Determine whether Solana applications cause or merely correlate with sandwich exposure

Determine whether Solana applications such as Axiom, Photon, GMGN, and BullX are themselves the source of protected-order-flow exposure that enables sandwich attacks, or whether their elevated victim rates result from correlated characteristics of the order flow they route.

Background

After validator-level exposure declines on Solana, sandwich victims become disproportionately concentrated among users of several applications. Axiom, in particular, accounts for a large share of victims and exhibits a substantial excess ratio even when users adopt Jito’s jitodontfront flag.

The concentration is consistent with application-level exposure, but the observed data cannot distinguish direct disclosure or leakage by the applications from other properties of their routed order flow, such as user behavior, liquidity selection, or submission infrastructure.

References

In the later period, the strongest signal instead appears at the application layer, although our data does not establish whether the applications themselves are the exposure source or whether correlated order flow characteristics contribute to the excess.

— No Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks  (2609.28115 - Heimbach et al., 23 Sep 2026) in Section 5.4.2, “Application-Level Exposure” (Section 5.4, Solana)