On-chain investigationSolanaSandwich attacks

Solana sandwich bots took $29.7M from memecoin buyers

Bots on Solana trade on both sides of other traders' memecoin buys and keep the difference. We went through 11 months of the chain's swaps to count the attacks and see which trades get hit.

At a glance
A sandwich bot buys a coin just before your trade and sells it just after, so your trade fills at a worse price and the bot keeps the difference. On Solana we counted 6,850,144 sandwich attacks between 30 October 2025 and 7 October 2026, made by 2,545 bot wallets against 2,154,994 different wallets. The bots took $29.7 million before their costs, nearly all of it on Pump.fun memecoins and 39% of it from other bots' trades. The daily count grew 15 times over, and trades that allowed wide slippage were hit far more often.
6.9 million
Sandwich attacks in 11 months
2.2 million
Wallets caught in one
$29.7M
Taken by the bots, before costs
96%
On Pump.fun coins
Key findingsEach line has its own share link
  1. 6.9 million

    6.9 million sandwich attacks on Solana between 30 October 2025 and 7 October 2026, by 2,545 bot wallets against 2.2 million wallets.

  2. $29.7M

    The bots took $29.7 million from the trades they wrapped, before fees. In a checked sample they kept 68% after fees and tips.

  3. 39%

    39% of the take came out of trades by other bots: snipers, high-volume wallets and rival sandwich bots.

  4. 96%

    96% of the sandwiches hit Pump.fun memecoins, on the launch curve or on PumpSwap.

  5. 15x

    From about 3,400 per day in late 2025 to 51,900 per day in September 2026.

  6. 14x

    On Pump.fun coins, Jupiter swaps allowing 20% to 50% slippage were sandwiched 14 times as often as those allowing under 3%.

01 · A worse priceSomeone bought just before you

You buy a memecoin and get fewer coins than the app showed. Most people blame a busy market. Often a bot got there first.

In mid-September a wallet spent about $240 in SOL, Solana's own coin, on a memecoin. A fraction of a second earlier, another wallet had bought the same coin on the same exchange. About two seconds later, that wallet sold everything it had bought. Its purchase had pushed the price up, so the first wallet got 6% fewer coins than it would have got without it. The other wallet made about $11 on the round trip and kept about $8 after fees.

One sandwich, three tradespool 3KFb…7orr, 16 September 2026
The bot buys2.77 SOL of the coin0.285 SOL per million00:15:17, slot 447,383,785step 1The victim buys2.47 SOL of the same coin0.303 SOL per million00:15:17, slot 447,383,786step 2The bot sellseverything it bought0.297 SOL per million00:15:19, slot 447,383,793step 3Price = SOL paid or received per million coins, from the swap records. Times are UTC.
Without the bot's buy, the pool would have sold the victim the coin at 0.284 SOL per million. Prices from the swap records, checked against the transactions on a public Solana node.

That pattern has a name: a sandwich attack. The bot's buy and its sell are the two slices of bread, and the other trade is the filling. Bitquery records swaps on most Solana exchanges, including all the big memecoin venues, so we went through 11 months of them, to 7 October 2026, and counted the sandwiches.

02 · The trickWhat is a sandwich attack?

When you swap on a Solana exchange, you trade against a pool: a pot of two coins, say SOL and a memecoin, whose price moves with every trade. Buying the memecoin pushes its price up for whoever buys next. Your app shows a quote and asks how far the price may move before the trade should fail. That setting is called slippage, or slippage tolerance. At 20%, you accept up to 20% fewer coins than the quote.

A sandwich bot lives in that gap. If it learns about your order before it lands, it buys first and pushes the price up. Your trade then fills at a higher price, still inside your limit. The bot sells straight after, at the higher price your own buy created. The gap between its buy and its sell is its profit, and it comes out of your trade.

How a sandwich worksthe price of a coin in one pool, trade by trade
pricethe price you were quoted1. bot buysprice goes up2. you buyat the higher price3. bot sellsat the top, then exitsYour slippage setting decides how high step 1 can push the price before your trade fails instead of filling.
A simplified picture. In real attacks other trades often land between the three steps.

Solana has no public waiting room for transactions, the mempool that Ethereum has, so a bot has to learn about your trade some other way. A study published in September 2026 by researchers at ETH Zurich, the University of Lisbon, Flashbots and Category Labs found that most Solana sandwiches no longer sit right around the victim. The bot's buy and sell land a few blocks apart, often in blocks made by different validators, the computers that take turns building Solana's blocks. We use that study's rules, plus one of our own, so that our count can be set next to theirs.

