arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

保護されたブロックチェーン注文へのサンドイッチ攻撃を調査

No Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks

Lioba Heimbach, Ozan Solmaz, Burak Öz, Christof Ferreira Torres

この論文をやさしく読む

ひとことで言うと

非公開の注文経路などで守られたはずのブロックチェーン取引にも、サンドイッチ攻撃が起きていることを六チェーンで調べた研究である。

何に役立つ?

取引保護の設計や監査で、どの層から情報が露出し得るかを検討する根拠になる。

この研究の面白いところ

三年間の測定で、公開メモリプール型とは異なる攻撃の位置や主体の集中を見いだし、チェーンごとに異なる露出経路を示した。

どこまで分かった?

件数は提案した検出法とボット行動の絞り込みに基づく観測値である。要旨はすべての攻撃を網羅したとまでは述べていない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

先回り取引は長年Ethereumの公開メモリプールを悩ませ、利益になる取引を狙う者が潜む「暗い森」と呼ばれてきた。対策としてEthereumなどのブロックチェーンでは、取引を攻撃者から隠すためにプライベートRPCや組み込みの保護機能を利用することが増えている。本研究では、これらを保護された注文フローと呼ぶ。しかし、その先回り防止効果と、必要な信頼の前提は十分に分かっていない。そこでEthereum、Solana、Tron、Base、Arbitrum、Monadの六つのブロックチェーンで、保護された注文フローに対するサンドイッチ攻撃を三年間にわたり測定した。ブロック内とブロック間にまたがる幅広い攻撃を捉える検出法を導入し、ボットの行動で絞り込んで正当な取引と区別した。先回りから守られるはずの取引に対し、Solanaで2,800万件、Tronで38,567件、Ethereumで30,607件、Baseで1,889件のサンドイッチ攻撃を特定した。さらに再編成されたブロックからEthereumの被害者2,875件が判明した。公開メモリプールでの通常のサンドイッチ攻撃と異なり、これらは被害取引のすぐ前後にはめったに現れず、Solana以外では少数の主体によって行われていた。分析では、Solanaではバリデータとアプリケーションの層、Ethereumでは注文フローのオークションと再編成ブロック、Tronでは遅延を利用した先回りを防げない先着順の並べ方、Baseでは保留中の取引を露出させるRPCの不具合と予測しやすい被害者の行動など、各層で情報が露出する経路を明らかにした。既存の先回り対策が利用者の期待よりかなり弱い保証しか与えない場合があり、サンドイッチ攻撃に対する一貫した強い防御が必要だと結論づける。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-23(UTC)
最新改訂
2026-09-23 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Front-running has long plagued Ethereum's public mempool, earning it the nickname of a "dark forest", where predators lurk for profitable transactions. In response, Ethereum and other blockchain ecosystems increasingly rely on private RPCs and native protections to shield transactions from adversaries, which we refer to as protected order flow. Yet the effectiveness of these mechanisms in preventing front-running, and what trust assumptions they entail, remain poorly understood. In this work, we conduct the first longitudinal, three-year measurement study of sandwich attacks against protected order flow across six blockchains: Ethereum, Solana, Tron, Base, Arbitrum, and Monad. We introduce detection heuristics that capture wide attacks, both within and across blocks, and filter on bot behavior to distinguish sandwiches from legitimate trading activity. We identify 28.0 million sandwich attacks on Solana, 38,567 on Tron, 30,607 on Ethereum, and 1,889 on Base against transactions intended to be protected from front-running. Reorged blocks expose a further 2,875 Ethereum victims. Unlike conventional public-mempool sandwiches, these attacks rarely occur tightly around their victims and, outside Solana, are carried out by a small number of entities. Our analysis uncovers exposures at every layer: validator- and application-level exposure on Solana, order-flow auctions and reorged blocks on Ethereum, first-come-first-served ordering that fails to prevent latency-based front-running on Tron, and both an RPC bug that exposes pending transactions and predictable victim behavior on Base. These findings show that existing front-running protections can provide substantially weaker guarantees than users expect, highlighting the need for stronger end-to-end defenses against sandwich attacks.

arXiv ID: 2609.28115 / 要約の誤りについて