BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Flashbots Loses Around $20M in Innovative Cyber Attack: Insider Information Exploited by Hacker

Hacker exploits vulnerability in mev-boost relay to drain five MEV bots".

An innovative cyber attack has led to the loss of around $20 million by Flashbots, a developer of bots dedicated to mining MEV (maximum extractable value) to generate profits in Ethereum.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The incident occurred on Monday, April 3, and was reported by several prominent Ethereum developers, including Mudit Gupta and Sam Sun. “A user managed to drain five MEV bots by exploiting a vulnerability in the mev-boost relay,” Sun explained on Twitter.

However, it is important to note that no ETH was removed from the Flashbots organization itself. The stolen funds were spread across eight addresses, with three of them storing the majority of the stolen amount.

To do so, the hacker had to become a network validator beforehand. To that end, he deposited the necessary 32 ethers (ETH) on March 15. When it was his turn to propose a block as a validator, he had the opportunity to rearrange transactions in the way he needed for his attack.

Validators are not run on Flashbots software; they are part of the Ethereum protocol and run on the Ethereum core protocol software. To prevent similar attacks in the future, the Flashbots developer group released a patch that instructs relayers to publish the block to the Beacon network before returning to the proposer.

- Advertisement -

The Flashbots developer group reacted to the event by releasing a patch to prevent this type of attack. Broadly speaking, the patch instructs relayers, which are mediators between blocks and validators, to “publish the block to the Beacon network before returning to the proposer (and if it fails, not to return the content to the proposer at all).”

In addition to the release of this solution, Flashbots announced that it would publish a report on what happened in the next few hours.

The bots that Flashbots develops operate as high-frequency traders that use their resources to capture arbitrage opportunities on networks such as Ethereum. These bots are referred to as MEV-boost.

With solutions like MEV-boost, Flashbots allow Ethereum validators to capture and monetize transaction profits due to the insider information they possess about the current state of the network.

A “sandwich attack” is a technique that takes advantage of asset price volatility to produce a financial gain. The attacker buys or sells a large amount of an asset to move the price in his favor, and then performs a transaction to exploit someone else who is trading that asset. Finally, the attacker completes the sandwich by selling or buying back the asset at a favorable price and making a net profit.

As detailed by blockchain security and analytics account PeckShield, the stolen funds were spread across eight addresses, with three of them storing the most funds at the time of writing.

A brief analysis of the attack Mudit Gupta, a well-known Ethereum and Polygon developer, explained, “In this case, the validator is taking advantage of the fact that the MEV bot incurs a loss on the first sandwich transaction.”

“The vulnerability is due to a design flaw in Flashbots, which does not financially penalize the creator of the malicious transaction. This has led to a situation where the economic incentive is broken and only works thanks to a tacit agreement not to do wrong,” he explained.

In that sense, he detailed that the punishment for violating the rules (a fine of 1 ETH or about $1,800 USD) is less than the potential profit that can be made through manipulation.

Information on the MEV bot hacker’s address and the theft of millions of ethers is also provided.

Overall, Gupta says this situation highlights the limitations and risks of MEV on Ethereum. As MEV adoption increases, it is likely that more vulnerabilities will be discovered, and more attention and action will be required to prevent them, according to the specialist.

Read Next

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Dips Below $70K on Iran Invasion Plan Reports

Bitcoin fell below $70,000 on Thursday as reports emerged of U.S. military plans for...

Fenbushi Capital Founder Offers Bounty for Wallet Recovery

Venture capitalist Bo Shen is offering a 10-20% bounty for help recovering $42 million...

JP Morgan Holds $6,300 Gold Target, Raises 2026 Forecast

JP Morgan reaffirmed its Gold price target of $6,300 per ounce for year-end 2026...

Moulton Bans Staff from Using Political Prediction Markets

Rep. Seth Moulton (D-MA) has banned his entire congressional staff from trading on prediction...

US lawmakers introduce bill banning officials from prediction markets

Bipartisan lawmakers introduced the PREDICT Act to ban high-ranking federal officials and their families...

Must Read

5 Best Hacking eBooks for Beginners

In this article we present the 5 Best Hacking eBooks for beginners as ranked by our editorial teamWelcome to the world of hacking, where...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading