Jito banned 15 validators due to evidence of sandwich attacks, using a more sophisticated 'wide sandwich' approach.Jito banned 15 validators due to evidence of sandwich attacks, using a more sophisticated 'wide sandwich' approach.

Jito cracks down on Solana validators after on-chain report exposes MEV abuse

2025/10/23 01:10

Jito, one of the main providers of block building and liquid staking, has banned another 15 validators for evidence of sandwich attacks. A recent report showed transaction reordering was still happening, and up to 6% of proposed blocks by validators contained sandwiched attacks. 

Jito, one of the main block-building and liquid staking services, has banned another 15 validators from receiving JitoSOL. The ban happened after a recent report that validators still performed sandwich attacks, front-running Solana traders. 

Jito responded to a recent report on various types of sandwich attacks, which led to another wave of validator bans. 

Previously, Jito has also fought against dishonest validators that relied on dishonest block building and front-running trades. 

The latest problem with dishonest block proposals was uncovered by on-chain researchers from 0xGhostLogs. They discovered anomalous transactions in 23 validators, which relied on staking pools from Marinade and Jito. Six of those validators also received subsidies from the Solana Foundation. 

When proposing a new block as a leader, over 6% of leader slots contained sandwich attacks, targeting retail trades. 

Jito bans 15 additional validators after data emerges of widespread sandwich attacksSome validators had a larger share of wide sandwich attacks, with most of the traffic targeting specific apps and small-scale meme token trades. | Source: Sandwiched

Some validators had up to 12.3% of proposed blocks containing wide sandwich attacks. Wide sandwich attacks continue on Solana, with an estimated 222,272 victims

Block builders use more sophisticated MEV attacks

Validators have switched to more sophisticated front-running attacks. Previously, attacks happened in single leader slots and were readily detected. 

Validators then switched to multi-slot attacks, also known as wide sandwich attacks. Researchers noted 93% of attacks were coming from a so-called ‘wide sandwich’, where the front-running and back-running transactions were not in the same proposed block. 

This type of attack extracted 30K to 60K SOL per month, with a record 87,000 SOL in January 2025. 

In this type of attack, a slot leader that proposes blocks can reorder transactions and avoid detection. With increased DEX activity, sandwich attacks are undermining confidence in using Solana as a retail trade platform. 

Attackers also wait for high-value transactions, which can be visible in private mempools. Then, they can inject trades of their own, which causes loss for the original trader. 

Axiom, Bloom, and Photon users were most affected

The main source of attack was private mempools and lists of upcoming transactions, which were shared among validators. 

Any entity can apply to propose Solana blocks and become a validator, with limited governance tools to avoid dishonest behavior. The validators apparently colluded in some cases, targeting specific Solana apps. 

Around 70% of extracted SOL came from users on the Axiom trading platform, followed by Bloom and Photon. The bulk of sandwich attacks make less than $1, but some lead to as much as $10K in losses. Overall, some attackers pay up to 10 SOL in daily fees for priority transactions and bribes. 

Meme coin traders were the most affected, further adding to the volatility of newly launched assets and low-cap memes. Users of aggregators and wallets were relatively unaffected, due to a different order flow and routing. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

The post Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO appeared on BitcoinEthereumNews.com. Aave DAO is gearing up for a significant overhaul by shutting down over 50% of underperforming L2 instances. It is also restructuring its governance framework and deploying over $100 million to boost GHO. This could be a pivotal moment that propels Aave back to the forefront of on-chain lending or sparks unprecedented controversy within the DeFi community. Sponsored Sponsored ACI Proposes Shutting Down 50% of L2s The “State of the Union” report by the Aave Chan Initiative (ACI) paints a candid picture. After a turbulent period in the DeFi market and internal challenges, Aave (AAVE) now leads in key metrics: TVL, revenue, market share, and borrowing volume. Aave’s annual revenue of $130 million surpasses the combined cash reserves of its competitors. Tokenomics improvements and the AAVE token buyback program have also contributed to the ecosystem’s growth. Aave global metrics. Source: Aave However, the ACI’s report also highlights several pain points. First, regarding the Layer-2 (L2) strategy. While Aave’s L2 strategy was once a key driver of success, it is no longer fit for purpose. Over half of Aave’s instances on L2s and alt-L1s are not economically viable. Based on year-to-date data, over 86.6% of Aave’s revenue comes from the mainnet, indicating that everything else is a side quest. On this basis, ACI proposes closing underperforming networks. The DAO should invest in key networks with significant differentiators. Second, ACI is pushing for a complete overhaul of the “friendly fork” framework, as most have been unimpressive regarding TVL and revenue. In some cases, attackers have exploited them to Aave’s detriment, as seen with Spark. Sponsored Sponsored “The friendly fork model had a good intention but bad execution where the DAO was too friendly towards these forks, allowing the DAO only little upside,” the report states. Third, the instance model, once a smart…
Share
2025/09/18 02:28
Share
Ethereum Foundation Moves Entire $650M+ Treasury to Safe Multisig

Ethereum Foundation Moves Entire $650M+ Treasury to Safe Multisig

The post Ethereum Foundation Moves Entire $650M+ Treasury to Safe Multisig appeared on BitcoinEthereumNews.com. EF completes full treasury migration to Safe smart accounts, joining Vitalik Buterin as key Safe user + Safe smart accounts cross 750M transactions milestone.   The Ethereum Foundation has completed the migration of its full treasury, over 160,000 ETH worth approximately $650 million to Safe{Wallet}, following months of successful DeFi testing. Safe{Wallet}, operated by Safe Labs (a fully owned subsidiary of the Safe Foundation), is the crypto industry’s trusted smart account standard for multisig wallets, securing billions of dollars in assets for institutions, DAOs, and projects. The move follows the Foundation’s June 2025 treasury policy announcement, which committed to actively participating in Ethereum’s DeFi ecosystem. Since February, the EF had been testing Safe with a separate DeFi-focused account, dogfooding protocols including Aave, Cowswap, and Morpho as part of their strategy to support applications built on Ethereum. After testing a 3-of-5 multisig configuration on January 20th, the Foundation has now consolidated its remaining ETH holdings into Safe, completing the transition from their previous custom-built multisig solution. This implementation enables the Ethereum Foundation to actively participate in DeFi via Safe while maintaining battle-tested security standards, marking another step toward Safe’s vision of moving the world’s GDP onchain through battle-tested self-custody infrastructure. “Safe has proven safe and has a great user experience, and we will transfer more of our funds here over time,” the Ethereum Foundation announced, indicating this is the beginning of a deeper commitment to the Safe smart account standard. Safe’s Momentum The timing is notable: Safe has just crossed 750 million transactions (751,062,286 as of today) with over 57.5 million Safes created across multiple chains. The protocol has emerged as crypto’s de facto standard for multisig wallets, securing billions in institutional and DAO treasuries. Safe also counts Ethereum co-founder Vitalik Buterin among its prominent users, who revealed in May 2024 that…
Share
2025/10/23 04:15
Share