Why does switching to a private mempool still leave me open to sandwich attacks?
κΈ°ν
Private and encrypted mempools now route more than half of Ethereum transactions, but encrypting a transaction does not hide everything a searcher needs. The trading pair, the direction of a swap, and a coarse size range can be inferred from surrounding chain state and timing metadata even when the transaction bytes are fully encrypted. A paper accepted at NeurIPS 2026 derives exact leakage thresholds at which this partial information remains sufficient to run a profitable sandwich attack against users who believe they are protected. The result is a false safety assumption: users opt into private relays and stop worrying, while searchers adapt their strategies to the residual signal that leaks through. There is no production tooling today that lets a user measure how much information their transaction leaks before they submit it, so the protection is unauditable.
μ μ€μνκ°
Encryption is not privacy if the residual observable signal is enough to attack, and the first tool that quantifies per-transaction leakage turns privacy from a claim into a verifiable property.
κΈ°ν νκ° λ°©μ
κΈ°ν μ μλ μΈ‘μ κ°μ΄ μλ μ μ£Όκ΄μ νκ°μ λλ€. μΌλ§λ λΆνΈνμ§, μΌλ§λ μμ£Ό λ°μνλμ§, νμ¬ ν΄κ²°μ± μ΄ μΌλ§λ λΆμ‘±νμ§λ₯Ό λ°μν©λλ€. μ μκ° λμμλ‘ λ§λ€ κ°μΉκ° λ λλ€κ³ μκ°ν©λλ€.
λ°μνμ λ μΌλ§λ ν° λΆνΈμ μ΄λνλμ§.
μ€μ λ‘ μΌλ§λ μμ£Ό μ νκ² λλμ§.
νμ¬ μ΄λ₯Ό ν΄κ²°ν λ§ν λκ΅¬κ° μΌλ§λ λΆμ‘±νμ§.
ν΄κ²°ν κ°μΉ μλ λ λ§μ λ¬Έμ λ€
μμ‘μ 곡κ°νμ§ μκ³ μ§κΈ λ₯λ ₯μ μ¦λͺ ν μ μλ μ΄μ λ 무μμΌκΉ?
Blockchainμ²΄μΈ κ° μκΈ μ΄λμ΄ μ΄κΈ° μΈν°λ·λ³΄λ€ μμ§λ λ 무μμ΄ μ΄μ λ 무μμΌκΉ?
Blockchainκ·μ μ€μκ° μμ§λ PDF ν μ₯κ³Ό κΈ°λμ μμ‘΄νλ μ΄μ λ 무μμΌκΉ?
Blockchainμ μ ν 컀μ€ν°λλ μ¬μ ν ν€λ₯Ό μμ΄λ²λ¦¬κ±°λ νμ¬λ₯Ό μ λ’°νλ κ² μ¬μ΄μ μ νμΈκ°?
Blockchainμ€λ¬Ό μμ°μ ν ν°ννλ λ° μ μμ§λ μ€κ°μΈμ΄ μ΄ λͺ μ©μ΄λ νμν κΉμ?
Blockchainμ€ν μ΄λΈμ½μΈμ μ μΈν°λ· μμ΄ κ²°μ ν μ μμκΉμ?