Cointime

Download App
iOS & Android

1inch Unveils RabbitHole Feature to Protect MetaMask Users From "Sandwich Attacks"

Validated Project

The 1inch RabbitHole feature will protect MetaMask users from sandwich attacks, one of the most common ways of extracting MEV in DeFi.

The 1inch Network is thrilled to introduce the 1inch RabbitHole, a brand new feature that aims to protect MetaMask users swapping on 1inch from sandwich attacks — the most common type of front-running.

Sandwich attacks explained

When making swaps on decentralized exchanges, users can potentially become victims of a so-called “sandwich attack,” a way of getting maximal extractable value (MEV). Although technically not illegal, sandwich attacks are still a type of manipulating crypto prices by taking advantage of decentralized exchanges’ underlying tech. And a sandwich attack could lead to significant losses for a user.

To run sandwich attacks, specifically created bots are used that scan decentralized exchanges’ memory pools (mempools) where transactions are waiting to be processed. If a bot detects a large pending swap trade, it initiates two transactions: one before the trade and the other one after the trade, basically “sandwiching” the victim’s trade. To get the first transaction directly before the victim’s trade, extra gas fees are paid.

Say, a user wants to buy 1,000 X tokens for 20 Y tokens with a 1% slippage tolerance — meaning that the minimum amount of X tokens they agree to receive is 1,000–1% = 990.

A sandwich bot detects the trade and places a buy transaction for Y directly before the victim’s trade and a sell transaction for Y directly after the victim’s trade. Subsequently, three transactions are executed.

  • Transaction 1: the bot executes the buy transaction, and the high purchase of asset Y pumps its price.
  • Transaction 2: the victim buys Y at a higher price than originally expected, and the large trade pumps Y’s price even higher.
  • Transaction 3: the bot sells Y, pocketing the price difference.

As a result, the user loses their 1% entirely.

The very first sandwich attack is believed to be carried out on Bancor on February 27, 2018:

Since then, users have lost substantial funds due to sandwich attacks, which hit roughly 4% of all swap transactions. In 2022 so far, estimated losses have amounted to the equivalent of at least $800 mln.

The 1inch RabbitHole: a shield from sandwich attacks

The 1inch RabitHole is a feature that solves the problem of sandwich attacks by sending swap transactions on 1inch directly to validators and avoiding putting them to the mempool where sandwich bots can attack them.

To achieve that, the RabbitHole aggregates providers, such as Flashbots, BloXroute, Eden and Manifold, that enable sending swap transactions directly to validators.

The RabbitHole will specifically benefit MetaMask users, as, while some crypto wallets (including the 1inch Wallet, Ledger and Trezor) are capable of creating and signing a transaction, but not broadcasting it immediately, MetaMask is not.

The RabbitHole is designed as a proxy, connecting 1inch users’ MetaMask wallets and Ethereum validators. Its unique algorithm will check swap transactions on 1inch for the threat of a sandwich attack, and, if such a threat is detected, the transaction will be sent directly to validators, using one of the aggregated providers.

For a testing period, the RabbitHole will be free to use. Upon receiving feedback from the community, a decision will be made regarding payment options for the RabbitHole. One possible option could be staking a certain amount of 1INCH tokens.

A step-by-step guide on using the 1inch RabbitHole is available in the Help Center.

Comments

All Comments

Recommended for you

  • Messari ·

    State of TRON Q1 2024

    TRON (TRX) is a public open-sourced blockchain network using a Delegated-Proof-of-Stake (DPoS) mechanism. It utilizes an election mechanism that determines who maintains the network. All TRX stakers vote onchain on which candidates they want to become Super Representatives. In each epoch, the top 27 most voted-for candidates become Super Representatives within the active set and take turns producing blocks. An election occurs every six hours.

  • Modular Data Layer for Gaming and AI, Carv, Raises $10M in Series A Funding

    Santa Clara-based Carv has secured $10m in Series A funding led by Tribe Capital and IOSG Ventures, with participation from Consensys, Fenbushi Capital, and other investors. The company plans to use the funds to expand its operations and development efforts. Carv specializes in providing gaming and AI development with high-quality data enhanced with human feedback in a regulatory-compliant, trustless manner. Its solution includes the CARV Protocol, CARV Play, and CARV's AI Agent, CARA. The company is also preparing to launch its node sale to enhance decentralization and bolster trustworthiness.

  • The US GDP seasonally adjusted annualized rate in the first quarter was 1.6%

    The seasonally adjusted annualized initial value of US GDP for the first quarter was 1.6%, estimated at 2.5%, and the previous value was 3.4%.

