Papers
Topics
Authors
Recent
Search
2000 character limit reached

Cross-Chain Sandwich Attacks

Updated 26 November 2025
  • Cross-Chain Sandwich Attacks are multi-chain exploits that leverage public cross-chain messages to front-run and back-run swap transactions.
  • The attack synchronizes front-run and back-run transactions across chains, enabling attackers to extract significant profits by exploiting timing advantages.
  • Mitigation strategies such as encrypted events, private relayers, and time-lock commitments are proposed to curb information leakage and secure cross-chain communications.

A cross-chain sandwich attack is a multi-chain extension of the classic single-chain maximum extractable value (MEV) sandwich, exploiting cross-chain message leaks in decentralized finance (DeFi) protocols built around liquidity-pool-based cross-chain bridges. By eavesdropping on public on-chain events from a source blockchain, the attacker gains an information advantage, enabling the strategic placement of front-running and back-running transactions on a destination chain. This attack undermines current MEV defenses, leading to significant extractable value and threatening the security guarantees of cross-chain infrastructure (Li et al., 19 Nov 2025).

1. Formal Definition and Attacker Model

A cross-chain sandwich attack occurs between two blockchains, denoted S (source) and D (destination), connected by a cross-chain messaging protocol (CCMP), which includes Commit, Verify, Consensus, and Execute steps. The victim user UU submits a cross-chain swap intent via Commit on S, emitting a public on-chain event mm that reveals the swap parameters—token pair (X,Y)(X,Y), input amount Δxv\Delta x_v, slippage svs_v, destination liquidity pool PP, and minimum return.

An adversary A\mathcal{A} observes this event at block NsN_s before the intended swap transaction TvT_v appears in D's mempool, introducing a time advantage Δt\Delta t. The adversary computes the optimal front-running input mm0 using the slippage-equality condition: mm1 where mm2 are pre-attack reserves, and mm3 is the swap fee. The attacker times their front-run transaction mm4 prior to mm5, and then back-runs with mm6 immediately after mm7 on D.

The expected profit, accounting for noisy swaps and stochasticity, is

mm8

where mm9 is the probability of no intervening swaps, (X,Y)(X,Y)0 the probability of remaining profitable despite noise, and (X,Y)(X,Y)1 the mean positive/negative rates, respectively [(Li et al., 19 Nov 2025), Eq. 2]. In scenarios without single-chain competition, the theoretical maximum profit is (X,Y)(X,Y)2.

2. Vulnerability in Liquidity-Pool-Based Cross-Chain Bridges

Protocols such as Symbiosis, ThorSwap, and deBridge parallel single-chain AMM semantics on the destination chain but require relayers to transmit all swap parameters through on-chain events on the source chain. In standard operation:

  • Users initiate swaps via BridgeContract on S, emitting an OracleRequest event with full calldata for execution on D.
  • Relayers access and forward this public event.
  • Only during the Execute phase on D does the actual victim swap (X,Y)(X,Y)3 become pending in D's mempool.

The public emission of calldata—including assets, amounts, target pools, and slippage—provides adversaries a guaranteed information lead, unmitigated by destination-chain mempool privacy or ordering defenses. This underlying protocol design is the core enabler of cross-chain sandwich attacks (Li et al., 19 Nov 2025).

3. Execution Sequence and Attack Workflow

The attack proceeds as follows:

  1. The user submits a swap on S, triggering the emission of an OracleRequest event at (X,Y)(X,Y)4.
  2. (X,Y)(X,Y)5 monitors S, retrieves (X,Y)(X,Y)6, and locally simulates it to extract pool (X,Y)(X,Y)7, amount (X,Y)(X,Y)8, and slippage (X,Y)(X,Y)9.
  3. Δxv\Delta x_v0 computes and submits the optimal front-run transaction Δxv\Delta x_v1 on D, timed immediately after Δxv\Delta x_v2.
  4. Relayers conduct consensus and submit the victim's transaction Δxv\Delta x_v3 for execution on D.
  5. Δxv\Delta x_v4 posts the back-run transaction Δxv\Delta x_v5 immediately after Δxv\Delta x_v6, typically leveraging higher gas price or private relays to win block inclusion.
  6. Profits accrue as Δxv\Delta x_v7, where Δxv\Delta x_v8 is cumulative gas cost.

This approach yields a systematic information advantage: the attacker's Δxv\Delta x_v9 always arrives on D before any mempool-based MEV bot can react, and in back-running, empirical analysis shows attackers win the race for 55% of instances [(Li et al., 19 Nov 2025), Table VI]. The workflow by design subverts mempool-based ordering fairness by acting before svs_v0 is even visible in the destination infrastructure.

