# MEV shield

why do we need mev shield, and how does it work?

_Source: https://beta.taostats.io/docs/concepts/chain-runtime/mev-shield_

_Last reviewed: 2026-09-15_

why do we need mev shield, and how does it work?

## MEVbots explained

Maximum Extractable Value (MEV) bots scan the chain and look for transactions to "steal" assets from.  There have been a number of approaches to hinder these Bots from operating on chain.

When a transaction moves through a liquidity pool, there is an opportunity for slippage: where another transaction precedes your transaction, changing the price and affecting the amount of tao/alpha you receive.

> [!NOTE]
> Example
>
>   An isolated transaction will have a small price impact due to the liquidity pool
>
>   ![Diagram of a single token swap through an AMM subnet pool, with input tau, pool tau/alpha reserves, output alpha, and a resulting price-impact percentage](https://beta.taostats.io/images/docs/concepts/taostats-mev-swap-price-impact-diagram.png)
>
>   But a large transaction in front of this one adds slippage:
>
>   ![Diagram decomposing an AMM swap's adverse execution into price impact plus slippage caused by a large front-running transaction](https://beta.taostats.io/images/docs/concepts/taostats-mev-slippage-frontrun-diagram.png)
>
>   In this example, 4% of the transaction is lost to slippage.
>
>   This is what the MEV bots do.

## First fix: Limits

All transactions should set a slippage limit.  This means - "hey, the price is x, and I am ok with a change of y% for the transaction."

The slippage limit should be small - a 4% slippage limit in the example above cost 20 alpha (\~ 2 tao).  For high liquidity subnets, you can be well below 1%.

### The MEV bots calculate their MAX extraction on every transaction

If your limit is very loose, the bot may decide to attack your transaction.

If you have no limit set:  The MEV bots can extract as much as they want.

![Dark-themed transaction log table with buy/sell pills, entity, alpha amount, tao value, per-unit price, percentage, and truncated wallet address columns](https://beta.taostats.io/images/docs/concepts/taostats-mev-transaction-log-table.png)

## MEVShield

A tight limit price should be enough to stop MEV bots. MEV shield goes further: it hides your transaction until it is in a block, so there is nothing to front-run.

How it works:

1. Each block producer publishes a fresh **ML-KEM-768** public key every block. The chain exposes the key to use as `NextKey`: the key of the producer two blocks ahead.
2. Your wallet signs your real transaction (for example, a stake), then encrypts the whole signed transaction to `NextKey` with ML-KEM-768 and **XChaCha20-Poly1305**.
3. The wallet submits the ciphertext in a wrapper call, `submit_encrypted`. Anyone watching the transaction pool sees only the wrapper, not what's inside.
4. The block producer who holds the matching private key decrypts your transaction and includes it in the block it produces.

### Advantages:

By encrypting the transaction, the MEVBot cannot see what you have done, and therefore cannot schedule a transaction in front of your trade.

### Disadvantages

Each transaction using MEV shield must be signed twice:

* Sign the transaction
* Sign the encryption wrapper.

Taostats (and other providers) can sign the encryption wrapper for you, so you only enter your password once.

![Transaction confirmation panel with two checkboxes for enabling MEV shield protection and delegating submission, plus a Confirm button](https://beta.taostats.io/images/docs/concepts/taostats-mev-shield-confirm-dialog.png)

### Why does Taostats disable MevShield for transactions  `<1` tao?

For transactions `<1` tao, you are not likely going to be mevved - the potential gain for the attackers is too small compared to the risk.

### Why does taostats disable MevShield for root stakes?

Root staking has no price impact or slippage you cannot be mevved on a root transaction - so no need for 2 signatures.
