How Does a Solana Bot Exploit MEV for $30M Profit?

In the endlessly evolving world of cryptocurrencies, an audacious Solana-based bot known as “arsc” has swiftly advanced to notoriety. This ingenious program has leveraged a technique called “sandwich attack” to pilfer approximately $30 million from Solana users within just two months. The operation centers on a cunning exploitation of maximal extractable value (MEV), a concept referring to the profit a miner can make through the inclusion, exclusion, or reordering of transactions within a blockchain block. Bots like “arsc” exploit this by essentially cutting in line. They strategically position a user’s transaction amidst two they control, facilitating the purchase of crypto at lower than market prices and the subsequent immediate sale at a higher rate, all within the span of a single block.

This sophisticated scheme has been traced back to a few key wallets, including one particularly large cache purportedly used for cold storage. Housing over $19 million, its assets are predominantly in Solana’s SOL and Circle’s USD Coin (USDC). Besides cold storage, there’s another hive of activity – a wallet engaging continuously in decentralized finance (DeFi) processes, shrewdly converting SOL to USDC. The ceaseless churn of these conversions is part of a grander strategy to veil the bot’s manipulations from the wary eyes of researchers and users alike.

Tracking the Trails of MEV Bots

In the dynamic panorama of digital currencies, a Solana-based bot nicknamed “arsc” has surged to infamy. It masterfully employs a “sandwich attack” to usurp around $30 million from users on the Solana network over a mere two months. By exploiting a niche known as maximal extractable value (MEV), it profits by manipulating the sequence of transactions in a blockchain block.

“arsc” intrudes into the transaction queue, sandwiching an unsuspecting user’s trade between its own. This ploy allows the bot to buy cryptocurrency cheaply and flip it immediately at a higher price in one block, making an instant profit.

Investigators have linked the scam to several wallets, with one holding a staggering $19 million – purportedly a cold storage trove, rich in Solana’s SOL and USD Coin (USDC) from Circle. Another wallet under scrutiny shows relentless DeFi activity, constantly trading SOL for USDC. This frenzy masks the bot’s activities, keeping the operation under the radar of researchers and Solana participants.

Explore more

Ethereum Tests Glamsterdam Upgrade Amid Market Volatility

The activation of the Glamsterdam upgrade on the Sepolia testnet marks a critical phase in Ethereum’s infrastructure scaling as the network tests a gas limit increase from 60 million to 200 million. This substantial expansion of the gas limit represents a calculated gamble on the robustness of current hardware, aimed at accommodating a new wave of high-throughput decentralized applications. While

How to Design and Optimize AI Prompts for Production

The shift from experimental chatbots to high-scale enterprise intelligence systems in 2026 has transformed prompt engineering from a creative writing exercise into a disciplined branch of software engineering. The most effective production prompts use structural separation to distinguish between trusted system instructions and untrusted content from user inputs or retrieved documents. When an application processes thousands of model calls against

What Are the Best Email Marketing Tools for SMBs in 2026?

Small businesses often choose Constant Contact because it offers an extensive library of templates and specialized tools for managing event registrations and ticketing directly through emails. However, the broader landscape of digital outreach has shifted significantly, transforming email from a simple messaging tool into a sophisticated infrastructure for revenue growth and long-term customer retention. In 2026, the success of a

EY Breach Exposes Goldman Sachs and Man Group Client Data

Administrative IT tickets used for routine tax services inadvertently served as a repository for sensitive client data that was eventually stolen by hackers. This security failure at Ernst & Young (EY) has sent ripples through the financial sector, as it compromised the personal information of high-net-worth individuals associated with Goldman Sachs and the London-based hedge fund Man Group. While these

New Phishing Campaign Impersonates AI Tools to Steal MFA Codes

The campaign exploits the established trust that advertising agencies place in AI tools to bypass multi-factor authentication protocols that were previously considered secure. This sophisticated operation, identified in late 2026, represents a significant shift in the threat landscape, moving away from generic banking lures and toward the highly specialized tools used by modern marketing professionals. By impersonating platforms such as