Skip to content
Blockchain

Why does switching to a private mempool still leave me open to sandwich attacks?

82

机会

Private and encrypted mempools now route more than half of Ethereum transactions, but encrypting a transaction does not hide everything a searcher needs. The trading pair, the direction of a swap, and a coarse size range can be inferred from surrounding chain state and timing metadata even when the transaction bytes are fully encrypted. A paper accepted at NeurIPS 2026 derives exact leakage thresholds at which this partial information remains sufficient to run a profitable sandwich attack against users who believe they are protected. The result is a false safety assumption: users opt into private relays and stop worrying, while searchers adapt their strategies to the residual signal that leaks through. There is no production tooling today that lets a user measure how much information their transaction leaks before they submit it, so the protection is unauditable.

为什么重要

Encryption is not privacy if the residual observable signal is enough to attack, and the first tool that quantifies per-transaction leakage turns privacy from a claim into a verifiable property.

我如何评估机会

机会评分是我的个人判断,而非量化指标:痛苦程度、发生频率,以及当前解决方案的匮乏程度。分数越高,意味着我认为越值得去构建。

严重性7/10

出现时造成的痛苦程度。

频率8/10

人们实际遇到它的频率。

空白空间9/10

当前针对它的优质工具有多匮乏。

更多值得解决的问题