When you stake into a subnet, or sell alpha back to TAO, your transaction trades against a liquidity pool. That makes it visible while it waits to be included in a block, and a visible trade can be front-run. MEV Shield is how taostats hides your transaction until it is already in a block. This post covers what it does, what you will see when you stake, and when it turns itself off.
The problem in two minutes
Trading through a pool always moves the price. Part of that is price impact, which is predictable from the size of your trade and the depth of the pool. The rest is slippage from other trades: between the moment you submit and the moment you land, someone else may stake or unstake in the same pool and shift the price.
Usually that is a coincidence. Sometimes it is not. An MEV bot that watches pending transactions can spot your stake, place its own trade just ahead of yours and take a profit from the price move your trade causes. The result is a worse fill for you and a gain for the bot.
The idea is simple: if bots cannot read your transaction, they cannot trade ahead of it. In practice that takes four steps.
- A fresh public key every block. Each block producer publishes a new ML-KEM-768 public key every block, and the chain exposes the key for the producer two blocks ahead as
NextKey. - Your wallet signs, then encrypts. It signs the real transaction, for example a stake, then encrypts the whole signed transaction to
NextKeyusing ML-KEM-768 and XChaCha20-Poly1305. - Only the wrapper is public. The ciphertext is submitted inside a wrapper call named
submit_encrypted. Anyone watching the transaction pool sees the wrapper and nothing about what is inside. - The producer decrypts and includes it. The block producer that holds the matching private key decrypts your transaction and includes it in the block it produces.
The cost is an extra signature. The transaction itself has to be signed, and so does the encryption wrapper. How much of that you notice depends on the mode you pick.
When you confirm a stake, unstake or swap that can be shielded, you will see the protection summarised and can change it. There are three choices.
This is the recommended option. Your wallet signs the transaction once, and taostats seals it and submits it on your behalf, so you enter your password a single time. It is the fastest and simplest way to be protected.
Your wallet encrypts the transaction itself and submits the shield wrapper directly on-chain, without taostats in the middle. You sign both the transaction and the wrapper, and the flow waits until the block is finalised, so it takes longer. It is not offered with hardware wallets.
The transaction is submitted as it is, with no protection from front-running. It can be reasonable for small amounts, where there is little for a bot to gain, but it is a choice, not a default for large trades.
Not every transaction needs protection, and asking for a second signature when there is nothing to protect would only add friction. taostats turns shielding off, or leaves it off by default, in three situations.
- Root staking. Staking to the root subnet uses TAO only and goes through no pool, so there is no price impact and no slippage to exploit. The confirmation shows "MEV protection unnecessary".
- Small amounts. By default, shielding is on for stakes above τ1 and off below it, because the potential gain for an attacker is too small to be worth the trouble. You can still switch it on yourself.
- Moves that are not trades. Sending TAO and transferring alpha to another wallet are not swaps through a pool, so they do not use the shield at all.
It is worth being precise about the limits, so that it is not asked to do a job it was not built for.
- It does not remove price impact. Your trade still moves the pool, and you still receive less than the quoted price implies.
- It does not replace a slippage limit. If your limit is very loose, a bad fill is still possible from ordinary price movement.
- It does not hide your wallet's history. Once a transaction is in a block, it is as public as any other.
The documentation has a full page on MEV Shield, including why bots target loose slippage limits, and another on price impact and slippage with the underlying formulas. If you are new to how subnet prices work, is a good companion to this post.



