A cat-and-mouse game: how to frontrun a transaction in the future?
Devcon·Thu, Oct 9, 2025, 12:00 AM
This talk will describe the attack-defense game in the MEV world. First it will briefly discuss MEV transactions and how it can protect projects from hackers. Then it will delve into attack-defense games between MEV bots. Finally it will discuss our latest observations and direction in this cat-and-mouse game.
Transcript
[Music] hello everyone um my name is shei and I'm a security engineer at Fen and uh for the for the past year we have been digging into them M world so we have some uh insights to share to bring some new methodologies into this world and uh the topic is how to fund Runner transaction in the future so in 2023 we have seen a lot of fundr Runners has trans resed millions of dollars in the hacking incidents for example like conf they rescued uh 5.4 million and also bloack and also in the kyber swap incident they rescued 5.7 million and return those funds to the protocols these are like white hat hackers but we are seeing a decline declining trend for this uh in 2024 and there are main some some reasons for that so before that let me go over around uh about the background of MV and for earning so this is how a transactions life cycle so on the top you can see when the user want to send the transaction he want to send it to the Builder first then the validator then the validator will propose a block and commit it to the chain but if there is a front runner uh when the user sends the transaction to the Builder the FrontRunner will see this transaction and uh he when he detects this transaction is profitable he'll replace the beneficiary to himself and then add a little bit more gas on to that so the Builder will place his transaction in front of the normal transaction so the um users transaction will be reverted so the front runner will gain profit from this so then the roow of private mol came they say we will keep transaction private uh and this is beneficiary for most parties first Arbitrage are fair like MV B they want to balance the pools they find the a better SW path when and also user they don't need to suffer from um sandwiches and also the side effect of this is that hackers transactions they are protected by the pr and pool as well uh for example in the previous uh examples uh those fun Runners are not able to Fun Run with a private transaction and is fun running de and we found the uh answer to this question is no not on the Block Level let me explain that so we have seen a lot of like this it's called a two-phase style attack so first uh if if a hacker want to hack something he will first deploy a assistant contract and do some preparation and finally he'll send another transaction to trigger the vulnerable function of the victim so to exploit it um all a mbot or a fundr runner needs to do is to extract all the functions of a contract uh by using the function signatures and call every function and if it happens to be the trigger function uh aont Runner will be able to like font run this transac that that has not never been sent to the Builder before and so it becomes a uh catam Mouse game between the MV Bots and hackers and there are like hackers they are they thought have some like better strategies to protect their contracts for example here we have a address verification B it's easy to bypass all it boss need to do is to add some hints and also if it has a authentication uh like here you you have a hash of some uh address uh if it's compared it's compared to a fixed hash but all a bot needs to do is to change that equal sign to a not equal sign and also then hackers thought of some more sophisticated uh methods for example they hide the parameter to uh to the vulnerable function directly in the parameter in the function and we found that the goal is really to find the input that to trigger a profitable path in the contract because it's already in this contract and fuzzing is a good tool to do that so what is fuzzing it's basically generate a random input this random is not really random uh and then it execute the program observe and analyze the execution collect interesting information and if it's a profitable path we will exit otherwise we repeat using the collected information and there are different purposes for fuzzing in web two you might be corrupting corrupting some memory in web three AIO space it might be work some invariance and here we are really to find a um profitable path so the effects really depends on the input generation here are some her istic uh functions uh or generation methods we uh want to offer you and the important thing is about theistic functions uh these are the that makes the fuzzing different and there are some pros and cons to fuzzing for example it's fast accurate and easy to build a prototype and also for the uh it can be time consuming uh especially in some chains that have a very low block time interval and what we want to um promote is that I think we should bring more Web Two methodologies into web 3 for example we haven't seen sta analysis something like that and we're bringing fuzzing also adding added some ttin analysis and symbolic execution into our
Automatic transcript — names and jargon may be misspelled.