Determine whether Ethereum reorgs are deliberately induced for sandwich exposure

Determine whether any observed Ethereum chain reorganizations were deliberately triggered to expose private transactions for subsequent sandwich attacks, and whether inducing such reorganizations is economically or operationally feasible under the relevant consensus conditions.

Background

Private Ethereum transactions can lose their confidentiality when they are included in a stale block that is later reorganized out of the canonical chain, because the stale block may have been publicly broadcast. The paper identifies private transactions subsequently sandwiched after re-inclusion, including transactions that were not individually visible in the public mempool.

The authors note that an attacker might theoretically profit by inducing a reorganization, for example by incentivizing validators to build on a competing branch. However, the study does not establish whether the observed reorganizations were caused for this purpose or whether such an attack would be economically or operationally viable.

References

In principle, an attacker who could induce such a reorg might profit from the resulting exposure, for example by incentivizing validators to build on a competing branch. Whether such a strategy is economically or operationally feasible depends on the consensus conditions and the cost of inducing the reorg, and our empirical evidence is not sufficient to determine whether any of the observed reorgs were triggered for this purpose.

— No Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks  (2609.28115 - Heimbach et al., 23 Sep 2026) in Section 5.1.4, “Reorged Blocks” (Section 5.1, Ethereum)