03 · The scaleHow many sandwich attacks happen on Solana?

By those rules, sandwich bots carried out 6.9 million attacks on Solana in the 11 months. They caught 2.2 million different wallets between their buys and sells, many of them more than once.

Not all of those wallets belonged to people. About 100,000 of them were bots by Bitquery's other Solana counts: snipers that buy new coins in their first seconds, wallets that swap 10,000 times per month or trade around the clock, and other sandwich bots. Those bot wallets made 37% of the trades that got caught.

The count grew through the year. In November and December last year the bots made about 3,400 sandwiches per day. By September they made 15 times as many, and the first week of October was busier still.

Sandwich attacks per daymonthly average, Solana, 30 October 2025 to 7 October 2026
020k40k60k80kOct20255kNov3kDec4kJan202611kFeb18kMar19kApr13kMay14kJun13kJul19kAug45kSep52kOct65k
October 2025 holds two days and October 2026 seven. Bot's buy and sell in the same slot: 6% of all sandwiches.

Trading on Pump.fun, the site where most new Solana memecoins start, grew too, but less: Pump.fun swaps per day tripled over the same months, so the attack rate per swap was about 6 times as high. Counted the way the September study counts, which includes the launch trades we leave out, our daily figure for November to June matches the study's own.

What we countedSolana, 30 October 2025 to 7 October 2026
Sandwich attacks6,850,144
Average per day20,000
Per day, Nov and Dec 20253,400
Per day, September 202651,900
Victim wallets2,154,994
Victim trades wrapped40.6 million
Victim wallets that were bots99,725
Bot wallets2,545
Gross take309,010 SOL, $29.7 million
Sandwiches that paid the bot84%
Buy and sell in one slot6%
Launch flips left out3.2 million, $44.3 million
Per day, Nov to Jun, study's way20,700
The study's figure, same months20,663

04 · The venuesWhere do the attacks happen?

Almost all of them hit memecoins launched on Pump.fun. 96% of the sandwiches landed in a coin still on Pump.fun's launch curve, the pricing formula a new coin trades on at first, or in a coin that had moved on to PumpSwap, Pump.fun's own exchange.

Where the sandwiches wereshare of sandwich attacks by exchange
PumpSwap62%Pump.fun launch curve34%Meteora3.1%Raydium1.0%Other0.1%
Pump.fun's launch curve and PumpSwap together: 96%. Exchanges with under 0.5% each are combined in the last bar.

Memecoins suit the bots. Their pools are small, so one buy moves the price a lot, and their buyers tend to allow wide slippage because prices jump around. The deep pools of large coins barely show up.

We left out one kind of round trip. In a coin's first seconds, bots buy, a crowd of buyers piles in, and the bots sell into the rush. That is sniping, a separate behaviour, so round trips that start within about four seconds of a coin's first trade are not counted here. Round-trip bots made 3.2 million of these, worth $44.3 million to them, more than all the sandwiches together.

05 · The takeHow much do sandwich bots make?

The bots took 309,010 SOL from the trades they wrapped, worth $29.7 million at the price of SOL in the minute of each attack. That is the gross: what came back from the pools minus what went in.

What the bots tookgross take per month, US dollars at the minute price of SOL
$0$2.0M$4.0M$6.0MOct2025$112KNov$726KDec$642KJan2026$2.1MFeb$2.2MMar$2.3MApr$2.1MMay$2.3MJun$1.7MJul$2.3MAug$5.3MSep$5.8MOct$2.0M
Gross: SOL back from the pools minus SOL in, before venue fees, network fees and tips. Total $29.7 million. October 2025 holds two days and October 2026 seven.

Single attacks are small. The median sandwich made the bot $2.33, and one in ten made more than $12. Fees and tips take a cut. We checked 63 attacks on a public Solana node, 42 from one week in September and 21 from the other months, counting every fee and tip the bots paid. The bots kept 68% of the gross, and 18 of the 63 attacks lost money once costs were paid.

What the bots made came out of their victims' trades. On PumpSwap and on the launch curve the price follows a fixed formula, so for the sandwiches with one victim and nothing else in between we could work out how many coins each victim would have got without the bot. The victims' loss came to 1.3 times the bots' take on PumpSwap and 1.2 times on the launch curve. In those sandwiches, the take was a floor for what the victims lost.

Some of the take came out of other bots' trades. Weighted by what each victim paid, 39% of the take came from bot wallets such as snipers, and $18.1 million from everyone else.

