Skip to content

Lesson 6 · 5 min · Advanced

Spot the bug: front-running and MEV

On this page

Spot the bug — front-running / MEV

MEV (Maximal Extractable Value) is value extractable from transaction ordering. A searcher or validator can see your pending transaction in the mempool and insert their own before it (front-running) or after it (back-running), profiting at your expense. Sandwich attacks (front-run + back-run around a swap) are the classic.

A sandwich around your swap

mempool: your swap is visibleblock order1 · searcher buys first(front-run)2 · your swap fillsat a worse price3 · searcher sells after(back-run)price upsearcher profits the differencethe fix: minOut, set in your transactionyour swap reverts if it would get less
The searcher sees your pending swap, buys ahead of it to push the price up, lets your swap fill at the worse price, then sells. A minOut slippage limit makes your swap revert instead of filling that badly.

Vulnerable swap (front-runnable)

Click the line you think is the bug
Vulnerable swap (front-runnable)
These are toy snippets

Real audit work involves far more: privilege analysis, oracle manipulation, cross-contract interactions, gas-griefing, and the interaction of multiple “individually safe” functions. The snippets here teach pattern recognition for the four most famous classes; they don't make you an auditor.

How this connects to the rest of NodeScholar

Smart contracts are the substrate for DeFi and DAOs (most of the attacks in the DAOs unit are smart-contract bugs), and they underlie the cross-chain bridges in the Cross-chain Lab. The security unit covers the broader risk mindset.

Key takeaways

A one-page summary of Smart Contracts — Spot the Bug. Print it for quick reference.

  • A smart contract is code deployed to a chain that executes automatically when called; the contract address holds state and code.
  • Solidity (Ethereum and EVM chains) is the dominant smart-contract language: state variables, functions, modifiers, and events.
  • The "spot the bug" snippets cover the four classic vulnerability classes: reentrancy, integer overflow (pre-0.8), access control, and front-running/MEV.
  • Reentrancy — a callback re-enters the contract before state updates settle — is the most famous class (the DAO hack, 2016).
  • Audits, formal verification, and battle-tested libraries (OpenZeppelin) reduce but never eliminate risk; immutability means bugs are forever.
  • Smart contracts are the substrate for DeFi, DAOs, NFTs, and most of what makes crypto programmable — and most of what makes it dangerous.

Unit check

80% to complete this unit
5 questions

Pass the unit check (4 of 5) to complete this unit.

Educational only, not financial or legal advice.