Great to see rigorous work on why private order flow is sometimes exploited. The big two vectors for Ethereum: - OFAs that dangerously share full tx info with trusted searchers (that turn out to be untrustworthy) - User error that destroys the security model of OFAs
🚨 New paper alert 🚨 No Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks w/ Ozan Solmaz @boez95 @ChristofTorres Bots watch every pending trade in Ethereum's public mempool and sandwich the ones worth attacking. Hence the nickname: the dark forest. In response, Ethereum and other chains built protections, from private RPCs to mechanisms native to the chain, that shield trades from these bots. We call this protected order flow. How well are these users actually protected? We measured it in a three-year study of sandwich attacks by persistent bots against protected order flow on Ethereum, Solana, Tron, Base, Arbitrum, and Monad. The protections on these chains range from private RPCs on Ethereum and private submission to a centralized sequencer on Base and Arbitrum, to first-come-first-served ordering in Tron's public mempool and local mempools on Solana and Monad. Local mempools were never meant as a full front-running prevention, but they do limit who sees a trade before it lands. On four of the six chains, we observe protected order flow sandwich attacks: 28.0M attacks on Solana, 38,567 on Tron, 30,607 on Ethereum plus 2,576 more through reorged blocks, and 1,889 on Base. We trace each chain's exposure and find that it sits in various places along a transaction’s path. 🟠 Ethereum: OFAs can expose enough information to make private trades sandwichable, especially when the same transaction reaches multiple OFAs or when searchers receive full transaction details. Reorged blocks also expose private transactions. We find transactions that were private and untouched in a block that got reorged, and then sandwiched on the canonical chain. 🟠 Solana: transactions are sent to the upcoming leaders, and early on we find that a few leaders carry far more attacks in their blocks than their share of blocks, i.e., they are likely the exposure source for these transactions. From 2025 that fades, but we see that victims concentrate around a few apps. 🟠 Tron: we presume that bots win latency races in the public mempool, so the first-come-first-served ordering in block building does not fully prevent sandwiches. 🟠 Base: we see two different kind of exposure. One lines up with a documented RPC bug that exposed pending transactions. The other has attackers preying on victims who trade on a predictable schedule, if the vicim does the same trade every couple of blocks, the attacker can front-run them without observing the pending trade. Protected order flow sandwiches look very different from public mempool sandwiches. The attacker's transactions often land in a different block than the victim's, and unlike in the public mempool, their success is not guaranteed. These attackers simply don't act with the same certainty. The dark forest may have shrunk, but we show there's an even darker corner of it, where users who think they're protected still get front-run. Protection has to hold at every layer, from the app to the RPC to the block producer. Encrypted mempools and TEE-based designs can help, by keeping transaction contents out of attackers' reach until inclusion. But even they might not be enough on their own without privacy, for example if the victim is too predictable. Link: arxiv.org/abs/2609.28115
2
42
2,682
Bringing prediction markers to the L1 just as we give builders a free option to cancel payloads after the fact.
Glad to see that Ethereum L1 will have a new strong prediction market contender that is dedicated to decentralization, and being ethical and not corposlop, and to actually trying to do interesting and meaningful things with this class of economic primitive. firefly.social/post/x/210212…
1
2
24
2,517
Dune has been the most important cultural tool for crypto data b/c its generous free plans + emphasis on query code visibility removed the trust and accessibility barriers to being an anon. Sad to see, but obviously smart for business. Time to build your own pipelines.
Open onchain data built a generation of analysts, including myself. It’s time to give back. We need an Onchain Data Foundation: > Onchain data education > Sustainable access to tools like Dune for upcoming analysts How do we fund this and who wants to help build it?
2
44
4,048
An aggressive slot time reduction should have been the Hegotá headliner, but that time has passed. If we don't at least lay the groundwork now for it to happen in future forks, we're likely going to have 12 second slots for many more years to come. Ship quick slots.
