{"id":22013,"date":"2025-03-13T11:02:00","date_gmt":"2025-03-13T09:02:00","guid":{"rendered":"https:\/\/forklog.com\/en\/sandwich-attack-victim-swapped-732583-for-18636\/"},"modified":"2025-03-13T11:02:00","modified_gmt":"2025-03-13T09:02:00","slug":"sandwich-attack-victim-swapped-732583-for-18636","status":"publish","type":"post","link":"https:\/\/forklog.com\/en\/sandwich-attack-victim-swapped-732583-for-18636\/","title":{"rendered":"Sandwich-attack victim swapped $732,583 for $18,636"},"content":{"rendered":"<p>A cryptocurrency trader <a href=\"https:\/\/etherscan.io\/tx\/0xee9fcd2b9996e96b642cb4cda47fc140f98fdaf07ee02657743d4bfcc4670106\">swapped<\/a> about $732,583 in USDC for about $18,636 in USDT across six separate swaps, falling victim to a large sandwich attack.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Unknown entity got sandwiched for 714k today on six separate USDC -> USDT swaps. (Traded with 100% slippage allowed.)<\/p>\n<p>They swapped 732583.429405 USDC for 18636.232611 USDT.<\/p>\n<p>A promised ?: <a href=\"https:\/\/t.co\/0rFNE4DfoP\">pic.twitter.com\/0rFNE4DfoP<\/a><\/p>\n<p>\u2014 DeFiac (@TheDEFIac) <a href=\"https:\/\/twitter.com\/TheDEFIac\/status\/1899875034065494491?ref_src=twsrc%5Etfw\">March 12, 2025<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The trader used the USDC\u2013USDT liquidity pool on Uniswap v3.<\/p>\n<p>According to The DeFi Report founder Michael Nadeau, an MEV bot front-ran the trader\u2019s transaction, creating a price disparity between the two assets. The bot also instructed block builder bobTheBuilder to process its transaction first.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Is anyone safe using DeFi?<\/p>\n<p>A user on <a href=\"https:\/\/twitter.com\/Uniswap?ref_src=twsrc%5Etfw\">@Uniswap<\/a> v3 was just sandwiched attacked out of $216k while simply trying to swap $221k USDC to USDT.<\/p>\n<p>Mind you, this was a pool that had over $35m of USDC and USDT it.<\/p>\n<p>This is insane.<\/p>\n<p>How did it happen?<\/p>\n<p>An MEV bot front-ran the tx by\u2026 <a href=\"https:\/\/t.co\/cyzu4M6qfz\">pic.twitter.com\/cyzu4M6qfz<\/a><\/p>\n<p>\u2014 Michael Nadeau | The DeFi Report (@JustDeauIt) <a href=\"https:\/\/twitter.com\/JustDeauIt\/status\/1899869531511660688?ref_src=twsrc%5Etfw\">March 12, 2025<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cThis is insane. Keep in mind that this was a pool that had over $35m in USDC and USDT,\u201d<\/em> he lamented.<\/p>\n<\/blockquote>\n<p>To extract additional profit, the attacker uses specialised bot software to scan the mempool for large pending swap trades on decentralised platforms.<\/p>\n<p>He then initiates two transactions \u2014 before and after the victim\u2019s planned swap \u2014 forming a \u201csandwich\u201d. The first inflates the price of the coins the victim is buying. The second realises profit by selling the assets.<\/p>\n<p>The specialist offered several recommendations to avoid a similar fate:<\/p>\n<ol class=\"wp-block-list\">\n<li>Reduce slippage on your transactions.<\/li>\n<li>Do not use Uniswap. Switch to Cowswap or another aggregator that can provide better execution and prevent MEV.<\/li>\n<li>Use a custom <span data-descr=\"remote procedure call\" class=\"old_tooltip\">RPC<\/span> that does not broadcast your transactions publicly.<\/li>\n<\/ol>\n<p>DeFi Llama developer 0xngmi suggested that \u201creally bad swaps\u201d disguised money laundering.<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\">\n<p lang=\"en\" dir=\"ltr\">i think some of these really bad swaps could be money laundering<\/p>\n<p>if you have NK illicit funds you could construct a very mev-able tx, then privately send it to a mev bot and have them arb it in a bundle<\/p>\n<p>that way you wash all the money with close to 0 losses<\/p>\n<p>\u2014 0xngmi (@0xngmi) <a href=\"https:\/\/twitter.com\/0xngmi\/status\/1899781324010914112?ref_src=twsrc%5Etfw\">March 12, 2025<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cYou can create an MEV-compatible transaction, then privately send it to a bot to include it in a bundle and achieve your aim with almost zero losses,\u201d<\/em> he explained.<\/p>\n<\/blockquote>\n<p>A user going by TheDEFIac agreed with 0xngmi\u2019s hypothesis, noting the movement of assets before each of the sandwich transactions.<\/p>\n<p>They follow a long, unusual path \u2014 funds arrived from accounts on Binance and Bybit and, after 15\u201320 days, from \u201cclean\u201d addresses were deposited via transfers to Aave and Compound into the USDC\u2013USDT pool to other wallets.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cThis could be either someone \u2018burning\u2019 a lot of money or some odd attempt at laundering it,\u201d<\/em> he concluded.<\/p>\n<\/blockquote>\n<p>In November 2024, <a href=\"https:\/\/forklog.com\/en\/news\/record-high-for-bnb-chain-blocks-affected-by-sandwich-bots\">a record 35.5%<\/a> of blocks on the EVM-compatible BNB Chain suffered \u201csandwich attacks\u201d.<\/p>\n<p>Earlier, a well-known MEV bot on Solana earned <a href=\"https:\/\/forklog.com\/en\/news\/solana-mev-bot-amasses-30-million-in-two-months\">about $30m<\/a> from arbitraging user trades in just two months.<\/p>\n<p>Not all such manoeuvres are effective. In September, the software took a $11.7m flash loan for a \u201csandwich attack\u201d on a $5,000 Shuffle (SHFL) trade. The bot executed 14 transactions across various DeFi platforms and <a href=\"https:\/\/forklog.com\/en\/news\/mev-bot-borrows-12-million-nets-just-20\">made $20 in profit<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cryptocurrency trader swapped about $732,583 in USDC for about $18,636 in USDT across six separate swaps, falling victim to a large sandwich attack. Unknown entity got sandwiched for 714k today on six separate USDC -> USDT swaps. (Traded with 100% slippage allowed.) They swapped 732583.429405 USDC for 18636.232611 USDT. A promised ?: pic.twitter.com\/0rFNE4DfoP \u2014 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":22012,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[44,1093,1231],"class_list":["post-22013","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybercrime","tag-defi","tag-mev"],"aioseo_notices":[],"amp_enabled":true,"views":"66","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/22013","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/comments?post=22013"}],"version-history":[{"count":0,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/posts\/22013\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media\/22012"}],"wp:attachment":[{"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/media?parent=22013"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/categories?post=22013"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/forklog.com\/en\/wp-json\/wp\/v2\/tags?post=22013"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}