New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Revert. Retry. Profit? The Rise of Spam-Based MEV on Rollups | Krzysztof Gogol | ETHWarsaw [4]

ETH WarsawSun, Nov 9, 2025, 12:00 AM

Speaker

Krzysztof Gogol

Revert. Retry. Profit? MEV on L2s. Krzysztof Gogol discussed the role of MEVs in flooding L2s with reverted swap transactions. 🎥 Recorded at ETHWarsaw 2025 Follow ETHWarsaw on social media for the latest updates! X (Twitter): https://x.com/ETHWarsaw LinkedIn: https://www.linkedin.com/company/ethwarsaw Telegram chat: https://t.me/joinethwarsaw

Transcript

Hello, it's great uh to be here uh together with you. Um I'm going to talk about uh rollups MAV private mele and actually you can wonder how MAV is possible on the rollups that are running on a centralized sequencer where nobody actually can see what's inside meool and I yeah I show you different uh different techniques different MAV strategies that are recently popping up there. I'm going to share with you a part of the research that I was doing as a as a part of my PhD at University of Turing. That research was uh founded by the grant from a flashbot research. But uh let's start with uh to make sure that everybody's on the same page.

What is MAV and what is MAV attack? So it is a very recent example of what happened on Ethereum in March in yeah one of the blocks. So a trader was trying to swap uh 2 20ou uh 220,000 USDC on unis swap v3 and uh he was simply swapping USDC into USDT. So you would expect that for uh 200,000 USDT you will receive also 200 uh US uh uh DT. However to a big surprise of that trader he received only 5,000 uh USDT.

So very simple trade uh just a swap one stable coin into another one and out of out of the sudden yeah most of the money disappeared and simply what happened uh one of the MAV BAV searcher noticed such a pending uh swap in the meool me is something like a waiting room for the transactions waiting to be executed that transaction is uh present uh here so that mav both notice that uh transaction and uh bribe uh block producer so that two extra transactions were inserted one before that uh swap one after that uh we uh we say that one was front running the other was a back running and this a and as a result simply that uh mav both together with that uh blog builder they make a profit over 200 uh thousand And at the expense of that right there, this is actually example of one of the most extreme mavs. It's a sandwich attack. Generally, MAV stands for the maximal extractable value and it's about influencing the order of the transactions in a block. Ethereum but also other blockchains generally work that way that there is it's very well defined how the blocks in the blockchain are be being produced there's the whole consensus mechanisms however there are very little rules or no rules regarding the ordering of a transactions inside a block and in case of the Ethereum actually everybody can see what are the transactions that are in the map that are pending that are about to be included and Then some uh searchers they simply look for the different constructions of uh transactions inside the block and yeah come up with the ideas what to do so that they can extract some uh extra profit without taking any any risk and there are uh very different types of MAV. Luckily most of those MAV transactions they are actually beneficial for the users and uh like arbitr represent 60% of the MAV it's about equaling prices for example between unis swap pancake swap and binance liquidations of the bad debt from the a or other lending protocols represents another 30% and only maybe 10 15% of mav transactions are those on which uh attacks.

However, in case of the Ethereum, they all require that the manpool of the transactions is public. So the question would be how can we uh do mav transactions when actually we do not see uh what transactions are in the meool what transactions are uh pending about to be executed and this is how uh most of the rollups are operating most of the rollups today I know ck sync our bit room base they run on the centralized sequencer by the way we can trust that centralized sequencer but they also have a private at Mampool they have a very low uh gas fees. You can see here that on Ethereum, yeah, uh you need to pay around $5 to do a swap on those L2s. You just pay a few cents for that. And also rollups have much faster finality.

Instead of waiting yeah 12 seconds on Ethereum for your block to be produced, rollups produce blocks in 200 milliseconds or one two seconds at the longest. And actually on those conditions, they're like a perfect conditions for a new uh MAV strategy. So even if you do not know what transactions are going to be included in the in the block because they are encrypted, you can make a guess because you can see the transactions that were that were executed so far. And simply by analyzing the patterns that were in the blocks already executed, you can make some predictions what's going to happen in the next block. And then you can send some uh swaps inside that block and based on some uh statistical based on the statis on the probability some of those uh trades that you are sending blind they will be successful you make profit of them some will be unsuccessful and they will be reverted from the blockchain.

However, what is special about L2S gas fees are so low that even if your transaction is reverted and yeah, you are not successful with your MAV attempt, you pay very little uh very little gas fees. This is what yeah you see here how much you pay on Ethereum and how much you pay on the L2s and as a result of I mean those conditions uh it's still a profitable to give it a try and to do that uh speculative MAV or MAV attacks on the uh private mess on Ethereum and also what we see is that once uh there was a big uh upgrade on Ethereum one year ago it was Dankun that introduced blobs and there's a results uh gas fees on rollups went down sign significantly and not surprisingly or surprisingly after that Deon upgrade you can see that the percentage of the reverted transactions actually uh rose quite significantly from like uh 1 2% to uh 20 or sometimes 40%. So today's today around 20% of all of the transactions that are on the rollups they are being reverted. So they are unsuccessful and most of them actually are those MAV uh are those MAV attempts. It's not so uh actually easy to understand what the reverted transactions are trying to do on the blockchain because reverted transactions they do not emit event logs.