We published a (very!) detailed snapshot of our thinking on Hegotá priorities. You’ll hear me continue to discuss faster ethereum and faster blocks in the coming weeks, we think this is a critical one to get done here.
2
11
67
8,373
This echoes my opinion of the current issuance EIP. I'm not against reducing rewards, but I think we should be more ambitious than simply changing changing the curve. Let's target the stakers that provide outsized value to the network (minority client, geographically decentralized, solo stakers, etc.) and find sybil resistant ways to pay them outsized shares of issuance. The strongest version we have ready today is correlation penalties (EIP-7716, let's increase the parameters massively), but we should envision a world with proofs of client usage, rewards that taper off when many validators are run on the same machine, and some form of proof-of-location. These are non-trivial, but I think it's what we should build towards. Also, we if we're worried about the staking ratio climbing in the short-term, then we should set the churn limit to dynamically decrease and slow the climb. Cut it in half for now and it buys us twice the time (in the projected worst case).
The thing I don't like most about cutting issuance discource is lack of positive vision for Ethereum validator set. Original design was not prescient enough, but has clear design goals: hundreds of thousands of individual stakers, running Ethereum all across the world. Status quo proponents also have a version of positive vision - e.g. Lido has built community staking, is decentralizing and geographically distributing validator set. We're successfully making a staking protocol that can bring Ethereum closer to original goals via opinionated, non-neutral decisions that base protocol can't adopt. Cutting is just "do it or it's going to get worse", no clear vision of good validator set we're solving for. They're given up on original vision, but don't want to clearly admit it and offer a new one.
3
5
40
3,446
imo two things are true: - changing the issuance curve makes ETH less credible - the protocol overpays for security with ugly long-term effects Whether the community embraces or rejects this, debating it every six months means that we have only the drawbacks of both issues.
🚨 New EIP: Tapered Issuance Burn We just submitted an EIP to ethereum/EIPs: a minimal, market-driven fix to Ethereum's issuance policy removing the incentive for stake growth beyond 50% of ETH supply. EIP-8361 by @pintail_xyz, @jdetychey, @dapplion, @pa7x1, @ladislaus0x & @drakefjustin 🧵
12
8
58
6,328
dataalways ⚡️🤖 retweeted
MEV-SBC’26 kicks off in 5 minutes! Join us at the Stanford alumni center or via the livestream vimeo.com/event/6044800
1
3
6
550
best mev conference of the year 🔥🔥🔥
Please join us for MEV-SBC '26 tomorrow! 📍 Thursday, July 30, 9:30 AM @ Stanford This annual workshop highlights the past year of MEV research and surfaces problems worth exploring next in cryptography, mechanism design, data, P2P, consensus, incentives, and their intersections
1
5
1,180
dataalways ⚡️🤖 retweeted
Privacy isn't a FEATURE. It's the HABITAT. @phildaian from Flashbots at shaperotator.day Brooklyn, NY
2
9
35
5,180
dataalways ⚡️🤖 retweeted
The agenda for MEV-SBC '26 is live! 📍 Thursday, July 30 @ Stanford This annual workshop highlights the past year of MEV research and surfaces the problems worth exploring next in cryptography, mechanism design, data, P2P, consensus, incentives, and where they intersect.
