What is a sandwich attack in a sniper bot, explained in plain English
A sandwich attack is a front-running technique where a bot places a buy order immediately before your trade and a sell order immediately after, forcing you to buy at a higher price and capturing the difference as profit. When a Telegram sniper bot is used for token launches, it can both perform sandwich attacks on others and become the victim of one.
How a sandwich attack works step by step
-
You submit a trade - Your sniper bot or trading bot sends a buy order for a token on a decentralized exchange like Raydium. This order enters the public mempool (the queue of pending transactions).
-
The attacker spots your transaction - A malicious bot monitors the mempool for large or predictable trades. It sees your order and calculates how much the price will shift when your trade executes.
-
The attacker front-runs you - The attacker’s bot submits its own buy order with a higher gas priority fee. Validators include the attacker’s transaction first because it pays more. This pushes the token price up slightly before your order goes through.
-
Your trade executes at a worse price - Your original buy order now fills at the inflated price caused by the attacker’s purchase. You get fewer tokens than you expected.
-
The attacker back-runs you - Immediately after your trade, the attacker sells the tokens they just bought. The price drops back down, and the attacker keeps the difference between the inflated price and the normal price.
The result: you paid more, the attacker profited, and the token price returned to roughly where it started.
Why sniper bots are especially vulnerable
Sniper bots are designed to buy tokens within the first few seconds of a liquidity pool opening. This creates ideal conditions for sandwich attacks:
-
High urgency - Snipers often set maximum slippage (the allowed price change) to 50% or more to ensure the trade goes through. This gives attackers room to push the price far before your order fills.
-
Predictable timing - The exact moment a Raydium pool launches is public information. Attackers can prepare their sandwich transactions in advance.
-
Competition among snipers - Multiple snipers targeting the same launch create a cascade of front-running. Each sniper’s order can sandwich the next, making the first few trades extremely expensive.
How attackers execute the sandwich
The attacker does not need special access. They simply:
- Run a bot that watches the mempool for large or time-sensitive trades
- Calculate the optimal buy and sell amounts to maximize profit without triggering your slippage limit
- Submit both transactions with high priority fees so validators include them in order
On Solana, where block times are fast and transaction fees are low, this can happen within a single block or across consecutive blocks.
What you can do to reduce the risk
-
Use a private mempool or MEV-protected RPC - Services like Jito, Bloxroute, or private Telegram bot RPC endpoints submit your transaction directly to validators, bypassing the public mempool. This is the most effective protection.
-
Set reasonable slippage - For sniper bots, 5 - 10% slippage is usually enough for most launches. Anything above 20% invites sandwich attacks.
-
Use a bot with built-in MEV protection - Some Telegram trading bots offer a “sandwich protection” mode that routes transactions through private mempools. This is not a guarantee, but it helps.
-
Trade smaller amounts - Sandwich attackers target larger trades because the profit is higher. Smaller orders are less likely to be worth the attacker’s effort.
-
Check the token’s liquidity and holder distribution - Tokens with very low liquidity or a single large holder are more prone to manipulation, including sandwich-style attacks.
The limits of protection
No method is foolproof. Private mempools can still be monitored by validators, and some validators run their own sandwich bots. MEV protection adds latency, which can cause your sniper bot to miss the launch entirely. There is always a trade-off between speed and security.
If a token is heavily manipulated from the start, even a perfectly executed trade can lose money. Sandwich attacks are one of many ways that early trading on new launches carries high risk.
Not financial advice. pepecoinsol.xyz publishes market data and general information about Pepe. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.