Sandwich Attacks on Base and Arbitrum: How Much MEV Risk Is Really Left in 2026
The sandwich that could not happen
Someone posted in a group recently in full panic: he had swapped a sizeable ETH position on Base and received noticeably less than the quote, and the replies were instantly full of "classic sandwich attack, you got MEV'd." I pulled the hash. It was not a sandwich. He had traded through a shallow pool at 12% slippage that a token's website had told him to set, and the pool had simply done exactly what that tolerance authorized. Nobody frontran him. He handed the difference over with a signature.
That story captures the modern confusion about MEV on rollups. The old nightmare — bots scanning a public memory pool, jumping in front of your trade, and dumping on you — is largely architecturally dead on Base and Arbitrum. But money is still lost to adjacent effects and, far more often, to settings that mimic an attack. Here is the accurate picture, because fear of the wrong threat makes you misprice the real ones.
Why the classic sandwich needs a mempool
A traditional sandwich requires three ingredients: seeing a victim's profitable trade before it executes, inserting an order ahead of it, and selling into it right after. On Ethereum mainnet that was historically possible because pending transactions sat in a public mempool where bots could watch, simulate, and bid for ordering priority. The trade was visible in advance and the order of execution was for sale.
Base and Arbitrum do not work that way today. Both send transactions to a single sequencer that orders them on a first-come, first-served basis and there is no public mempool of pending user transactions to frontrun. A bot cannot see your unconfirmed swap in a queue and leap ahead of it, because the queue is not public and the ordering is not auctioned transaction-by-transaction. The moment you understand this, half the "MEV protection" products marketed for L2 trading reveal themselves as insurance for a house that cannot catch fire in that room.
What is actually left
Removing simple sandwiches does not remove all MEV. The surviving forms are real but narrower:
- Backrunning. After a large public trade moves a price, anyone can trade immediately behind it. This profits from your price impact but does not make your fill worse — it helps the price recover, which can actually reduce divergence.
- JIT liquidity. Bots add liquidity around very large predictable swaps to skim fees, then remove it. This slightly changes fee economics, again without attacking your execution price.
- Low-liquidity pool manipulation. In tiny pools, a well-timed trade can move an oracle-dependent protocol or exploit a protocol that reads spot prices. This targets protocols, not routine swappers, and is why reputable lending markets use time-weighted prices.
- Cross-domain and settlement-time MEV. As rollups decentralize sequencing and shared sequencing layers arrive, ordering markets may re-emerge in new forms. This is a developing area, not an active threat to a normal user in 2026.
The dominant cause of bad fills on L2 remains the one in the opening story: price impact in shallow pools plus excessive slippage tolerance. The settings strategy is fully covered in the slippage tolerance guide — tolerance is permission for a worse price, and on permissionless pools there will always be someone willing to take exactly what you permit.
Mainnet vs Base vs Arbitrum: the honest risk table
| Risk | Ethereum mainnet | Base | Arbitrum |
|---|---|---|---|
| Classic mempool sandwich | Possible (mitigated by private routing) | Not possible via mempool | Not possible via mempool |
| Ordering transparency | MEV auctions | Single sequencer, FCFS | Single sequencer, FCFS |
| Backrunning / JIT | Common | Exists | Exists |
| Shallow-pool impact loss | Real | Real — top cause | Real — top cause |
| Cost of protection | Private RPC worth it | Mostly unnecessary | Mostly unnecessary |
The centralization caveat deserves a sentence: "no mempool sandwich" comes with a trust assumption that the sequencer cannot or will not manipulate ordering itself. That is a real decentralization discussion — and part of the broader risk model in the L2 security risks guide — but the practical execution risk for an individual trader today points elsewhere.
The protection list that actually matters
- Set tight slippage and raise grudgingly. 0.1% for stables, 0.5-1% for majors, 1-2% for volatile tokens, never near double digits unless you have a specific, verified reason. This single rule prevents nearly every "I got MEV'd" story I have reviewed.
- Check pool depth before sizing up. If your trade is a meaningful fraction of the pool's liquidity, the problem is impact, not bots. Split large trades over time or move to a deeper pool.
- Use routers with protected routing. Modern Uniswap routing and intent-based systems route around toxic flow and expose MEV-protected execution by default on these chains.
- Verify tokens on the explorer. Fee-on-transfer and pausable token contracts produce losses that feel like attacks. The explorer checks are in the Basescan guide.
- Ignore slippage instructions from token promoters. "Set 10-15% to buy" is not a technical requirement. It is documentation of how the contract or pool treats buyers.
- Use a private RPC only if it is free and convenient. Endpoint choice helps on mainnet and is harmless on L2; setup is in the RPC guide. Just never pay for "MEV insurance" on rollup trades without understanding what is insured.
How to read a suspicious receipt
When a fill looks wrong, diagnose before panicking. Open the transaction on the explorer and compare the quoted minimum-received amount with what actually arrived: a gap exactly at your tolerance, on a token with thin liquidity, is a self-inflicted slippage fill, not a frontrun. A genuine sandwich on a public-mempool chain shows three linked transactions — buy ahead, your trade, sell behind — wrapped around yours. On Base or Arbitrum you will essentially never see that triplet sandwiching a normal swap; when fill quality is poor, the receipt instead shows one transaction executing against a shallow pool.
Failed swaps deserve the same calm read: a revert costs gas but moves no tokens, and the causes are usually approvals, stale quotes, or token mechanics — the failed transaction guide works through them. A transaction that reverted cannot have been sandwich-robbed, which rules out another whole category of panic.
The bottom line
On Base and Arbitrum in 2026, you are not playing against mempool bots the way mainnet traders did in 2021 — the sequencer architecture quietly retired that opponent. You are playing against liquidity (or the lack of it) and against your own willingness to sign generous tolerances. Respect those two, verify tokens, use protected routing, and the MEV boogeyman stops being the thing to fear. The scary loss stories are still worth studying; most of them, read carefully, turn out to be ordinary trades against shallow pools with permissions left wide open.
Trade on Base / Arbitrum with Low Fees
Choose a trusted platform to swap, bridge, and trade on L2 networks.
Affiliate links — we may earn a commission at no extra cost to you.