Skip to content
Blockchain

Why does switching to a private mempool still leave me open to sandwich attacks?

82

Opportunità

Private and encrypted mempools now route more than half of Ethereum transactions, but encrypting a transaction does not hide everything a searcher needs. The trading pair, the direction of a swap, and a coarse size range can be inferred from surrounding chain state and timing metadata even when the transaction bytes are fully encrypted. A paper accepted at NeurIPS 2026 derives exact leakage thresholds at which this partial information remains sufficient to run a profitable sandwich attack against users who believe they are protected. The result is a false safety assumption: users opt into private relays and stop worrying, while searchers adapt their strategies to the residual signal that leaks through. There is no production tooling today that lets a user measure how much information their transaction leaks before they submit it, so the protection is unauditable.

Perché è importante

Encryption is not privacy if the residual observable signal is enough to attack, and the first tool that quantifies per-transaction leakage turns privacy from a claim into a verifiable property.

Come valuto l'opportunità

L'Opportunity Score è la mia valutazione personale, non una misurazione: quanto fa male, con quale frequenza colpisce e quanto poco esiste per risolverlo oggi. Un punteggio più alto significa che lo ritengo più degno di essere sviluppato.

Gravità7/10

Quanto dolore provoca quando si manifesta.

Frequenza8/10

Quanto spesso le persone ci si imbattono davvero.

Spazio bianco9/10

Quanti pochi strumenti validi esistono oggi per affrontarlo.

Altri problemi che vale la pena risolvere