Documentation / Concepts Bittensor / Chaîne et Runtime
MEV shield
Dernière vérification le 2026-09-15
why do we need mev shield, and how does it work?
MEVbots explained
Maximum Extractable Value (MEV) bots scan the chain and look for transactions to "steal" assets from. There have been a number of approaches to hinder these Bots from operating on chain.
When a transaction moves through a liquidity pool, there is an opportunity for slippage: where another transaction precedes your transaction, changing the price and affecting the amount of tao/alpha you receive.
First fix: Limits
All transactions should set a slippage limit. This means - "hey, the price is x, and I am ok with a change of y% for the transaction."
The slippage limit should be small - a 4% slippage limit in the example above cost 20 alpha (~ 2 tao). For high liquidity subnets, you can be well below 1%.
The MEV bots calculate their MAX extraction on every transaction
If your limit is very loose, the bot may decide to attack your transaction.
If you have no limit set: The MEV bots can extract as much as they want.
MEVShield
A tight limit price should be enough to stop MEV bots. MEV shield goes further: it hides your transaction until it is in a block, so there is nothing to front-run.
How it works:
- Each block producer publishes a fresh ML-KEM-768 public key every block. The chain exposes the key to use as
NextKey: the key of the producer two blocks ahead. - Your wallet signs your real transaction (for example, a stake), then encrypts the whole signed transaction to
NextKeywith ML-KEM-768 and XChaCha20-Poly1305. - The wallet submits the ciphertext in a wrapper call,
submit_encrypted. Anyone watching the transaction pool sees only the wrapper, not what's inside. - The block producer who holds the matching private key decrypts your transaction and includes it in the block it produces.
Advantages:
By encrypting the transaction, the MEVBot cannot see what you have done, and therefore cannot schedule a transaction in front of your trade.
Disadvantages
Each transaction using MEV shield must be signed twice:
- Sign the transaction
- Sign the encryption wrapper.
Taostats (and other providers) can sign the encryption wrapper for you, so you only enter your password once.
Why does Taostats disable MevShield for transactions <1 tao?
For transactions <1 tao, you are not likely going to be mevved - the potential gain for the attackers is too small compared to the risk.
Why does taostats disable MevShield for root stakes?
Root staking has no price impact or slippage you cannot be mevved on a root transaction - so no need for 2 signatures.