Whose trades paidshare of the bots' gross take, by the kind of wallet caught in the middle
Trades by other bots39%, $11.6 millionTrades by other wallets61%, $18.1 million
Weighted by what each victim paid. Bot wallets: snipers, wallets with 10,000+ swaps per month or trading around the clock, and other sandwich bots.

06 · The botsWho runs the sandwich bots?

In all, 2,545 wallets made the sandwiches. The money is spread over about a thousand of them: the ten that took the most made 13% of it, and the top thousand made 95%.

The top thousand wallets took most of itshare of the gross take, wallets ranked by what they took
Top 10 wallets13%Next 9034%Next 90048%The other 1,5455%
2,545 wallets in all.
WalletSandwichesGross takeActiveFirst SOL from
NULLio…XD7qZh95,0317,525 SOL, $701,199Mar 2026 to Oct 2026Bitstamp hot wallet
popo3R…JPMuHz53,7946,726 SOL, $551,458Dec 2025 to Sep 2026an unlabelled wallet
E45YLW…ykx2s165,7855,771 SOL, $545,597Oct 2025 to Jul 2026not traced
94iQuY…RE2pEm58,4595,066 SOL, $455,598Oct 2025 to Oct 2026not traced
tefsDG…FDumyf45,4913,746 SOL, $312,455Feb 2026 to Jul 2026an unlabelled wallet
ARARAw…vpqi8937,1082,983 SOL, $263,961Apr 2026 to Oct 2026not traced
7q15WZ…Y6PGxg22,7732,645 SOL, $253,206Oct 2025 to Oct 2026not traced
5981En…YAsJs342,7632,103 SOL, $228,515Aug 2026 to Oct 2026Coinbase hot wallet
93kgxY…e51pbp6,9862,681 SOL, $226,578Feb 2026 to Jul 2026Kraken hot wallet
FB5jAs…pL7g9N109,2411,905 SOL, $219,492Aug 2026 to Oct 2026an unlabelled wallet
Gross take before costs; first SOL from Bitquery's transfer records up to 30 August 2026.

The wallets do not last long. Half of them made sandwiches on 7 days or fewer, and no month saw more than 777 at work. Bot owners switch wallets often, which makes them hard to block one address at a time.

We looked for the first SOL that reached the 20 wallets that took the most, using Bitquery's transfer records up to 30 August. Of those, 11 got it from another wallet in that period, and three came straight from exchange hot wallets, the wallets exchanges pay customers from, at Bitstamp, Coinbase and Kraken, according to Bitquery's address labels. No funder paid for more than one of the 20. Of the other nine, six were already at work when our records begin, one started after the transfer records end, and two got no SOL from another wallet in the month before they started.

07 · SlippageDoes a high slippage setting invite an attack?

Jupiter, the swap router many Solana apps use, records the slippage limit of every swap it sends. In November last year, 21% of the wallets swapping through Jupiter allowed 10% or more on at least half of their swaps. By September that share was 30%, and in the first week of October 36%.

Wider slippage, month by monthshare of wallets swapping through Jupiter whose typical swap allowed 10% or more
0%10%20%30%40%21%Nov202519%Dec26%Jan202625%Feb21%Mar28%Apr21%May16%Jun17%Jul22%Aug30%Sep36%Oct
A wallet counts when the median setting of its Jupiter swaps in the month was 10% or more. Arbitrage loops and swaps with no real quote are left out. October 2026 runs to the 7th.

A wide setting leaves room for an attack. We matched every Jupiter swap against the sandwiches. Across all of them, swaps that allowed 20% to 50% landed inside a sandwich 96 times as often as swaps that allowed under 0.5%. Most of that gap is about which coins people traded. Nearly all the swaps with tight settings, 97% of those under 0.5%, went into pools other than Pump.fun's, where bots barely work.

So we compared swaps into the same kind of coin. Among Jupiter swaps into Pump.fun memecoins, those that allowed 20% to 50% were caught 14 times as often as those that allowed under 3%.

On the same coins, wider settings get sandwiched moreJupiter swaps into Pump.fun coins caught inside a sandwich, per 10,000, by slippage setting
Exact quote (0)36 per 10,000Under 0.5%27 per 10,0000.5% to 1%17 per 10,0001% to 3%8 per 10,0003% to 10%44 per 10,00010% to 20%87 per 10,00020% to 50%148 per 10,00050% or more33 per 10,000
Jupiter swaps whose route went through a Pump.fun launch curve or PumpSwap pool, 30 October 2025 to 7 October 2026. A swap counts when one of its pool trades was a victim inside a sandwich. Across all Jupiter swaps, the 20% to 50% band was hit 96 times as often as the under-0.5% band.

