Blockspace Forensics Consortium

MOCKUP · Data as of {to} · updated daily from Dune Logo
Blockspace ForensicsCONSORTIUM
Join
BNB Chain · MEV forensics

Every sandwich on BNB Chain, documented. Block by block.

An open effort by BNB Chain builders, validators, searchers and researchers. We document toxic MEV from public on-chain data, attribute it, and publish recommendations. Every number is public, every rule is versioned.

Sandwiches detected
…
Victim transactions
…
Victim trade volume
…
Gross attacker profit
…
{days} computed days, {from} to {to} · confirmed + probable · profit ≥ $1 · rules v0.1.0-draft
The trend

Every computed day, on the record.

One bar per UTC day, computed once the day has closed.

Sandwiches per computed dayconfirmed + probable · computed days only
View as table

ConfirmedThe back-run reverses the front-run within 1% at a profit, and the two legs share an actor.

ProbableProfitable, with one of those signals. Counted, and labelled as such.

Pattern onlyThe shape alone. Not counted anywhere on this site.

How it works

Every block, checked the same way.

Rules anyone can read, queries anyone can re-run.

01

Detect

Every block, every DEX pool. We look for the same-pool bracket: an attacker's front-run, a victim's swap, then the attacker's back-run.

02

Attribute

From the block's own structure: which builder built it, which validator sealed it, which address took the profit.

03

Publish

Every figure comes from a public query on Dune. Rules are versioned, and each sandwich records the version that caught it.

04

Recommend

Findings come with recommendations to builders, validators, the Alliance and wallets. We don't enforce them; the record shows whether they were followed.

Builder scorecard

Who builds the blocks that carry sandwiches.

Raw counts follow market share. The share of a builder's own blocks that carry a sandwich is the figure that compares.

Builder Blocks built Share of blocks Sandwiches Blocks with a sandwich

A block is attributed to the builder that paid for it: each builder's payment sits inside the block itself. Any builder named here can reply, and its reply will be shown next to its figures.

Full scorecard, with validators, on Dune →
Orderflow

Whose users get sandwiched.

Every swap is attributed to the app that built it: a wallet, a trading app, an aggregator or a DEX's own site. The app chooses the RPC that broadcasts the swap and the partners that route it.

…
of victim transactions came from automated single-pair accounts, not app users
…
came through a named app
…
had no app named: private or still-unidentified contracts
App Swaps Sandwiched Sandwiched per 10,000 swaps

The ten named apps with the most sandwiched swaps, sorted by rate. Apps are named only from a public source; integrator ids appear as written on-chain.

Every app on Dune →
Working alongside the Good Will Alliance

The Alliance sets the standard. We keep the record.

Two efforts, one goal. According to BNB Chain, the Good Will Alliance cut sandwich attacks by about 95%. We document what is left, in public.

BNB Good Will Alliance · since March 2025

The commitment

  • Ethical standards for block building on BNB Chain
  • A public list of MEV-protected builders
  • Validators accept blocks only from builders on the list
Blockspace Forensics Consortium

The record

  • Every block documented, every day, from public data
  • Named rates per builder, validator and app, with a right of reply
  • Recommendations to the Alliance, builders and validators, who decide what to act on
Recommendations

Recommended practice, role by role.

We have no power to enforce anything. We document what happens on-chain and recommend what should change; builders, validators, the Alliance and wallets decide what to do with it.

Builders

  1. Filter sandwich and front-running bundles out of every block.
  2. Tag blocks and declare bid addresses, so attribution is exact.
  3. Publish a response when a finding concerns you.

Validators

  1. Accept bids only from builders with a clean record.
  2. When you build a block yourself, build it clean.
  3. Publish the list of builders you accept.

Searchers

  1. Don't submit sandwich or front-running bundles.
  2. Arbitrage, liquidations and back-runs are out of scope.
  3. Respond when an address you control is documented.

Wallets & dApps

  1. Route swaps through MEV-protected endpoints by default.
  2. Default to tight, sensible slippage.
  3. Tell users when a trade was sandwiched.
Recommendations v0.1 · draft
Members

Members.

Members have joined the effort. Each one contributes to the analysis as far as its technical means allow, and to the fight against sandwich attacks and toxic MEV. Being a member changes nothing in how anyone is documented.

The member list is published at launch.

Open by default

Don't take our word for it.

Every number on this site traces back to raw chain data through public queries. If a figure is wrong, you can show us exactly where.

Our commitmentEverything in the open. No side taken. Only facts.

dex.trades · bnb.blocksraw chain data→ net flowsper tx, per pool→ bracketsdetection, tiers→ attributionbuilder, validator, app→ this pagedaily, after UTC close

Public queries

The whole pipeline lives on Dune, readable and re-runnable.

Open the dashboard →

Versioned rules

Rule changes are numbered and dated. Old findings keep the version that produced them.

Read the methodology →

Disputes, in public

Think a finding is a false positive? File it. The case and the decision are published.

Dispute channel opens at launch
Contribute

Help keep the record.

Share data, review the method or challenge a finding. Builders, validators, searchers, wallets, dApps and researchers are all welcome.

Start with the data on Dune Membership requests open at launch