Research & Papers

New Math Shows How Much Crypto Privacy Actually Stops Sneaky Trades

⚡One leaked number can still let bots quietly skim money off crypto trades.

Deep Dive

Every crypto trade briefly sits in a public waiting room called a 'mempool' before it goes through. Bots watch that room, spot a big trade coming, buy the same coin first, let your trade push the price up, then sell — skimming a profit straight from your pocket. This trick, called a 'sandwich attack,' costs crypto users real money every day. New research accepted to the NeurIPS 2026 conference by Tingyi Lin, Jiazhuo Li and Ruoran Lai asks a practical question: if we encrypt the waiting room, how much can stay visible before the bots can still rob you?

The answer is precise, and a little uncomfortable. Privacy tools don't have to hide everything — but the single number that decides whether a bot profits is the *smallest* trade size consistent with what leaked. If a bot can infer your trade is at least, say, a certain amount, it can sandwich profitably. Meanwhile the *upper* end of your trade range is basically irrelevant. In plain terms: it's the opposite of how most people assume privacy works, where hiding the biggest detail feels most important.

The paper also finds two more wrinkles. When several competing bots bid for the right to front-run you, the venue running that auction tends to scoop up all the winnings — the bots end up working for nothing. And if you hide the *direction* of your trade too, simple pre-trade front-running breaks down, but sneaky trades placed right after yours can still turn a profit.

The catch: this is mathematics, not a product. It assumes one specific style of exchange pricing (the formula behind the popular exchange Uniswap v2) with zero fees, and real platforms are messier. So don't read it as a promise that your wallet is safe or doomed today. Read it as a blueprint showing privacy engineers exactly where the line is — and how close 'mostly private' can sit to 'not private enough.'

Key Points
  • 'Sandwich attacks' are bots spotting your crypto trade and cutting in line to profit off it; keeping trades private is the main defense.
  • The researchers prove that only the *smallest* trade size a bot can guess matters — anything above a specific threshold still lets it profit.
  • With multiple bots competing, the auction venue tends to capture all the gains, and hiding your trade's direction blocks simple attacks but not follow-up trades.

Why It Matters

Sets a concrete bar for crypto wallets and exchanges — and warns that 'mostly private' may still cost you money.

📬 Get the top 10 AI stories daily