So if you are analyzing what they are doing, you need to look into the traces, internal transactions, check with which smart contracts they were trying to uh interact whether it was uh some uh DEX pool or there were some uh stable coins and this is and this is what we did in our uh research and actually we uh saw that majority like even 80% or on some L2S 90% of those uh transactions that are unsuccessful, they are uh swaps or they are trying to execute a swap. And what was even more interesting that uh from those uh reverted swaps more than a half they were trying to uh do swaps at unis swap v3 and they were trying uh to trade uh only one current cryptocurrency pair USDC and uh e which is actually providing more uh evidences than those uh reverted transactions. they are simply those speculative math uh attempts. And then going further, we also applied some statistical analysis, maybe today you you would say uh AI to uh look for some patterns within those uh failed transactions on L2s and we observed a few uh interesting u paradigms. Maybe the most interesting is that a lot of MAV bots actually split trades and their duplicates their trades.

So because those gas fees on L2s are so cheap, the block is produced so fast and you want to make sure that for example your arbitr transaction is executed first. So what you can do, you can simply send your swap maybe three times because maybe one of them will reach the sequencer faster. You can also uh split your swap into a smaller parts. And for example, if you want uh to do MAV with of a value with a transaction of value 1,000, you can send three or four $300 uh swaps and those strategies actually they are working very fine where where yeah where you are trying to do such a revert based uh MAV. Then another approach that uh you can take is to play with the priority fee.

So generally on EVM chains there is something like a priority fee and every transaction or every user can decide whether his transaction is paying priority fee or not. And the higher the priority fee you pay then um your your transaction should be at the beginning of the block. If you don't pay it it should be uh it should be at the end. And a lot of chains actually support such a priority fee auctions but uh not all of them. For example, Arbitum and CK sync are a good examples of L tools that they that do not support a priority fee.

But for the sake of the EVM compatibility, they still accept a priority fee. And what we observe and was quite surprising is that even a do chain's priority fee doesn't make any impact on where your transaction is in the block. Still a lot of users pay it which is simply a wasted uh a wasted money. Rollups are generally working on a revert protection mechanism and on making uh influencing or deciding on the order of uh transactions within a block and there are two new approaches at the beginning of this year in April Arbitum introduced so-called uh time boost. Uh time boost is similar a little similar to what Salana is offering at GTO there and there is something like a express line.

So for a time of for example eight blocks ahead or 10 blocks ahead you can buy a prior priority line like the spot at the beginning of the block and then if you win some uh such a uh some auction then you can decide which transaction you put at the beginning of every uh block. Then a very different approach is represented by uh B and uni chain they introduced uh pre-confirmations there I think the first rollups that introduced preconfirmations and gen generally the block production on uni chain was rather slow it was like uh on optack it was just two seconds and with the flashbots that every block is divided into 10 uh preconfirmations each uh uh um produced around every 200 milliseconds and then within that preconfirmation there's also uh there's uh auction with the priority fee and all those things are important because the faster the blockchain the less MAV there is there's less probability that the MAV will be successful and also it's more difficult to execute sandwich attack when the blockchain is fast so Maybe uh going to uh conclusions there are uh different uh conclusions and takeaways depending who you are. So first of all if you are a trader and if you are using I know unis swap or any other um decks on the blockchain make sure that you always set a slipage tolerance because sandwich attacks are very detrimental for the users. As I show you at the beginning, even if you are swapping a stable coin for a stable coin, you can lose almost everything. But protecting against those sandwich attacks is extremely simple.

You just need to set up a sleepage tolerance to I know two 5%. And that's all. The important thing is those sandwich attacks can happen also on uh blockchains on their tools that are having encrypted uh meles. So encrypted meles actually doesn't mean there is no mav. The takeaway number two is actually for the mav searchers.

If you are uh doing arbitrage or doing liquidations or or Oracle extractable value, you can simply go um and the mele is private, you can still try to extract uh MAV that is out there in arbitrage for example and you can do that by uh duplicating your transactions or by splitting your trades into a smaller uh parts. And uh last but not least uh some takeaway for the rollup uh designers. So generally reverts uh the fact that almost 20% of transactions reverts on rollups is not a bug uh of any rollup but it's more a consequence of the uh design decisions that were taken earlier. And then what rollups can do and some already experiment with that like a uni chain for example is so-called revert protection and that revert protection uh will work that way that even if your transaction is uh reverted it fails it's not included in the blockchain state then you don't have to pay a gas fee okay so be coming back to the to where we started how you can do the mav on the fast roll up with um private mele. So generally uh it's possible there is that new strategy of doing uh me there.

It's simply ME based on the reverted failed uh transactions. So yeah, thank you and [Music]

thank you.

You can you can follow me on Twitter or LinkedIn and I will post our full research report in one week there.

Amazing. Thank you. Are there any questions? Yeah, there is a question. Um, there you go.

Hey, great talk. Uh, so at the end you mentioned revert protection. So do you mean that it's good to introduce this to a rollup? Uh, because it sounds like if we have revert protection then this kind of spammers don't pay at all. Mhm.

Yes, that's actually a very good uh question about how that revert protection should be uh should be uh designed. So there are maybe uh two uh sides of that. One is that um every revert reverted transaction is contributing to the base fee and when the base fee is going up it also affects other users of the blockchain. So because 20% of the transactions reverts it means that other users of the blockchain they need to pay higher gas fee. So by getting rid of those reverts uh other users will benefit.

What actually rollups could try to do and actually some are al also experimenting with that is that they will also wave the um base fee but uh but the priority fee will still be charged. So if the for example the reverted transaction is taking part in some auction yeah that partyier will be paid but the base fee for the benefit of the whole community will be uh waved.

Amazing. Anything else?

No. Thank you so much Kristoff.

Thank you.

Automatic transcript — names and jargon may be misspelled.