Sandwich Attacks Plague Solana, But One Platform Shows Promise
Sandwich attacks have become a pervasive issue on the Solana blockchain, with an estimated 28 million such incidents recorded over the past three years. However, a new academic study suggests that traders utilizing Jupiter Ultra may be experiencing significantly fewer of these exploits. This finding emerges from the first multi-year academic analysis of protected order flow attacks across major blockchain networks.
Study Highlights Application-Level Design Impact
The research, titled “No Place to Hide: An Analysis on Protected Order Flow Sandwich Attacks,” was published on arXiv on September 23, 2026. Conducted by researchers from Category Labs, ETH Zurich, Flashbots, and the University of Lisbon, the study examined sandwich attack activity on Ethereum, Solana, Tron, Base, Arbitrum, and Monad. The results underscore the critical role that application-level design choices play in determining the frequency of user exploitation.
A sandwich attack occurs when a bot detects a pending user swap, places a buy order immediately before it to inflate the price, and then sells after the user’s trade executes at the higher price. This results in the user receiving a worse execution price, with the bot profiting from the difference.
Solana’s technical architecture is considered particularly conducive to such attacks. Its low transaction fees enable bots to conduct sandwich attempts cheaply and at a large scale, while the visibility of its mempool provides bots with the necessary information to front-run trades.
Jupiter Ultra Demonstrates Superior Protection
To quantify the impact of these attacks, the study employed an “excess ratio” to measure how often users of each application fell victim to sandwich attacks relative to a statistical baseline. Jupiter Ultra recorded an overall excess ratio of 0.7, indicating that its users were sandwiched less frequently than statistically expected. In scenarios involving single victims, this ratio rose to 2.0, still considerably lower than its competitors.
The contrast with other Solana trading platforms is striking. Axiom registered an excess ratio of 18.9, Photon 11.1, and both BullX and GMGN exceeded ratios of 10.
Jupiter attributes its superior performance to Ultra V3, launched on October 17, 2025, which introduced several protective features. Private routing conceals transaction details until execution, thereby removing the information advantage that sandwich bots exploit. Dynamic slippage estimation adjusts tolerance levels in real-time, moving away from static user-defined parameters. The platform also integrated “Iris meta-aggregation” and “Ultra Signaling” to further enhance transaction privacy and execution quality.
Jupiter claims aggressive results, including 34 times better sandwich protection compared to competitors, an average positive slippage of +0.6 basis points, and execution fees that are 8 to 10 times lower than rival platforms.
Blockchain Architecture Not the Sole Factor
A significant conclusion from the study is that the blockchain itself is not the only determinant of vulnerability. Application-level design choices—such as how a trading platform routes orders, what information it exposes to the public mempool, and how it manages slippage—play a crucial role in dictating which users are targeted and how often.
Despite these advancements, the researchers emphasized that sandwich attacks have not been eradicated on Solana. Validators still present a potential vector for exposure, and while Jupiter Ultra mitigates the problem, it does not entirely eliminate it.



