
  6. Check your past transactions. You've probably been sandwiched dozens of times. The cumulative cost is real money that belongs in your wallet, not a bot's.

16. FAQ SECTION

Q: Can MEV bots steal my entire wallet balance?

A: No. Sandwich attacks only affect the specific trade you're making. But unlimited token approvals (which many DEXs request) can put your entire balance at risk if a malicious contract exploits them. Always use limited approvals when possible.

Q: Is MEV illegal?

A: Not currently. Sandwich attacks exploit protocol design, not code vulnerabilities. They occupy a legal gray area. Arbitrage MEV is generally considered legitimate market activity. The line between "smart trading" and "harmful extraction" remains legally undefined.

Q: Do centralized exchanges have MEV?

A: Not in the same form. CEXs control their own order books and matching engines. While they have their own manipulation risks (wash trading, spoofing), the specific MEV mechanisms of public blockchains don't apply.

Q: How much does Flashbots Protect cost?

A: Nothing. It's a free RPC endpoint. You might pay slightly higher gas fees because your transaction goes through a private relay, but the protection from MEV attacks usually saves you far more than the extra gas costs.

Q: Does MEV exist on Layer-2s?

A: Yes, though typically at lower volumes. As Layer-2 gas costs decrease, MEV activity is increasing. Arbitrum and Optimism both see sandwich attacks, though the economics are different from Ethereum mainnet.

Q: Can I sue a MEV bot operator?

A: Practically, no. Most MEV bots operate anonymously. Even if identified, the legal framework for prosecuting MEV extraction doesn't exist in most jurisdictions.

Q: Will Ethereum 2.0 or future upgrades fix MEV?

A: No. The shift to Proof of Stake actually created more consistent MEV opportunities for validators. Future upgrades like MEV-Burn might reduce incentives but won't eliminate the structural problem entirely.

Disclaimer:

This article is for informational and educational purposes only. It does not constitute financial, investment, or legal advice. The author is not a financial advisor, and nothing in this article should be interpreted as a recommendation to buy, sell, or hold any cryptocurrency or use any specific trading tool or platform. MEV protection tools and strategies mentioned carry their own risks, including smart contract vulnerabilities, RPC failures, and user error. Past performance of any security, strategy, or protocol does not guarantee future results. Cryptocurrency trading involves substantial risk of loss. Always conduct your own research (DYOR) and consult a qualified professional before making financial decisions. The statistics and figures cited are sourced from third-party analytics platforms and represent estimates, not audited financial statements.

Transparency:

The author has no financial relationship with any of the tools, protocols, or companies mentioned in this article. No affiliate links are included.

How do you rate this article?

3


Crypto Strategist
Crypto Strategist

I am Dr. Kamran Jalali, Crypto researcher & educator. Deep analysis on crypto trends, AI tokens, RWA, and smart money, in plain language. No hype. Just honest research to help you make smarter decisions.


Dr Kamran Jalali
Dr Kamran Jalali

Most people lose money in crypto not because the market is against them — but because nobody ever taught them the rules of the game. I am Dr. Kamran Jalali. I write about crypto in plain, simple language that anyone can understand — no confusing jargon, no hype, no false promises. Here you will find honest breakdowns of how crypto really works, why traders fail, how to protect your money, and how to make smarter decisions in the digital asset world. Whether you are completely new to crypto or have been in

Publish0x

Send a $0.01 microtip in crypto to the author, and earn yourself as you read!

20% to author / 80% to me.
We pay the tips from our rewards pool.