6
14
63
25,872
dataalways ⚡️🤖 retweeted
Announcing Ethlabs: a non-profit R&D lab for Ethereum and ETH Our mission is to make Ethereum the settlement layer of the global economy. The internet became global because shared protocols created a common language between networks. Private systems remained useful, but bounded. Finance is approaching a similar moment. As value, assets, and markets become digital, the world needs shared settlement infrastructure. Ethereum is uniquely positioned to become that shared base layer, the neutral foundation on which users, institutions, and agents can transact without intermediation. What we believe: • We believe credible neutrality matters. Ten years of uptime and the lowest counterparty risk. Ground that cannot be pulled away by any one country, institution, company, or person. • We believe ETH matters. The most valuable, programmable store of value. A decade of broad distribution, deep liquidity in onchain markets, and maximally trustless asset on Ethereum. • We believe DeFi matters. Markets, liquidity, credit, exchange, and coordination, open to anyone. • We believe adoption matters. Principles do not change the world until people benefit from them. We sit between two worlds: real usage from the builders at the frontier, and the protocol that has to support it. We work with users, applications, wallets, L2s, infrastructure teams, institutions, ETH holders, core devs and researchers, then turn what they actually need into protocol work, shared standards, infrastructure, and shipped products. Ethlabs is independent but Ethereum is a shared project. We are one node in a much larger network of stewards. This is the multi-node future. We have spent the better part of the past decade contributing to Ethereum core research and development. We are opinionated and transparent. We move with urgency, learn in public, and course-correct when we’re wrong. We are building a lean, talent-dense team for people who want to do the most important work of their careers: join@ethlabs.org
532
1,023
4,455
1,826,544
Long overdue CL diversity update: Lighthouse usage was steady for a while but seems to be increasing again the past couple months. Proposers using LH exclusively now account for ~50% of the slots we get requests in at Flashbots relay.
Replying to @dataalways
Lighthouse usage continues to climb. Proposers using the client exclusively make up about 47%, but almost all multi-client setups include it as well: about 57% of proposers use at least some Lighthouse. If we add in Vouch (unknown composition) this grows as high as 70%.
4
6
35
6,840
Prysm continues to be downonly. Still the second biggest client, but incredibly distant to Lighthouse. It doesn't look like the outage/bug they had late last year caused a big exodus, mostly just long-term trending down.
1
8
843
Nimbus and Lodestar have seen upticks in multi client setups. Lodestar usage jumped over 5x in one day earlier this year, probably from a single large proposer set adding it to their setup.
2
16
2,054
truly incredible.
“I said to YOU to never sell your Bitcoin. I never said that THE COMPANY wouldn’t sell its Bitcoin.” Jesus Christ.
1
7
933
dataalways ⚡️🤖 retweeted
With Quasar now integrated, PropAMMs are quoting in 94% of mev-boost blocks!
We are now live with a @titanbuilderxyz compatible propAMM maker quote update web-socket. Please see our documentation at docs.quasar.win/propamm/make… More to come soon as we start to bring on more market makers and volume!
7
37
4,154
dataalways ⚡️🤖 retweeted
As of today, BuilderNet supports prioritised updates This means propAMMs and other designs that want to prioritise some calls over others are now feasible This + Titan's announcement earlier this week mark the beginning of a new chapter in transaction execution on Ethereum with a whole new set of challenges, opportunities and unknown unknowns (definitely tighter spreads) Making this new market efficient and reducing the need to rely on trusted intermediaries will require a lot of coordination across the ecosystem As a first step, we want landing updates to be permissionless. So we're launching v0 of a registry format we hope will become an industry standard - one where builders don't need to trust the prioritised updater. We've been collaborating with other builders and DeFi teams on this behind the scenes - post coming soon. Landing updates is just the beginning, we're cooking on several related features. Some of them are predictable, some of them are not - stay tuned. Docs in next tweet
8
13
78
18,095
Meet 0x841: a fresh sandwich bot lurking in the dark forest--currently attacking about 1500 users per day, while going almost unnoticed. What's particularly scary: most of the victims are using private mempools and should be protected.
21
39
267
49,420
These attacks flip the usual competitive dynamics on their head. Traditional sandwiches are low-risk and competitive, with most of the revenue bid away to the proposer. These attacks are riskier for the bot, but face little competition—letting 0x841 keep more of the value.
1
1
17
2,529
We need stronger cryptographic guarantees around order flow. Handshakes and legal agreements are not enough. In the short term, that means moving as much as possible into TEEs. In the long term, it means building encrypted mempools that preserve execution quality.
1
4
30
3,114