4. Heuristic Detection and Empirical Characterization

Detection of real-world cross-chain sandwich attacks is accomplished via a heuristic model tailored to historical Symbiosis bridge data. Key detection rules include:

  • Directionality: Both svs_v1 and svs_v2 execute svs_v3, while svs_v4 reverses (svs_v5).
  • Temporal windows: svs_v6 block(svs_v7) svs_v8; and svs_v9 block(PP0) PP1, where PP2 is a block search window.
  • Amount-matching: The ratio PP3 must be within PP4 to confirm economic linkage.
  • Address association: Either same recipient address or both transactions interact with the same pool.
  • Exclusion: Pairs where PP5 and PP6 are mined in the same block are classified as single-chain attacks and omitted.

This formalizes identification of sandwich pairs PP7 matching the specification above [(Li et al., 19 Nov 2025), Sec. IV-A].

Empirical Results (Symbiosis, Aug 10–Oct 10 2025)

Metric Value Note
Cross-chain swaps analyzed 60,130
Valid swaps (filtered) 37,649 95% had PP8 s
Detected sandwich pairs 316,809
Single-chain sandwiches 269 0.085% of total
Total bridged volume $412,632,065 Filtered set
Attacker profit (excl. gas) $5,273,857 1.28% of bridged volume
Largest individual profit $20,284
Unexploited profit (estimated) $1,425,500
Most attacked pool BUSD–WBNB (PancakeSwap) 57.65% attacks, 60.1% attacked vol.

The Ethereum→BSC route accrued $P91,447,602(1.691,447,602 (1.6%), and Arbitrum→BSC \\mathcal{A}$06,109 (0.12% of total) (Li et al., 19 Nov 2025).

Empirical parameter estimates: $\mathcal{A}$1, $\mathcal{A}$2, $\mathcal{A}$3, $\mathcal{A}$4, aggregate $\mathcal{A}$5. Attackers placed $\mathcal{A}$6 and $\mathcal{A}$7 in immediate proximity to source and destination events, affirming the theoretical model [(Li et al., 19 Nov 2025), Fig. 9].

5. Limitations of Existing Defenses

Prevailing MEV mitigation frameworks—including proposer/builder separation (PBS) [Yang '25], fair transaction ordering [Kelkar '20/'22/'23], and encrypted/private mempool mechanisms [Choudhuri '24/'25]—are effective only at or after the point $\mathcal{A}$8 becomes mempool-visible or block-inclusion is determined on the destination chain. Since the critical leak occurs on S, before D is engaged, these tools are structurally incapable of protecting against cross-chain sandwich attacks:

  • PBS cannot prevent $\mathcal{A}$9 from being included before $N_s$0 on D.
  • Fair ordering only governs transactions visible at D’s consensus time.
  • Mempool privacy on D offers no protection when S reveals transaction intent openly.

This indicates a fundamental gap: leakage at the cross-chain message layer is orthogonal to defenses focused solely on destination-chain transaction ordering (Li et al., 19 Nov 2025).

6. Mitigation Strategies and Protocol Redesign

Mitigating cross-chain sandwich risk requires protocols to eliminate or severely restrict the emission of actionable calldata from the source chain. Potential mitigations include:

  • Private Relayers: Transmitting $N_s$1 off-chain only to trusted relayers prevents public leaks but introduces centralization and trust issues.
  • Encrypted Events and Off-Chain Decryption: On-chain events are published in encrypted form, with execution on D triggered by a threshold decryption committee. This approach incurs complexity and on-chain cost.
  • Destination-Side Path Computation: Only generic swap intents $N_s$2 are emitted on S, with the routing/pool selection deferred to on-chain DEX aggregators at execution on D. This makes pool-guessing futile for attackers.
  • Time-Lock Commitments: Users submit hash commitments to swap details on S, revealed only after a short time delay less than $N_s$3, so adversaries cannot reconstruct full calldata ahead of D&#39;s mempool arrival.</li> </ul> <p>All effective strategies aim to sever the information flow from S to public observers prior to D’s mempool admission, fundamentally altering the risk surface for multi-chain MEV (<a href="/papers/2511.15245" title="" rel="nofollow" data-turbo="false" class="assistant-link" x-data x-tooltip.raw="">Li et al., 19 Nov 2025</a>).</p> <h2 class='paper-heading' id='significance-and-research-implications'>7. Significance and Research Implications</h2> <p>Cross-chain sandwich attacks demonstrate critical emergent vulnerabilities as DeFi infrastructure integrates cross-chain composability and liquidity. The observed profits ($5.27M, 1.28% of bridged value in two months) and systemic bypass of all existing MEV defenses highlight the urgent need for bridge and DEX designers to reconsider message flows and on-chain data exposure (Li et al., 19 Nov 2025). Current research establishes formal models for attacker behavior, supplies robust detection methodologies, and suggests protocol-level countermeasures, but secure-by-design interoperability remains an open challenge. A plausible implication is that further deployment of liquidity-pool bridges without redesign may materially worsen MEV extraction and user harm in multi-chain ecosystems.

    Definition Search Book Streamline Icon: https://streamlinehq.com
    References (1)

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Cross-Chain Sandwich Attacks.