  • The main culprit of China's 43 billion yuan illegal money laundering case was arrested in the UK, involved in the UK's largest Bitcoin money laundering case

    Local time in the UK, Qian Zhimin appeared in Westminster Magistrates' Court for the first time under the identity of Yadi Zhang. She was accused of obtaining, using or possessing cryptocurrency as criminal property from October 1, 2017 to this Tuesday in London and other parts of the UK. Currently, Qian Zhimin is charged with two counts of illegally holding cryptocurrency. Qian Zhimin is the main suspect in the Blue Sky Gerui illegal public deposit-taking case investigated by the Chinese police in 2017, involving a fund of 43 billion yuan and 126,000 Chinese investors. After the case was exposed, Qian Zhimin fled abroad with a fake passport and held a large amount of bitcoin overseas. According to the above Financial Times report, Qian Zhimin denied the charges of the Royal Prosecution Service in the UK, stating that she would not plead guilty or apply for bail.

  • Nigeria’s Central Bank Denies Call to Freeze Crypto Exchange Users’ Bank Accounts

    In response to the news that "the Central Bank of Nigeria has issued a ban on cryptocurrency trading and requested financial institutions to freeze the accounts of users related to Bybit, KuCoin, OKX, and Binance exchanges," the Central Bank of Nigeria (CBN) stated in a document that the CBN has not officially issued such a notice, and the public should check the official website for the latest information to ensure the reliability of the news. According to a screenshot reported by Cointelegraph yesterday, the Central Bank of Nigeria has requested all banks and financial institutions to identify individuals or entities trading with cryptocurrency exchanges and set these accounts to "Post-No-Debit" (PND) status within six months. This means that account holders will not be able to withdraw funds or make payments from these accounts. According to the screenshot, the Central Bank of Nigeria has listed cryptocurrency exchanges that have not obtained operating licenses in Nigeria, including Bybit, KuCoin, OKX, and Binance. The Central Bank of Nigeria will crack down on the illegal purchase and sale of stablecoin USDT on these platforms, especially those using peer-to-peer (P2P) transactions. In addition, the Central Bank of Nigeria pointed out that financial institutions are prohibited from engaging in cryptocurrency transactions or providing payment services to cryptocurrency exchanges.

  • Universal verification layer Aligned Layer completes $20 million Series A financing

    Ethereum's universal verification layer Aligned Layer has completed a $20 million Series A financing round, led by Hack VC, with participation from dao5, L2IV, Nomad Capital, and others. The Aligned Layer mainnet is scheduled to launch in the second quarter of 2024. As the EigenLayer AVS, Aligned Layer provides Ethereum with a new infrastructure for obtaining economically viable zero-knowledge proof verification for all proof systems.

  • Socket - First Chain Abstraction Protocol

    Over the last few years, the Ethereum ecosystem has made tremendous strides in advancing the modular roadmap, a strategic plan aimed at enhancing scalability and efficiency through specialization and layering within the blockchain network. This has led to the development of an increasing number of chains, each specialized for distinct use cases. The cost of spinning up a new rollup has decreased significantly, blobs and data availability have made settling transactions even cheaper, and we now have L3s on top of L2s. It’s only a matter of time before we get to a world of 10,000 rollups and chains.

  • The total open interest of Bitcoin contracts on the entire network reached 31.41 billion US dollars

    According to Coinglass data, the total open position of Bitcoin futures contracts on the entire network is 487,500 BTC (approximately 31.41 billion US dollars).Among them, the open position of CME Bitcoin contracts is 143,600 BTC (approximately 9.23 billion US dollars), ranking first;The open position of Binance Bitcoin contracts is 109,400 BTC (approximately 7.07 billion US dollars), ranking second.

  • Bitcoin mining difficulty increased by 1.99% to 88.1T yesterday, a record high

    According to BTC.com data reported by Jinse Finance, the mining difficulty of Bitcoin has increased by 1.99% to 88.1T at block height 840,672 (22:51:52 on April 24), reaching a new historical high. Currently, the average network computing power is 642.78EH/s.

  • Reth’s path to 1 gigagas per second, and beyond

    We started building Reth in 2022 to provide resilience to Ethereum L1, and solve execution layer scaling on Layer 2. Today we’re excited to share Reth’s path towards 1 gigagas per second in L2 in 2024, and our longer-term roadmap for going beyond that. We invite the ecosystem to collaborate with us as we push the frontier of performance and rigorous benchmarking in crypto.