The tightest settings were not the safest. Swaps under 0.5% were caught more often than swaps at 1% to 3%, mostly in a burst in March and April, and swaps that allowed 50% or more were hit less often than those at 20% to 50%. Jupiter also carries only a small part of the victims' trades; most victims traded on Pump.fun directly. Past a few percent, the more room a trade leaves, the more often a bot takes it.

08 · Across blocksWhy do most attacks span several blocks?

In only 6% of the sandwiches did the bot buy and sell in the same block. Solana makes a block, which it calls a slot, about every 0.4 seconds, and each validator makes four in a row. In three of every four attacks the bot's sell came two to eight slots after its buy, so the two were often in blocks made by different validators.

How far apart the bot's buy and sell landshare of sandwich attacks by slots between the bot's buy and its sell
Same slot6%1 to 3 slots44%4 to 7 slots37%8 to 11 slots13%
A slot is Solana's block time, about 0.4 seconds; one validator makes four in a row.

That shape fits what the September study found. In 2024, sandwiches on Solana bunched up in blocks made by a few validators. The Solana Foundation and large staking pools then stopped sending stake to validators caught doing it, the last round in October 2025. The attacks did not stop. They moved to a form that needs no friendly validator, which suggests the bots learn about trades somewhere before the trades reach the chain. The study found the victims bunched up among users of a few trading apps, without saying how the orders leaked. We saw the same kind of leak on Robinhood Chain, where bots front-ran a trading app's memecoin orders.

09 · DefenceHow to avoid a sandwich attack

Keep slippage to a few percent. A wide setting such as 20% may save a failed trade during a rush, and our numbers show it is also the setting that bots catch most often.

Do not rely on a single protection switch. Many trading apps offer an MEV protection setting; MEV is the profit that bots and validators take by reordering trades. The most common switch only stops another trade from going ahead of yours inside a Jito bundle, a package of trades sent to a validator together. The September study found that most attacks no longer go that way, and that the most-hit app's victims had the switch on almost every time.

Bots make the most from large buys in small pools, where one order moves the price furthest. If you need a lot of a thinly traded memecoin, split the buy and keep each part's slippage tight.

10 · MethodHow we counted

We used Bitquery's records of every successful swap on the Solana exchanges it covers, from 30 October 2025 to 7 October 2026, 10.7 billion in all, on Pump.fun, PumpSwap, Raydium, Meteora, Orca and other pools. The same history is sold as files on the Bitquery Data Store and can be queried through Bitquery's DEX trades API.

A sandwich, by the September study's rules: a wallet buys a coin in a pool and later sells 99% to 101% of it back in the same pool, and the whole round trip fits inside three validators' turns in a row, about five seconds. In between, another wallet trades the same coin in the same direction, for at least 1% of the bot's buy and at a worse price than the bot got, and that wallet is not making such a round trip itself. A wallet counts as a sandwich bot if it made at least 100 sandwiches, at least 60% of them for a profit, and if sandwich trades were at least a quarter of all its swaps. We added one rule: round trips that start in a coin's first 10 slots are sniping and are left out, and the bot test is then run again without them. Counted with those round trips, as the study counts, our figure for November to June is 20,700 per day against the study's 20,663.

We checked the rule three ways. We took 78 sandwiches, 57 from one week in September and 21 from the other months, and checked each one on a public Solana node: the order of the three trades, the amounts, the pool, and that the bot's trades touched no other coin. All 78 held up. We wrote the rule a second time in plain code and ran it on the raw swaps of 25 sampled pools: it found the same 84 sandwiches, with the same victims. Then a separate program, written without our code, recounted the headline figures from the same records, and all 39 matched.

11 · EvidenceAddresses and transactions cited

WhatAddress or transaction
Opening example: the bot4nptUN…M5eHjf
Opening example: the victim5zDYdt…U35YGT
The PumpSwap pool3KFb37…rP7orr
The bot's buy3UFKEq…q8Vv
The victim's buy4tFE4W…uM7S
The bot's sell2ZNFAv…A2QS
Top bot wallet 1NULLio…XD7qZh
Top bot wallet 2popo3R…JPMuHz
Top bot wallet 3E45YLW…ykx2s1
Top bot wallet 494iQuY…RE2pEm
Top bot wallet 5tefsDG…FDumyf
Funder: Kraken hot wallet6LY1Jz…kZzkzF
Funder: Bitstamp hot wallet9D8xSH…ur7Cc9
Funder: Coinbase hot wallet9obNtb…5uWQkE

FAQ

What is a sandwich attack in crypto?

A sandwich attack is when a bot buys a coin just before your trade and sells it just after. Your trade fills at the higher price the bot's buy created, and the bot sells at the higher price your buy created. The difference is the bot's profit and your loss.

How common are sandwich attacks on Solana?

Very common. We counted 6.9 million in the 11 months we studied, and the daily count in September 2026 was 15 times that of late 2025. Almost all hit memecoins on Pump.fun.

Who are the victims of sandwich attacks?

Mostly memecoin buyers on Pump.fun. Some are bots themselves, such as snipers, and their trades paid 39% of what the sandwich bots took. The rest came from other wallets.

How much do sandwich bots make on Solana?

About $29.7 million in our window, before costs. Most attacks made the bot a few dollars, but a few made far more.

What slippage should I set to avoid sandwich attacks?

A few percent at most. On Pump.fun memecoins, swaps that allowed 20% to 50% slippage got sandwiched far more often than swaps that allowed 1% to 3%. A wide setting saves a trade in a rush, but it is the room a bot needs.

Does MEV protection stop sandwich attacks on Solana?

Only partly. The most common protection switch stops other trades from going ahead of yours inside a Jito bundle, but a September 2026 study found most Solana attacks no longer go that way. Low slippage still matters.

Can a sandwich bot take coins out of my wallet?

No. A sandwich bot cannot touch your wallet. It only makes your trade fill at a worse price, within the slippage you allowed.

Limits on these figures

The count is a floor. Bitquery does not yet cover some Solana exchanges, among them HumidiFi and Tessera V (ticket BIT-15871), and about 1.6% of blocks are missing from the trade history (BIT-15870). Attacks there are invisible.

The rule is strict. A bot that sells only part of what it bought, keeps selling after the window closes, or splits the attack across two wallets is not counted. Counting the round trips whose sell ran past the window would raise the total to 7.9 million and the take to $47.3 million, but much of that extra take came from buyers who arrived later, not from the trades in between.

Near misses are common. In sample hours, round trips that missed the rule by a little (the amount off by up to 10%, or the sell one validator's turn late) came to between a fifth of the counted sandwiches and about as many.

Round trips in a coin's first 10 slots are counted as sniping and left out, and the bot test is run again without them. Pools where hundreds of wallets made round trips in the same block were left out on one day (15 August 2026) because they were too big for our count to handle.

Pump.fun launch-curve sandwiches that started between 08:35 and 13:08 UTC on 26 May 2026 are left out: in those hours the records name SOL two different ways (ticket BIT-15930), which breaks the buy-or-sell test.

The gross take is SOL back from the pools minus SOL in, from Bitquery's swap records, before venue fees, network fees and tips. Pump.fun sale amounts include its fee from 8 June 2026 and exclude it before (ticket BIT-15926); counting both periods without the fee lowers the total by about 3%.

Whether a bot saw a victim's order before it landed cannot be proven from the chain. The persistence test leaves out wallets that win less than 60% of their round trips; some wallets that pass may be fast traders riding a buying rush.

About 3% of the sandwiches had only Pump.fun's own Mayhem-mode trading program as the victim, a program wallet and not a person; it is left out of the count of victim wallets.

17,849 sandwiches paid in coins with no dollar price in our records count toward the total but not toward the dollar figures, including the median.

Funders come from transfer records up to 30 August 2026. Exchange names come from Bitquery's address labels.

Run it yourself

Check a Solana trade in plain English

Every swap in this story comes from Bitquery's Solana data. The Bitquery MCP server puts that data behind an AI assistant, so you can ask who traded a pool just before and after your swap, what a wallet has been doing, or where its money came from, without writing the query yourself. The full history of Solana trades is also sold as files on the Bitquery Data Store.

List the trades in a pool around your swapSee every round trip a wallet made in a coinFind which wallet first funded a trading botCheck a wallet against Bitquery's labels
Explore Bitquery MCP →Figures measured from Solana swaps, 30 October 2025 to 7 October 2026, checked on 10 October 2026.
Legal disclaimer

This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.

The findings describe swaps observed on Solana between 30 October 2025 and 7 October 2026. A trade is counted as a sandwich, and a wallet as a sandwich bot, by the rules set out in the method section; the counts depend on those rules and on Bitquery's records of the chain. Wallets are described by their behaviour on the chain. None of them is attributed to a named person or group.

Pump.fun, PumpSwap, Jupiter, Raydium, Meteora and Orca are named because the trades described here ran through their programs. That says nothing about the conduct of those companies.

Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.

Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.